Kent, UK

What pfBlockerNG adds

pfBlockerNG extends pfSense with managed IP lists, country and network aliases, and DNS block-list features. It turns external feeds into firewall and DNS policy that can be updated automatically.

Why I use it

I use it to reduce unwanted DNS requests and to create repeatable firewall aliases from maintained feeds. It complements AdGuard Home: AdGuard focuses on client-visible DNS policy, while pfBlockerNG sits at the firewall and can act on both DNS and network ranges.

How I keep it safe

  • Start with reporting before enforcing new feeds
  • Use allow-lists for required services
  • Review feed quality and update failures
  • Keep country blocking aligned with an actual requirement
  • Check firewall logs when legitimate traffic stops
  • Document which layer—DNS or IP—made the decision

Review false positives, maintain allow-lists for required services and stage changes so DNS or business-critical traffic is not unexpectedly interrupted.

Install pfBlockerNG through the supported pfSense package manager, start with a small reputable feed set and enable logging before applying broad blocking policies.

How to deploy or reproduce it

Official documentation