Testing firewall rules with qfeeds

Started by DEC740airp414user, January 25, 2026, 04:36:46 PM

Previous topic - Next topic
Allright! Will look into it together with Deciso and get back to you. Thanks for digging into it already, very helpful!
EDIT: Code is available on GitHub for review if you want to dig into it further: https://github.com/opnsense/plugins/tree/master/security/q-feeds-connector

Your Threat Intelligence Partner  qfeeds.com

Today at 01:30:09 AM #16 Last Edit: Today at 02:46:26 AM by vk2him
Quote from: Q-Feeds on January 26, 2026, 06:10:59 PMAllright! Will look into it together with Deciso and get back to you. Thanks for digging into it already, very helpful!

FYI - I'm seeing this issue too however I'm using the qfeed Domains blocklist only within AGH and not within Unbound.  I'm running OPNsense 25.7.11_9-amd64  with AGH setup as the main DNS on port 53, and Unbound is on 5335. Within AGH I have 127.0.0.1:5335 setup as a Private reverse DNS server, and for Local resolution via Unbound on 127.0.0.1:5335 - this has been working well for years.

Blocking of sites on the qfeeds Domains blocklist within AGH worked well previously, however it now seems to have stopped as the example problem url's posted earlier in this thread are no longer blocked and they display warnings in my browser.

The widget shows the blocked number incrementing as I have the floating rules setup to block the qfeeds IPs which works properly - it's just the Domain blocklist isn't working anymore

edited to add - this is the url added to the AGH Qfeeds Malware Domains shown in the screenshot:
https://api.qfeeds.com/api.php?feed_type=malware_domains&api_token=tip_xxxxxxx