About OPNsense
OPNsense is an open-source firewall project, and this repository contains its web GUI, API and systems backend. Its topics point to a broad feature set that includes a firewall, intrusion prevention, proxy, VPN, traffic shaping, a captive portal and routing, built on a BSD base.
The project invites developers to contribute and has designed its build process so that anyone can build and write code. Build tools are freely available in a separate tools repository, an architecture overview is on docs.opnsense.org, and the repository offers Makefile targets such as make package for assembling a package from the current state of the code. The team aims to evolve toward a new codebase gradually rather than in one big switch.
OPNsense is written mostly in PHP and is committed to staying available under the 2-clause BSD license, with every contribution required to carry the same terms. Contributions can be as simple as testing functionality, filing bug reports or sending pull requests.
Key features
- Web GUI for firewall management
- API and system backend
- Intrusion prevention and proxy
- VPN and traffic shaping
- Captive portal and routing
- BSD-based platform
Good fit for
- →Home or office network firewall
- →Perimeter security and VPN gateway
- →Guest access with a captive portal
- Built with
- PHP
- Tags
- firewall
- router
- vpn
- ips
- bsd
- captive-portal
- traffic-shaping
- security
- networking
OPNsense: questions and answers
- What is OPNsense used for?
- OPNsense is an open-source firewall and routing platform; this repository holds its web GUI, API and system backend, licensed under BSD-2-Clause. It is a good fit for home or office network firewall, perimeter security and VPN gateway, and guest access with a captive portal.
- Is OPNsense open source?
- Yes. OPNsense is open source under the BSD-2-Clause licence. Its source code is on GitHub at opnsense/core and is written mainly in PHP.
- Is OPNsense free?
- Yes. OPNsense is open source, so the software itself is free to use.
- Can I self-host OPNsense?
- Yes. OPNsense can be self-hosted on your own server or infrastructure; there is no official hosted version.
- What is OPNsense an alternative to?
- OPNsense is an open-source alternative to Fortinet, Palo Alto Networks, Check Point and Sophos. Other open-source alternatives to Fortinet include pfSense, Suricata and ModSecurity.
- Is OPNsense actively maintained?
- Yes. The most recent commit to OPNsense was on 2 October 2026. The project has 4.7k stars on GitHub.
Open-source alternatives to OPNsense
See all
pfSense
Security
Main repository for pfSense
Apache-2.0vs Fortinet★ 5.7k
Suricata
Security
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network
GPL-2.0vs Palo Alto Networks★ 6.7k
ModSecurity
Security
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Ap
Apache-2.0vs Cloudflare★ 9.8k
BunkerWeb
Security
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
AGPL-3.0vs Cloudflare★ 11k
OpenZiti
Networking & VPN
The parent project for OpenZiti. Here you will find the executables for a fully zero-trust
Apache-2.0vs Twingate★ 4.4k
Firezone
Networking & VPN
Blazing-fast remote access
Apache-2.0vs Tailscale★ 9.1k
SaaS alternatives to OPNsense
See all
Fortinet
Security
FortiGate firewalls and a broad security fabric for network, cloud and endpoints
SaaS
Palo Alto Networks
Security
Network, cloud and endpoint security vendor selling firewalls, SASE and SOC tools
SaaS
Check Point
Security
Network firewalls, cloud and endpoint security from an Israeli security vendor
SaaS
Sophos
Security
Endpoint, firewall and managed detection and response services for businesses
SaaS
Cato Networks
Security
Cloud-native SASE platform combining SD-WAN and network security
SaaS
Cisco Umbrella
Security
Cloud security service providing DNS-layer protection and secure web gateway
SaaS

