OPNsense Forum

English Forums => Virtual private networks => Topic started by: TheDragon on October 22, 2025, 07:27:34 PM

Title: FR: Will OPNsense adopt the new Endpoint-Independent NAT Patch?
Post by: TheDragon on October 22, 2025, 07:27:34 PM
As per the title really, I was reading that Tailscale sponsored a NAT Implementation in FreeBSD, which has made its way into pfSense - https://tailscale.com/blog/nat-traversal-improvements-pt-1#sponsoring-freebsds-endpoint-independent-nat-patch

This seems like a really useful compromise, which I imagine would be fairly popular.

For clarity I'm not seeking timelines or anything - I'm purely seeking clarity on whether its on the roadmap and/or whether any maintainers would be likely to be interested in implementing it in OPNsense?

Title: Re: FR: Will OPNsense adopt the new Endpoint-Independent NAT Patch?
Post by: cdine on November 18, 2025, 11:29:58 AM
Just replying to also voice my desire and support of this feature.

The Tailscale team has done some great work with this upstream in FreeBSD/pf with the FreeBSD Foundation's support. They called out OPNSense by name, so I do hope this makes its way in to OPNSense once it makes its way in to FreeBSD stable. From the looks of things, it is not yet there - see discussion in the review link below.

There appears to have also been an issue opened in the OPNSense repo asking for support of this, but it was auto-closed.

Links:
Title: Re: FR: Will OPNsense adopt the new Endpoint-Independent NAT Patch?
Post by: Monviech (Cedrik) on November 18, 2025, 11:46:30 AM
Reading the reviews link it does not seem like that commit is in FreeBSD 14. Which means this will not hit the OPNsense kernel for a while if its not backported. So this looks more like it takes well into 2026-27 and FreeBSD 15 based OPNsense.