OPNsense 22.7, codenamed “Powerful Panther”, has been released and brings a new Captive Portal, improved VPN features, and numerous security updates.
Release Highlights
New Captive Portal
The Captive Portal has been completely redeveloped:
- DynFi-based new Captive Portal
- Modernized user interface
- Improved voucher management
- Flexible authentication options
- Better integration with RADIUS servers
WireGuard Improvements
WireGuard support has been further optimized:
- Updated WireGuard kernel module
- Improved configuration interface
- Optimized performance
- Extended routing options
- Better multi-tunnel management
FreeBSD Updates
- Updated FreeBSD 13.1 base
- Improved network stack
- Updated drivers
- Security patches
Firewall and Routing
- Inline IPS mode for Suricata improved
- Extended alias types
- Optimized rule processing
- Improved gateway monitoring
- Extended Multi-WAN functionality
Unbound DNS
- Updated Unbound DNS resolver
- Improved DNS-over-HTTPS support
- Extended local zone management
- Optimized cache performance
Plugin Updates
- Updated HAProxy plugin
- Improved ACME client plugin for Let’s Encrypt
- Updated Nginx plugin
- Various plugin bugfixes
Web Interface
- Modernized design with improvements
- Extended dashboard widgets
- Improved diagnostics tools
- Optimized API functionality
Migration from 22.1
The upgrade from OPNsense 22.1 to 22.7 can be performed via System > Firmware in the web interface. A prior backup of the configuration is recommended.
Conclusion
OPNsense 22.7 impresses with the new Captive Portal and WireGuard improvements. The release demonstrates the continuous development of the open-source firewall. As an experienced OPNsense integrator, we are at your side for planning and implementing your network security.
More on these topics:
More articles
Firewall for small businesses 2026: the honest comparison
Firewall for small businesses 2026 compared: FritzBox, OPNsense, pfSense Plus, Sophos XGS and Fortinet FortiGate -- what fits for 5 to 50 users?
The Cloud Is Not a Backup: On-Premises TrueNAS as Your Resilient Extra Layer
After destroyed data centers, even AWS pointed customers to their own backups. Why an on-premises backup layer with TrueNAS (immutable ZFS snapshots, pull replication, air-gap) is a mandatory part of any data strategy.
MFA Methods: TOTP vs. FIDO2 vs. Push — Which for SMBs?
MFA comparison for SMBs: TOTP, FIDO2 and push notifications in practice. Phishing resistance, cost, and rollout with Authentik or Keycloak.