Free and open source · Apache 2.0
Stop threats at the edge of your network.
pfBlockerNG adds IP blocklists, GeoIP filtering and DNS-level blocking of ads, trackers and malware to pfSense, all managed from one dashboard.
Maintained since 2014 · One-command install for pfSense CE and Plus
Illustration with example data.
- 12,450distinct domains blocked
- 613,289matches in the DNSBL_BBC group
- 282,647blocks from the Adaway feed
- 46,267telemetry lookups to one host stopped
- 34feeds working together
- 14DNSBL groups
- 101top-level domains seen
- 54countries in DNS replies
- 240pre-defined feeds to choose from
- 1,529TLDs available for TLD Allow
What it does
Every layer of blocking, in one package.
Pull IPv4 and IPv6 threat feeds into pfSense aliases and firewall rules, updated on your schedule.
GeoIP summary
Top reply GeoIP
54 countries seen
Where your network's DNS answers point, by country. Rather than blocking the world, permit the countries you need and protect open WAN ports and outbound LAN traffic. GeoLite2 data by MaxMind, refreshed daily.
Pre-defined feeds import with one click, and Adblock Plus lists such as OISD and HaGeZi load as they are: ||host^ anchors, @@ exceptions, regex rules, $important and $badfilter. Each run reloads only what changed; force a re-parse or re-download whenever you want.
Top feed
Top TLD
Top DNSBL group
Blocked per day
Example: the Reports tab of a real pfBlockerNG install, filled with sample data.
SafeSearch forces these domains onto the safe version.
Googlewww.google.com and each country site, such as www.google.ca and www.google.co.uk
YouTubewww.youtube.com, m.youtube.com, www.youtu.be, www.youtube-nocookie.com
Bingwww.bing.com
DuckDuckGoduckduckgo.com, sent to safe.duckduckgo.com
Yandexyandex.com, yandex.ru, ya.ru, and the other Yandex country sites
Pixabaypixabay.com, sent to safesearch.pixabay.com
Block whole top-level domains you never use.
Get started
Running in minutes.
No extra hardware and nothing to compile. Install with one command from the project repository, or from the pfSense Package Manager, and a setup wizard walks you through the first configuration.
Full installation guide- 1
Install the package
Project repositoryRecommended
Run on the firewall over SSH as root. One command from any starting state: a fresh firewall, a Package Manager install or another channel. It is safe to re-run, and it adds the Software tab for updates and channel changes from the GUI.
Stable: Production use.
fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel stableTesting: Prereleases validating the next stable.
fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel testingEdge: Prereleases opening the next release family.
fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel edgeNightly: Bleeding edge, rebuilt from the development tip.
fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel nightlypkg.pfblockerng.com is the project's package repository, hosted on GitHub Pages from the public pfBlockerNG/pkg repository.
Versions, packages per pfSense release and older builds: pkg.pfblockerng.com
Full installation guidepfSense Package Manager
System › Package Manager › Available Packages › pfBlockerNG
Netgate decides which version its catalogue carries, and it usually lags behind. Installs from it have no Software tab; pfSense's own update badge covers them.
- 2
Run the 4-step setup wizard
Pick inbound (WAN) and outbound (LAN) interfaces for the IP rules, then let DNSBL create its sinkhole VIP automatically with a default whitelist. Running the wizard replaces any existing pfBlockerNG settings.
Wizard walkthrough with screenshots - 3
Watch it work
Open the Alerts tab to see blocks as they happen and fine-tune your lists.
Reading reports and adding exceptions
Documentation
The user guide.
FAQ
Questions, answered.
Tap a card to flip it. Answers come from the user guide and the project README.
0 of 6 answers opened
Help pfBlockerNG keep going.
A star helps others discover it.
You've opened 3 answers. If pfBlockerNG saves you time, a star supports our development.
Star on GitHub Still stuck? Ask on RedditGuides from the community
Forums and how-tos.
Walkthroughs and discussions recommended in the r/pfBlockerNG community bookmarks.
The official repository
Developed in public on GitHub.
Read the code, follow the roadmap, report a bug or send a pull request. A star helps more people find the project.
News
Latest from the project.
Releases and r/pfBlockerNG community posts, collected from their RSS feeds.
Collected 11 Oct 2026; refreshed on every site build.
The people behind it
pfBlockerNG is created by BBcan177, who designs, supports and maintains it with André Brait.
Since 2014, pfBlockerNG has been protecting assets behind consumer and corporate networks running pfSense, the open-source firewall based on FreeBSD.
The development of pfBlockerNG was forged out of the passion to create a unified solution to manage IP and domain feeds with rich customization and management features.
Built in the open, kept alive by its community.
Your support has helped drive new development into features that advance the protection of your network and give insight into the activity lurking in it. Kind words, helping others in the forum, feedback to improve the package and code patches are all very much welcomed and appreciated.
Need a site-specific feature? We are open to developing custom features. contact@pfblockerng.com
Latest from Reddit /r/pfBlockerNG
View allPatreon · pfBlockerNG
Support our development
Pledges fund new features, testing on every pfSense release, and support in the forums.
Newest posts from r/pfBlockerNG, as of 11 Oct 2026.
