The IPtables crowdsec_blacklists & crowdsec6_blacklists get empty after some time thus blocking is not reliable and very temporary. The IPtables are filled after restart of crowdsec_firewall service but IPs last only few minutes (10-20 minutes) then the tables get empty until next scheduled CAPI pull (every 2 hours). So the tables are empy (crowdsec not blocking anything) for most of the time!
EDIT: Sorry, I forgot to mention that this issue is related to crowdsec on pfSense 2.8.1.
The IPtables crowdsec_blacklists & crowdsec6_blacklists get empty after some time thus blocking is not reliable and very temporary. The IPtables are filled after restart of crowdsec_firewall service but IPs last only few minutes (10-20 minutes) then the tables get empty until next scheduled CAPI pull (every 2 hours). So the tables are empy (crowdsec not blocking anything) for most of the time!
EDIT: Sorry, I forgot to mention that this issue is related to crowdsec on pfSense 2.8.1.