pfblockerNG

Blocking Tor with pfBlockerNG in pfSense

I came across few hosts in my pfsense firewall logs hammering my home webserver through Tor. While I understand Tor’s network value, I do not want middle nodes or exit nodes hitting my home webserver for any reasons; I use it for basically media streaming. So, I decided to “block” T0r and pfBlockerNG comes once again to the rescue!

Searching online for a Tor Nodes list (being lazy as usual) I found Dan at www.dan.me.uk offering nice full list including more than just Tor exit nodes. The list is flagged so that you can write your own scripts around it and selectively grab Tor relays and exit nodes IPs as you wish. Since most of the work has already been done by Dan, I’m using his list to create my own IPv4 and IPv6 Tor IP banlists for pfblockerNG.

From Dan’s website, you can fetch https://www.dan.me.uk/torlist/ (FULL) or https://www.dan.me.uk/torlist/?exit (EXIT only) for a list of ips only, one per line – updated every 30 minutes. Ideal for constructing your own tor banlists. Please note that https://www.dan.me.uk/torlist/ can be fetched ONCE every 30 minutes and visiting that link will prevent you from accessing the list again until after the 30 minutes grace period. I don’t blame him!

Umm… You can only fetch the data every 30 minutes – sorry. It’s pointless any faster as I only update every 30 minutes anyway.
If you keep trying to download this list too often, you may get blocked from accessing it completely.
(this is due to some people trying to download this list every minute!)

Anyways, I created two (2) lists off of Dan’s to separate IPv4 and IPv6 Tor Nodes IPs and use them in pfblockerNG; that’s what I will be sharing with you today in case they are of use to you too.

My lists do not make any distinction between Tor Relays and Exits; it simply aggregates them into a block all Tor Nodes IPs, updated hourly:

IPv4 Tor Nodes IPs: https://unlockforus.com/pfblockerng/tor_nodes_ipv4.txt
IPv6 Tor Nodes IPs: https://unlockforus.com/pfblockerng/tor_nodes_ipv6.txt

Feel free to use them in your pfBlockerNG and please, be aware that fetching these lists more than ONCE PER HOUR only increases the load on the server hosting it with no benefit to anyone.

Blocking Tor with pfBlockerNG in pfSense

In PfSense, assuming that you have already installed and enabled pfBlockerNG, browse to Firewall => pfBlockerNG

Create new Alias under IPv4 and IPv6 (if IPv6 traffic is allowed in your network) as follows:

pfblockerng_tor_nodes_ipv4

Creating the new Alias is self explanatory:

Alias Name: Tor Nodes IPv4
List Description: UnlockForUs full list of all TOR nodes sourced from www.dan.me.uk/torlist/
IPv4 Lists: AUTO ON https://unlockforus.com/pfblockerng/tor_nodes_ipv4.txt TorNodesBlockIPs_ipv4
List Action: Deny Both (or other if you wish to allow outgoing traffic, etc.)
Update Frequency: Every Hour
Enable Logging: Enable

Blocking Tor with pfBlockerNG in pfSense

Scroll down and click Save to commit your settings and finally browse to Firewall => pfBlockerNG => Update TAB to force a manual reload.

pfblockerng_force_update

Repeat the steps above to create your IPv6 Tor Nodes IPs alias if also needed:

Alias Name: Tor Nodes IPv6
List Description: UnlockForUs full list of all TOR nodes sourced from www.dan.me.uk/torlist/
IPv4 Lists: AUTO ON https://unlockforus.com/pfblockerng/tor_nodes_ipv6.txt TorNodesBlockIPs_ipv6
List Action: Deny Both (or other if you wish to allow outgoing traffic, etc.)
Update Frequency: Every Hour
Enable Logging: Enable

Cheers!

Related Post

Thunar Split View for Linux Lite and others Thunar, the default Xfce file manager, doesn't support split view. But thanks to Xfce user Román who decided to take this issue into his own hands, an...
Lite Sources – Easily switch Linux Lite Repo... It seems to happen time and time again; some users report issues when checking for new updates in Linux Lite. There is an array of events that could c...
Fix System Settings Docky icon displayed as blueto... Docky, like Plank or Cairo Dock, is an advanced shortcut bar that sits at the edges of your screen. It provides easy access to some of the files, fold...

Leave a Reply