Skip to main content
Cloud / STACKIT / Products / Quick Deployment OPNsense Firewall - Open-Source Firewall

Quick Deployment OPNsense Firewall - Open-Source Firewall

OPNsense as a quick deployment on STACKIT: open-source firewall VM with IDS/IPS, GeoIP filtering, and VPN via IPsec, OpenVPN, and WireGuard.

Network
Pricing Model The STACKIT infrastructure you use (server, network, floating IP) is billed via the STACKIT pricing calculator; OPNsense itself is open source and free of license fees
Availability Runs as a virtual machine on STACKIT; region details as documented by STACKIT
Data Sovereignty Operated within the STACKIT cloud; configuration and rule set stay inside your project
Reliability SLA as provided for the STACKIT infrastructure services used; OPNsense is open-source software under customer responsibility SLA

What is the OPNsense firewall quick deployment?

OPNsense is an open-source firewall platform. STACKIT offers it as a quick deployment: a documented guide for installing, setting up, and configuring OPNsense as a virtual machine in your STACKIT project. This combines STACKIT’s flexible Infrastructure as a Service environment with an enterprise-grade firewall.

It is not a managed service operated by STACKIT but third-party software on STACKIT infrastructure: operations, updates, and the rule set remain your responsibility. According to STACKIT, OPNsense offers the same features as expensive commercial firewall solutions, often including additional features.

Key capabilities

  • IDS/IPS: Intrusion detection and prevention to identify and block attacks
  • GeoIP filtering: Filtering traffic based on geographic origin
  • VPN: IPsec, OpenVPN, and WireGuard for site and client connectivity
  • Web interface: Configuration without UNIX command-line expertise
  • Free sizing: VM size adjusted to your own requirements
  • Open source: No license fees, no artificial feature limitations, transparent security practices, community maintained
  • Automated provisioning: Terraform-based deployment with a WAN (vtnet0) and a LAN interface (vtnet1)

Typical use cases

Perimeter firewall: Inbound and outbound traffic of a STACKIT project passes through a central firewall instance with its own rule set.

Attack detection: IDS/IPS inspects traffic for known attack patterns and blocks them before they reach your workloads.

VPN connectivity: Sites and clients connect securely to the cloud environment via IPsec, OpenVPN, or WireGuard.

Origin-based filtering: GeoIP rules cut unwanted traffic from regions without business relevance.

Benefits

  • No license fees: Only the STACKIT infrastructure you use is billed
  • Full feature set: No artificial limitations as found in some commercial appliances
  • Familiar operation: A well-known web interface for administrators
  • Sovereign operation: Firewall and rule set run inside your own STACKIT project
  • Automatable: Provisioning via Terraform instead of manual installation

Working with innFactory

As an official STACKIT partner, innFactory supports you with the OPNsense quick deployment: network and zoning concept, sizing of the firewall VM, building the rule set, connecting sites via VPN, and hardening management access after the initial setup.

Typical Use Cases

Central perimeter firewall in front of STACKIT workloads
Intrusion detection and prevention (IDS/IPS) in your own network
Site-to-site and client VPN via IPsec, OpenVPN, or WireGuard
GeoIP-based filtering of unwanted source countries
Replacing commercial firewall appliances with an open-source solution

Technical Specifications

Administration Managed through a web interface; no UNIX command-line expertise required
Deployment model Quick deployment: STACKIT documents installation, setup, and configuration of OPNsense on STACKIT infrastructure
Licensing Free and open-source software with no license fees and no artificial feature limitations, maintained by the community
Management access Web interface reachable through a floating IP on port 443 (HTTPS)
Network interfaces Two interfaces: vtnet0 bound to WAN, vtnet1 bound to LAN
Provisioning Provisioned via a Terraform script; a service account key is stored as secrets.json beforehand
Security features Intrusion detection and prevention (IDS/IPS) plus GeoIP filtering
Sizing Freely selectable VM size to match your requirements
VPN IPsec, OpenVPN, and WireGuard

Frequently Asked Questions

What is the OPNsense firewall quick deployment?

STACKIT provides a quick deployment for the open-source firewall OPNsense: a documented guide for installing, setting up, and configuring OPNsense as a virtual machine on STACKIT infrastructure. OPNsense itself is third-party software, not a managed service operated by STACKIT.

Which security features does OPNsense provide?

The documentation lists intrusion detection and prevention (IDS/IPS), GeoIP filtering, and VPN via IPsec, OpenVPN, and WireGuard.

Are there any license fees?

No. OPNsense is free and open-source software with no license fees and no artificial feature limitations. Only the STACKIT infrastructure you use is billed.

How is the firewall provisioned?

According to the documentation, provisioning is handled by a Terraform script. A service account key stored as secrets.json is required. The first interface, vtnet0, is bound to WAN and the second interface, vtnet1, to LAN.

How is the firewall administered?

OPNsense is administered through a web interface reachable via a floating IP on port 443. UNIX command-line knowledge is not required.

What should I take care of after the deployment?

For initial access to the web UI, the deployment adds a firewall rule that allows access from all WAN IPs. STACKIT recommends changing this after the first setup. The preconfigured credentials should be changed immediately as well.

How large does the virtual machine need to be?

The VM size can be adjusted freely to your requirements. Throughput, the number of VPN connections, and the use of compute-intensive features such as IDS/IPS are the decisive factors.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

70 comparable products found across other clouds.

Ready to start with Quick Deployment OPNsense Firewall - Open-Source Firewall?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation