OPNsense Admin for Openclaw

Automate OPNsense firewall administration, backups, and security monitoring via API and SSH.

transcendenceia
v1.0.3
Feb 10, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install opnsense-admin

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install opnsense-admin using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is OPNsense Admin?

The OPNsense Admin skill provides a comprehensive interface for managing OPNsense firewalls, including DNS, IDS/IPS, and general network configurations. It leverages both RESTful API integrations and SSH command execution to provide high-privilege control over your network infrastructure, making it a vital part of your Openclaw Skills library. Whether you are automating routine configuration backups or troubleshooting complex network issues, this skill streamlines the administrative lifecycle for OPNsense 26.1+ environments. By integrating with the firewall's internal systems, it allows for seamless rule management, service monitoring, and performance diagnostics.

OPNsense Admin Use Cases

  • Automated configuration backups with custom retention periods to prevent data loss
  • Real-time monitoring of Suricata IDS/IPS status and security alerts
  • Managing Unbound DNS resolver settings, blocklists, and DNS over TLS
  • Creating and modifying firewall rules, NAT settings, or network aliases
  • Restarting or reloading critical network services like DHCP or DNS via remote command execution

How OPNsense Admin Works

  1. Authenticates with the OPNsense host using generated API keys or SSH credentials stored in environment variables or configuration files.
  2. Executes RESTful API requests to the OPNsense core or specific plugin endpoints (like IDS or Unbound) to retrieve or update configuration data.
  3. Processes system health, firmware status, and service states through specialized helper scripts for high-level visibility.
  4. Performs administrative tasks such as configuration exports, rule updates, or service restarts using the most efficient protocol (API or SSH).
  5. Returns structured feedback regarding the success of network operations and provides diagnostic data for troubleshooting.

OPNsense Admin Setup

To begin using this tool within Openclaw Skills, you must first generate API credentials in your OPNsense dashboard under System -> Access -> Users -> API. Then, configure your environment using one of the following methods:

Method A: Environment Variables

export OPNSENSE_HOST="192.168.1.1"
export OPNSENSE_KEY="your_api_key"
export OPNSENSE_SECRET="your_api_secret"

Method B: Credentials File (Recommended)

mkdir -p ~/.opnsense
cat > ~/.opnsense/credentials << EOF
OPNSENSE_HOST=192.168.1.1
OPNSENSE_PORT=443
OPNSENSE_KEY=your_api_key
OPNSENSE_SECRET=your_api_secret
EOF
chmod 600 ~/.opnsense/credentials

OPNsense Admin Data Schema & Taxonomy

The skill organizes management data through standardized OPNsense API structures and local file system exports. Use the following table to understand the data organization:

Data Component Format Primary Source
Credentials Environment/Plaintext ~/.opnsense/credentials
Configuration Backups XML / RRD /api/core/backup/backup
Service Status JSON /api/core/system/status
DNS Statistics JSON /api/unbound/diagnostics/stats
Firewall Rules PF Table Data /api/diagnostics/firewall/
Local Storage Directory Path Default: ./backups

OPNsense Admin Advanced Features

  • Support for scheduled, automated configuration backups including full RRD performance data
  • Multi-method service control enabling the ability to Start, Stop, Restart, or Reload services like dhcpd and unbound
  • Secure SSL/TLS certificate validation for production-grade API calls with an optional insecure mode for self-signed certificates
  • Granular control over Suricata IDS/IPS modes allowing for safe monitoring before enabling active blocking
  • Extensible API helper script for custom GET and POST requests to any available OPNsense plugin or core module

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*