Pfsense on Blue Iris PC or Separate PC?

bugsysiegals

Getting the hang of it
Joined
Nov 1, 2018
Messages
179
Reaction score
27
Location
Racine, WI
Thanks for sharing the video, I’ll have to see if there’s anything new I can learn.
 

davej

Getting the hang of it
Joined
Apr 25, 2014
Messages
279
Reaction score
69
Just keep a backup of your pfSense config (Diagnostics > Backup/Restore), I do this before I make any changes where I might fack something up as well.

Then if something happens, repair the faulty device/drive, reinstall pfSense, reload config. I already had to do this once...
Thanks for the above hint. I am slowly getting pfSense figured out. Last night I put a temporary block rule on my BI pc and am watching the firewall log as Windows 10 tries desperately to call home.
 

davej

Getting the hang of it
Joined
Apr 25, 2014
Messages
279
Reaction score
69
I am now playing with pfBlockerNg DNSBL and am wondering how I could add a local Hosts file to the list of DNSBL feeds? I don't know if I can put that in the BI www folder or if I can put it on the pfSense machine? (EDIT-- I can do either)
 
Last edited:

concord

Getting comfortable
Joined
Oct 24, 2017
Messages
665
Reaction score
741
Maybe an easier way is to create a github.com account, put put your hosts.txt there and add it pfBlockerNg DNSBL list.

Been a while since I last looked a pfSense, not sure if it can access a local file from pfBlockerNg DNSBL, but you try SSHing or log in locally into your box, see if you can create a myhosts.txt under /var/db/pfblockerng/deny/ or something, then add it to your DNSBL lists...
 

davej

Getting the hang of it
Joined
Apr 25, 2014
Messages
279
Reaction score
69
Yeah, there seems to be a way to make it read a local file, but my BI machine is always running, so I went to the Windows options and enabled IIS and can just plop the text file into the c:\inetpub\wwwroot folder. If I add that location to the the DNSBL feeds it should be able to read that file off of my BI machine (port 80 not 81). I guess the effect will be identical to having that HOSTS file installed on every computer.
 
Top