Overview
OPNsense Core implements the web GUI, APIs, and system-management backend used by the FreeBSD-based OPNsense firewall/router appliance. It manages firewall rules, routing, VPNs, traffic shaping, captive portal features, and other network-appliance configuration as part of the full OPNsense system.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Manage firewall and routing features through GUI and APIs
The core management layer exposes packet filtering, NAT, routing, VPN, and related system settings through browser interfaces and APIs.
Connect appliance configuration to backend services
OPNsense models, controllers, and backend actions coordinate system configuration and network daemons behind a unified management interface.
For operating a GUI-managed firewall or router appliance
OPNsense fits dedicated hardware or VM gateways, VPN endpoints, and firewall deployments that benefit from browser-based administration.
Evaluate the full appliance in an isolated VM rather than this repo alone
The core repository is only one part of OPNsense. Use the official image in an isolated WAN/LAN lab and avoid conflicts with existing gateway, DHCP, and DNS infrastructure while testing.
Official sources
- [1]opnsense/core repository(2026-09-20)
- [2]OPNsense Core README(2026-09-20)
- [3]OPNsense Core BSD-2-Clause license(2026-09-20)
- [4]OPNsense documentation(2026-09-20)
Supplemental curator note
This repository is not a standalone application; it is the core GUI/API/backend code for the FreeBSD-based OPNsense appliance. Evaluate it using an official OPNsense image in an isolated VM lab, and validate firewall, NAT, VPN, and routing rules before placing it in a real gateway path.
Try it in 3 steps
- 1
Download the official OPNsense image
Evaluate the complete appliance rather than trying to run the core repository as a standalone application.
https://opnsense.org/download/ - 2
Install it in an isolated WAN/LAN VM
Keep the lab separate from existing gateways and DHCP services.
Create a VM with isolated WAN and LAN adapters - 3
Inspect configuration through the Web GUI
Review interfaces, firewall rules, routes, and VPN settings before connecting the appliance to a real network.
Open the OPNsense Web GUI from the isolated LAN
Growth
Growth trends · Last 30 days
4,683 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 153
- Open PRs
- 45
- Issues opened
- 300
- Issues closed
- 319
- PRs opened
- 138
- PRs merged
- 107
Issues
300 / 319
Pull requests
138 / 107
Maintenance
- Median first response
- 2.6 hr
- Issue response rate
- 53.3% (49/92)
Based on up to the 100 newest issues opened by external users in the last 90 days. A first comment from an OWNER, MEMBER, or COLLABORATOR counts as a response; issues whose full comment history cannot be checked are excluded. The median and response rate update weekly.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- firewall
- gui
- api
- ips
- proxy
- vpn
- shaping
- captive-portal
- bsd
- routing
- hacktoberfest
- Stars
- 4,683
- Forks
- 993
- Watchers
- 124
- Open issues
- 259
- Contributors
- 325
- Primary language
- PHP
- License
- BSD-2-Clause
- Repository last updated
- Sep 19, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- RustDesk124,007 Stars
A cross-platform Rust remote desktop with NAT traversal, relay fallback, and optional self-hosted ID/relay infrastructure.
Rust - Sherlock92,144 Stars
A Python OSINT CLI that checks username-based account candidates across social networks.
Python - curl42,893 Stars
A command-line data-transfer tool and embeddable libcurl library supporting HTTP(S), FTP, SFTP, SMTP, MQTT, WebSocket, and many other URL-based protocols.
C - Trivy37,984 Stars
A scanner for vulnerabilities, SBOM data, misconfigurations, secrets, and licenses across containers, Kubernetes, and repositories.
Go - Tailscale36,666 Stars
A WireGuard-based networking client whose tailscaled daemon and CLI connect devices to a private network.
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.