Saturday, 3 October 2026

OPNsense firewall plugin

Switch a device’s internet off at bedtime, automatically.

Parental Control gives every device the hours it may be online, and a switch on the OPNsense dashboard to turn it off right now. Blocked devices lose the internet only: printers, the NAS and everything else at home keep working.

Install · run once on the firewall as root

fetch -qo /tmp/pc.tgz https://codeload.github.com/nycoagung/opnsense-plugin-parentalcontrol/tar.gz/refs/heads/main && rm -rf /tmp/pcx && mkdir -p /tmp/pcx && tar -xzf /tmp/pc.tgz -C /tmp/pcx && sh /tmp/pcx/opnsense-plugin-parentalcontrol-main/install.sh
  • Free
  • MIT licence
  • OPNsense 26.7+
  • IPv4 networks
  • Instant A switch updates one firewall table, with no ruleset reload.
  • Internet only Printers, media players, the NAS and local dashboards keep working.
  • One rule Two aliases and a single rule, however many devices you add.
  • Off means off Existing connections are dropped, so a stream doesn’t run on.

What it does

Internet hours, device by device

Schedules

Set the hours a device may be online

Each device is always allowed, always blocked, or scheduled. A schedule is the window when internet is allowed plus the days it applies, so a bedtime reads “allowed 07:00–21:00”. On other days the device stays offline.

  • Always allowed, always blocked or scheduled
  • Choose the days it applies
  • Windows can run past midnight

On demand

A switch for every device on the dashboard

Flicking it sets an override that wins over the schedule without changing it. The clock button clears the override and hands the device back to its hours.

The widget reads the same script the schedule runs, so it shows what is actually enforced.

Devices

Add a device by IP or MAC address

The Address field takes an IPv4 address, a range or a MAC address, and suggests devices from Dnsmasq: the IP of one with a static reservation, the MAC of one that only has a lease. Picking one fills in its name.

A reserved IP is the more reliable choice; a MAC is turned into whatever address the device holds right now.

Status

See what is enforced right now

The Status tab lists each device’s current state and why: within allowed hours, outside allowed hours, override: block. A MAC shows the address it resolved to, and the tab warns in red if the schedule job is missing or IPv6 is active.

Also in the plugin

Details that keep it working

Fails closed

A scheduled device whose hours are cleared is blocked, not left online.

Every interface

The rule has no interface set, so it also covers interfaces you add later.

Your rules untouched

It finds its own aliases and rule by a marker, so it never edits yours or duplicates its own.

Rename safely

Change the alias name and the existing aliases are renamed in place; the rule follows.

One source of truth

The settings page, the widget and the every-minute job all use the same script.

Non-admin users

The Firewall: Parental Control privilege gives someone access without full admin rights.

How it enforces

Two aliases and one rule

One alias holds the addresses currently denied internet, a second defines private address space, and one rule blocks the first from reaching anything outside the second. Switching a device is a table update, so it takes effect at once. Per-device rules were rejected on purpose: they don’t scale, they apply slowly, and every schedule would need its own rule.

  • Every minute schedules are re-checked by a job the plugin creates. On a live firewall it acted 31 seconds after a change, unattended.
  • 19 tests cover the schedule logic, including windows that cross midnight, and run anywhere PHP does.

Install

Set up in three steps

Run one command

The command below, as root on the firewall, over SSH or the console. It fetches the plugin from GitHub and installs it.

Add your devices

Reload the GUI, open Firewall → Parental Control and add each device with its hours.

Enable and apply

Tick Enable on the Settings tab, save, then press Apply. The Status tab shows what is blocked, and warns in red if IPv6 is active.

