I believe what I am trying to do is set up a wireless network (wifi?)
using a mini pc as an opnsense box
what im struggling to understand - is if I want to create a network ssid -- and use WPA2 encryption...
- I have 4 ethernet ports
- I want to connect my mini pc to my isp modem (as the gateway to internet)
- then I want my devices to connect to the opensense box - to have traffic go through the firewall and unbound using quad nine
https://docs.opnsense.org/manual/how-tos/interface_wireless_internal.html
do I need to install the addon Radius - in order to set up a network? (ssid: password for people to log in with)
do I need to do anything special in order for my mini pc to be used as a wifi router / connect things to it
Quote from: lumilumi on June 04, 2026, 08:21:10 AMI believe what I am trying to do is set up a wireless network (wifi?)
using a mini pc as an opnsense box
what im struggling to understand - is if I want to create a network ssid -- and use WPA2 encryption...
- I have 4 ethernet ports
- I want to connect my mini pc to my isp modem (as the gateway to internet)
- then I want my devices to connect to the opensense box - to have traffic go through the firewall and unbound using quad nine
https://docs.opnsense.org/manual/how-tos/interface_wireless_internal.html
do I need to install the addon Radius - in order to set up a network? (ssid: password for people to log in with)
do I need to do anything special in order for my mini pc to be used as a wifi router / connect things to it
You should not use opnsense as a wifi access point. It can work, but its terrible. Get the proper standalone wifi access point and attach it to one of the ports.
I thought that wireless access points were by default a bit unsecure - do you have a reccommendation for one less than $100?
Quote from: lumilumi on June 04, 2026, 09:13:44 AMI thought that wireless access points were by default a bit unsecure
You thought wrong. Access points from Ubiquiti or Grandstream have WPA3 and WPA3 Enterprise support. They also support per SSID VLAN segmentation and they can work with RADIUS authentication servers. And lets not even get into performance metrics and reliability.
There are several things you should never do with your opnsense box.
Use it as a soft switch.
Use it as an wifi access point.
Use USB devices on it.
Quote from: lumilumi on June 04, 2026, 09:13:44 AM- do you have a reccommendation for one less than $100?
Grandstream GWN7604. Keep in mind that some of these devices are not shipped with power supply so you will need PoE injector or PoE switch.
You could find a used wifi router that has current OpenWRT support and just use it as a access point.
Quote from: lumilumi on June 04, 2026, 09:13:44 AMI thought that wireless access points were by default a bit unsecure - do you have a reccommendation for one less than $100?
TP-Link Omada has some nice Wall models for sub € 100 prices over here so check if it's the same in the U.S.A. :)
Stay away from TP-Link garbage !!!! Check level-1 tech forums if you want to see why.
Quote from: Nullman on June 05, 2026, 05:02:19 PMStay away from TP-Link garbage !!!! Check level-1 tech forums if you want to see why.
You have now basically told me NOTHING...
- Provide a link to the specific sub-forum or topic there.
- Specify what is going on exactly and what I will read there in short.
Then I might actually take the effort to do so ;)
FYI :I think I have read enough in the past about their Omada stuff and some regular Routers/Switches/Accesspoints to know if it's a good or bad brand, but feel free to proof me wrong! :)
Quote from: nero355 on June 05, 2026, 05:55:01 PMYou have now basically told me NOTHING...
I was not talking to you.
Quote from: nero355 on June 05, 2026, 05:55:01 PM- Provide a link to the specific sub-forum or topic there.
- Specify what is going on exactly and what I will read there in short.
Then I might actually take the effort to do so ;)
FYI :
I think I have read enough in the past about their Omada stuff and some regular Routers/Switches/Accesspoints to know if it's a good or bad brand, but feel free to proof me wrong! :)
No.
