{{#HAS_DISPLAY_NAME}}

{{DISPLAY_NAME}}

{{KIND_BADGE}} IPv6 →

{{IF}}

{{/HAS_DISPLAY_NAME}} {{#NO_DISPLAY_NAME}}

{{IF}}

IPv6 → {{KIND_BADGE}}
{{/NO_DISPLAY_NAME}} {{#VLAN_HEADER}}

VLAN {{VLAN_ID}} on parent {{VLAN_PARENT}}

{{/VLAN_HEADER}}
{{STATUS_SUMMARY}} {{#DRIFT_BADGE}}{{#B_DRIFT}}{{B_LABEL}}{{/B_DRIFT}}{{#B_OK}}In sync{{/B_OK}}{{/DRIFT_BADGE}} {{#SHOW_LIVE_STATS}} {{/SHOW_LIVE_STATS}} {{#SHOW_BRIDGE_STATS}} {{/SHOW_BRIDGE_STATS}} {{#CAN_READ_LOGS}} {{/CAN_READ_LOGS}}
{{#READONLY_SYSTEM}}
System interface ({{IF}}). OgmaProtect does not manage addresses on encapsulation or pflog interfaces.
{{/READONLY_SYSTEM}} {{#LOOPBACK}}
Loopback interface. Addresses here (e.g. 127.0.0.1) apply to this host only. Removing the last IPv4 or IPv6 address for a family can affect local services that rely on localhost.
{{/LOOPBACK}} {{#FLASH}}
{{FLASH}}
{{/FLASH}}
{{#STATUS_BOARD}}

Interface status

Admin state

{{TILE_STATE_VALUE}}

Configured: {{TILE_STATE_SUB}}

{{#TILE_STATE_DRIFT}}

State drift

{{/TILE_STATE_DRIFT}}
{{#TILE_LINK}}

Link

Not measured

{{/TILE_LINK}} {{#TILE_IPV4}}

IPv4

{{TILE_IPV4_COUNT}}

{{#TILE_IPV4_HAS_MODE}}

Mode: {{TILE_IPV4_MODE}}

{{/TILE_IPV4_HAS_MODE}} {{#TILE_ADDR_DRIFT}}

Address drift

{{/TILE_ADDR_DRIFT}}
{{/TILE_IPV4}} {{#TILE_IPV6}}

IPv6

{{TILE_IPV6_COUNT}}

Manage IPv6 →

{{#TILE_ADDR_DRIFT}}

Address drift

{{/TILE_ADDR_DRIFT}}
{{/TILE_IPV6}}

MTU

{{TILE_MTU_VALUE}}

{{TILE_MTU_SUB}}

{{#TILE_MTU_DRIFT}}

MTU drift

{{/TILE_MTU_DRIFT}}
{{#TILE_TPUT}}

Throughput

Not measured

{{/TILE_TPUT}}
{{/STATUS_BOARD}} {{#BATCH_SECTION}} {{/BATCH_SECTION}} {{#SHOW_ADDRESSES}} {{#ADDRESS_PENDING}}

Confirm address change

A live address change by {{ADDRESS_PENDING_ACTOR}} is awaiting confirmation and reverts automatically in {{ADDRESS_PENDING_REMAINING}} seconds unless you keep it.

If this page stops loading after the change, do nothing — the interface addressing reverts to its previous state by itself at the deadline.

{{#ADDRESS_PENDING_REVERT_FAILED}}
Automatic revert failed — the interface addressing may be inconsistent. The change keeps retrying in the background; if it persists, resolve it from the console.
{{/ADDRESS_PENDING_REVERT_FAILED}} {{#WRITE}}
{{/WRITE}}
{{/ADDRESS_PENDING}}

Configured addresses

{{#WRITE}} {{/WRITE}}
{{CFG_ROWS}}
Family Address Prefix Primary Action
{{#NO_ADDRS}}

No addresses configured yet.

{{/NO_ADDRS}} {{#ADDRESS_DELETE_WINDOW}}

This interface carries the default route. Removing an address here briefly clears all of its addresses, so each removal is applied with a {{ADDRESS_DELETE_WINDOW_SECS}}-second auto-revert window — confirm it on the next page or it undoes itself and the address comes back.

