OPNsense default-drops traffic arriving on non-LAN interfaces (e.g. WireGuard tunnels used as management networks). Even with os-net-snmp running and configured, SNMP is unreachable from external management hosts because no firewall rule allows it. Now adds a floating pass rule for UDP/161 → (self) after configuring the service, then applies the firewall. Skips the rule if one with the same description already exists (idempotent). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>