Help fixing 'erroneous' Q-Feeds Block

Started by Taunt9930, August 08, 2026, 02:17:29 PM

Previous topic - Next topic
August 08, 2026, 02:17:29 PM Last Edit: August 08, 2026, 02:41:55 PM by Taunt9930
Hi All,

I am not sure if this is a Q-feeds issue, OPNSense Firewall Issue, or a me issue.

After working for some time, I noticed the other day that my Aqara presence sensors can no longer be controlled by the Aqara app. Upon looking at the OPNSense firewall live log, it appears that connections from those devices into the firewall/out to the internet is suddenly being blocked by my Qfeeds rule blocking connections to the qfeeds created malware-ip feed.

EDIT: The event is also shown in the Qfeeds events pane.

When I search for the IP on the TIP, nothing comes up - no IOC's.

This (happily) appears to be the only connection being blocked by this rule - connection to this IP from the two Aqara Device IP's.

EDIT: If I go to firewall > Diagnostics > aliases and select the qfeeds malware alias in the dropdown, and search for the IP, it does not appear to be in the list. Why is it being blocked? What can I do to work out why this is suddenly being blocked. If I disable the qfeeds rule, all is well.

The IP in question is 43.131.7.8

Thanks - I appreciate any help anyone can give!

I searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

Quote from: vk2him on Today at 12:14:10 AMI searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

All of that is in my original post.

It is being blocked by the qfeeds rule - as indicated by the firewall log, and as indicated by being in the qfeeds event list - despite, as I said above, not being on the IOC list, or the qfeeds alias list on the device itself.

Disabling the qfeeds rule resolves the problem.