OPNMGR
OPNsense fleet managementWatch, back up and update every OPNsense firewall you look after.
The repository is published as OPNMGR; the running application calls itself OPNManager.
MIT licensed Self-hosted
What it is
One place for the whole OPNsense fleet, grouped by customer and site — health telemetry that becomes incidents, configuration backups compared against a baseline you approved, and updates rolled out in rings.
Who it is for
Anyone supporting OPNsense across more than a handful of customers, who currently finds out a tunnel is down because somebody rings up.
What it does
- Agents report check-ins, gateway latency and loss, VPN tunnel state, CARP status, service state and certificate expiry — and a problem becomes one incident that closes when it actually clears, rather than an email per poll.
- Scheduled configuration backups per firewall, compared against the baseline you approved, with the diff named by rule description. Nothing is ever restored automatically.
- Update campaigns through canary, pilot and production rings with manual progression, and never both members of a CARP pair at once.
Also in the project
- Customers group sites, sites group firewalls — each with code, timezone, contacts and a default maintenance window
- Per-firewall WAN throughput, CPU load, memory and disk trends collected on each check-in
- Maintenance windows that withhold notification while health collection continues
- Per-firewall API key and HMAC signing; secrets and SSH keys encrypted at rest with XChaCha20-Poly1305
The real interface
Taken from the project's own repository, in both themes where the project has both. Select any screenshot to open it at full size.
What it needs, and what it does not do
Both lists come from the project's own README. Installation steps are deliberately not copied here — they change, and a stale copy on a marketing site is worse than a link.
Prerequisites and dependencies
- Ubuntu 22.04 LTS or newer, PHP 8.0+ (CI builds against 8.3), MySQL 8.0+ or MariaDB 10.6+, Apache 2.4+ or Nginx 1.18+
- An agent plugin installed on each OPNsense firewall; firewalls need outbound HTTPS to the manager and no inbound port
- Validated against OPNsense 26.7 (FreeBSD 14); earlier releases are untested rather than known broken
Limitations the project states
- The agent package is not in the repository — you build it from the tracked plugin source and place it on your own server before enrolment will work.
- The two firewall lockdown policies have not been exercised against a live firewall by the maintainer; apply to one firewall you can reach out-of-band first.
- No LTS line and no published release cadence — read the changelog before upgrading.
Licence
OPNsense itself is a separate project under BSD-2-Clause. OPNMGR is not affiliated with or endorsed by Deciso B.V.
Two ways to run it. Clone the repository and follow the installation guide — the software is free and nothing is held back. Or ask MSP Reboot to set it up and host it, which is a paid service quoted per engagement.
Want the tools without the setup work?
MSP Reboot installs, configures and hosts these projects as a paid service. The software itself stays free and self-hostable — you never have to buy anything to use it.