pfSense integration

pfSense threat feeds

Add Q-Feeds threat intelligence to pfSense with pfBlockerNG. Import curated blocklists of malicious IP addresses and domains, and block bad traffic at the network edge automatically.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds and pfSense integration?

The integration brings curated cyber threat intelligence to pfSense through the pfBlockerNG package. pfBlockerNG downloads Q-Feeds blocklists of malicious IP addresses over HTTPS and turns them into firewall aliases that block traffic in your rules.

With the DNSBL feature you also block malicious domains at resolution time. Because the feeds refresh automatically, protection stays current without manual list management, and it runs on the free, open-source pfSense platform.

What you can block

What you can block on pfSense

Malicious IP feeds

pfBlockerNG imports Q-Feeds IP lists as aliases to block inbound and outbound traffic to malicious hosts, botnets and C2 servers.

Malicious domain feeds

The DNSBL feature blocks phishing and malware domains at DNS resolution, before a connection is ever made.

Benefits

Why add Q-Feeds to your firewall

  • Enhanced threat detection

    Cross-reference threat information to reduce false positives and identify genuine threats more effectively.

  • Updated every 20 minutes

    Your firewall stays ahead of the latest threats with intelligence refreshed every 20 minutes.

  • Increased resilience

    Rely on multiple sources for continuous protection and reduce the risk of blind spots in your security.

  • Improved incident response

    Faster, more precise response right on the edge of your network, saving time on internal investigations.

Setup

Integrate Q-Feeds with pfSense in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal IP and domain feed URLs.

  2. Install pfBlockerNG

    In pfSense, install the pfBlockerNG package from the System, Package Manager if it is not already present.

  3. Add the Q-Feeds lists

    Add your Q-Feeds IP URL as an IPv4 list and your domain URL under DNSBL, then set the update frequency.

  4. Enforce in firewall rules

    Enable the generated aliases in your firewall rules to start blocking malicious traffic immediately.

FAQ

Frequently asked questions about the pfSense integration

How do I add threat feeds to pfSense?

You install pfBlockerNG, add your personal Q-Feeds IP URL as an IPv4 list and your domain URL under DNSBL, then enable the generated aliases in your firewall rules.

Do I need pfBlockerNG?

Yes. pfBlockerNG is the free package that imports external IP and domain lists into pfSense and enforces them as aliases and DNSBL rules.

Which indicators can I block?

You can block malicious IP addresses as firewall aliases and malicious domains through DNSBL, covering botnets, malware and phishing.

How often are the feeds updated?

The feeds refresh every 20 minutes, and you set pfBlockerNG to pull them on a matching schedule so pfSense stays current.

Is there a free version?

Yes. The Q-Feeds Community edition is free and lets you test the pfSense integration before upgrading to Plus or Premium.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access