OPNsense

Threat intelligence on OPNsense

Improve your security posture on OPNsense with three different threat intelligence packages. Register on our TIP for the free package, or activate Plus or Premium to unlock more, right on the edge of your open-source firewall.

  • 2,500+Intelligence sources
  • 20 minFastest update interval (Premium)
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds OPNsense integration?

The Q-Feeds integration adds curated cyber threat intelligence to your open-source OPNsense firewall through a native plugin, available from the official OPNsense repository. The plugin imports Q-Feeds lists of malicious IP addresses as firewall aliases, which you enforce in your firewall rules. If Unbound is your DNS resolver, the plugin can also register Q-Feeds domain feeds as an Unbound blocklist, so lookups for malicious domains are blocked too.

The aliases update automatically, so traffic to and from known-bad hosts, botnets and command-and-control servers is blocked at the edge, with no manual list management required. Q-Feeds combines commercial, OSINT and governmental sources for broad, reliable coverage.

With free, Plus and Premium packages, the integration scales from a free proof of concept to real-time protection on production firewalls.

Threat intelligence

Our promise

Enriching your firewall with threat intelligence will strengthen your security even more, right on the edge of your network.

  • Curated best-in-class threat intelligence
  • Always up to date gathered and selected from over 2500 sources
  • Improve security for both OT & IT
Setup

How to use Q-Feeds with OPNsense

We've built a convenient plugin, publicly available via the official OPNsense repository. Follow our integration manual to get up and running.

OPNsense setup guide
Explainer

OSINT vs Paid (Commercial) feeds

The difference between OSINT and Paid (Commercial) feeds mainly lies in the source of the data, not in how we handle it.

OSINT feeds are gathered from publicly available sources, such as community projects, research groups, open lists, news articles, and fora.

Paid feeds come from professional cybersecurity vendors who continuously collect and enrich threat data using proprietary systems.

At Q-Feeds, we apply the same rigorous process to both types of feeds. Every dataset goes through quality checks, priority scoring, and false positive validation before it's published. This ensures that regardless of the source, all indicators in our platform meet the same standard of accuracy and reliability.

In short: OSINT and Commercial feeds differ by origin, but Q-Feeds ensures both are equally verified and trustworthy.

Features

External Attack Surface Management

EASM is part of the Threat Intelligence Portal and is included with a Plus or Premium licence.

Open ports

We have an on-demand and scheduled scanner available which scans for open ports and sends you an email if something has changed.

Web vulnerabilities

Check your infrastructure for potential web vulnerabilities, also both on-demand and scheduled.

Network vulnerabilities

Detect network vulnerabilities on your external IP addresses.

Similar domains

Our scanner checks for similar domains and if they resolve. Similar domains might be used for phishing campaigns.

Reverse DNS

Check if certain IP addresses are linked to domain names. This supports you to determine the origin of connections.

Stolen credentials on the dark web

Monitor the dark web for stolen credentials and take appropriate action.

Setup

How to add threat intelligence to OPNsense in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and choose the package that fits your needs.

  2. Install the Q-Feeds plugin

    Install the Q-Feeds plugin from the official OPNsense repository, following our integration manual.

  3. Connect your feed

    Enter your API key so the plugin creates firewall aliases from your Q-Feeds intelligence and keeps them updated. Enable Register domain feeds as well if you want Unbound DNS to block malicious domains.

  4. Enforce in a firewall rule

    Reference the Q-Feeds alias in a firewall rule to block malicious traffic immediately.

FAQ

Frequently asked questions about the OPNsense integration

How does Q-Feeds work with OPNsense?

A native Q-Feeds plugin imports curated malicious IP intelligence as firewall aliases, which you reference in OPNsense firewall rules to block known-bad traffic automatically. Optionally, it registers Q-Feeds domain feeds with Unbound DNS to block lookups for malicious domains.

Where do I get the OPNsense plugin?

The plugin is publicly available in the official OPNsense repository. Our integration manual walks you through installing and configuring it.

How often is the intelligence updated?

Update frequency depends on your package: every 24 hours on Community, every 4 hours on Plus and every 20 minutes on Premium.

What can it block?

You can block traffic to and from malicious IP addresses, botnets and command-and-control infrastructure, and, through Unbound DNS, lookups for malicious domains. This improves security for both IT and OT networks. Malicious URL feeds are not supported by the plugin, because blocking a URL path needs a proxy or web filter.

Is it really free to start?

Yes. The free package lets you run the OPNsense integration at no cost, and you can upgrade to Plus or Premium for faster, premium intelligence at any time.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access