Hi All,
I am not sure if this is a Q-feeds issue, OPNSense Firewall Issue, or a me issue.
After working for some time, I noticed the other day that my Aqara presence sensors can no longer be controlled by the Aqara app. Upon looking at the OPNSense firewall live log, it appears that connections from those devices into the firewall/out to the internet is suddenly being blocked by my Qfeeds rule blocking connections to the qfeeds created malware-ip feed.
EDIT: The event is also shown in the Qfeeds events pane.
When I search for the IP on the TIP, nothing comes up - no IOC's.
This (happily) appears to be the only connection being blocked by this rule - connection to this IP from the two Aqara Device IP's.
EDIT: If I go to firewall > Diagnostics > aliases and select the qfeeds malware alias in the dropdown, and search for the IP, it does not appear to be in the list. Why is it being blocked? What can I do to work out why this is suddenly being blocked. If I disable the qfeeds rule, all is well.
The IP in question is 43.131.7.8
Thanks - I appreciate any help anyone can give!