Hello,
I've done some experiment around AI and opnsense. I start last year by training a SLM with some opnsense functions, less than 12, to see how it goes. Two month later, my Lora was working well with the 102 functions and I decide to make a lab to check what it can do alone on a real opnsense connected directly to internet.
My lab was an Agentic SOC (Security Operation Center) with 3 kind of SLMs (1 opnsense, 1 SOC, 1 CERT). The purpose was to check what was possible to do with some small servers without GPU. You can find some informations on this here . It has worked pretty good and the opnsense agent was able to had or remove some rules to the firewall. It's not what you have in mind but can give some ideas. It worked well, in the sense that more specialized agents had to be created as the attacks occurred.
I've tried after that to go from the side-car version to the full opnsense integrated SLM. version. Still in French. It was working pretty good excepted that you have to have more CPU and RAM due to inference directly in the box.
I hope this information regarding the use of SLMs with OPNsense has been helpful.
I am currently looking into whether this operational approach using LoRAs (OPNsense, WireGuard, CrowdSec) is still relevant, given how much LLMs have evolved over the past eight months.
I have started a new project(English) addressing various issues related to managing sensitive information in cybersecurity, particularly concerning firewalls—specifically, how to use an LLM without compromising sovereignty or the confidentiality of configurations. With a small testing interface. Should have bug as it's under heavy dev for the moment.
I hope I haven't been too long-winded or boring.
Pat.
I've done some experiment around AI and opnsense. I start last year by training a SLM with some opnsense functions, less than 12, to see how it goes. Two month later, my Lora was working well with the 102 functions and I decide to make a lab to check what it can do alone on a real opnsense connected directly to internet.
My lab was an Agentic SOC (Security Operation Center) with 3 kind of SLMs (1 opnsense, 1 SOC, 1 CERT). The purpose was to check what was possible to do with some small servers without GPU. You can find some informations on this here . It has worked pretty good and the opnsense agent was able to had or remove some rules to the firewall. It's not what you have in mind but can give some ideas. It worked well, in the sense that more specialized agents had to be created as the attacks occurred.
I've tried after that to go from the side-car version to the full opnsense integrated SLM. version. Still in French. It was working pretty good excepted that you have to have more CPU and RAM due to inference directly in the box.
I hope this information regarding the use of SLMs with OPNsense has been helpful.
I am currently looking into whether this operational approach using LoRAs (OPNsense, WireGuard, CrowdSec) is still relevant, given how much LLMs have evolved over the past eight months.
I have started a new project(English) addressing various issues related to managing sensitive information in cybersecurity, particularly concerning firewalls—specifically, how to use an LLM without compromising sovereignty or the confidentiality of configurations. With a small testing interface. Should have bug as it's under heavy dev for the moment.
I hope I haven't been too long-winded or boring.
Pat.
"