Official package repository

Install pfBlockerNG.

Self-hosted FreeBSD pkg repository for pfSense CE & pfSense Plus. Pick a channel and run its command on your firewall as root.

Channels

Stable

Latest 3.3.10

Final tagged releases (X.Y.Z) from a maintained release line. Production use.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel stable
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel stable to change.
# pfBlockerNG (stable channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-stable: {
  url: "https://pkg.pfblockerng.com/stable/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Testing

Latest 3.3.11.a1

Nonzero-patch prereleases (X.Y.Z.aN/bN/rN, Z ≠ 0) validating the next Stable of the current line. For users verifying an upcoming fix.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel testing
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel testing to change.
# pfBlockerNG (testing channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-testing: {
  url: "https://pkg.pfblockerng.com/testing/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Edge

Latest 3.3.11.a1

Patch-zero prereleases (X.Y.0.aN/bN/rN) opening the next release family. Earliest adopters.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel edge
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel edge to change.
# pfBlockerNG (edge channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-edge: {
  url: "https://pkg.pfblockerng.com/edge/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Nightly not for daily use

Latest 20261004144422.8704087

Untagged snapshot builds (YYYYMMDDHHMMSS.<7-character source SHA>) from a pinned source SHA. Every invocation builds. Bleeding edge — the only guarantee is that CI passed. Nightly versions intentionally sort above semantic versions: moving off Nightly is an explicit repository-qualified downgrade.

Install, upgrade, or switch to this channel (any starting state):

fetch -qo - https://pkg.pfblockerng.com/install.sh | sh -s -- --channel nightly
Manual conf (advanced)

The bootstrap auto-detects this; in a hand-written conf, replace <varver> (the edition-version: ce-2.8, plus-26.03, …) with your box's value.

# Generated at boot by pfblockerng_repo_generate (ADR-39) — do not edit; re-run install.sh --channel nightly to change.
# pfBlockerNG (nightly channel) — self-hosted pkg repository (ADR-17).
# Signed catalogue (issue #2675): the trust anchor is our own ECDSA key, whose
# fingerprint the boot rc.d hook installs; the fetch is plain HTTP because pkg's
# CA store is Netgate-pinned on pfSense Plus and unreachable from the GUI.
# The URL is fully resolved for this box's edition/version (ADR-39; arch-less/NO_ARCH,
# issue #1806); the boot rc.d hook updates it on a pfSense OS upgrade.
# priority 100 sits above the base Netgate `pfSense` repo so cross-repo
# resolution (pkg install/upgrade, GUI Install) selects the pfBlockerNG build.
pfblockerng-nightly: {
  url: "https://pkg.pfblockerng.com/nightly/<varver>",
  mirror_type: none,
  signature_type: fingerprints,
  fingerprints: "/usr/local/etc/pkg/fingerprints/pfblockerng",
  priority: 100,
  enabled: yes
}

Published packages

Stable

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.10FreeBSD:16:*8.53.1178ec1eb1.7 MiB
2.83.3.10FreeBSD:15:*8.33.1178ec1eb1.7 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.10FreeBSD:16:*8.53.1178ec1eb1.7 MiB
26.033.3.10FreeBSD:16:*8.53.1178ec1eb1.7 MiB
25.113.3.10FreeBSD:16:*8.43.1178ec1eb1.7 MiB

Testing

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.11.a1FreeBSD:16:*8.53.11350dfda1.7 MiB
2.83.3.11.a1FreeBSD:15:*8.33.11350dfda1.7 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.11.a1FreeBSD:16:*8.53.11350dfda1.7 MiB
26.033.3.11.a1FreeBSD:16:*8.53.11350dfda1.7 MiB
25.113.3.11.a1FreeBSD:16:*8.43.11350dfda1.7 MiB

Edge

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.93.3.11.a1FreeBSD:16:*8.53.11350dfda1.7 MiB
2.83.3.11.a1FreeBSD:15:*8.33.11350dfda1.7 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.073.3.11.a1FreeBSD:16:*8.53.11350dfda1.7 MiB
26.033.3.11.a1FreeBSD:16:*8.53.11350dfda1.7 MiB
25.113.3.11.a1FreeBSD:16:*8.43.11350dfda1.7 MiB

Nightly

pfSense CE

pfSenseVersionABIPHPPythonPublishedCommitSize
2.920261004144422.8704087FreeBSD:16:*8.53.1187040872.2 MiB
2.820261004144422.8704087FreeBSD:15:*8.33.1187040872.2 MiB
Older nightlies (8)
pfSenseVersionABIPHPPythonPublishedCommitSize
2.920261003141518.b6263b7FreeBSD:16:*8.53.11b6263b72.2 MiB
2.820261003141518.b6263b7FreeBSD:15:*8.33.11b6263b72.2 MiB
2.920261002153428.f577926FreeBSD:16:*8.53.11f5779262.2 MiB
2.820261002153428.f577926FreeBSD:15:*8.33.11f5779262.2 MiB
2.920261001161826.a3c5e4aFreeBSD:16:*8.53.11a3c5e4a2.2 MiB
2.820261001161826.a3c5e4aFreeBSD:15:*8.33.11a3c5e4a2.1 MiB
2.920260930154618.71d98a2FreeBSD:16:*8.53.1171d98a22.1 MiB
2.820260930154618.71d98a2FreeBSD:15:*8.33.1171d98a22.1 MiB

pfSense Plus

pfSenseVersionABIPHPPythonPublishedCommitSize
26.0720261004144422.8704087FreeBSD:16:*8.53.1187040872.2 MiB
26.0320261004144422.8704087FreeBSD:16:*8.53.1187040872.2 MiB
25.1120261004144422.8704087FreeBSD:16:*8.43.1187040872.2 MiB
Older nightlies (12)
pfSenseVersionABIPHPPythonPublishedCommitSize
26.0720261003141518.b6263b7FreeBSD:16:*8.53.11b6263b72.2 MiB
26.0320261003141518.b6263b7FreeBSD:16:*8.53.11b6263b72.2 MiB
25.1120261003141518.b6263b7FreeBSD:16:*8.43.11b6263b72.2 MiB
26.0720261002153428.f577926FreeBSD:16:*8.53.11f5779262.2 MiB
26.0320261002153428.f577926FreeBSD:16:*8.53.11f5779262.2 MiB
25.1120261002153428.f577926FreeBSD:16:*8.43.11f5779262.1 MiB
26.0720261001161826.a3c5e4aFreeBSD:16:*8.53.11a3c5e4a2.2 MiB
26.0320261001161826.a3c5e4aFreeBSD:16:*8.53.11a3c5e4a2.2 MiB
25.1120261001161826.a3c5e4aFreeBSD:16:*8.43.11a3c5e4a2.1 MiB
26.0720260930154618.71d98a2FreeBSD:16:*8.53.1171d98a22.1 MiB
26.0320260930154618.71d98a2FreeBSD:16:*8.53.1171d98a22.1 MiB
25.1120260930154618.71d98a2FreeBSD:16:*8.43.1171d98a22.1 MiB

Repository files

Browse every channel, version and ABI — and the raw pkg(8) catalogs your firewall fetches — in a directory-style listing.

📁 Browse the repository →