Netgate SG-1000 microFirewall

Author Topic: DNSBL Not Blocking Ads or Yahoo  (Read 276 times)

0 Members and 1 Guest are viewing this topic.

Offline kidseven112002

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
DNSBL Not Blocking Ads or Yahoo
« on: December 27, 2017, 11:32:58 am »
Can't seem to get DNSBL working properly; configs attached. Pulled the updated ad list that isn't working nor is my yahoo.com custom list working. Please review and let me know what I'm doing wrong.

Offline BBcan177

  • Moderator
  • Hero Member
  • *****
  • Posts: 2601
  • Karma: +810/-5
    • View Profile
    • Click for Support
Re: DNSBL Not Blocking Ads or Yahoo
« Reply #1 on: December 27, 2017, 05:06:14 pm »
Settings look ok... Are you sure that your LAN devices have their DNS settings configured to use pfSense DNS Only?  If you have other DNS Servers configured then it will bypass DNSBL.

From pfSense you can confirm that a domain is blocked via:
Code: [Select]
host -t A example.com
And on Windows use a
Code: [Select]
nslookup example.com
If the Domain is filtered via DNSBL, it will reply with the DNSBL VIP Address that you configured.
"Experience is something you don't get until just after you need it."

 | http://pfblockerng.com | Twitter @BBcan177  | #pfBlockerNG |

Offline kidseven112002

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Re: DNSBL Not Blocking Ads or Yahoo
« Reply #2 on: January 04, 2018, 11:59:55 am »
Thanks for the config verification, but still no go. Should my host DNS be set to the 10.10.10.1 address? I have them pulling the DNS from pfsense DHCP. Still no luck...

Offline RonpfS

  • Hero Member
  • *****
  • Posts: 705
  • Karma: +96/-2
    • View Profile
Re: DNSBL Not Blocking Ads or Yahoo
« Reply #3 on: January 04, 2018, 02:26:32 pm »
Your host has to use pfsense+DNSBL DNS Resolver service.
From a PC I get
Code: [Select]
C:\Users\User1>nslookup steepto.com
Server :   pfsense.local
Address:  172.xx.xxx.254

Nom :    steepto.com
Address:  10.10.10.1
« Last Edit: January 04, 2018, 03:44:45 pm by RonpfS »
2.3.5-RELEASE-p1 (amd64)
Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
pfBlockerNG 2.1.2_2/Dev, suricata 4.0.1_1

Offline kidseven112002

  • Newbie
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Re: DNSBL Not Blocking Ads or Yahoo
« Reply #4 on: January 04, 2018, 03:23:03 pm »
That was it!! Thank you ;D