Manage OPNsense firewalls centrally
Maintaining two, three or ten OPNsense firewalls one by one through their web interfaces costs time and inevitably leads to differences between them. This guide explains when central management pays off, how it works and what to look out for.
When central management pays off
As soon as more than one firewall is involved: an HA pair, several sites, or separate test and production systems. The pain points are always the same:
- The same rule or alias has to be created by hand several times – and somewhere it gets forgotten.
- The firewalls' configurations drift apart without anyone noticing.
- Updates get postponed because nobody has an overview of which system is at which version.
- Certificates expire because each firewall manages its own.
What OPNsense provides – and what it does not
Within an HA pair, OPNsense can synchronise parts of the configuration between the nodes. For several independent firewalls or sites there is no shared interface in OPNsense: every firewall is maintained on its own. Central management closes exactly that gap without changing the firewalls themselves – it works through the REST API that OPNsense provides anyway.
How central management works with OPNexus
OPNexus runs as its own service (Docker) next to your firewalls and talks to each one with an API key. You maintain definitions once, centrally, and roll them out to single firewalls or whole device groups:
- Rules and aliases: maintained centrally, with a result per target firewall; plus hierarchical rulebases with inheritance.
- NAT: port forward, 1:1 and outbound NAT, including a comparison between cluster nodes.
- VPN: define IPsec (site-to-site), OpenVPN and WireGuard once and roll them out.
- Certificates: a live overview of remaining lifetimes, trust store and ACME.
- Network: interfaces, VLANs, virtual IPs, gateways, routes, DNS and DHCP per firewall.
- Updates, logs and audit: fleet firmware updates, central log search and a complete change history.
Every change follows the same flow: preview → roll out → confirm. If you do not confirm a rule change within the time window (three minutes by default), it is rolled back automatically. More in the guide Rolling out rules safely.
Spotting differences
Managing centrally also means seeing where things do not match. OPNexus compares the rules and NAT entries that are actually active between the nodes of a cluster and reports differences. Rules that were created by hand in the OPNsense interface can also be adopted into central management, without anything being written to the firewall.
Security and operations
- Self-hosted: your firewall data stays with you – no cloud and no account with us.
- Encrypted connections: HTTPS with pinned firewall certificates; API credentials are not kept in the database.
- Access: optional two-factor sign-in and roles (admin and read-only).
- Traceable: every change is in the audit log with time, user and result.
- Not in the data path: OPNexus only manages configuration. If it is down, the firewalls keep running unchanged.
Who it is for – and who it is not for
OPNexus is aimed at administrators who run their own OPNsense firewalls – in a company, a club or a homelab. Multi-tenancy and customer portals for service providers who look after many third-party environments are deliberately not a goal.
Frequently asked questions
Do I have to install anything on the firewalls?
No. You create an API key on each firewall; OPNexus itself runs separately on its own server.
What does OPNexus cost?
Nothing. The software is free, self-hosted and the source code is available to read (licence: PolyForm Shield).
Which OPNsense versions are supported?
It was developed and tested against OPNsense 25.7 through 26.7, including major upgrades from the interface. Individual functions need newer versions; for example, interface IP configuration can only be changed through the API from 26.7.6.
What happens if OPNexus goes down?
The firewalls keep running unchanged because OPNexus is not in the data path. Only central management is unavailable until it is back.
Try OPNexus
Free, self-hosted, source available. Installed in a few minutes.