OPNexus Deutsch Install

← Back to home

Manage OPNsense firewalls centrally

Maintaining two, three or ten OPNsense firewalls one by one through their web interfaces costs time and inevitably leads to differences between them. This guide explains when central management pays off, how it works and what to look out for.

When central management pays off

As soon as more than one firewall is involved: an HA pair, several sites, or separate test and production systems. The pain points are always the same:

What OPNsense provides – and what it does not

Within an HA pair, OPNsense can synchronise parts of the configuration between the nodes. For several independent firewalls or sites there is no shared interface in OPNsense: every firewall is maintained on its own. Central management closes exactly that gap without changing the firewalls themselves – it works through the REST API that OPNsense provides anyway.

How central management works with OPNexus

OPNexus runs as its own service (Docker) next to your firewalls and talks to each one with an API key. You maintain definitions once, centrally, and roll them out to single firewalls or whole device groups:

Every change follows the same flow: preview → roll out → confirm. If you do not confirm a rule change within the time window (three minutes by default), it is rolled back automatically. More in the guide Rolling out rules safely.

Spotting differences

Managing centrally also means seeing where things do not match. OPNexus compares the rules and NAT entries that are actually active between the nodes of a cluster and reports differences. Rules that were created by hand in the OPNsense interface can also be adopted into central management, without anything being written to the firewall.

Security and operations

Who it is for – and who it is not for

OPNexus is aimed at administrators who run their own OPNsense firewalls – in a company, a club or a homelab. Multi-tenancy and customer portals for service providers who look after many third-party environments are deliberately not a goal.

Frequently asked questions

Do I have to install anything on the firewalls?

No. You create an API key on each firewall; OPNexus itself runs separately on its own server.

What does OPNexus cost?

Nothing. The software is free, self-hosted and the source code is available to read (licence: PolyForm Shield).

Which OPNsense versions are supported?

It was developed and tested against OPNsense 25.7 through 26.7, including major upgrades from the interface. Individual functions need newer versions; for example, interface IP configuration can only be changed through the API from 26.7.6.

What happens if OPNexus goes down?

The firewalls keep running unchanged because OPNexus is not in the data path. Only central management is unavailable until it is back.

Try OPNexus

Free, self-hosted, source available. Installed in a few minutes.

Go to installation