Hi,
I'm using OPNSense as my main router with a number of switches and APs of different brands. Is there a way to see a visual or text-based map of all of the clients on the system (like the ARP list), but also showing where they came through?
Use case:
- Knowing that a desktop is connected through a specific switch
- Knowing that a Wifi device moved between APs
OpnSense does not know anything about this other than on which interface a client is connected to, so what you want is not feasible using it.
There is network equipment available that can show you things like that, however. Take a look at Unifi switches and APs. My personal opinion is that they are quite good at making those, less good at making routers (I use OpnSense for that).
You do not need a dream box or any of their routers, though. The network controller can be run on x64 hardware or as a VM (the software is called Unifi OS server and is free).
Quote from: fmstrat on October 05, 2026, 07:13:42 PMIs there a way to see a visual or text-based map of all of the clients on the system (like the ARP list), but also showing where they came through?
Someone has made EXACTLY THAT for OPNsense a couple of months ago IIRC :)
Quote from: meyergru on October 05, 2026, 07:21:08 PMThere is network equipment available that can show you things like that, however.
Take a look at Unifi switches and APs.
My personal opinion is that they are quite good at making those, less good at making routers (I use OpnSense for that).
You do not need a dream box or any of their routers, though. The network controller can be run on x64 hardware or as a VM (the software is called Unifi OS server and is free).
And seemed to work more reliable than the Network Topology View from Ubiquiti in the UniFi Controller from what I have seen so far !!
Not bad for something that was made over a weekend... LOL! :P
Quote from: nero355 on October 05, 2026, 09:50:48 PMSomeone has made EXACTLY THAT for OPNsense a couple of months ago IIRC :)
How so? Any IP packet does not carry any information through what cascade of layer 2 or layer 3 devices it passed before it reached OPNsense. Technically impossible.
Unless the devices in question are themselves manageable and you use an NMS via e.g. SNMP that queries these and employs some clever heuristics. This solution of course exists.
Quote from: Patrick M. Hausen on October 05, 2026, 09:58:44 PMHow so?
Like so : https://forum.opnsense.org/index.php?topic=50932.0
Needed some time to find the right topic ;)
QuoteAny IP packet does not carry any information through what cascade of layer 2 or layer 3 devices it passed before it reached OPNsense. Technically impossible.
Unless the devices in question are themselves manageable and you use an NMS via e.g. SNMP that queries these and employs some clever heuristics. This solution of course exists.
Aks the developer and we will see what he says :)
I rarely declare something outright impossible.
In this particular case: the proof is in the pudding. Nobody but the person who started that cited thread has seen a single line of code. And quite possibly not even them. I call fake unless proven otherwise.
So do I.
Aha. Found it:
https://github.com/flaviuvlaicu/opnsense-topo-map
I had a look at the code. The plugin does not actually discover the network topology. It merely collects clients from ARP/Kea; the relationships between clients, switches and APs are then defined manually by the user via drag & drop and stored in topology.json.
There is no LLDP, SNMP, switch MAC-table or controller data being queried. Therefore, the plugin cannot determine which switch/port a client is actually connected through, nor can it detect when a wireless client roams from one AP to another.
So essentially, it is a graphical network diagram editor with an automatically populated client list, not an automatic topology discovery tool.
That said, I would be rather cautious about installing software from arbitrary GitHub repositories on an OPNsense firewall.