Official package repository

Install pfBlockerNG.

Self-hosted FreeBSD pkg repository for pfSense CE & pfSense Plus. Pick a channel and run its command on your firewall as root.

Channels

Stable

Latest 3.3.8

Final tagged releases (X.Y.Z) from a maintained release line. Production use.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel stable
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel stable to change.
# pfBlockerNG (stable channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-stable: {
  url: "https://pkg.pfblockerng.com/stable/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Testing

Latest 3.3.8

Nonzero-patch prereleases (X.Y.Z.aN/bN/rN, Z ≠ 0) validating the next Stable of the current line. For users verifying an upcoming fix.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel testing
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel testing to change.
# pfBlockerNG (testing channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-testing: {
  url: "https://pkg.pfblockerng.com/testing/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Edge

Latest 3.3.8

Patch-zero prereleases (X.Y.0.aN/bN/rN) opening the next release family. Earliest adopters.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel edge
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel edge to change.
# pfBlockerNG (edge channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-edge: {
  url: "https://pkg.pfblockerng.com/edge/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Nightly not for daily use

Latest 20260907145518.e7b41e9

Untagged snapshot builds (YYYYMMDDHHMMSS.<7-character source SHA>) from a pinned source SHA. Every invocation builds. Bleeding edge — the only guarantee is that CI passed. Nightly versions intentionally sort above semantic versions: moving off Nightly is an explicit repository-qualified downgrade.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel nightly
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel nightly to change.
# pfBlockerNG (nightly channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-nightly: {
  url: "https://pkg.pfblockerng.com/nightly/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Published packages

Stable

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
2.83.3.8FreeBSD:15:*8.33.11498690e1.7 MiB
Older releases (8)
pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
2.83.3.7FreeBSD:15:*8.33.11f540a731.7 MiB
2.93.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
2.83.3.4FreeBSD:15:*8.33.11f540a731.7 MiB
2.93.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
2.83.3.3FreeBSD:15:*8.33.1116fd5621.7 MiB
2.93.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB
2.83.3.2FreeBSD:15:*8.33.11f2c56501.7 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
26.033.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
25.113.3.8FreeBSD:16:*8.43.11498690e1.7 MiB
Older releases (9)
pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
26.033.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
25.113.3.7FreeBSD:16:*8.43.11f540a731.7 MiB
26.073.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
26.033.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
26.073.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
26.033.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
26.073.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB
26.033.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB

Testing

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
2.83.3.8FreeBSD:15:*8.33.11498690e1.7 MiB
Older releases (10)
pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
2.83.3.7FreeBSD:15:*8.33.11f540a731.7 MiB
2.93.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
2.83.3.4FreeBSD:15:*8.33.11f540a731.7 MiB
2.93.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
2.83.3.3FreeBSD:15:*8.33.1116fd5621.7 MiB
2.93.3.3.a1FreeBSD:16:*8.53.1116fd5621.7 MiB
2.83.3.3.a1FreeBSD:15:*8.33.1116fd5621.7 MiB
2.93.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB
2.83.3.2FreeBSD:15:*8.33.11f2c56501.7 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
26.033.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
25.113.3.8FreeBSD:16:*8.43.11498690e1.7 MiB
Older releases (11)
pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
26.033.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
25.113.3.7FreeBSD:16:*8.43.11f540a731.7 MiB
26.073.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
26.033.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
26.073.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
26.033.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
26.073.3.3.a1FreeBSD:16:*8.53.1116fd5621.7 MiB
26.033.3.3.a1FreeBSD:16:*8.53.1116fd5621.7 MiB
26.073.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB
26.033.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB

