CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Free security solutions on Linux and OPNsense — catalog

A practical inventory of free (and affordable) solutions we configure on Linux or OPNsense to cover detection, prevention, threat intelligence and visibility. Not just names — what each does, plus how feeds integrate into the firewall.

IDS / IPS — intrusion detection and blocking

SIEM / host + log detection

Reputational / collaborative IPS

Threat intelligence / feeds

How to integrate feeds into OPNsense (practical)

The most practical way to use threat intelligence: bring the feeds (Q-Feeds, Spamhaus, FireHOL, Abuse.ch) in as an auto-refreshing firewall alias, then a block rule. No SOC, no complicated scripts.

# OPNsense: Firewall -> Aliases -> Add
#   Type: URL Table (IPs)   Refresh frequency: 1 day
#   Content: URL-ul feed-ului, de ex:
#     Q-Feeds:     URL dedicat per cont (IP-uri + domenii malitioase)
#     Spamhaus:    https://www.spamhaus.org/drop/drop.txt
#     FireHOL:     https://iplists.firehol.org/files/firehol_level1.netset
# apoi Firewall -> Rules -> Floating -> action Block, Source = aliasul

# echivalent pe Linux pur (nftables + cron care reincarca setul zilnic):
curl -s https://www.spamhaus.org/drop/drop.txt \
  | grep -oE '^[0-9.]+/[0-9]+' \
  | while read cidr; do sudo nft add element inet filter blocklist "{ $cidr }"; done

Firewall / network filtering

VPN / secure access

Vulnerability scanning / audit

Visibility / monitoring

Incident response

Example: typical SMB stack (quick install)

A concrete starting point for a minimum viable stack:

# OPNsense (from shell): IDS/IPS + collaborative IPS
pkg install os-suricata os-crowdsec

# Linux host: CrowdSec + reputation feed in nftables
curl -s https://install.crowdsec.net | sudo sh && sudo apt -y install crowdsec
# + add a feed (Q-Feeds/Spamhaus) as a URL table alias in OPNsense (see above)

Conclusion

You do not need all of them — pick based on risk and team. Typical SMB stack: Suricata + CrowdSec on OPNsense, a Q-Feeds/Abuse.ch feed as a firewall alias, Wazuh on hosts, WireGuard for access. We design, configure and monitor it for you.

Let's discuss your project →