{{/ADDRESS_DELETE_WINDOW}}
{{/SHOW_ADDRESSES}} {{#WIREGUARD}}

WireGuard tunnel

{{#WG_DRIFT_BADGE}}{{#B_OK}}in sync{{/B_OK}}{{#B_DRIFT}}drift{{/B_DRIFT}}{{#B_ERROR}}error{{/B_ERROR}}{{#B_SKIP}}not checked{{/B_SKIP}}{{/WG_DRIFT_BADGE}}
{{#WG_ERROR}}
{{WG_ERROR}}
{{/WG_ERROR}} {{#WG_OK}}
Server public key
{{WG_PUBLIC_KEY}}

Give this to each peer as this router's public key. The private key stays in the secret store.

{{#WG_LISTEN}}

Listen port {{WG_LISTEN_PORT}}

{{/WG_LISTEN}}

Peers

{{#WG_PEERS_TRUNCATED}}
This tunnel has more peers than can be shown and edited safely from the web UI. Manage its peers on the device instead — editing here is disabled to avoid dropping peers.
{{/WG_PEERS_TRUNCATED}}
{{WG_PEER_ROWS}}
{{#WG_VIEW_ONLY}}

You have read-only access to this tunnel. Adding or removing peers requires interface write permission (net-admin role).

{{/WG_VIEW_ONLY}} {{#WG_CAN_WRITE}}
+ Add peer

One CIDR per line — the IPs this peer may send and receive through the tunnel.

{{#WG_CAN_SECRET_WRITE}}

An extra symmetric key mixed into this peer's handshake (defence in depth). It is stored in the secret store and never shown again.

{{/WG_CAN_SECRET_WRITE}}
{{/WG_CAN_WRITE}} {{#WG_NEED_SECRET_DELETE}}

Changing peers (add, remove, enable/disable) or deleting this tunnel also needs secret write permission (net-admin role) — every apply re-materializes the server private key from the secret store. Those controls appear once you have it.

{{/WG_NEED_SECRET_DELETE}} {{/WG_OK}}
{{/WIREGUARD}} {{#PPPOE}}

PPPoE client

{{#PPPOE_DRIFT_BADGE}}{{#B_OK}}in sync{{/B_OK}}{{#B_DRIFT}}drift{{/B_DRIFT}}{{#B_ERROR}}error{{/B_ERROR}}{{#B_SKIP}}not checked{{/B_SKIP}}{{/PPPOE_DRIFT_BADGE}}
{{#PPPOE_ERROR}}
{{PPPOE_ERROR}}
{{/PPPOE_ERROR}} {{#PPPOE_OK}}
Authentication
{{PPPOE_AUTHPROTO}}
{{#PPPOE_HAS_AUTHNAME}}
Username
{{PPPOE_AUTHNAME}}
{{/PPPOE_HAS_AUTHNAME}} {{#PPPOE_HAS_SERVICE}}
Service
{{PPPOE_SERVICE}}
{{/PPPOE_HAS_SERVICE}} {{#PPPOE_HAS_AC}}
Access concentrator
{{PPPOE_AC_NAME}}
{{/PPPOE_HAS_AC}}
Device
{{PPPOE_DEV}}
Phase
{{PPPOE_PHASE}}
State
{{PPPOE_STATE}}
Session id
{{PPPOE_SID}}
{{#PPPOE_HAS_RETRIES}}
PADI / PADR retries
{{PPPOE_PADI_RETRIES}} / {{PPPOE_PADR_RETRIES}}
{{/PPPOE_HAS_RETRIES}}
{{#PPPOE_NEGOTIATED}}

Negotiated addresses

local {{PPPOE_LOCAL}} → peer {{PPPOE_PEER}}

{{/PPPOE_NEGOTIATED}} {{#PPPOE_NEGOTIATING}}

Negotiating… no IPCP addresses yet (the session is not established).

{{/PPPOE_NEGOTIATING}}
{{/PPPOE_OK}}
{{/PPPOE}} {{#TUNNEL}}

Tunnel ({{TUNNEL_TYPE}})

