{"id":650,"date":"2026-05-18T09:35:13","date_gmt":"2026-05-18T07:35:13","guid":{"rendered":"https:\/\/disorder.dk\/wonderware\/?p=650"},"modified":"2026-05-18T09:35:13","modified_gmt":"2026-05-18T07:35:13","slug":"opnsense-with-dynamic-feed-of-indicators-of-compromise","status":"publish","type":"post","link":"https:\/\/disorder.dk\/wonderware\/2026\/05\/18\/opnsense-with-dynamic-feed-of-indicators-of-compromise\/","title":{"rendered":"OPNsense with Dynamic feed of Indicators of Compromise"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>This is not a commercial. No prior or any contact was made to Q-feeds.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With a fresh install of OPNsense, I have been looking for tips on how to cover the most security, the fastest and with the least amount of effort. Not to skip learning, but to enhance security as fast as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I came by Q-feeds, which is a company that offers dynamically updated threat lists and they have an official OPNsense plugin! Q-feeds is also European based and offers a free subscription, which the downside of being 7 days delayed on updates. <a href=\"https:\/\/docs.opnsense.org\/manual\/qfeeds.html\">https:\/\/docs.opnsense.org\/manual\/qfeeds.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sign up for the free service or paid: <a href=\"https:\/\/qfeeds.com\/opnsense\/\">https:\/\/qfeeds.com\/opnsense\/<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"322\" src=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-api-1024x322.png\" alt=\"\" class=\"wp-image-652\" srcset=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-api-1024x322.png 1024w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-api-300x94.png 300w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-api-768x241.png 768w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-api-1536x483.png 1536w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-api-2048x644.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Install the OPNsense Q-feeds plugin. Go to <strong>System <\/strong>&gt; <strong>Firmware <\/strong>&gt; <strong>Plugins <\/strong>and search for &#8220;<strong>q<\/strong>&#8220;, press the <strong>+<\/strong> icon out in the right side to install it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"559\" src=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-plugin-1024x559.png\" alt=\"\" class=\"wp-image-653\" srcset=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-plugin-1024x559.png 1024w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-plugin-300x164.png 300w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-plugin-768x419.png 768w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-plugin-1536x839.png 1536w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/03-qfeeds-plugin-2048x1118.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A new menu option will appear, you might have to refresh browser with F5 for it to appear. Click <strong>Security <\/strong>&gt; <strong>Settings <\/strong>and insert the API key from the Q-feeds dashboard.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"592\" src=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/04-qfeeds-settings-1024x592.png\" alt=\"\" class=\"wp-image-654\" srcset=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/04-qfeeds-settings-1024x592.png 1024w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/04-qfeeds-settings-300x173.png 300w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/04-qfeeds-settings-768x444.png 768w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/04-qfeeds-settings-1536x888.png 1536w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/04-qfeeds-settings.png 1564w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Q-feeds will help you with updated lists of malicious IP addresses and malicious domain names, to use in two simple firewall rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The LAN rule is set up to block any devices on your network from connecting to bad actors. The direction is <strong>in<\/strong>, as its blocking data <strong>INTO <\/strong>the LAN interface from your devices.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/05-qfeeds-LAN-1024x682.png\" alt=\"\" class=\"wp-image-655\" srcset=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/05-qfeeds-LAN-1024x682.png 1024w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/05-qfeeds-LAN-300x200.png 300w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/05-qfeeds-LAN-768x512.png 768w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/05-qfeeds-LAN-1536x1024.png 1536w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/05-qfeeds-LAN-2048x1365.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The WAN rule is set up to block any bad actors on the Internet to connect to devices on your network. The direction is <strong>in<\/strong>, as its blocking data <strong>INTO <\/strong>the WAN interface from bad actors on Internet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"807\" src=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/06-qfeeds-WAN-1024x807.png\" alt=\"\" class=\"wp-image-656\" srcset=\"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/06-qfeeds-WAN-1024x807.png 1024w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/06-qfeeds-WAN-300x237.png 300w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/06-qfeeds-WAN-768x606.png 768w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/06-qfeeds-WAN-1536x1211.png 1536w, https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/06-qfeeds-WAN-2048x1615.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You can also activate <strong>Log <\/strong>on both <strong>LAN <\/strong>and <strong>WAN<\/strong>, to track packages blocked by these rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I am currently unsure how to test if the rules are working. There is also some uncertainty on the ranking of firewall rules, since the q-feeds rules can not be ranked in front of the default defined rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please do comment on how to properly verify and test this \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is not a commercial. No prior or any contact was made to Q-feeds. With a fresh install of OPNsense, I have been looking for tips on how to cover the most security, the fastest and with the least amount of effort. Not to skip learning, but to enhance security as fast as possible. I<\/p>\n<p class=\"excert-link-wrapper\"><a href=\"https:\/\/disorder.dk\/wonderware\/2026\/05\/18\/opnsense-with-dynamic-feed-of-indicators-of-compromise\/\" class=\"excerpt-more-link\" >Continue Reading<span class=\"screen-reader-text\"> &#8220;OPNsense with Dynamic feed of Indicators of Compromise&#8221;<\/span><span class=\"meta-nav\"> &rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":651,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[76,77],"tags":[43,81,78],"class_list":["post-650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network","category-security","tag-network","tag-opnsense","tag-security"],"jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"jetpack_featured_media_url":"https:\/\/disorder.dk\/wonderware\/wp-content\/uploads\/2026\/01\/01-qfeeds-firewall-before.png","_links":{"self":[{"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/posts\/650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/comments?post=650"}],"version-history":[{"count":2,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/posts\/650\/revisions"}],"predecessor-version":[{"id":681,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/posts\/650\/revisions\/681"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/media\/651"}],"wp:attachment":[{"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/media?parent=650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/categories?post=650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/disorder.dk\/wonderware\/wp-json\/wp\/v2\/tags?post=650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}