OPNsense has released version 24.1. The release, codenamed “Savvy Shark”, brings numerous improvements to the open-source firewall platform.
Key New Features
Modernized Interface
OPNsense 24.1 brings a modernized MVC-based interface with improved user guidance. The interface has been redesigned in many areas and offers a more consistent user experience.
Improved Authentication
- Deferred Authentication for multi-factor authentication (MFA)
- Improved LDAP/RADIUS integration
- Extended TOTP support
Firewall and Networking
- Improved firewall alias management with new types
- Extended traffic shaping functionality
- IPv6 improvements
System Updates
- Update to FreeBSD 13.2-p9
- PHP 8.2 with security updates
- Updated Phalcon 5 framework
- Unbound DNS updated to version 1.19
VPN and Security
- Improved WireGuard support
- Updated IPsec configuration via swanctl
- OpenVPN improvements
- Updated Suricata IDS/IPS engine
API Improvements
- Extended REST API for automation
- Improved API key management
- New API endpoints for configuration management
Upgrade Notes
Existing OPNsense installations can be updated to version 24.1 via the built-in update system. It is recommended to create a complete backup of the configuration before updating.
Implementation Support
DATAZONE supports you with the implementation and operation of your OPNsense firewall. Contact us for individual consultation.
More on these topics:
More articles
MFA Methods: TOTP vs. FIDO2 vs. Push — Which for SMBs?
MFA comparison for SMBs: TOTP, FIDO2 and push notifications in practice. Phishing resistance, cost, and rollout with Authentik or Keycloak.
pfSense Plus vs. OPNsense 2026: Current Feature Comparison
pfSense Plus vs. OPNsense 2026 technical comparison: WireGuard, Zenarmor, HAProxy, Suricata, MFA and HA -- licensing, community and migration paths.
OPNsense HA with CARP: 3 Real-World Pitfalls
OPNsense HA with CARP in SMB environments: the three most common pitfalls -- config drift, sync-interface saturation and DHCP failover -- with fix procedures.