# pfBlockerNG DNS and IP Blocking on pfSense: 2026 Setup

Source: https://srvscripts.com/guides/pfblockerng-dns-ip-blocking/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

pfBlockerNG turns a pfSense firewall into a network-wide filter: it pulls domain blocklists into the Unbound resolver so that ad, tracker and malware names resolve to a sinkhole, and it builds IP aliases from GeoIP and threat feeds that firewall rules can deny. It is one of the first packages most administrators install after the base system, and it is also one of the easiest to misconfigure so that legitimate traffic breaks in confusing ways. This guide uses pfBlockerNG-devel, the actively maintained branch, on pfSense CE 2.9.

In short: Install pfBlockerNG-devel from the package manager, run the wizard under Firewall » pfBlockerNG to set the inbound and outbound interfaces and accept the default DNSBL feeds, then confirm Unbound is the resolver for all LAN clients.

**Short answer:** Install pfBlockerNG-devel from the package manager, run the wizard under Firewall » pfBlockerNG to set the inbound and outbound interfaces and accept the default DNSBL feeds, then confirm Unbound is the resolver for all LAN clients. Add IP lists under Firewall » pfBlockerNG » IP for GeoIP or threat feeds with the action set to Deny Inbound or Deny Both, run Update » Force Reload, and check Reports » DNSBL to see blocked queries.

## Install and run the wizard

Under System » Package Manager » Available Packages install `pfBlockerNG-devel`. Open Firewall » pfBlockerNG; on first launch the wizard starts. It asks for the inbound interface, normally WAN, and the outbound interface, normally LAN and any VLANs, then whether to enable DNSBL and which address the sinkhole should use. Accept the default 10.10.10.1 virtual address unless it overlaps with a real subnet. The wizard subscribes to a sensible default set of DNSBL feeds, downloads them and reloads Unbound. When it finishes, the General tab shows pfBlockerNG enabled with a cron interval; hourly is fine for most sites.

DNSBL only works if clients actually use Unbound on pfSense. Under Services » DHCP Server confirm the DNS server handed to clients is the firewall’s interface address, and consider a firewall rule per LAN interface that redirects or blocks outbound TCP and UDP 53 to any other resolver, otherwise devices with hard-coded public DNS bypass the filter. Encrypted DNS in browsers is a separate problem; blocking known DoH provider domains with a DNSBL feed is the pragmatic answer.

## DNSBL feeds and whitelisting

Under DNSBL » DNSBL Groups you can add further feeds. Each group has a list of URLs, a state such as ON or FLEX, and an action. Start conservative: an aggressive blocklist will break a payment page or a smart TV within a day. When something breaks, the DNSBL » Whitelist tab takes exact domains or wildcards, and the Reports » DNSBL page has a plus icon next to each blocked entry to whitelist it directly.

Custom domains you want blocked go in the DNSBL » DNSBL Category » Custom list. Blocking is applied by Unbound returning the sinkhole address, and the built-in web server on that address logs the request, which is how the reports know which client asked.

## IP lists and GeoIP

Under IP » IPv4 add a group with feed URLs or select from the built-in feed list, and set the action. Deny Inbound blocks the listed addresses from reaching your public services and is safe. Deny Both also blocks outbound and can break updates or CDN traffic if a feed is over-broad, so use it only for clearly malicious feeds. GeoIP lives under IP » GeoIP and needs a free MaxMind licence key entered on the General tab before the country databases download. Blocking whole continents inbound on a firewall that hosts public services reduces noise substantially; blocking them outbound is rarely appropriate.

pfBlockerNG creates firewall rules automatically with the `pfB_` prefix and places them according to the rule order setting on the IP tab. Review Firewall » Rules » WAN after a reload to see them, and keep the order at the default so your own rules remain above them.

## Apply and verify

After any change go to Update, choose Force and Reload All, and watch the log for feed download errors. Then test from a client on the LAN:

```
dig doubleclick.net @10.0.10.1 +short
dig example.com @10.0.10.1 +short
```

The first should return the sinkhole address and the second a real address. Reports » Alerts shows the DNSBL and IP hits in near real time, and Reports » DNSBL Block Stats gives totals per feed. On the firewall shell, `pfctl -t pfB_Top_v4 -T show | wc -l` confirms an IP alias table is populated.

## Pitfalls and keeping it healthy

The most common pitfall is a feed that fails to download, leaving an empty alias that silently matches nothing while the administrator believes blocking is active. Check the Update log after every reload and set MaxMind and feed credentials before enabling the lists that need them. A second one is DNSBL breaking Unbound entirely after a huge list is added on a low-memory appliance; keep the total domain count proportionate to RAM. Finally, remember that DNSBL does not block a client that has already cached a record; flush the client’s resolver cache when testing. For firewall placement of the segments you are protecting, see [Configure VLANs on pfSense with a managed switch](/guides/pfsense-vlan-managed-switch/).

## PfBlockerNG DNS at a glance

Covers: Install and run the wizard, DNSBL feeds and whitelisting, IP lists and GeoIP and Apply and verify.

**Official documentation:** [pfSense documentation](https://docs.netgate.com/pfsense/en/latest/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [AutoSSL failed: fixing DCV errors, CAA records, CDN proxies and blocked /.well-known/](https://srvscripts.com/guides/autossl-failed-cpanel-dcv-caa-cdn/) · [Replacing cxs: malware scanning with LMD (maldet), ClamAV and ImunifyAV on hosting servers](https://srvscripts.com/guides/cxs-replacement-malware-scanning/) · [Enabling ModSecurity with OWASP CRS or Comodo rules on DirectAdmin and managing per-domain exclusions](https://srvscripts.com/guides/directadmin-modsecurity-owasp-crs/).

## Frequently asked questions

### Does pfBlockerNG DNS blocking work with DNS over HTTPS clients?

Not directly. A browser or device using DoH bypasses Unbound, so add a DNSBL feed that lists known DoH endpoints and block outbound TCP 853 and non-firewall port 53 to push clients back to the firewall resolver.

### How long does the initial pfBlockerNG download and reload take?

With the default feeds, a few minutes on a broadband connection. Large GeoIP or threat feeds can extend the first reload to ten minutes or more; subsequent cron updates only fetch changed lists.

### Can I undo pfBlockerNG changes if it blocks something important?

Yes. Whitelist the domain or address on the relevant tab and force a reload, or disable pfBlockerNG on the General tab, which removes its firewall rules and Unbound entries immediately while keeping your configuration for later.
