There's a central management withing Business Edition:https://shop.opnsense.com/product/opnsense-business-edition/Or from my employer:https://www.max-it.de/loesungen/opnsense-firewall/plugins/Both only offer an overview which firewall is connected, a button to jump on UI and central upgrade management.Since franco is now employed by Deciso I believe the business edition may get more features soon.
It's a sort of decentralised approach... Well, you need an OPNsense to run the management plugin but that's it.Cheers,Franco
Do I need one license per OPNsense or is one license enough for all of my OPNsense boxes?
Quote from: Gauss23 on January 19, 2021, 10:05:51 amDo I need one license per OPNsense or is one license enough for all of my OPNsense boxes?Business edition for all managed devices.Cheers,Franco
We are managing more than 50+ OPNsense here, all around the world So we have developped: - a central management solution (cloud) - a plugin (with some API extensions) - a Zabbix templateSo with this, OPNSense is provisionned from our CMS: - custom settings (hostname, dns, plugins...) - authentication - firewall rules - autossh service to an "hub" for dynamic IP/restricted WAN, and tunneling for GUI access - full supervision by Zabbix (including running services) - configuration/status (DHCP leases) access directly from our CMS - remote upgrade, with scheduling - alerts by email / slack : gateway status, services... - daily XML backupingThis solution is currently oriented for our usage, but we can easily extend it.You can contact us if you are interested!
How will be the communication between the centralized administration opnsense and the other opnsenses when I place a centralized device to internet? Is there e.g. a cyclic polling of configuration possible or do I need a direct reachability from the central device to satelites or can I use a VPN wich is started from the satelite to the central instance?