IP blocking
Build IPv4 and IPv6 aliases from feeds, GeoIP data, and custom entries. Use generated rules or reference the aliases from your own pfSense rules.
pfSense package · IP + DNS policy
pfBlockerNG turns trusted IP and domain feeds into live pfSense policy, with reports, safe exceptions, and one place to operate both enforcement paths.
§ 01 · Two components
IP blocking and DNSBL solve different problems. Use either component independently, or combine them for network- and name-level enforcement.
Build IPv4 and IPv6 aliases from feeds, GeoIP data, and custom entries. Use generated rules or reference the aliases from your own pfSense rules.
Evaluate domain lists in Unbound, including Adblock Plus and EasyList rules, with selectable response modes and per-query reporting.
Trace blocked traffic and names, add precise exceptions, inspect update logs, and keep the last good data when a feed download fails.
§ 02 · Operating model
pfBlockerNG downloads, validates, normalizes, and publishes data into the pfSense services already responsible for enforcement.
§ 03 · Start here
Install pfBlockerNG from the project repository, configure a small verified policy, then explore the wider project.
Choose a channel and use the copy-ready commands from the official package repository.
Establish safe defaults, apply one small list, and verify enforcement before expanding policy.
Repositories, issues, releases, architecture work, and the people building pfBlockerNG.