Skip to content

Threat intelligence API / integrations

OPNsense

OPNsense can keep a table of addresses in step with a list on the web, and use that table in firewall rules. Add the ThreatCluster IP feed as an alias, block traffic to it, and the firewall refreshes the list by itself. The feed is a public text file, so this needs no API key.

Prerequisites

  1. An OPNsense firewall you can sign in to. The screenshots are from OPNsense 26.7, run as a virtual machine on 29 September 2026.
  2. The feed address: https://threatcluster.io/api/iocs/public/ips.txt

Setup

  1. Open Firewall, then Aliases, and select the plus button. Set Type to URL Table (IPs), paste the feed address into Content, and set Refresh Frequency to 0 days and 1 hour. Select Save, then Apply.

    The OPNsense Edit Alias dialog with the name ThreatCluster_IPs, type URL Table (IPs), a refresh frequency of 0 days and 1 hour, and the feed address as content
    Alias names cannot contain spaces or hyphens, so use an underscore.
  2. The alias list shows how many addresses loaded.

    The OPNsense Aliases table with ThreatCluster_IPs listed as a URL Table with 97 entries loaded
    97 addresses loaded.
  3. Open Firewall, then Rules, and add a rule: action Block, interface LAN, direction in, source any, destination the alias. Turn on logging so you can see what it stops. Select Save, move the rule to the top, then select Apply.

    The OPNsense Rules table with three LAN rules, the first a block rule for IPv4 from any source to the ThreatCluster_IPs alias, above the two default allow rules
    The block rule is first. A new rule is added at the bottom, below the default rule that allows LAN traffic out, where it would never match. Tick the rule, then select the arrow on the top row to move it above.
  4. Check it from the firewall's shell. The first command counts the addresses in the live table.

    pfctl -t ThreatCluster_IPs -T show | wc -l
    A terminal on the firewall counting 97 addresses in the table and printing the first four
    The table the rule reads from.

    The second asks the firewall whether an address is in the table.

    pfctl -t ThreatCluster_IPs -T test 103.101.85.123
    A terminal on the firewall testing two addresses against the table: the feed address matches, the other does not
    An address from the feed matches. An address that is not on it does not.

Worth knowing

  1. pfSense has the same feature under Firewall, then Aliases, then URLs, as a URL Table (IPs) alias. We have not tested it.
  2. Shared addresses. An address can host many sites. Keep logging on for the first week and look at what the rule stops.
  3. Domains. This alias type takes addresses only. For domains, use the Pi-hole or AdGuard Home guide.
  4. If a block is wrong. Tell us at /corrections so it comes off the feed for everyone.