Recent posts

#1
Q-Feeds (Threat intelligence) / Re: License Renewal
Last post by Patrick M. Hausen - October 05, 2026, 11:42:09 PM
Looks good! Thanks.
#2
Q-Feeds (Threat intelligence) / Re: License Renewal
Last post by Q-Feeds - October 05, 2026, 11:40:28 PM
Hi Patrick! Thank you for your feedback as well. It only wasn't visible for customers who have purchased the license via our 'old' website. We've switched to the new website in July. As an early adopter you weren't able to see it. We've now backfilled the database so it should be visible for you as well.
#3
26.7 Series / Re: os-upnp plugin not working...
Last post by AlpAne - October 05, 2026, 11:13:00 PM
Quote from: nero355 on October 05, 2026, 09:42:31 PM
Quote from: AlpAne on October 05, 2026, 04:40:23 PMI just checked and I already have a rule in Firewall: NAT: Source NAT that I set up earlier, Interface: WAN, Version: IPv4, Protocol: TCP/UDP, Source Address: LAN, Translate Source IP: Single host or Network, Static-port: Enabled.

The only thing I'm unsecure about is Translate Source IP: Single host or Network, the field for Interface address is empty.
In my case it's an Alias filled with Host Addresses but you can ofcourse just enter a whole /24 subnet for example.

Post a screenshot so we can double check for you :)

You cannot view this attachment.

You cannot view this attachment.

You cannot view this attachment.
#4
General Discussion / Re: Going from no VLAN to VLAN...
Last post by Privacygear.nl - October 05, 2026, 10:54:59 PM
Quote from: prutz0rIs there anything missing from that tutorial?

Hi prutz0r, I wrote the PrivacyGear guide you linked. Thanks for using it, and your question was a fair one: the guide assumed a brand-new network.

I've added a section for exactly your situation (keeping your existing 192.168.1.0/24 by moving the LAN assignment onto the VLAN instead of creating a second interface, plus what happens to static leases). While checking it against the OPNsense docs I also fixed the DHCP step (Dnsmasq instead of the end-of-life ISC server) and the firewall rule order.

English version, no Google Translate needed:
https://privacygear.nl/en/guides/opnsense-vlan-guide/

Hope the mesh setup works out.
#5
General Discussion / Re: Network map with connectio...
Last post by meyergru - October 05, 2026, 10:54:49 PM
Aha. Found it:

https://github.com/flaviuvlaicu/opnsense-topo-map

I had a look at the code. The plugin does not actually discover the network topology. It merely collects clients from ARP/Kea; the relationships between clients, switches and APs are then defined manually by the user via drag & drop and stored in topology.json.

There is no LLDP, SNMP, switch MAC-table or controller data being queried. Therefore, the plugin cannot determine which switch/port a client is actually connected through, nor can it detect when a wireless client roams from one AP to another.

So essentially, it is a graphical network diagram editor with an automatically populated client list, not an automatic topology discovery tool.

That said, I would be rather cautious about installing software from arbitrary GitHub repositories on an OPNsense firewall.
#6
General Discussion / Re: Network map with connectio...
Last post by meyergru - October 05, 2026, 10:44:01 PM
So do I.
#7
Development and Code Review / Re: OPNsense - Topology map &...
Last post by Patrick M. Hausen - October 05, 2026, 10:18:52 PM
Quote from: nero355 on April 08, 2026, 02:44:08 PMIt would be funny if the result of programming done by one person over the weekend works more reliable than the whole Ubiquiti UniFi Development Team has done in the UniFi Controller Topology Overview over the many years that it exists! LOL! :)

Off-screen narrator: "But apparently it was not."
#8
26.7 Series / Re: Alias file bluk update cha...
Last post by RobLatour - October 05, 2026, 10:17:25 PM
QuoteWith IPv6 privacy addresses, the address currently used can change, and the alias will only catch it once it appears in the NDP table. Phones using randomized MAC addresses can also be a problem here.


Once again securtiy and privacy meet, pistoles drawn, on the field of honour.
#9
General Discussion / Re: School Chromebook bypasses...
Last post by Patrick M. Hausen - October 05, 2026, 10:17:14 PM
If the Chromebook is school managed I would trust them to a certain degree to put proper protection in place and just isolate the device from the rest of the network.

What would he do with that second hand laptop? My very educated bet is that the school managed device is 100% mandatory for any school related work.
#10
General Discussion / Re: Network map with connectio...
Last post by Patrick M. Hausen - October 05, 2026, 10:15:05 PM
I rarely declare something outright impossible.

In this particular case: the proof is in the pudding. Nobody but the person who started that cited thread has seen a single line of code. And quite possibly not even them. I call fake unless proven otherwise.