OPNsense plugin · os-mac-alias-cache 1.0

MAC Alias Cache

Shows what every MAC-type firewall alias really resolves to, and rebuilds them from current host discovery data on demand, instead of waiting up to twelve hours for stale addresses to age out.

Why this plugin

OPNsense resolves MAC-type aliases through a cache of addresses reported by its host discovery. When a device is still being seen, its entry is refreshed. When it is no longer reported at all (it left, moved to an unwatched interface, or its records expired), its last addresses stay in the cache for up to 12 hours, in its own alias and in every alias that nests it. Rules keep matching an address that may already belong to another device.

Firewall > Diagnostics > Aliases cannot fix that: its flush and delete act on the pf table only, and the next alias refresh reloads the table from the same cache.

Using it

Firewall > Diagnostics > MAC Alias Cache lists each MAC alias with its entries, the MACs that match, the addresses cached versus those host discovery reports now, and the aliases that nest it.

Flush & rebuild replaces the cache with one seeded only from current host discovery data and rebuilds every MAC alias and every alias nesting one, under core's own alias update lock. If the host list cannot be read, or is empty, it refuses and changes nothing, because core would otherwise rebuild every MAC alias as empty.

From a shell: configctl macaliascache status and configctl macaliascache flush.

Limits

Source and install

Install it from the LegoTypes repository: see Install. Source: LegoTypes/plugins, branch add-mac-alias-cache.