OPNsense 21.7, codenamed “Noble Nightingale”, has been released and brings significant improvements to the open-source firewall. This release is based on FreeBSD 13 for the first time and delivers numerous new features.
Release Highlights
FreeBSD 13 as the Base
The switch to FreeBSD 13 is the most important change in this release:
- Updated network stack with improved performance
- Better hardware support
- Updated cryptography libraries
- Optimized memory management
WireGuard Kernel Module
OPNsense 21.7 integrates a native WireGuard kernel module:
- Significantly better performance compared to the previous userspace implementation
- Easier configuration via the web interface
- Stable operation for site-to-site and road warrior VPN
- Support for multiple tunnels simultaneously
Improved Firmware Update System
The update system has been fundamentally redesigned:
- Faster and more reliable updates
- Better error handling for update issues
- Easy rollback capability
- Improved progress display
Firewall Improvements
- Redesigned alias management
- Improved GeoIP filtering
- Optimized rule processing
- Extended logging capabilities
IPsec Updates
- Updated strongSwan VPN stack
- Improved IKEv2 support
- Extended cipher options
- Optimized tunnel management
Web Interface
The user interface received various improvements:
- Modernized dashboard
- Faster page loading times
- Improved firmware status widget
- Extended diagnostics tools
Security Updates
- Updated OpenSSL
- Suricata IDS/IPS updates
- Unbound DNS resolver update
- Numerous CVE fixes
Migration from 21.1
The upgrade from OPNsense 21.1 to 21.7 can be performed via the web interface under System > Firmware. A prior backup of the configuration is strongly recommended.
Conclusion
OPNsense 21.7 is an important release that brings significant performance improvements with FreeBSD 13 as the base and the native WireGuard kernel module. As an experienced OPNsense integrator, we are happy to advise you on planning and implementing your firewall infrastructure.
More on these topics:
More articles
MFA Methods: TOTP vs. FIDO2 vs. Push — Which for SMBs?
MFA comparison for SMBs: TOTP, FIDO2 and push notifications in practice. Phishing resistance, cost, and rollout with Authentik or Keycloak.
pfSense Plus vs. OPNsense 2026: Current Feature Comparison
pfSense Plus vs. OPNsense 2026 technical comparison: WireGuard, Zenarmor, HAProxy, Suricata, MFA and HA -- licensing, community and migration paths.
OPNsense HA with CARP: 3 Real-World Pitfalls
OPNsense HA with CARP in SMB environments: the three most common pitfalls -- config drift, sync-interface saturation and DHCP failover -- with fix procedures.