Threat intelligence on OPNsense
Improve your security posture on OPNsense with three different threat intelligence packages. Register on our TIP for the free package, or activate Plus or Premium to unlock more, right on the edge of your open-source firewall.
- 2,500+Intelligence sources
- 20 minFastest update interval (Premium)
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds OPNsense integration?
The Q-Feeds integration adds curated cyber threat intelligence to your open-source OPNsense firewall through a native plugin, available from the official OPNsense repository. The plugin imports Q-Feeds lists of malicious IP addresses as firewall aliases, which you enforce in your firewall rules. If Unbound is your DNS resolver, the plugin can also register Q-Feeds domain feeds as an Unbound blocklist, so lookups for malicious domains are blocked too.
The aliases update automatically, so traffic to and from known-bad hosts, botnets and command-and-control servers is blocked at the edge, with no manual list management required. Q-Feeds combines commercial, OSINT and governmental sources for broad, reliable coverage.
With free, Plus and Premium packages, the integration scales from a free proof of concept to real-time protection on production firewalls.
Our promise
Enriching your firewall with threat intelligence will strengthen your security even more, right on the edge of your network.
- Curated best-in-class threat intelligence
- Always up to date gathered and selected from over 2500 sources
- Improve security for both OT & IT
How to use Q-Feeds with OPNsense
We've built a convenient plugin, publicly available via the official OPNsense repository. Follow our integration manual to get up and running.
OPNsense setup guideOSINT vs Paid (Commercial) feeds
The difference between OSINT and Paid (Commercial) feeds mainly lies in the source of the data, not in how we handle it.
OSINT feeds are gathered from publicly available sources, such as community projects, research groups, open lists, news articles, and fora.
Paid feeds come from professional cybersecurity vendors who continuously collect and enrich threat data using proprietary systems.
At Q-Feeds, we apply the same rigorous process to both types of feeds. Every dataset goes through quality checks, priority scoring, and false positive validation before it's published. This ensures that regardless of the source, all indicators in our platform meet the same standard of accuracy and reliability.
In short: OSINT and Commercial feeds differ by origin, but Q-Feeds ensures both are equally verified and trustworthy.
External Attack Surface Management
EASM is part of the Threat Intelligence Portal and is included with a Plus or Premium licence.
Open ports
We have an on-demand and scheduled scanner available which scans for open ports and sends you an email if something has changed.
Web vulnerabilities
Check your infrastructure for potential web vulnerabilities, also both on-demand and scheduled.
Network vulnerabilities
Detect network vulnerabilities on your external IP addresses.
Similar domains
Our scanner checks for similar domains and if they resolve. Similar domains might be used for phishing campaigns.
Reverse DNS
Check if certain IP addresses are linked to domain names. This supports you to determine the origin of connections.
Stolen credentials on the dark web
Monitor the dark web for stolen credentials and take appropriate action.
How to add threat intelligence to OPNsense in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and choose the package that fits your needs.
Install the Q-Feeds plugin
Install the Q-Feeds plugin from the official OPNsense repository, following our integration manual.
Connect your feed
Enter your API key so the plugin creates firewall aliases from your Q-Feeds intelligence and keeps them updated. Enable Register domain feeds as well if you want Unbound DNS to block malicious domains.
Enforce in a firewall rule
Reference the Q-Feeds alias in a firewall rule to block malicious traffic immediately.
Prefer a different platform?
Threat intelligence feeds
Curated IP, URL and domain feeds for your whole stack.
Fortinet
Add IP, URL and domain threat feeds to your FortiGate with native External Connectors.
Palo Alto
Palo Alto firewalls can be hardened with our threat intelligence.
Sophos XGS
Enhance the Sophos XGS firewall with our threat intelligence.
Frequently asked questions about the OPNsense integration
How does Q-Feeds work with OPNsense?
A native Q-Feeds plugin imports curated malicious IP intelligence as firewall aliases, which you reference in OPNsense firewall rules to block known-bad traffic automatically. Optionally, it registers Q-Feeds domain feeds with Unbound DNS to block lookups for malicious domains.
Where do I get the OPNsense plugin?
The plugin is publicly available in the official OPNsense repository. Our integration manual walks you through installing and configuring it.
How often is the intelligence updated?
Update frequency depends on your package: every 24 hours on Community, every 4 hours on Plus and every 20 minutes on Premium.
What can it block?
You can block traffic to and from malicious IP addresses, botnets and command-and-control infrastructure, and, through Unbound DNS, lookups for malicious domains. This improves security for both IT and OT networks. Malicious URL feeds are not supported by the plugin, because blocking a URL path needs a proxy or web filter.
Is it really free to start?
Yes. The free package lets you run the OPNsense integration at no cost, and you can upgrade to Plus or Premium for faster, premium intelligence at any time.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access