A practical inventory of free (and affordable) solutions we configure on Linux or OPNsense to cover detection, prevention, threat intelligence and visibility. Not just names — what each does, plus how feeds integrate into the firewall.
IDS / IPS — intrusion detection and blocking
- Suricata — signature IDS/IPS, inline; natively integrated in OPNsense (os-suricata), ET Open + Abuse.ch rules
- Snort 3 — classic IDS/IPS with Talos rules; good as a second cross-validation engine
- Zeek (Bro) — network traffic and metadata analysis (not just signatures) — deep visibility, ideal for threat hunting
SIEM / host + log detection
- Wazuh — SIEM + HIDS: log collection, file integrity (FIM), rootkit detection, CIS/PCI compliance, Windows/Linux agents
- OSSEC — classic HIDS (Wazuh's base): integrity, correlation, alerting
- Grafana + Loki — centralized log aggregation and visualization, dashboards + alerting
Reputational / collaborative IPS
- CrowdSec — collaborative IPS: behavioral scenarios + global reputation (IPs reported by the whole network); nftables/nginx bouncer; OPNsense os-crowdsec plugin
- Fail2ban — log-based banning (SSH, nginx) — simple, local, mature; good for pinpoint rules
Threat intelligence / feeds
- Q-Feeds — a European (NL) threat intelligence aggregator — combines dozens of sources into blocklists of malicious IPs and domains. Integrates directly into OPNsense / pfSense / FortiGate as a URL Table alias (auto-refresh) — paste the URL, add a block rule, done. Community feed + affordable SMB plans. The simplest way to bring threat intel into a firewall without your own SOC.
- Team Cymru — bogon lists, UTRS (collaborative BGP blackhole), community IP/ASN reputation services
- Abuse.ch — Feodo (botnet C2), URLhaus (malware URLs), SSLBL (bad certs), ThreatFox (IOCs) — straight into Suricata or as a firewall alias
- Spamhaus DROP / EDROP — networks controlled by attackers — integrable as a URL table in the firewall
- FireHOL / blocklist.de — aggregated abusive-IP lists (SSH brute-force, scanning), ready to import, by aggressiveness level
- MISP — threat intelligence sharing platform (IOCs) — the source feeding rules, feeds and blocklists across teams
How to integrate feeds into OPNsense (practical)
The most practical way to use threat intelligence: bring the feeds (Q-Feeds, Spamhaus, FireHOL, Abuse.ch) in as an auto-refreshing firewall alias, then a block rule. No SOC, no complicated scripts.
# OPNsense: Firewall -> Aliases -> Add
# Type: URL Table (IPs) Refresh frequency: 1 day
# Content: URL-ul feed-ului, de ex:
# Q-Feeds: URL dedicat per cont (IP-uri + domenii malitioase)
# Spamhaus: https://www.spamhaus.org/drop/drop.txt
# FireHOL: https://iplists.firehol.org/files/firehol_level1.netset
# apoi Firewall -> Rules -> Floating -> action Block, Source = aliasul
# echivalent pe Linux pur (nftables + cron care reincarca setul zilnic):
curl -s https://www.spamhaus.org/drop/drop.txt \
| grep -oE '^[0-9.]+/[0-9]+' \
| while read cidr; do sudo nft add element inet filter blocklist "{ $cidr }"; done
Firewall / network filtering
- nftables — modern Linux firewall: sets, rate-limit, NAT, logging
- OPNsense + GeoIP2 — country blocking, IP aliases, feed integration (Q-Feeds, Spamhaus)
- pfBlockerNG (pfSense) — GeoIP + DNSBL + reputation feeds in one plugin
VPN / secure access
- WireGuard — modern, fast, simple VPN; native in kernel and OPNsense; site-to-site or road-warrior
- OpenVPN — mature, flexible, TLS; good for compatibility
- IPsec / strongSwan — standard site-to-site, interoperable with Fortinet/Cisco
Vulnerability scanning / audit
- OpenVAS / Greenbone — network vulnerability scanner, periodic reports
- Lynis — host hardening audit for Linux (CIS-like score)
- Trivy — scan Docker images / IaC for CVEs
- ClamAV — open-source antivirus (mail, files; OPNsense plugin)
- AIDE / auditd — file integrity + kernel-level system auditing
Visibility / monitoring
- ntopng — real-time traffic analysis, DPI, flows, top talkers
- Zabbix / Prometheus — infrastructure monitoring + alerting
- Netdata — real-time per-host metrics, zero-config
- Suricata EVE + Grafana — dashboards from Suricata alerts (eve.json)
Incident response
- TheHive + Cortex — incident case management + automated analyzers (IOC enrichment)
- MISP — IOC correlation across incidents and teams
Example: typical SMB stack (quick install)
A concrete starting point for a minimum viable stack:
# OPNsense (from shell): IDS/IPS + collaborative IPS
pkg install os-suricata os-crowdsec
# Linux host: CrowdSec + reputation feed in nftables
curl -s https://install.crowdsec.net | sudo sh && sudo apt -y install crowdsec
# + add a feed (Q-Feeds/Spamhaus) as a URL table alias in OPNsense (see above)
Conclusion
You do not need all of them — pick based on risk and team. Typical SMB stack: Suricata + CrowdSec on OPNsense, a Q-Feeds/Abuse.ch feed as a firewall alias, Wazuh on hosts, WireGuard for access. We design, configure and monitor it for you.