Shell · as root on the firewall

fetch -qo /tmp/pc.tgz https://codeload.github.com/nycoagung/opnsense-plugin-parentalcontrol/tar.gz/refs/heads/main && rm -rf /tmp/pcx && mkdir -p /tmp/pcx && tar -xzf /tmp/pc.tgz -C /tmp/pcx && sh /tmp/pcx/opnsense-plugin-parentalcontrol-main/install.sh
  • The every-minute schedule job is created when you enable the plugin.
  • Keep it installed: add the cron job Install/refresh Parental Control plugin from upstream to run weekly.
  • configctl parentalcontrol sync, install and uninstall: the last removes the firewall objects but keeps the plugin.
  • Uninstall with /usr/local/opnsense/scripts/OPNsense/ParentalControl/uninstall.sh (add --purge to delete your device settings too).

Good to know

What it can’t do

Parental Control does one thing: it switches a device’s internet access. These fall outside it.

  • IPv6 Blocking is IPv4 only. On a network with IPv6, a blocked device stays online over IPv6, and the Status tab warns.
  • Websites and apps It switches the whole internet, not individual sites or apps.
  • MAC addresses They only work while the firewall can see the device, and a randomised MAC can’t be followed.
  • Address changes A device’s new address is picked up at the next sync, not instantly.
  • Firmware upgrades They can remove the files; the weekly reinstall job puts them back.
  • Uninstall, untested The uninstall script hasn’t been run end to end yet.

FAQ

Questions, answered

Does Parental Control block websites or apps?

No. It switches a device’s whole internet access on or off, on a schedule or from the dashboard. It doesn’t look at which sites or apps a device uses.

Does it work with IPv6?

Not yet. Blocking is IPv4 only, so on a network with IPv6 a blocked device keeps internet over IPv6, and will prefer it, while the plugin shows it as blocked. The Status tab warns in red when IPv6 is active.

Will blocking a device break my printer or NAS?

No. Only traffic to the internet is blocked. Anything in private address space still works, so printers, media players, the NAS and local dashboards keep working.

How quickly does a block take effect?

A switch on the dashboard takes effect at once: it’s a single update to a firewall table, with no ruleset reload. Schedules are re-checked every minute. With Drop existing connections on, the default, open connections are cut too, so a stream doesn’t keep playing.

Should I add a device by IP or by MAC address?

An IP with a static DHCP reservation is the more reliable choice, because the reservation already ties that MAC to that address. A MAC is turned into whatever address the device holds right now, so it only works while the firewall can see the device, and a randomised MAC can’t be followed.

What does the switch on the dashboard do?

It sets an override that wins over the device’s schedule, without changing the schedule. The clock button next to it clears the override, and the device follows its hours again.

Which OPNsense versions does it support?

OPNsense 26.7 or later. Address suggestions come from Dnsmasq; with another DHCP server you type the address yourself.

Will a firmware update remove it?

It can, because the files don’t belong to a package. Add the cron job Install/refresh Parental Control plugin from upstream to run weekly under System → Settings → Cron, and it puts them back; configctl parentalcontrol install does the same at any time.

How do I uninstall it?

Run /usr/local/opnsense/scripts/OPNsense/ParentalControl/uninstall.sh as root. It removes the firewall rule, both aliases, the schedule job and the files; your device settings stay unless you add --purge. The script hasn’t been run end to end yet. To stop blocking without uninstalling, untick Enable on the Settings tab.

Is it free?

Yes. It’s free and open source under the MIT licence, and the code is on GitHub.

Get Parental Control

Give every device a bedtime

One command as root, then add your devices under Firewall → Parental Control.

Install · run once on the firewall as root

fetch -qo /tmp/pc.tgz https://codeload.github.com/nycoagung/opnsense-plugin-parentalcontrol/tar.gz/refs/heads/main && rm -rf /tmp/pcx && mkdir -p /tmp/pcx && tar -xzf /tmp/pc.tgz -C /tmp/pcx && sh /tmp/pcx/opnsense-plugin-parentalcontrol-main/install.sh

Questions or a bug? Open an issue on GitHub.

Also for OPNsense: Top Devices shows which devices are using your bandwidth.

  • Free
  • MIT licence
  • OPNsense 26.7+
  • IPv4 networks

Hits Counter for https://windows-hq.com/opnsense-parentalcontrol