OPNsense 19.7, codenamed “Jazzy Jaguar”, has been released and brings numerous improvements to the popular open-source firewall distribution.
Release Highlights
New Firmware Upgrade System
The firmware upgrade system has been completely redesigned. Updates can now be applied more reliably and faster. The new system is based on improved package management and ensures smooth updates.
Multi-WAN Improvements
Multi-WAN functionality has been significantly improved:
- Gateway groups with more flexible weighting
- Improved failover detection
- Optimized load balancing algorithms
- Faster switchover times during connection failures
Firewall Improvements
- Improved alias management with new types
- Optimized NAT rule management
- Extended logging options
- Improved ruleset for IPv6
VPN Updates
- WireGuard support available as a plugin
- Updated OpenVPN with security fixes
- Improved IPsec configuration
- Extended VPN status overview
Web Interface
The user interface has been further modernized:
- Faster loading times
- Improved dashboard with customizable widgets
- Redesigned navigation
- Responsive design improvements
Security Updates
OPNsense 19.7 includes numerous security updates:
- Updated FreeBSD kernel with security patches
- OpenSSL updates
- Suricata IDS/IPS update
- Various CVE fixes
Migration from 19.1
The upgrade from OPNsense 19.1 to 19.7 can be performed directly via the web interface. It is recommended to create a backup of the configuration beforehand.
Conclusion
OPNsense 19.7 is a solid release with many practically relevant improvements. The Multi-WAN optimizations and WireGuard support in particular make the update attractive. As an experienced OPNsense integrator, we are happy to advise you on planning and implementing your firewall infrastructure.
More on these topics:
More articles
Backup Strategy for SMBs: Proxmox PBS + TrueNAS as a Reliable Backup Solution
Backup strategy for SMBs with Proxmox PBS and TrueNAS: implement the 3-2-1 rule, PBS as primary backup target, TrueNAS replication as offsite copy, retention policies, and automated restore tests.
OPNsense Suricata Custom Rules: Write and Optimize Your Own IDS/IPS Signatures
Suricata custom rules on OPNsense: rule syntax, custom signatures for internal services, performance tuning, suppress lists, and EVE JSON logging.
Systemd Security: Hardening and Securing Linux Services
Systemd security hardening: unit hardening with ProtectSystem, PrivateTmp, NoNewPrivileges, CapabilityBoundingSet, systemd-analyze security, sandboxing, resource limits, and creating custom timers.