Install the LegoTypes plugins
One command adds the signed LegoTypes package repository to your firewall. From then on the plugins install, update and uninstall in System > Firmware like any other.
What it provides
- os-wg-client-tunnels: WireGuard upstream tunnels, built and enforced from a provider's config file.
- os-mac-alias-cache: see and rebuild MAC firewall aliases.
1. Add the repository (once)
In a shell on the firewall (console option 8, or SSH as root):
pkg add https://legotypes.github.io/opnsense-repo/os-legotypes.pkg && \
pkg install -fy -r LegoTypes os-legotypes && \
/usr/local/opnsense/scripts/firmware/register.php install os-legotypes
The three steps: install the repository package (it brings the repository's address and its trusted signing-key fingerprint), reinstall it from the now-verified signed repository, and register it with the firmware as the GUI does for any plugin.
2. Check the key (recommended)
The first command is trust on first use over HTTPS; every later package is verified against the fingerprint it installs. Compare that fingerprint with the one published here:
cat /usr/local/etc/pkg/fingerprints/LegoTypes/trusted/*
sha256 213c16793ee5bec26098d5be9017e0888af98a94b86e4abddc4e42a78bbe4610
It is the SHA-256 of the repository's public signing key, also kept in the repository source. pkg update -r LegoTypes should end with LegoTypes repository update completed; a signature problem shows as No trusted public keys found, and nothing from the repository is used.
3. Install plugins
System > Firmware > Plugins lists the LegoTypes plugins beside the official ones; install with the + button. They show tier 4: OPNsense reserves its trusted tiers for its own repository and Zenarmor's, and marks every community repository tier 4.
Updates and removal
- New versions arrive with System > Firmware > Updates, as for any plugin.
- Uninstall a plugin from the Plugins tab. Uninstalling
os-legotypesremoves the repository; plugins already installed from it stay until you remove them.
Supported
OPNsense 26.7 on amd64 (FreeBSD 15). Packages are built and signed by the repository's GitHub Actions workflow from the plugin sources in LegoTypes/plugins; every published build is also kept as a release.