Quote from: RobertoZ on June 05, 2026, 02:56:00 AMYou could find a used wifi router that has current OpenWRT support and just use it as a access point.
well, the reason I am switching to opensense, is that openwrt has been filled with llm coding -- I could never get it to work properly anyway -_-
is there a guide for this I could look into? I still have my openwrt one box
Quote from: Nullman on June 04, 2026, 09:29:42 AMQuote from: lumilumi on June 04, 2026, 09:13:44 AMI thought that wireless access points were by default a bit unsecure
You thought wrong. Access points from Ubiquiti or Grandstream have WPA3 and WPA3 Enterprise support. They also support per SSID VLAN segmentation and they can work with RADIUS authentication servers. And lets not even get into performance metrics and reliability.
There are several things you should never do with your opnsense box.
Use it as a soft switch.
Use it as an wifi access point.
Use USB devices on it.
Quote from: lumilumi on June 04, 2026, 09:13:44 AM- do you have a reccommendation for one less than $100?
Grandstream GWN7604. Keep in mind that some of these devices are not shipped with power supply so you will need PoE injector or PoE switch.
thank you very much for the recommendation!
I will shop around
in all honesty - is there anyone around who has used something like this method before that would be willing to walk me through it?
is it complicated for a networking newbie?
I have already set up opensense box on a mini pc (and gone through some of the settings / watched many tutorials / learned a lot about networks)
I have already done some work with openwrt as well and my router is already in bridge mode
I have just never worked through using a wireless access point (I feel so old fashioned, lol)
Quote from: lumilumi on June 06, 2026, 06:06:13 AMI have already done some work with openwrt as well and my router is already in bridge mode
I have just never worked through using a wireless access point (I feel so old fashioned, lol)
Much of it is new to me also but in my unqualified opinion an opnsense router coupled with openwrt access point(s) is an appealing combo for a home user. You are able to re-purpose your existing gear or buy cost effective secondhand and there is ample documentation on both. I have a couple of meraki units, running openwrt in 'dumb AP mode', connected via a small managed switch. You can in theory connect the APs directly to the opnsense box, but this can lead to interface issues on the router side. Check out the openwrt guides for access point only mode. Then consult the docs here for opnsense vlans.
not to say I know much - but isn't llm generated code extremely unsecure as well? Wouldn't that ruin the whole point of trying to use a firewall?
With hardware/driver support limiting what you can do with wifi on opnsense, and concerns you have about wireless access point security, physically separate devices would seem the best choice for you. That or no wireless network.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMin all honesty - is there anyone around who has used something like this method before that would be willing to walk me through it?
Not only i use it every day for the last 12 years, i implemented such solutions to a lot of people. And they use it for many years not even thinking about it.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMis it complicated for a networking newbie?
Its not complicated. Once you figure out how to configure interfaces in opnsense, you are pretty much set. How are you going to configure your access point depends on what that device actually is.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMI have already set up opensense box on a mini pc (and gone through some of the settings / watched many tutorials / learned a lot about networks)
In this case, the most complicated part for a newbie would be configuring additional port on opnsense to work on a different subnet. Once you do that, you just attach access point to that port, and you are done.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMI have just never worked through using a wireless access point (I feel so old fashioned, lol)
Its because there are endless ways on how you can do this. Not all of them are correct though. Especially if security and performance are your priority. Just because some solution works doesnt mean its implemented correctly.
Quote from: keeka on June 06, 2026, 08:00:03 AMMuch of it is new to me also but in my unqualified opinion an opnsense router coupled with openwrt access point(s) is an appealing combo for a home user. You are able to re-purpose your existing gear or buy cost effective secondhand and there is ample documentation on both. I have a couple of meraki units, running openwrt in 'dumb AP mode', connected via a small managed switch.
Repurposing your old gear is nice if your gear comes from reputable manufacturer that does things correctly,. OpenWRT is great. I love it. However, running OpenWRT on TP-Link is not the same as running it on Cisco Meraki. TP-Link has critical flaws in its hardware and how it handles its port during device booting. Cisco Meraki has no such issues. And lets not even go into build quality and internal hardware choices.
Quote from: keeka on June 06, 2026, 08:00:03 AMYou can in theory connect the APs directly to the opnsense box, but this can lead to interface issues on the router side. Check out the openwrt guides for access point only mode. Then consult the docs here for opnsense vlans.
