Free and open source · Apache 2.0

Stop threats at the edge of your network.

pfBlockerNG adds IP blocklists, GeoIP filtering and DNS-level blocking of ads, trackers and malware to pfSense, all managed from one dashboard.

Maintained since 2014 · One-command install for pfSense CE and Plus

From a real install
  • 12,450distinct domains blocked
  • 613,289matches in the DNSBL_BBC group
  • 282,647blocks from the Adaway feed
  • 46,267telemetry lookups to one host stopped
  • 34feeds working together
  • 14DNSBL groups
  • 101top-level domains seen
  • 54countries in DNS replies
  • 240pre-defined feeds to choose from
  • 1,529TLDs available for TLD Allow

What it does

Every layer of blocking, in one package.

Firewall › pfBlockerNG › IPExample

Pull IPv4 and IPv6 threat feeds into pfSense aliases and firewall rules, updated on your schedule.

198.51.100.23Abuse Feodo TrackerBlocked
203.0.113.140ISC ShodanBlocked
2001:db8::a1fSpamhaus Drop v6Blocked
198.51.100.77Emerging ThreatsBlocked
192.0.2.10AllowlistAllowed
203.0.113.9CINS ArmyBlocked

Get started

Running in minutes.

No extra hardware and nothing to compile. Install with one command from the project repository, or from the pfSense Package Manager, and a setup wizard walks you through the first configuration.

Full installation guide
  1. 1

    Install the package

    Project repositoryRecommended

    Run on the firewall over SSH as root. One command from any starting state: a fresh firewall, a Package Manager install or another channel. It is safe to re-run, and it adds the Software tab for updates and channel changes from the GUI.

    Stable: Production use.

    fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel stable

    pkg.pfblockerng.com is the project's package repository, hosted on GitHub Pages from the public pfBlockerNG/pkg repository.

    Versions, packages per pfSense release and older builds: pkg.pfblockerng.com

    pfSense Package Manager

    System › Package Manager › Available Packages › pfBlockerNG

    Netgate decides which version its catalogue carries, and it usually lags behind. Installs from it have no Software tab; pfSense's own update badge covers them.

    Full installation guide
  2. 2

    Run the 4-step setup wizard

    Pick inbound (WAN) and outbound (LAN) interfaces for the IP rules, then let DNSBL create its sinkhole VIP automatically with a default whitelist. Running the wizard replaces any existing pfBlockerNG settings.

    Wizard walkthrough with screenshots
  3. 3

    Watch it work

    Open the Alerts tab to see blocks as they happen and fine-tune your lists.

    Reading reports and adding exceptions

FAQ

Questions, answered.

Tap a card to flip it. Answers come from the user guide and the project README.

0 of 6 answers opened

Found your answer?
Help pfBlockerNG keep going.

A star helps others discover it.

Star on GitHub Still stuck? Ask on Reddit
See all 15 questions

Guides from the community

Forums and how-tos.

Walkthroughs and discussions recommended in the r/pfBlockerNG community bookmarks.

More on r/pfBlockerNG

The official repository

Developed in public on GitHub.

testspassing releasev3.3.11 licenseApache-2.0

Read the code, follow the roadmap, report a bug or send a pull request. A star helps more people find the project.

pfBlockerNG / pfBlockerNGLatest: v3.3.11
1,557 issues closed1,697 PRs merged158 open8 contributors14 releases

News

Latest from the project.

Releases and r/pfBlockerNG community posts, collected from their RSS feeds.

Subscribe to all

The people behind it

pfBlockerNG is created by BBcan177, who designs, supports and maintains it with André Brait.

Since 2014, pfBlockerNG has been protecting assets behind consumer and corporate networks running pfSense, the open-source firewall based on FreeBSD.

The development of pfBlockerNG was forged out of the passion to create a unified solution to manage IP and domain feeds with rich customization and management features.

BBcan177

Creator

Designs, supports and maintains pfBlockerNG with André Brait.

André Brait

Maintainer

Designs, supports and maintains pfBlockerNG with BBcan177.

Built in the open, kept alive by its community.

Your support has helped drive new development into features that advance the protection of your network and give insight into the activity lurking in it. Kind words, helping others in the forum, feedback to improve the package and code patches are all very much welcomed and appreciated.

Need a site-specific feature? We are open to developing custom features. contact@pfblockerng.com

Newest posts from r/pfBlockerNG, as of 11 Oct 2026.

Screenshot from a test install. Numbers are sample data.

Top