MAC Alias Cache
Shows what every MAC-type firewall alias really resolves to, and rebuilds them from current host discovery data on demand, instead of waiting up to twelve hours for stale addresses to age out.
Why this plugin
OPNsense resolves MAC-type aliases through a cache of addresses reported by its host discovery. When a device is still being seen, its entry is refreshed. When it is no longer reported at all (it left, moved to an unwatched interface, or its records expired), its last addresses stay in the cache for up to 12 hours, in its own alias and in every alias that nests it. Rules keep matching an address that may already belong to another device.
Firewall > Diagnostics > Aliases cannot fix that: its flush and delete act on the pf table only, and the next alias refresh reloads the table from the same cache.
Using it
Firewall > Diagnostics > MAC Alias Cache lists each MAC alias with its entries, the MACs that match, the addresses cached versus those host discovery reports now, and the aliases that nest it.
Flush & rebuild replaces the cache with one seeded only from current host discovery data and rebuilds every MAC alias and every alias nesting one, under core's own alias update lock. If the host list cannot be read, or is empty, it refuses and changes nothing, because core would otherwise rebuild every MAC alias as empty.
From a shell: configctl macaliascache status and configctl macaliascache flush.
Limits
- A flush cannot remove an address host discovery still reports; those age out with host discovery's own expiry (Interfaces > Neighbors > Automatic Discovery).
- It does not probe hosts: host discovery records ARP and NDP only, which an active host with a fresh entry does not send.
- It acts only when asked; there is no schedule and nothing runs on install.
Source and install
Install it from the LegoTypes repository: see Install. Source: LegoTypes/plugins, branch add-mac-alias-cache.