What pfBlockerNG adds
pfBlockerNG extends pfSense with managed IP lists, country and network aliases, and DNS block-list features. It turns external feeds into firewall and DNS policy that can be updated automatically.
Why I use it
I use it to reduce unwanted DNS requests and to create repeatable firewall aliases from maintained feeds. It complements AdGuard Home: AdGuard focuses on client-visible DNS policy, while pfBlockerNG sits at the firewall and can act on both DNS and network ranges.
How I keep it safe
- Start with reporting before enforcing new feeds
- Use allow-lists for required services
- Review feed quality and update failures
- Keep country blocking aligned with an actual requirement
- Check firewall logs when legitimate traffic stops
- Document which layer—DNS or IP—made the decision
Review false positives, maintain allow-lists for required services and stage changes so DNS or business-critical traffic is not unexpectedly interrupted.
Install pfBlockerNG through the supported pfSense package manager, start with a small reputable feed set and enable logging before applying broad blocking policies.
