This setup allows you to route traffic for specific Autonomous Systems (ASNs), specific IPs or networks through a (WireGuard) tunnel on OPNsense.
Before starting, make sure you have:
- Gateways for IPv4 and IPv6 configured (we will use them later).
- An interface assigned for the WireGuard tunnel
(⚠️ no IP configuration required on the tunnel interface). - Shell/SSH access to your OPNsense firewall.
- Valid SSL certificate (OR HTTP access)
- Go to Firewall → Aliases.
- Create two aliases:
- ASN_TO_TUNNEL_V4 type: URL Table (IPs) Refresh Frequency: Empty / 1 content: file:///conf/_aliases/ASN_TO_TUNNEL_V4.txt
- ASN_TO_TUNNEL_V6 type: URL Table (IPs) Refresh Frequency: Empty / 1 content: file:///conf/_aliases/ASN_TO_TUNNEL_V6.txt
These will be filled dynamically by the script later.
-
Go to Firewall → Rules → Floating.
-
Create two rules (one for IPv4, one for IPv6):
-
General
- Disabled: Checked (recommended for testing — once aliases are filled, you can enable the rules)
- Action: Pass
- Quick: Checked
- Interface: All (or limit to where routing should apply)
- Direction: In
-
Network
- TCP/IP Version: IPv4 (second rule IPv6)
- Protocol: TCP/UDP (or any you need)
- Source: Any
- Destination:
ASN_TO_TUNNEL_V4(orASN_TO_TUNNEL_V6) - Destination Port Range: (optional, e.g. 80–443)
-
Advanced
- Gateway: Select the WireGuard gateway (IPv4 or IPv6 accordingly)
-
-
Go to Firewall → NAT → Outbound.
-
Ensure mode is set to Hybrid.
-
Create two rules per LAN interface (one IPv4, one IPv6):
- Interface: Tunnel interface (always the same one)
- TCP/IP Version: IPv4 (second rule IPv6)
- Protocol: Any
- Source Address: The LAN/subnet you want to route
- Destination Address: Any
- Translation / Target: Interface address
Copy the following files to your OPNsense box:
scp update_asn_alias.sh root@OPNsense:/root/
scp asn.list root@OPNsense:/root/
scp actions_asnaliasupdate.conf root@OPNsense:/usr/local/opnsense/service/conf/actions.d/
scp actions_updateawsurltable.conf root@OPNsense:/usr/local/opnsense/service/conf/actions.d/Then restart the service framework:
service configd restart- Go to System → Settings → Cron.
- Add a new entry:
- Minutes:
30 - Hours:
3 - Days/Months/Weekdays:
* - Command:
Update ASN aliases
- Minutes:
- Add a new entry:
- Minutes:
30 - Hours:
2 - Days/Months/Weekdays:
* - Command:
Update AWS URL Table
- Minutes:
Before running the final check, verify the configuration inside your update_asn_alias.sh script:
OPNSENSE_URL="https://firewall.fqdn" # FQDN with a valid SSL certificate OR httpOPNSENSE_PORT="4443" # Typically 443 or 4443 depending on your setup (OR 80)
Run the script manually once:
/root/update_asn_alias.shThen verify in Firewall → Aliases that:
ASN_TO_TUNNEL_V4ASN_TO_TUNNEL_V6
contain networks as expected.
You can also check the last update timestamp in the alias list to confirm successful runs.
update_asn_alias.sh– main update scriptupdate_aws_urltable.sh– aws update scriptasn.list– list of ASNs/IPs/Networks to be routedactions_asnaliasupdate.conf– configd integrationactions_updateawsurltable.conf– configd integration
Traffic matching the configured ASNs, IPs or networks will now be routed through your WireGuard tunnel.
This script fetches the official AWS IP ranges from
https://ip-ranges.amazonaws.com/ip-ranges.json
and writes selected networks (Amazon EC2 and/or CloudFront) into a target file.
The target file can be used in OPNsense URL tables to automatically maintain
a list of AWS networks for firewall rules.
- Supports both IPv4 and IPv6 ranges
- Region filtering (e.g.,
us-west-2,eu-central-1) - Optional inclusion of:
AMAZON(general AWS ranges, often EC2)CLOUDFRONT(content delivery edges)- Global CloudFront-only mode
- Inserts/updates a managed block between
# BEGIN AWS-AUTOand# END AWS-AUTO
without touching manual entries in the file - Generates deduplicated and sorted lists
-
Adjust configuration variables at the top of the script:
REGIONS→ AWS regions to includeINCLUDE_AMAZON/INCLUDE_CLOUDFRONTCLOUDFRONT_GLOBAL_ONLYTARGET_FILE→ destination file for OPNsense
-
Run the script manually or via cron:
sh update_aws_ipranges.sh
-
Point an OPNsense URL table alias to the generated file.
A generated block inside asn.list looks like:
# BEGIN AWS-AUTO (managed; do not edit inside)
# generated: 2025-09-04T21:00:00Z
# regions: us-west-2 | amazon=1 | cloudfront=1 | cf_global_only=1
13.34.32.0/24
13.35.0.0/16
...
2600:9000::/28
# END AWS-AUTO
curl,jq,sort,sed,awk,mkdir
Note: Only the lines inside the managed block are updated.
Manual entries outside this block remain untouched.