Selective Routing
Enable per-app routing modes, custom profiles, and URL-table based flows so only the traffic you choose goes through VPN.
Gator gives homelab operators a calmer way to manage WireGuard VPNs, selective routing, Tailscale setup, backups, migration, and drift-aware tunnel operations without living in firewall menus all day.
Gator does not try to abstract away your firewall. It gives you faster, safer tools for the OPNsense workflows operators already run by hand.
Enable per-app routing modes, custom profiles, and URL-table based flows so only the traffic you choose goes through VPN.
Create, import, deploy, activate, deactivate, and re-adopt OPNsense WireGuard profiles without hand-editing firewall objects.
Build and operate WireGuard site-to-site tunnels with SSH-assisted deployment, health checks, restart, teardown, and lockdown flows.
Install the OPNsense Tailscale plugin, configure authentication, inspect status, and manage advertised subnets from the same console.
Move legacy firewall rules into the MVC/API system with savepoint-based apply and confirm flows that are safer to operate.
Gator keeps local ownership tied to live OPNsense state so drift is visible and managed resources can be reviewed or re-adopted cleanly.
Save multiple firewall instances and switch between production, lab, and recovery environments without rebuilding the app state.
Create, list, download, and delete local OPNsense configuration snapshots before risky changes or maintenance work.
Runs on your network with local auth, local SQLite state, and no hosted control plane sitting between you and your firewall.
Stop managing firewall state through brittle manual edits. Gator gives you one local control plane that stays aligned with your OPNsense instances.
Save your instance, verify API credentials, bootstrap the local admin account, and discover what is already configured.
Create or import WireGuard profiles, define selective routing behavior, configure Tailscale, and prepare site-to-site tunnels.
Push changes, create backups, use savepoint-based confirmation when needed, and let the reconciler surface drift before it surprises you.
Gator manages WireGuard VPNs, selective routing, site-to-site tunnels, Tailscale, migration, and backups on OPNsense. pfSense support is limited to setup and connection testing for now.
Gator is GPLv3 licensed and runs entirely on your infrastructure. No cloud lock-in, no subscription fees, and no hosted control plane standing between you and your firewall.