0.12.0
Added
-
Firewall VPN tunnels are first-class, type-labeled objects
(#42). WireGuard,
OpenVPN, and IPsec tunnels from OPNsense (peer/session/SA status
endpoints) and pfSense (OpenVPN/IPsec status; the WireGuard VPN gateway,
previously dropped, becomes tunnel health) land in a newtunnels
table — prune-per-type with empty-response guards, and no key material
stored, not even public keys. On the topology they draw as dashed
purple egress nodes hung off their firewall, labeled with type and
peer; on the routed view they sit beside the internet cloud, and a
subnet reachable through a tunnel rails off the tunnel node — drawn
even when nothing local claims it, because reachability through the
tunnel is its participation. WireGuard liveness derives from handshake
age (up / idle / down); tunnel interfaces stay out of the port model,
exactly as before. The demo network gains a site-b WireGuard peer so
both maps show the feature out of the box. The OPNsense API user needs
the VPN page privileges — optional, everything else degrades cleanly
without them. The terminating firewall's device page lists its tunnels
in their own section, separate from the port table. -
Routed view redesign: rails spread to a computed gap (wider for
more networks, capped for few); hypervisors and APs draw as spanning
boxes in tiers of their own, with guest VMs grouped inside their
hypervisor and wireless clients inside their AP — every host counts in
exactly one place. Dual-homed hosts known only from ARP now fuse by
canonical hostname into real host boxes (rail gateway addresses are
excluded, so dnsmasq's per-VLAN "gateway" rows can't invent a phantom
host). Boxes carry the topology's role icons and colors, and hovering
a network now dims isolated (gray) rails too.
Fixed
- OPNsense 403 poll notes now name the exact privilege to grant (and note
that a Status sub-privilege covers the VPN reads) instead of "the
matching page privilege". - Brocade/Ruckus FastIron ports no longer show the long-form port name
("GigabitEthernet1/1/10") as their description — that is the vendor
echoing the ifName when no comment is set, not documentation. - Snapshot polish: per-source data ages are humanized ("16 h", not
"967m"), VM cards drop the "· ?" when no hardware string exists, and
VPN tunnels now appear in the snapshot both on the map and as a table
under the terminating firewall. - Hypervisor device pages split vmk* kernel interfaces into their own
section — they carry the management addresses but no cable ends on
one, so they no longer pad the physical port list. - The configs page shows the firewall's management IP on its API-sourced
row, the patch-panel section header is just the panel's declared name,
and the topology toolbar controls share one height.