Skip to content

Latest commit

 

History

79 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Build Donate

os-plugins

OPNsense plugins maintained and distributed by Greelan.

Add the repository

Add the repository to your OPNsense installation via the console/SSH:

fetch -o /usr/local/etc/pkg/repos/Greelan.conf https://pkg.greelan.net/greelan.conf
pkg update

Plugins are then installed from the web UI under System > Firmware > Plugins. Find the relevant package and click +.

Plugins

os-blocky-greelan

Blocky is a fast DNS proxy and ad-blocker. This plugin puts its whole configuration in the OPNsense web UI, won't save a setting Blocky would refuse, and shows its log. If you already run Blocky elsewhere, you can import its config.yml to start from.

Blocking uses deny and allow lists that can differ between groups of clients and follow a weekly schedule. Queries go upstream over plain DNS, DNS over TLS, HTTPS or QUIC, and Blocky can serve DNS over TLS and HTTPS itself with a certificate from the trust store. There are also domain and host overrides, caching with prefetching, DNSSEC validation, rebinding protection, rate limiting, a query log, Prometheus metrics and High Availability sync.

Blocky answers on the DNS port (53 by default); disable the built-in Unbound/Dnsmasq resolver or run Blocky on another port.

os-notify-greelan

Push notifications for OPNsense system events, sent through Apprise to Telegram, Pushover, ntfy, Gotify, Discord, Slack, Matrix, email and many other services. Channels are built from a service picker or by importing an Apprise URL, and each one can choose which events it receives.

Events: configuration changes, logins and lockouts, gateway down and recovery (with outage duration), WAN address changes, interface link changes, VPN peers, new devices, intrusion detection alerts, Monit checks, services stopping, a filling state table, UPS power (apcupsd or NUT), firmware updates, certificate expiry, System Status entries, critical log messages, CARP state changes and firewall startup. Undelivered notifications are retried with a backoff for up to 24 hours.

A channel can also get a daily, weekly or monthly summary of the firewall's status, its events, firewall blocks, traffic and system health: by email as a formatted report with graphs, elsewhere as a short text linking to the full report on the firewall, which also keeps an archive of them.

os-s3-backup-greelan

Adds S3-compatible object storage (AWS S3, Backblaze B2, Cloudflare R2, Wasabi, MinIO and others) to System > Configuration > Backups, next to the Google Drive, Nextcloud and SFTP options. Backups are encrypted before they leave the firewall and old ones are removed beyond a set count.

About

Custom plugins for OPNsense

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Contributors

Languages