Edge

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
2.83.3.8FreeBSD:15:*8.33.11498690e1.7 MiB
Older releases (10)
pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
2.83.3.7FreeBSD:15:*8.33.11f540a731.7 MiB
2.93.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
2.83.3.4FreeBSD:15:*8.33.11f540a731.7 MiB
2.93.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
2.83.3.3FreeBSD:15:*8.33.1116fd5621.7 MiB
2.93.3.3.a1FreeBSD:16:*8.53.1116fd5621.7 MiB
2.83.3.3.a1FreeBSD:15:*8.33.1116fd5621.7 MiB
2.93.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB
2.83.3.2FreeBSD:15:*8.33.11f2c56501.7 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
26.033.3.8FreeBSD:16:*8.53.11498690e1.7 MiB
25.113.3.8FreeBSD:16:*8.43.11498690e1.7 MiB
Older releases (11)
pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
26.033.3.7FreeBSD:16:*8.53.11f540a731.7 MiB
25.113.3.7FreeBSD:16:*8.43.11f540a731.7 MiB
26.073.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
26.033.3.4FreeBSD:16:*8.53.11f540a731.7 MiB
26.073.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
26.033.3.3FreeBSD:16:*8.53.1116fd5621.7 MiB
26.073.3.3.a1FreeBSD:16:*8.53.1116fd5621.7 MiB
26.033.3.3.a1FreeBSD:16:*8.53.1116fd5621.7 MiB
26.073.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB
26.033.3.2FreeBSD:16:*8.53.11f2c56501.7 MiB

Nightly

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.920260907145518.e7b41e9FreeBSD:16:*8.53.11e7b41e92.1 MiB
2.820260907145518.e7b41e9FreeBSD:15:*8.33.11e7b41e92.1 MiB
Older nightlies (8)
pfSenseVersionABIPHPPythonPublishedCommitSize
2.920260906124313.caa1014FreeBSD:16:*8.53.11caa10142.1 MiB
2.820260906124313.caa1014FreeBSD:15:*8.33.11caa10142.1 MiB
2.920260905123014.713025fFreeBSD:16:*8.53.11713025f2.1 MiB
2.820260905123014.713025fFreeBSD:15:*8.33.11713025f2.1 MiB
2.920260904131824.58f7b57FreeBSD:16:*8.53.1158f7b572.1 MiB
2.820260904131824.58f7b57FreeBSD:15:*8.33.1158f7b572.1 MiB
2.920260903132308.2c012d8FreeBSD:16:*8.53.112c012d82.1 MiB
2.820260903132308.2c012d8FreeBSD:15:*8.33.112c012d82.1 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.0720260907145518.e7b41e9FreeBSD:16:*8.53.11e7b41e92.1 MiB
26.0320260907145518.e7b41e9FreeBSD:16:*8.53.11e7b41e92.1 MiB
25.1120260907145518.e7b41e9FreeBSD:16:*8.43.11e7b41e92.1 MiB
Older nightlies (12)
pfSenseVersionABIPHPPythonPublishedCommitSize
26.0720260906124313.caa1014FreeBSD:16:*8.53.11caa10142.1 MiB
26.0320260906124313.caa1014FreeBSD:16:*8.53.11caa10142.1 MiB
25.1120260906124313.caa1014FreeBSD:16:*8.43.11caa10142.1 MiB
26.0720260905123014.713025fFreeBSD:16:*8.53.11713025f2.1 MiB
26.0320260905123014.713025fFreeBSD:16:*8.53.11713025f2.1 MiB
25.1120260905123014.713025fFreeBSD:16:*8.43.11713025f2.1 MiB
26.0720260904131824.58f7b57FreeBSD:16:*8.53.1158f7b572.1 MiB
26.0320260904131824.58f7b57FreeBSD:16:*8.53.1158f7b572.1 MiB
25.1120260904131824.58f7b57FreeBSD:16:*8.43.1158f7b572.1 MiB
26.0720260903132308.2c012d8FreeBSD:16:*8.53.112c012d82.1 MiB
26.0320260903132308.2c012d8FreeBSD:16:*8.53.112c012d82.1 MiB
25.1120260903132308.2c012d8FreeBSD:16:*8.43.112c012d82.1 MiB

Repository files

Browse every channel, version and ABI — and the raw pkg(8) catalogs your firewall fetches — in a directory-style listing.

📁 Browse the repository →