Published: in Videos
Q-Feeds on OPNsense: 20,131 Blocks in 26 Days
Back in January, I published a video showing how to set up Q-Feeds threat intelligence on OPNsense. After six months of testing, I've recorded a follow-up looking at the results alongside the CrowdSec and Spamhaus blocklists already running on my firewall.
At the time of recording, Q-Feeds had recorded 20,131 blocks during the firewall's current 26-day uptime. In the video, I walk through the figures and the blocklists in use.
What is Q-Feeds?
Q-Feeds provides regularly updated lists of IP addresses and domains associated with malicious activity. The OPNsense connector imports IP feeds into firewall aliases, which can then be used in blocking rules. Domain feeds can also be used for DNS filtering.
The feed provides the intelligence, while your firewall rules determine how it is used. You can block incoming connections from listed addresses, outgoing connections to them, or both.
Protecting outbound connections
Firewall rules control which connections are permitted, but an allowed connection is not necessarily a trustworthy one. Allowing a computer to browse the web does not mean every destination it contacts is safe.
Threat intelligence adds another check. If a destination appears in the feed, a blocking rule can stop the connection even where the network's general access rules would otherwise permit it.
This can help prevent devices from communicating with known malicious infrastructure, providing another layer of protection alongside software updates and endpoint security.
Protecting exposed websites, mail and webmail
Outbound filtering is only part of the picture. Threat intelligence is also useful when you host services that must accept connections from the internet, such as websites, mail servers and webmail.
Those services need to remain accessible to legitimate users. You cannot simply block every incoming connection, but you can reject traffic from addresses listed in a threat intelligence feed before it reaches the service.
That is why CrowdSec was already running in my setup. Protecting services exposed to the internet matters just as much as controlling connections leaving the network. Q-Feeds can be used to filter traffic in both directions.
What the results show
At the time of recording, the Q-Feeds malware IP feed showed a database size of 313,422 and a blocked counter of 20,131.
The blocking counter resets when the firewall reboots, so these figures cover its current 26-day uptime rather than the full six months of testing.
That shows the Q-Feeds rules are actively matching and blocking traffic. It does not mean 20,131 individual attackers or prevented infections, as repeated attempts can contribute to the total.
Q-Feeds alongside CrowdSec and Spamhaus
The counters need to be considered in the context of the firewall configuration. Blocklists can overlap, and rule order affects which rule records a match. Traffic blocked by an earlier rule will not reach a later one.
A higher counter does not automatically prove that one list is better than another. The useful question is what each feed contributes to the overall configuration.
The follow-up video shows those figures in context, with Q-Feeds running alongside the existing CrowdSec and Spamhaus lists.