Archive > 22.7 Legacy Series
unbound blocklists not downloading in 22.7.11
jaydub:
My production OPNsense ver 22.7.11 no longer is blocking porn and other things because the blocklists are not downloading. From the error logs:
2023-01-24T16:19:40-07:00 Error unbound blocklist download : unable to download file from https://raw.githubusercontent.com/chadmayfield/pihole-blocklists/master/lists/pi_blocklist_porn_top1m.list (error : HTTPSConnectionPool(host='raw.githubusercontent.com', port=443): Max retries exceeded with url: /chadmayfield/pihole-blocklists/master/lists/pi_blocklist_porn_top1m.list (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x802615b20>: Failed to establish a new connection: [Errno 8] Name does not resolve')))
cookiemonster:
As per the error, have you been able to verify the name resolves from your firewall?
jaydub:
Hi Cookie,
Yes, when I put that address in a browser it brings up the list of site names so the dns is working. It had been working before 22.7 but I don't know the exact version that broke it.
jaydub:
I also should note that it is just not that one list, it is every list I have selected that gives that same error. I can go to any of these addresses in a browser and it shows me the text lists. Here are the ones I have selected and failed:
https://raw.githubusercontent.com/chadmayfield/pihole-blocklists/master/lists/pi_blocklist_porn_top1m.list
https://blocklistproject.github.io/Lists/alt-version/torrent-nl.txt
https://blocklistproject.github.io/Lists/alt-version/scam-nl.txt
https://blocklistproject.github.io/Lists/alt-version/redirect-nl.txt
https://blocklistproject.github.io/Lists/alt-version/ransomware-nl.txt
https://blocklistproject.github.io/Lists/alt-version/porn-nl.txt
https://blocklistproject.github.io/Lists/alt-version/piracy-nl.txt
https://blocklistproject.github.io/Lists/alt-version/malware-nl.txt
https://blocklistproject.github.io/Lists/alt-version/gambling-nl.txt
franco:
> Name does not resolve
That clearly tells us the firewall cannot look up any IP so all would naturally fail... but perhaps all work from your client without an issue.
You can test quite easily via Interfaces: Diagnostics: DNS Lookup.
Cheers,
Franco
Navigation
[0] Message Index
[#] Next page
Go to full version