{{#TUNNEL_DRIFT_BADGE}}{{#B_OK}}in sync{{/B_OK}}{{#B_DRIFT}}drift{{/B_DRIFT}}{{#B_ERROR}}error{{/B_ERROR}}{{#B_SKIP}}not checked{{/B_SKIP}}{{/TUNNEL_DRIFT_BADGE}}
{{#TUNNEL_ERROR}}
{{TUNNEL_ERROR}}
{{/TUNNEL_ERROR}} {{#TUNNEL_OK}}
Outer source
{{TUNNEL_SRC}}
Outer destination
{{TUNNEL_DST}}
{{#TUNNEL_HAS_VNETID}}
VNI / key
{{TUNNEL_VNETID}}
{{/TUNNEL_HAS_VNETID}} {{#TUNNEL_HAS_PARENT}}
Parent
{{TUNNEL_PARENT}}
{{/TUNNEL_HAS_PARENT}} {{#TUNNEL_HAS_INNER}}
Inner address
{{TUNNEL_INNER_LOCAL}}{{#TUNNEL_HAS_REMOTE}} → {{TUNNEL_INNER_REMOTE}}{{/TUNNEL_HAS_REMOTE}}/{{TUNNEL_INNER_PREFIXLEN}}
{{/TUNNEL_HAS_INNER}}

The tunnel type is fixed once created — delete and recreate to change it. The parent, outer endpoints, and other settings can be edited below.

{{#TUNNEL_PENDING}}

Confirm endpoint change

A live endpoint change by {{TUNNEL_PENDING_ACTOR}} is awaiting confirmation and reverts automatically in {{TUNNEL_PENDING_REMAINING}} seconds unless you keep it.

If this page stops loading after the change, do nothing — the tunnel reverts to its previous endpoints by itself at the deadline.

{{#TUNNEL_PENDING_REVERT_FAILED}}
Automatic revert failed — manual recovery required. From the console: ogmaprotectctl tunnel cancel {{TUNNEL_PENDING_TXN}}
{{/TUNNEL_PENDING_REVERT_FAILED}} {{#WRITE}}
{{/WRITE}}
{{/TUNNEL_PENDING}} {{#TUNNEL_CAN_EDIT_ENDPOINTS}}
Edit endpoints

Change the outer source and destination of this tunnel. The change is applied live behind a confirmation window — keep it before the countdown ends or it reverts automatically (no console needed). Both addresses are required and must be the same family.

{{/TUNNEL_CAN_EDIT_ENDPOINTS}} {{#TUNNEL_NOT_PENDING}} {{#TUNNEL_CAN_EDIT_INNER}}
Edit inner address

The routed address carried inside the tunnel. For a point-to-point pair use a /32 (IPv4) or /128 (IPv6) prefix and set the remote (peer). Leave the local address empty and save to remove the inner address.

{{/TUNNEL_CAN_EDIT_INNER}} {{#TUNNEL_CAN_EDIT_MTU}}
Edit MTU

The maximum transmission unit (bytes) for this interface. The minimum is 1280 (the IPv6 minimum); the maximum depends on the underlying hardware — the kernel rejects a value the NIC cannot carry. Writes mtu 9000 to hostname.{{IF}}, or removes the line when blank.

{{/TUNNEL_CAN_EDIT_MTU}} {{#TUNNEL_CAN_EDIT_SETTINGS}}
Edit tunnel settings

Adjust packet-handling settings for this tunnel. Leave a field unchanged to keep its current value. TTL and DF cannot be cleared once set (delete and recreate the tunnel to remove them).

{{#TUNNEL_HAS_VNETID_FIELD}}

Choose Set and enter a value — 0 is a valid VNI, not “unset”.{{#TUNNEL_VNETID_CLEARABLE}} Choose Remove to unset it entirely.{{/TUNNEL_VNETID_CLEARABLE}}

{{/TUNNEL_HAS_VNETID_FIELD}}
{{/TUNNEL_CAN_EDIT_SETTINGS}} {{#TUNNEL_CAN_EDIT_PARENT}}
Change parent interface

This learning-mode vxlan joins its multicast group on the parent. Changing the parent briefly bounces the interface (down→up). Choosing “point-to-point” clears the parent and switches the tunnel to a unicast destination.

