OPNsense 26.7, currently at 26.7.4 released on 15 September 2026, is a FreeBSD-based firewall that shares ancestry with pfSense but has its own installer, its own interface layout and a different rule model in places. This tutorial takes a clean box or VM with two network ports through installation, the setup wizard, and the minimum set of firewall and NAT rules that make it useful: allow LAN out, translate outbound traffic to the WAN address, and forward one inbound port to an internal server.
Applies to OPNsense 26.7 (26.7.4)
Table of Contents
Short answer: Boot the OPNsense 26.7 image, log in as installer with password opnsense, choose ZFS on GPT and install to the target disk, then reboot and assign WAN and LAN from the console. Log in to https://192.168.1.1 as root, complete the wizard, and under Firewall » Rules » LAN keep the default allow rule while adding specific rules on WAN; automatic outbound NAT covers LAN egress, and Firewall » NAT » Port Forward creates inbound forwards with a linked WAN rule.
Install and assign interfaces
Write the VGA or serial image to USB, or attach the DVD image to a VM, and boot. The live system starts and shows a login prompt; use the account installer with the password opnsense to launch the installer. Pick the keymap, then choose ZFS as the filesystem with GPT partitioning and a striped single-disk pool for most appliances. Select the disk, confirm the wipe, and let the copy run. You are asked to set the root password before the final reboot; choose a long one now. Remove the media and reboot into the installed system.
On the console menu choose option 1, Assign interfaces. The prompts ask whether to configure VLANs now, then for the WAN and LAN device names such as vtnet0 and vtnet1. Match them against the MAC addresses shown on the console. Option 2 sets the LAN address if you need something other than 192.168.1.1/24; it also enables DHCP on LAN and can switch the WebGUI to plain HTTP, which is not recommended.
Run the setup wizard
Browse to the LAN address, accept the self-signed certificate and log in as root. The wizard covers hostname and domain, DNS servers and whether to let the WAN override them, timezone, WAN mode (DHCP, static or PPPoE) with the option to block private and bogon networks on WAN, LAN address, and finally the root password again. When it completes, go to System » Firmware, click Check for updates and apply anything pending so the box is on the current 26.7.x build before it goes into service.
Firewall rules
OPNsense ships with a default allow rule on LAN and no allow rules on WAN, which is the correct starting point. Rules are evaluated top to bottom per interface, first match wins, and there is an implicit deny at the end. Under Firewall » Rules » LAN you will see the automatic anti-lockout rule and the default allow-all. For a small office that is acceptable; for a server segment replace the allow-all with narrower rules: allow TCP/UDP 53 to the firewall, allow TCP 80 and 443 to any, allow NTP, and block everything else with logging so you can see what you missed.
Under Firewall » Aliases create named groups for hosts, networks and ports before writing rules. An alias such as mgmt_hosts referenced in a rule is far easier to maintain than a rule per address. Apply changes with the Apply button that appears after each save; rules are not live until then.
NAT
Firewall » NAT » Outbound defaults to automatic mode, which generates a translation rule for every internal network to the WAN address. Leave it there unless you need static source ports for SIP or a specific public address per subnet, in which case switch to hybrid mode and add manual rules above the automatic ones.
For an inbound service, go to Firewall » NAT » Port Forward and add a rule: interface WAN, protocol TCP, destination WAN address, destination port 443, redirect target IP of the internal server, redirect target port 443, and leave Filter rule association set to add an associated filter rule. That creates the matching WAN allow rule automatically. If the service must also be reachable from inside by its public name, enable reflection under Firewall » Settings » Advanced or, better, publish a split-DNS override in Unbound.
Verify
From a LAN client, confirm DNS resolves and a site loads. From an outside host, test the forward and confirm nothing else answers:
curl -I https://203.0.113.10
nmap -Pn -p 22,80,443,8443 203.0.113.10
On the firewall itself, Firewall » Log Files » Live View shows matches in real time and is the fastest way to see whether a packet hit the rule you expected. Diagnostics » Firewall » States lists active translations.
The common pitfall is forgetting the Apply step, or writing a port forward while the internal server’s default gateway points elsewhere, so return traffic bypasses the firewall and the connection hangs after the SYN. Check the server’s route table before blaming the rule.
Install OPNsense 26.7 at a glance


Official documentation: OPNsense documentation, Linux man pages.
Related guides: Install pfSense CE 2.9 step by step with the network installer and ZFS · Troubleshoot MTU, fragmentation and slow VPN throughput · Set up HAProxy reverse proxy with Let’s Encrypt (ACME) on pfSense.
Frequently asked questions
Does OPNsense 26.7 still support UFS installs?
Yes, the installer still offers UFS, but ZFS is the sensible choice on any hardware with 4 GB of RAM or more because it provides snapshots and better resilience to power loss.
How long does an OPNsense installation take?
Copying the system to disk takes a few minutes; including interface assignment, the wizard and the first firmware update, plan for around twenty minutes on a typical appliance.
Can I undo a firewall rule change that locked me out?
Yes. Use the console menu option to reset the LAN address, which re-enables the anti-lockout rule, or restore an earlier configuration from System » Configuration » Backups, which keeps a history of every change.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- OPNsense 26.7 (26.7.4)
- Last full review
- Next review
- Sources
- docs.opnsense.org