You just need to make sure that your wireless device is working in AP mode. Avoid running wireless devices in router mode because then you have NAT and additional DHCP server which are not needed in this case.
so ive been talking too with my buddy about this
we've come up with the solution of
ISP modem -- connecting to mini PC running opensense
then repurposing my old "openwrt one" (openwrt one is a box that openwrt designed to run openwrt / supports their funds)
to run that as the wifi piece (since I already have this box)
I may switch the openwrt one to a netgear: https://www.amazon.com/NETGEAR-Wireless-Access-Point-WAX210PA/dp/B0DLDMHCWC
how do I configure the settings in order for the mini pc to "send the internet" to the openwrt one, so that the openwrt one can be my wifi access point?
Quote from: lumilumi on June 09, 2026, 01:22:20 AMhow do I configure the settings in order for the mini pc to "send the internet" to the openwrt one, so that the openwrt one can be my wifi access point?
You have choices. Each one requires OpenWRT one operating in AP mode.
1. You connect OpenWRT one to your existing LAN port.
2. You configure another port/subnet on opnsense box and connect your OpenWRT to that port.
Number 2 is proper way of doing thigs.
Quote from: lumilumi on June 09, 2026, 01:22:20 AMhow do I configure the settings in order for the mini pc to "send the internet" to the openwrt one, so that the openwrt one can be my wifi access point?
Just connect it to your network and create the SSID and you are DONE! :)
However if you have VLANs on your OPNsense then the whole story gets totally different and you need to do some reading before getting everything up and running...
But if I may ask :
What was the reason you have chosen to use OPNsense if you are having issues with this kind of stuff ?!
Why not simply buy a nice "All-in-One" Router or something targeted more at regular home users so to speak ??
Quote from: lumilumi on June 06, 2026, 08:11:28 AMnot to say I know much - but isn't llm generated code extremely unsecure as well? Wouldn't that ruin the whole point of trying to use a firewall?
The OpenWRT One is a great piece of kit. If you are using is as just an access point, it does no firewall duties, OpenSense will handle that.
There are numerous guides and tutorials on the web on how to setup an OpenWRT router as just an AP. It takes not even five minutes. Turn off all DHCP and DNS services. Configure it to get an automatic IP from upstream DHCP server (OpenSnese) and setup your SSID's and go.
Quote from: RobertoZ on June 09, 2026, 07:37:11 PMConfigure it to get an automatic IP from upstream DHCP server (OPNsense)
I always do two things :
- Give important devices their own Static IP Address configuration.
- Only configure a Static DHCP Mapping based on the MAC Address as the backup option for that configuration in case something breaks in the OS because of some update or whatever...
I would never use just one of the above on my network(s) :)
An interface is an interface. If the device has a builtin wifi device, then it can be used as an interface. Wifi can be AP, ad-hoc, bridge.
So what's the question?
Quote from: lumilumi on June 04, 2026, 09:13:44 AMI thought that wireless access points were by default a bit unsecure - do you have a reccommendation for one less than $100?
Looks like you're already sorted for hardware but in case you have to go shopping, keep the U7 Lite on your list. Unlike its bigger WiFi-7 siblings it lacks 6GHz and only has 2x2 antennas, but depending on the size of your home it may suit you fine. Mine has surprisingly good coverage and only uses ~6W PoE budget with conservative settings (I don't go crazy with high gain and ultrawide/DFS channels).
They don't bundle a power supply, though. You need either a PoE switch or an injector.
Supposedly you can set it up easily from your phone with just the app making it basically plug & play. I haven't tried that method.
Quote from: OPNenthu on June 10, 2026, 05:02:59 AMSupposedly you can set it up easily from your phone with just the app making it basically plug & play. I haven't tried that method.
Just...
Don't.I lost count of the number of times people were messing around with that thing and I always had to tell them :
- Use the UniFi Controller.
- Also use a nice PC or Laptop with a regular browser to access the webGUI.
And suddenly all the issues were solved like some kind of miracle! LOL!
All those phones and tablets and their stupid apps have really ruined this world... :'(
I'm only recommending it for the OP because I know it can be deployed simply. If they're just starting out I wouldn't push them toward hosting a UniFi controller and in that case they should probably skip the UniFi APs, tbh.
