OPNsense 22.7, codenamed “Powerful Panther”, has been released and brings a new Captive Portal, improved VPN features, and numerous security updates.
Release Highlights
New Captive Portal
The Captive Portal has been completely redeveloped:
- DynFi-based new Captive Portal
- Modernized user interface
- Improved voucher management
- Flexible authentication options
- Better integration with RADIUS servers
WireGuard Improvements
WireGuard support has been further optimized:
- Updated WireGuard kernel module
- Improved configuration interface
- Optimized performance
- Extended routing options
- Better multi-tunnel management
FreeBSD Updates
- Updated FreeBSD 13.1 base
- Improved network stack
- Updated drivers
- Security patches
Firewall and Routing
- Inline IPS mode for Suricata improved
- Extended alias types
- Optimized rule processing
- Improved gateway monitoring
- Extended Multi-WAN functionality
Unbound DNS
- Updated Unbound DNS resolver
- Improved DNS-over-HTTPS support
- Extended local zone management
- Optimized cache performance
Plugin Updates
- Updated HAProxy plugin
- Improved ACME client plugin for Let’s Encrypt
- Updated Nginx plugin
- Various plugin bugfixes
Web Interface
- Modernized design with improvements
- Extended dashboard widgets
- Improved diagnostics tools
- Optimized API functionality
Migration from 22.1
The upgrade from OPNsense 22.1 to 22.7 can be performed via System > Firmware in the web interface. A prior backup of the configuration is recommended.
Conclusion
OPNsense 22.7 impresses with the new Captive Portal and WireGuard improvements. The release demonstrates the continuous development of the open-source firewall. As an experienced OPNsense integrator, we are at your side for planning and implementing your network security.
More on these topics:
More articles
Backup Strategy for SMBs: Proxmox PBS + TrueNAS as a Reliable Backup Solution
Backup strategy for SMBs with Proxmox PBS and TrueNAS: implement the 3-2-1 rule, PBS as primary backup target, TrueNAS replication as offsite copy, retention policies, and automated restore tests.
OPNsense Suricata Custom Rules: Write and Optimize Your Own IDS/IPS Signatures
Suricata custom rules on OPNsense: rule syntax, custom signatures for internal services, performance tuning, suppress lists, and EVE JSON logging.
Systemd Security: Hardening and Securing Linux Services
Systemd security hardening: unit hardening with ProtectSystem, PrivateTmp, NoNewPrivileges, CapabilityBoundingSet, systemd-analyze security, sandboxing, resource limits, and creating custom timers.