{{/TUNNEL_CAN_EDIT_PARENT}} {{/TUNNEL_NOT_PENDING}} {{/TUNNEL_OK}}
{{/TUNNEL}} {{#BRIDGE}}

Bridge members

Current members

    {{#MEMBER_ROWS}}{{#M_NONE}}
  • No members configured
  • {{/M_NONE}}{{^M_NONE}}
  • {{M_NAME}}{{#M_HAS_DISPLAY}} {{M_DISPLAY}}{{/M_HAS_DISPLAY}} {{#M_IS_VLAN}}{{#M_HAS_VLAN_ID}}VLAN {{M_VLAN_ID}} · {{M_PARENT}}{{/M_HAS_VLAN_ID}}{{^M_HAS_VLAN_ID}}on {{M_PARENT}}{{/M_HAS_VLAN_ID}}{{/M_IS_VLAN}}{{^M_IS_VLAN}}{{#M_HAS_ADDR}}{{M_ADDR}}{{/M_HAS_ADDR}}{{#M_HAS_SEP}} · {{/M_HAS_SEP}}{{#M_HAS_VLAN_COUNT}}{{M_VLAN_COUNT}} VLAN{{#M_VLAN_PLURAL}}s{{/M_VLAN_PLURAL}}{{/M_HAS_VLAN_COUNT}}{{#M_HAS_BARE}}{{M_BARE}}{{/M_HAS_BARE}}{{/M_IS_VLAN}} {{#M_HAS_WARN}}{{/M_HAS_WARN}}
  • {{/M_NONE}}{{/MEMBER_ROWS}}
{{#WRITE}}
Add or remove members
{{#MEMBER_OPTIONS}}{{#M_NONE}}

No eligible member interfaces found.

{{/M_NONE}}{{^M_NONE}} {{/M_NONE}}{{/MEMBER_OPTIONS}}

Hover for cautions — e.g. an interface already in another bridge (checking it moves it here), or a physical port with VLAN children.

{{/WRITE}}

Bridge L2 settings

{{#WRITE}}
{{BRIDGE_MEMBER_HIDDEN}}
MAC address {{#BRIDGE_HAS_VETHER}}

An OpenBSD bridge presents the MAC of its L3 carrier interface (a vether). Set a static MAC here, or leave blank to inherit the kernel default. Use a unicast address (first octet even), e.g. 02:11:22:33:44:55.

{{/BRIDGE_HAS_VETHER}} {{#BRIDGE_NO_VETHER}}

This bridge has no L3 interface yet, so it has no MAC to manage. Add an IPv4/IPv6 address to the bridge first — its MAC is that carrier interface (a vether).

{{/BRIDGE_NO_VETHER}}
Spanning tree (RSTP/STP)

Spanning tree runs per member — enable it on the members below. The protocol and timers here are bridge-wide.

{{#BRIDGE_HAS_MEMBERS}}
Per-member options

DISCOVER floods unknown-destination frames out the port; Learning caches source MACs; Block non-IP drops non-IP/ARP frames; STP enables spanning tree on the port. Port priority (0–240) and path cost (1–200000000) are optional RSTP tuning.

{{#BRIDGE_MEMBER_FLAG_ROWS}} {{/BRIDGE_MEMBER_FLAG_ROWS}}
Member Discover Learning Block non-IP STP Port priority Path cost
{{BF_MEMBER}}
{{/BRIDGE_HAS_MEMBERS}}
{{/WRITE}} {{#BRIDGE_READONLY}}

You do not have write access to this bridge. Use the Live stats view to inspect its current MAC, spanning-tree state, and per-member flags.

{{/BRIDGE_READONLY}}
{{/BRIDGE}} {{#VLAN_SETTINGS_SECTION}}

VLAN settings

{{#WRITE}}
Parent interface {{#VLAN_CAN_EDIT_PARENT}}

The physical interface this VLAN tags on. Re-pointing moves the VLAN to a different port.

{{/VLAN_CAN_EDIT_PARENT}} {{#VLAN_DOTTED_PARENT}}

This VLAN's parent ({{VLAN_SETTINGS_PARENT}}) is fixed by its name. To use a different parent, delete this VLAN and create one on that interface.

{{/VLAN_DOTTED_PARENT}}

1280–65535. Leave blank to use the default (1500). Writes mtu 9000 to hostname.{{IF}}, or removes the line when blank.

MAC address

Set a static MAC, or leave blank to inherit the kernel default. Use a unicast address (first octet even), e.g. 02:11:22:33:44:55. Writes lladdr 02:11:22:33:44:55 to hostname.{{IF}}, or removes the line when blank.

Space-separated user groups (for pf rules etc.). 1–15 of letters/digits/_/-, not ending in a digit. The automatic vlan group is always present and isn't listed here. Writes one group <name> line per group to hostname.{{IF}}, or removes them when blank.

{{/WRITE}} {{#VLAN_READONLY}}

You do not have write access to this VLAN.

