pfSense package · IP + DNS policy

Block at the firewall. Block at the resolver.

pfBlockerNG turns trusted IP and domain feeds into live pfSense policy, with reports, safe exceptions, and one place to operate both enforcement paths.

GitHub star count GitHub fork count Latest release Apache 2.0 license

§ 01 · Two components

One policy surface.

IP blocking and DNSBL solve different problems. Use either component independently, or combine them for network- and name-level enforcement.

01 / IP

IP blocking

Build IPv4 and IPv6 aliases from feeds, GeoIP data, and custom entries. Use generated rules or reference the aliases from your own pfSense rules.

02 / DNS

DNSBL

Evaluate domain lists in Unbound, including Adblock Plus and EasyList rules, with selectable response modes and per-query reporting.

03 / OPERATE

Reports and control

Trace blocked traffic and names, add precise exceptions, inspect update logs, and keep the last good data when a feed download fails.

§ 02 · Operating model

Feeds become native policy.

pfBlockerNG downloads, validates, normalizes, and publishes data into the pfSense services already responsible for enforcement.

SourcesIP feeds, domain feeds, GeoIP, custom entries
pfBlockerNGDownload, parse, deduplicate, aggregate, prioritize
pfSensepf aliases and rules, Unbound DNSBL, reports and logs