What is the OPNsense firewall quick deployment?
OPNsense is an open-source firewall platform. STACKIT offers it as a quick deployment: a documented guide for installing, setting up, and configuring OPNsense as a virtual machine in your STACKIT project. This combines STACKIT’s flexible Infrastructure as a Service environment with an enterprise-grade firewall.
It is not a managed service operated by STACKIT but third-party software on STACKIT infrastructure: operations, updates, and the rule set remain your responsibility. According to STACKIT, OPNsense offers the same features as expensive commercial firewall solutions, often including additional features.
Key capabilities
- IDS/IPS: Intrusion detection and prevention to identify and block attacks
- GeoIP filtering: Filtering traffic based on geographic origin
- VPN: IPsec, OpenVPN, and WireGuard for site and client connectivity
- Web interface: Configuration without UNIX command-line expertise
- Free sizing: VM size adjusted to your own requirements
- Open source: No license fees, no artificial feature limitations, transparent security practices, community maintained
- Automated provisioning: Terraform-based deployment with a WAN (vtnet0) and a LAN interface (vtnet1)
Typical use cases
Perimeter firewall: Inbound and outbound traffic of a STACKIT project passes through a central firewall instance with its own rule set.
Attack detection: IDS/IPS inspects traffic for known attack patterns and blocks them before they reach your workloads.
VPN connectivity: Sites and clients connect securely to the cloud environment via IPsec, OpenVPN, or WireGuard.
Origin-based filtering: GeoIP rules cut unwanted traffic from regions without business relevance.
Benefits
- No license fees: Only the STACKIT infrastructure you use is billed
- Full feature set: No artificial limitations as found in some commercial appliances
- Familiar operation: A well-known web interface for administrators
- Sovereign operation: Firewall and rule set run inside your own STACKIT project
- Automatable: Provisioning via Terraform instead of manual installation
Working with innFactory
As an official STACKIT partner, innFactory supports you with the OPNsense quick deployment: network and zoning concept, sizing of the firewall VM, building the rule set, connecting sites via VPN, and hardening management access after the initial setup.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is the OPNsense firewall quick deployment?
STACKIT provides a quick deployment for the open-source firewall OPNsense: a documented guide for installing, setting up, and configuring OPNsense as a virtual machine on STACKIT infrastructure. OPNsense itself is third-party software, not a managed service operated by STACKIT.
Which security features does OPNsense provide?
The documentation lists intrusion detection and prevention (IDS/IPS), GeoIP filtering, and VPN via IPsec, OpenVPN, and WireGuard.
Are there any license fees?
No. OPNsense is free and open-source software with no license fees and no artificial feature limitations. Only the STACKIT infrastructure you use is billed.
How is the firewall provisioned?
According to the documentation, provisioning is handled by a Terraform script. A service account key stored as secrets.json is required. The first interface, vtnet0, is bound to WAN and the second interface, vtnet1, to LAN.
How is the firewall administered?
OPNsense is administered through a web interface reachable via a floating IP on port 443. UNIX command-line knowledge is not required.
What should I take care of after the deployment?
For initial access to the web UI, the deployment adds a firewall rule that allows access from all WAN IPs. STACKIT recommends changing this after the first setup. The preconfigured credentials should be changed immediately as well.
How large does the virtual machine need to be?
The VM size can be adjusted freely to your requirements. Throughput, the number of VPN connections, and the use of compute-intensive features such as IDS/IPS are the decisive factors.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
