Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - patlegu

#1
General Discussion / Re: Let's AI Opnsense!
August 14, 2026, 05:52:26 PM
Hello,

The pages should be accessibles now; there were some minor issues with the site's geographic exclusion settings.

No worries, I understand your point of view. I'm not trying to sell anything. What you'll find in my notebook (nope.breizhland.eu) is strictly for my personal use. I log my tests there, along with site translations for quick reference, cheat sheets, and so on. If others find it useful, that's great, but it's not the primary goal. To circle back to my previous message: all my tests are run on the CPU using SLMs (Small Language Models) with the lightest possible system footprint. The results aren't always perfect, but that's part of the game.

My colleagues didn't think a practical implementation was possible, but it turned out to be—thanks to automation tools (OpenTofu, Ansible, etc.) that dynamically manage the creation and teardown of SLMs as supplementary resources. Admittedly, at the individual SLM level, it's 10 times slower on a CPU, but it costs 25 to 30 times less. You can have multiple SLMs processing incident queues or work orders. I'm not claiming this is *the* solution, but others might well find it useful at some point. Or not. :-) I don't use an MCP server; I rely solely on custom-built corpora. Training and validation are based on JSONL files containing thousands of lines, which serve as the foundation for training these LoRAs.

As for my current project, I'm simply exploring ways to use SaaS-based LLMs while keeping sensitive information out of their reach. I don't claim the results will be definitive. We'll see—the project might not pan out—but I'll have learned a lot along the way.

Regarding firewall security, I completely agree. Adding an internal AI component only increases the attack surface; this test was intended solely to observe the potential outcome. Nothing was deployed to production based on this, and I certainly wouldn't recommend doing so—quite the opposite, in fact.

In any case, thanks for the feedback. Have a great day.
Pat.

I almost forgot: all these "projects" are merely PoCs and have no other value. They should not be put into production as-is.
#2
General Discussion / Re: Let's AI Opnsense!
August 14, 2026, 06:09:02 AM
Hello,

I've done some experiment around AI and opnsense. I start last year by training a SLM with some opnsense functions, less than 12, to see how it goes. Two month later, my Lora was working well with the 102 functions and I decide to make a lab to check what it can do alone on a real opnsense connected directly to internet.

My lab was an Agentic SOC (Security Operation Center) with 3 kind of SLMs (1 opnsense, 1 SOC, 1 CERT). The purpose was to check what was possible to do with some small servers without GPU. You can find some informations on this here . It has worked pretty good and the opnsense agent was able to had or remove some rules to the firewall. It's not what you have in mind but can give some ideas. It worked well, in the sense that more specialized agents had to be created as the attacks occurred.

I've tried after that to go from the side-car version to the full opnsense integrated SLM. version. Still in French. It was working pretty good excepted that you have to have more CPU and RAM due to inference directly in the box.

I hope this information regarding the use of SLMs with OPNsense has been helpful.

I am currently looking into whether this operational approach using LoRAs (OPNsense, WireGuard, CrowdSec) is still relevant, given how much LLMs have evolved over the past eight months.
I have started a new project(English) addressing various issues related to managing sensitive information in cybersecurity, particularly concerning firewalls—specifically, how to use an LLM without compromising sovereignty or the confidentiality of configurations. With a small testing interface. Should have bug as it's under heavy dev for the moment.

I hope I haven't been too long-winded or boring.
Pat.