// Engineering Log
What is OPNsense: an open-source firewall for the office
Published on 2026-09-22
// Fast route
This article belongs to the topic Networking and routing.
OPNsense — an open-source firewall and router. It is installed on a dedicated PC, mini-PC, or virtual machine and becomes the gateway between the office network and the Internet: it filters traffic, assigns addresses, brings up VPNs, and fails over to a backup provider. The project is distributed under a simplified two-clause BSD license, runs on FreeBSD, and releases major versions twice a year; the current one is 26.7 “Xenial Xenops”.
What it can do
According to the project description:
- stateful firewall for IPv4 and IPv6;
- multiple providers with load balancing and failover (Multi-WAN);
- VPN: IPsec, OpenVPN, WireGuard;
- high-availability pair of two devices using CARP with state synchronization;
- intrusion prevention system based on Suricata with Emerging Threats rules;
- reports, load graphs, and NetFlow traffic analysis.
The rest is added via plugins from the built-in catalog: reverse proxies, DNS filters, monitoring agents, and more.
Who it’s for
OPNsense is appropriate where a standard router is no longer enough: an office of 10–100 people with two providers, VPN for remote employees and branches, network segmentation (accounting, guests, cameras), and requirements to log and control traffic. For an apartment with a single provider it is excessive, and for a large network with dozens of branches you should compare it with enterprise solutions for support and centralized management.
Installation
- Hardware. You need a device with at least two network ports — WAN and LAN. Prefer Intel network cards: FreeBSD has the fewest problems with them. A virtual machine also works, for example in Proxmox, with two virtual adapters.
- Image. The image is downloaded from opnsense.org and written to a USB stick. The installer offers ZFS or UFS; ZFS is more resilient to power failures.
- Assigning interfaces. After the first boot the console asks which port is WAN and which is LAN. Further configuration is done in the web interface at the LAN address (default
192.168.1.1); the initial setup wizard walks through the main steps.
First configuration
- Change the root password and create a separate administrator user.
- Restrict access to the web interface to the internal network only. Do not expose it to the Internet: use VPN for remote administration.
- Update the system to the latest release of the branch.
- Firewall rules. By default LAN is allowed everything, WAN nothing. It’s better to separate network segments right away: guest Wi-Fi and cameras should not see work computers.
- Backup configuration. The entire configuration is a single XML file; export it after each significant change.
Backup link
For two providers in OPNsense you create two gateways with availability checks and a gateway group with priority levels: primary — level 1, backup — level 2. The group is specified in the rule for outgoing traffic. When the primary gateway check fails, traffic goes through the backup. More about failover schemes in the article about going out to the Internet via two providers.
API
OPNsense has a REST API for automation. Access is not given with the admin password but with a “key and secret” pair created for a user in the user manager. This pair is passed as the login and password for HTTP Basic Auth:
curl -u "API_KEY":"API_SECRET" https://192.168.1.1/api/core/firmware/statusCreate a separate user with minimal privileges for the API, rather than giving the key to the administrator.
OPNsense or pfSense
OPNsense grew out of a fork of pfSense in 2015, and the systems have much in common: FreeBSD, similar capabilities, the same class of tasks. They differ in release and licensing approach: OPNsense has a single open edition with biannual releases; pfSense has an open CE and a commercial Plus. A detailed comparison is in the article about pfSense.
When OPNsense is a good fit
If you need a full-featured firewall with VPN, a backup link, and network segmentation without licensing fees and you have someone to maintain it, OPNsense is a good choice. If you want an out-of-the-box device with minimal setup, a ready-made router is more practical — for example, MikroTik or Keenetic.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related