
OPNsense Beginner to Professional
By :

Let's dive into OPNsense's core features and the most common scenarios to deploy it.
What are the core features? The OPNsense core features all come with the default OPNsense installation, without any additional plugins.
The core features are as follows:
iptables
. The OPNsense webGUI generates the pf rules that are used for packet filtering and Network Address Translation (NATs). If, like me, you're a curious person and have access to a running OPNsense firewall, you can sneak a peak at the /tmp/rules.debug
file to see some of the pf rules. But be warned – don't touch anything there yet! In Chapter 5, Firewall, we will dive into the world of firewalls. If you are not running OPNsense yet, don't worry! In the next chapter, we'll install and configure it.ipfw
, the native packet filtering for FreeBSD, to classify and prioritize packets for the traffic shaping. With a traffic shaper, you'll be able to limit and reserve bandwidth and prioritize Quality of Service (QoS) traffic.Important Note
Dynamic DNS is a plugin installed by default on OPNsense.
Captive portal: Talking about guest networks and controlling users to join a network, this also applies to the captive portal in OPNsense. This feature can be used with the web proxy to authorize users to use the internet and has widespread usage in hotels, airports, shopping centers, and so on.
tcpdump
), and Netflow, and the list is increasing with each new version.Here are some of the other great OPNsense features:
There are many other features that can be added in OPNsense through plugins, and we will see in detail each core function and some plugins later in this book.
Note
You can obtain a full list of features at https://opnsense.org/about/features//.
OPNsense is very powerful and versatile and can be used in many ways. I'll try to cover the most common deployments, as follows:
There are other possible deployments, such as a web application firewall, a next-generation firewall, an advanced network router, a DNS filtering appliance, and Software Defined WAN (SD-WAN). It's not possible to cover all the possibilities in one book, but we will explore the most common ones in the following chapters.
Change the font size
Change margin width
Change background colour