Quote from: nero355 on June 09, 2026, 02:36:43 PMQuote from: lumilumi on June 09, 2026, 01:22:20 AMhow do I configure the settings in order for the mini pc to "send the internet" to the openwrt one, so that the openwrt one can be my wifi access point?
Just connect it to your network and create the SSID and you are DONE! :)
However if you have VLANs on your OPNsense then the whole story gets totally different and you need to do some reading before getting everything up and running...
because I want to have ore security in my network than just an all in one ....
But if I may ask :
What was the reason you have chosen to use OPNsense if you are having issues with this kind of stuff ?!
Why not simply buy a nice "All-in-One" Router or something targeted more at regular home users so to speak ??
Quote from: lumilumi on June 13, 2026, 03:39:46 AMbecause I want to have more security in my network than just an all in one ....
I am curious : Why do you think that exactly ? :)
Quote from: Nullman on June 06, 2026, 10:58:25 AMQuote from: lumilumi on June 06, 2026, 06:06:13 AMin all honesty - is there anyone around who has used something like this method before that would be willing to walk me through it?
Not only i use it every day for the last 12 years, i implemented such solutions to a lot of people. And they use it for many years not even thinking about it.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMis it complicated for a networking newbie?
Its not complicated. Once you figure out how to configure interfaces in opnsense, you are pretty much set. How are you going to configure your access point depends on what that device actually is.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMI have already set up opensense box on a mini pc (and gone through some of the settings / watched many tutorials / learned a lot about networks)
In this case, the most complicated part for a newbie would be configuring additional port on opnsense to work on a different subnet. Once you do that, you just attach access point to that port, and you are done.
Quote from: lumilumi on June 06, 2026, 06:06:13 AMI have just never worked through using a wireless access point (I feel so old fashioned, lol)
Its because there are endless ways on how you can do this. Not all of them are correct though. Especially if security and performance are your priority. Just because some solution works doesnt mean its implemented correctly.
Quote from: keeka on June 06, 2026, 08:00:03 AMMuch of it is new to me also but in my unqualified opinion an opnsense router coupled with openwrt access point(s) is an appealing combo for a home user. You are able to re-purpose your existing gear or buy cost effective secondhand and there is ample documentation on both. I have a couple of meraki units, running openwrt in 'dumb AP mode', connected via a small managed switch.
Repurposing your old gear is nice if your gear comes from reputable manufacturer that does things correctly,. OpenWRT is great. I love it. However, running OpenWRT on TP-Link is not the same as running it on Cisco Meraki. TP-Link has critical flaws in its hardware and how it handles its port during device booting. Cisco Meraki has no such issues. And lets not even go into build quality and internal hardware choices.
Quote from: keeka on June 06, 2026, 08:00:03 AMYou can in theory connect the APs directly to the opnsense box, but this can lead to interface issues on the router side. Check out the openwrt guides for access point only mode. Then consult the docs here for opnsense vlans.
You just need to make sure that your wireless device is working in AP mode. Avoid running wireless devices in router mode because then you have NAT and additional DHCP server which are not needed in this case.
all right - ive been trying to get my openwrt one box (bigblue) working in a dumb AP configuration (disabling DCHP) and attempting to set it to access point only mode
but problem 1 - opnsense box (blackbox) is not giving the internet to blue
problem 2 - when I disable dhcp (ignore the interface on blue) the ability to connect to blue (through ethernet or through wireless) does not work at all
for clarity
black is connected through ethernet to ISP modem - then blue is connected to black through ethernet as well
(i'm pretty sure im getting the ports correct cause I set them manually)
does anyone have any other ideas? or recommendations?
Quote from: keeka on June 06, 2026, 09:10:18 AMWith hardware/driver support limiting what you can do with wifi on opnsense, and concerns you have about wireless access point security, physically separate devices would seem the best choice for you. That or no wireless network.
thanks for the response - my plan is to use my old openwrt one box as an access point only!
Quote from: lumilumi on June 14, 2026, 03:48:52 AMdoes anyone have any other recommendations?
Get a all-in-one box, it will be more secure for you than doing the stuff all on your own.