OPNsense Forum

English Forums => Q-Feeds (Threat intelligence) => Topic started by: dinguz on July 22, 2026, 07:21:36 PM

Title: Q-Feeds flagging 94.237.108.179 (UpCloud) as suspicious: likely false positive
Post by: dinguz on July 22, 2026, 07:21:36 PM
I've noticed 94.237.108.179 is flagged as suspicious in Q-Feeds. This IP belongs to UpCloud and is referenced by fd.eacm.nl and portal.eacm.nl, both of which I use legitimately.

I don't have a paid Q-Feeds subscription, so my options to investigate further or submit this for reconsideration are very limited. This puts me in a bit of a bind: I can see the block happening, but I have no path to dispute it through Q-Feeds itself.

On top of that, the OPNsense GUI doesn't currently offer a way to whitelist an IP address for either the firewall blocklist or the Unbound blocklist. Right now my only option seems to be running a manual override at the firewall rule or Unbound config level, which feels like the wrong tool for what should be a simple exception case.

Has anyone else run into false positives with Q-Feeds on shared-hosting/VPS ranges (UpCloud, DigitalOcean, etc.)? Any pointers appreciated.
Title: Re: Q-Feeds flagging 94.237.108.179 (UpCloud) as suspicious: likely false positive
Post by: Patrick M. Hausen on July 22, 2026, 07:25:01 PM
Even as a free tier user you probably have an account, so log in to their portal and use the False Positive Reports form:

https://tip.qfeeds.com/views/support/my_false_positives.php

The OPNsense forum is definitely not the place for that.

HTH,
Patrick