OPNsense Forum

English Forums => High availability => Topic started by: ctmarc on December 12, 2025, 11:25:25 AM

Title: Permission to enter carp maintenance mode for other groups/users
Post by: ctmarc on December 12, 2025, 11:25:25 AM
Hello, I'm trying to set up a user group with slightly reduced privileges, on OPNsense 25.7.9-amd64.
This group should be able to switch into CARP maintenance mode, for example to update the system, besides other tasks.

Now the "Virtual IPs -> Status" page is accessible, but when clicking one of the 2 buttons, nothing happens except for a popup with title "Error changing status" and message "200". I'm not sure whether it's intended that way and root is required to modify network interfaces, or I've missed something, or whether it's maybe a bug.

Edit -- found the simple solution, after adding "all privileges" to the user, everything works, on the other hand it's not possible to lock anything anymore.