pfsense:pfblockerng:add_dnsbl_feeds
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:pfblockerng:add_dnsbl_feeds [2021/02/07 17:59] – peter | pfsense:pfblockerng:add_dnsbl_feeds [2021/02/07 18:06] (current) – [Forcing DNSBL feed updates] peter | ||
---|---|---|---|
Line 41: | Line 41: | ||
If we go back to the Feeds, a category (group) recommend adding is hpHosts. | If we go back to the Feeds, a category (group) recommend adding is hpHosts. | ||
- | After clicking the **+** next to the hpHosts category, you are taken to a DNSBL feeds page with all of the feeds under that category pre-populated. | + | After clicking the **+** next to the hpHosts category, you are taken to a DNSBL feeds page with all of the feeds under that category pre-populated. |
+ | |||
+ | All of the feeds in the list will initially be in the **OFF** state. | ||
+ | |||
+ | You can go through and enable each one individually or you can click **Enable All** at the bottom of the list. | ||
{{: | {{: | ||
Line 61: | Line 65: | ||
===== Other items worth mentioning ===== | ===== Other items worth mentioning ===== | ||
- | If you take a look at the **Malicious** category, you will notice that some feeds have selectable options, such as such as the SANS Internet Storm Center feeds (bullet points). I personally recommend switching the feed from ISC_SDH (high) to ISC_SDL (low) as the high feed has under 20 entries and the low feed includes the high feed. | + | If you take a look at the **Malicious** category, you will notice that some feeds have selectable options, such as such as the SANS Internet Storm Center feeds (bullet points). |
- | I addition, I haven’t seen many false positives when using the expanded | + | <WRAP info> |
+ | **NOTE: | ||
- | Take note of the door-arrow graphic icons next to several feeds. | + | In addition, not many false positives have been noticed when using the expanded (low) list. |
+ | </ | ||
+ | |||
+ | Take note of the door-arrow graphic icons next to several feeds. | ||
+ | |||
+ | * The door-arrow graphic means the feed is a subscription feed, which at the very least means you need to register for it. | ||
+ | * Some subscription feeds also have a fee associated with them. | ||
+ | * Subscription feeds can have a lower false positive rate and are typically updated on a more frequent basis. | ||
+ | * You will see selectable options and subscription feeds throughout the DNSBL feeds so it is important to understand what these graphics mean. | ||
{{: | {{: | ||
Line 110: | Line 123: | ||
To force the changes, go over to the **Update** tab within pfBlockerNG. | To force the changes, go over to the **Update** tab within pfBlockerNG. | ||
- | Heed the warning and make sure you are not going to run the updates near the time your cron job would automatically run. If the countdown timer is less than 5 minutes, | + | <WRAP important> |
+ | **WARNING: | ||
+ | |||
+ | If the countdown timer is less than 10 minutes, | ||
+ | |||
+ | </ | ||
{{: | {{: | ||
- | Assuming you are good on the time, go ahead and click the **Run** button. | + | Assuming you are good on the time, go ahead and click the **Run** button. |
+ | |||
+ | * Progress | ||
+ | * pfBlockerNG is smart enough to check for and eliminate duplicate DNS (# Dups) entries between the lists. | ||
{{: | {{: |
pfsense/pfblockerng/add_dnsbl_feeds.1612720789.txt.gz · Last modified: 2021/02/07 17:59 by peter