firewall-appliance
Installation
SKILL.md
Firewall Appliance: OPNsense & pfSense Management
Manage, troubleshoot, and harden OPNsense and pfSense firewalls via SSH. Both are FreeBSD-based, pf-powered firewall distributions - most concepts, commands, and patterns apply to both.
Target versions (July 2026):
- OPNsense CE: 26.7.1 (current Community Edition stable, "Xenial Xenops"; 26.7.1 contains four core security advisories). Business Edition remains a separate even-quarter lane - do not quote the BE number as the CE version
- pfSense CE: 2.8.1 / pfSense Plus: 26.03.1
- CrowdSec: v1.7.8
When to use
- Managing or troubleshooting OPNsense and pfSense firewalls over SSH
- Reviewing pf rules, NAT, CARP, Unbound, WireGuard, CrowdSec, or pfBlockerNG on these appliances
- Configuring VLANs, CARP HA failover, or interface assignments on firewall appliances
- Debugging connectivity between networks or VLANs routed through OPNsense/pfSense
- Hardening BSD firewall appliances and validating safe remote-change workflows