6 OPNsense plugins that make a home network a joy to use
“When you finally get tired of your ISP router, one of the most-recommended replacements is making your own with a custom OPNsense firewall. This puts the power back in your hands, limits what your ISP can do to your connection, and gives you plenty ...continues
See https://gadgeteer.co.za/6-opnsense-plugins-that-make-a-home-network-a-joy-to-use/
I wanted to create a VLAN to keep my Mastodon server separate from my LAN. Two days later, I now have 8 VLANs. I think I have a problem.
Looking for advice from #opnsense users - I'm looking to make the jump from openWRT, and eyeing up hardware.
A Trigkey g5 has caught my eye, an Intel n100 mini PC with two 2.5gb Intel i225-V NICs (rev 3 I believe from comments)
Already got a managed switch to hook it into.
Don't suppose anyone has already tested this model with OPNsense, or has any good advice about running it on similar mini PC hardware? Thanks
Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟱/𝟬𝟰/𝟮𝟴 (Valuable News - 2025/04/28) available.
https://vermaden.wordpress.com/2025/04/28/valuable-news-2025-04-28/
Past releases: https://vermaden.wordpress.com/news/
Took a while but I've discovered what I want/need for IPv6 dynamic iBGP peering with Cilium just isn't possible without hacking around OPNsense a bit.
Well, at least I *know* now it's not doable. Tweaking settings semi-blindly and poking logs wasn't exactly fulfilling.
As is par for the course I've found the GitHub issue for it closed by a stalebot.
@arichtman If you've put it in aliasses for the WAN connection, the private networks shouldn't matter .. you should never receive traffic from private networks on your wan port :)
Happy testing! I've been using #opnsense aliasses for certain routing decisions as well. I've set up a script to resolve domain names > dump the IP's in a csv > read them and route accordingly (over VPN). Soo much fun to have with that little box.
Added FireHOL blocklists to my router and feelin' powerful
Current status: Building a new version of #hbsdfw (a #HardenedBSD fork of #OPNsense ).
I"ll do a limited test deployment this week. If it works well enough, I'll publish it.
Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟱/𝟬𝟰/𝟮𝟭 (Valuable News - 2025/04/21) available.
https://vermaden.wordpress.com/2025/04/21/valuable-news-2025-04-21/
Past releases: https://vermaden.wordpress.com/news/
The hardware was refurbished, including a quick analysis of the equipment. I quickly realized that modern and up-to-date network firewall firmware could be installed on both devices without much effort and high costs. Since #BSDRP , #OPNSense and #pfSense no longer support x86 (i586/i686) architectures, the choice fell on the current #OpenWrt and #DDWRT versions for x86 (i586/i686) architectures. 2/3
@gadgetboy nice hardware ! I use #Protectli hardware to get #Coreboot + TPM out of the box. A bit pricier but worth it IMO. Check this guy's #OPNsense playlists to get started (including Wifi): https://www.youtube.com/@homenetworkguy/playlists
My aging #Ubiquiti Edgerouter-X is failing. So, I spent 3 hours yesterday trying to set up a new #Unifi Gateway Max without success. I'm returning it.
I decided to just get a #miniPC with dual 2.5Gbe and install #Opnsense on it. (This guy: https://a.co/d/431PbIV)
I'm hoping it arrives early because I'm not sure the Edgerouter will last until next month. I've also never used Opnsense, so this will be another grand experiment.
Maybe I'll install it in a VM on Proxmox for now so I can FAFO.
Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟱/𝟬𝟰/𝟭𝟰 (Valuable News - 2025/04/14) available.
https://vermaden.wordpress.com/2025/04/14/valuable-news-2025-04-14/
Past releases: https://vermaden.wordpress.com/news/
Wie bringt man die Mitmenschen nur dazu, den Mailverkehr zu verschlüsseln? Stöhn...
#OPNsense users, it is time to migrate your legacy #IPSEC VPN tunnels to the new connection setup. The Legacy IPSEC feature will be deprecated in 26.1.
I have updated my IPSEC post [1] with the new connection settings. The migration was not straightforward and required some changes, but it is not complicated either.
A little gem here is the #CIDR subnet mask notation used for Policy Based Routing, which allows multiple subnets (#VLANs) on both sides to be automatically routed, without the need for ongoing changes to tunnel settings.
[1]: https://du.nkel.dev/blog/2021-11-19_pfsense_opnsense_ipsec_cgnat/
Making use of another #maintenanceWindow and upgraded #opnsense to 25.1.5_4.
Boring as usual ;)
My #OpnSense router upgrade tanked today. However I managed to download an image with my phone as a hotspot and began the reinstall process ... Only to find that the installer was happy to use the existing settings off the hard drive! I'd like to thank whichever genius came up with that idea. It saved hours of fiddling around and Just Worked(TM) #BSD