{{/VLAN_READONLY}}
{{/VLAN_SETTINGS_SECTION}} {{#IFACE_SETTINGS_SECTION}}

Advanced settings

{{^IFACE_SETTINGS_READONLY}}
MTU, description, MAC and interface groups
{{#WRITE}}

1280–65535. Leave blank to use the default (1500). Writes mtu 9000 to hostname.{{IF}}, or removes the line when blank.

A free-text label stored on the interface itself (ifconfig description), visible in the system config. Up to 63 characters; no double quotes. Writes description "…" to hostname.{{IF}}, or removes the line when blank.

{{#IFACE_SETTINGS_SHOW_MAC}}
MAC address

Set a static MAC, or leave blank to inherit the kernel default. Use a unicast address (first octet even), e.g. 02:11:22:33:44:55. Changing the MAC of the management (default-route) interface is refused. Writes lladdr 02:11:22:33:44:55 to hostname.{{IF}}, or removes the line when blank.

{{/IFACE_SETTINGS_SHOW_MAC}}

Space-separated user groups (for pf rules etc.). 1–15 of letters/digits/_/-, not ending in a digit. Kernel auto-groups aren't listed here. Writes one group <name> line per group to hostname.{{IF}}, or removes them when blank.

{{#BATCH_SECTION}}

Re-asserting pushes the configured MTU, description, MAC and groups to the running interface without changing the configuration file. It also adopts any address the interface currently holds into the configuration — the review sheet shows exactly what would change before anything is applied.

{{/BATCH_SECTION}}
{{/WRITE}}
{{/IFACE_SETTINGS_READONLY}} {{#IFACE_SETTINGS_READONLY}}

You do not have write access to this interface.

{{/IFACE_SETTINGS_READONLY}}
{{/IFACE_SETTINGS_SECTION}} {{#PHYSICAL_VLANS}}

VLAN interfaces

802.1Q VLANs on this physical port. Bridging a VLAN adds it to a bridge without removing its parent relationship here.

    {{#CHILD_VLAN_ROWS}}
  • {{V_NAME}} {{#V_HAS_TAG}} VLAN {{V_ID}}{{/V_HAS_TAG}}{{#V_HAS_BRIDGE}} bridged in {{V_BRIDGE}}{{/V_HAS_BRIDGE}}
  • {{/CHILD_VLAN_ROWS}}
{{/PHYSICAL_VLANS}} {{#LIVE_IMPORT}}

On interface now (not in hostname file)

These addresses are active on the kernel but not saved in hostname.{{IF}}. Add any you want to persist across reboot.

{{#LIVE_IMPORT_ROWS}} {{/LIVE_IMPORT_ROWS}}
Family Address Prefix Action
{{LI_FAM}} {{LI_ADDR}} {{LI_PREFIX}} {{#LI_ADD}}
{{/LI_ADD}}{{#LI_UNSUP}}Unsupported netmask{{/LI_UNSUP}}
{{/LIVE_IMPORT}} {{#SHOW_ADDRESSES}} {{#WRITE}}

Add IP address

Use CIDR notation for the prefix (e.g. /24 for IPv4 or /64 for IPv6). Additional addresses are added as aliases unless you make the new one primary.

{{#DHCP_ALIAS_ADD_HINT}}

With IPv4 mode DHCP, new IPv4 addresses are static aliases only (same-subnet aliases often use /32).

{{/DHCP_ALIAS_ADD_HINT}}
{{#ADDRESS_CAN_WINDOW}} {{/ADDRESS_CAN_WINDOW}} {{#IFACE_IS_DEFAULT_EGRESS}}

This interface carries the default route — it is most likely how you are connected. Making an address primary here briefly removes the interface's addresses, so the safety window above is required and has been ticked for you.

{{/IFACE_IS_DEFAULT_EGRESS}}
{{#IFACE_PRIMARY_BLOCKED}}

Making an address primary is unavailable here: this interface carries the IPv6 default route and is DHCP-addressed, so the auto-revert safety window that would protect the change cannot be used. Switch its IPv4 mode to static first, or make the change from the console.

{{/IFACE_PRIMARY_BLOCKED}} {{^IFACE_PRIMARY_BLOCKED}} {{/IFACE_PRIMARY_BLOCKED}} {{#BATCH_SECTION}} {{/BATCH_SECTION}}
{{/WRITE}} {{/SHOW_ADDRESSES}}
{{#CAN_READ_LOGS}} {{/CAN_READ_LOGS}}