opn_security_audit
Run a comprehensive security audit of your OPNsense firewall to identify misconfigurations, assess security posture, and check compliance with PCI DSS, NIST SP 800-41, and CIS benchmarks.
Instructions
Run a comprehensive security audit of the OPNsense firewall.
Checks 11 security areas: firmware, firewall rules (MVC + legacy), NAT/port forwarding, DNS resolver security, system hardening (SSH, HTTPS, syslog), services, certificates, VPN status (incl. WireGuard config audit), HAProxy reverse proxy security, and gateway health.
Findings are tagged with applicable compliance frameworks: PCI DSS v4.0, BSI IT-Grundschutz, NIST SP 800-41, CIS Benchmarks.
Returns a structured audit report with findings categorized by severity (critical, warning, info). Each finding includes a recommendation and applicable compliance framework references.
Use this when you need to assess the security posture of the firewall, identify misconfigurations, or perform a routine health check.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||