OPNsense is a mature open-source firewall and routing platform: stateful filtering, network segmentation, VPN, intrusion prevention, traffic shaping and reporting, on hardware you choose.
It exists on this site for a consistent reason. If the argument for keeping your service desk, your monitoring and your databases inside your own control holds, it holds for the device that defines the perimeter too — no subscription that can lapse and disable filtering, no feature gated behind a licence tier, and a configuration you can read.
Who it’s for
Organisations that want the perimeter under the same ownership terms as the rest of the estate.
- Institutions segmenting card, core-banking or management networks from general traffic
- Multi-site organisations needing secure site-to-site connectivity between branches
- Teams replacing ageing perimeter equipment or consolidating several vendors
- Organisations that want firewall capability without recurring per-feature subscription cost
What we deliver
A designed, documented perimeter — with the firewall itself under monitoring rather than a blind spot.
Sizing and hardware specification
Throughput, session count and feature requirements matched to appropriate hardware, physical or virtual.
Installation and commissioning
Deployment with high-availability pairing where uptime requires it.
Firewall policy design
Rule sets built from an explicit written policy rather than accumulated ad hoc, with the intent behind each rule documented.
Network segmentation
VLANs and zones with inter-zone policy, so sensitive networks are isolated by design rather than by convention.
VPN configuration
IPsec and WireGuard site-to-site tunnels for branches, and remote access for staff with directory-integrated authentication.
Intrusion prevention
IPS rulesets and threat feeds configured and tuned against false positives.
High availability
Failover pairs with synchronised state, so a device failure is not an outage.
Logging and monitoring
Device health, session counts, tunnel state and interface throughput integrated into your monitoring platform.
Backup and documentation
Configuration backup, restore procedure, and documentation so the device is not knowledge held by one person.
On-premises versus cloud
Every criterion below is one your auditors will ask about. This is why we deploy inside your network by default.
| Criterion | On-premises, on your infrastructure | Public cloud / SaaS |
|---|---|---|
| Security | You control the firewall, the encryption keys, the access policy and the audit trail. | Shared infrastructure and a provider-defined security boundary. |
| Privacy | Data never leaves your network perimeter. | Data is stored and processed on third-party systems under their terms. |
| Autonomy | Full customisation, your upgrade schedule, no vendor lock-in. | Provider-driven roadmap and forced upgrade windows. |
| Integrity | You define backup, retention and recovery, and you test them. | You inherit the provider’s backup policy and their definition of acceptable loss. |
| Continuity | Service survives loss of internet connectivity; it runs on your intranet. | An outage or a commercial dispute at the provider becomes your outage. |
| Cost | Capital cost plus support; no per-seat escalation as headcount grows. | Per-user subscription that grows with your organisation. |
How it connects to the rest of your stack
Nothing we deploy is meant to stand alone. These are the joins we build as part of the same engagement.
- Monitoring — Firewall health, VPN tunnel state and interface saturation monitored alongside the rest of the infrastructure.
- Certificate management — Appliance and VPN certificates handled as part of the certificate lifecycle service, with expiry tracked.
- Asset management — Devices, hardware warranties and support arrangements tracked with renewal dates.
Engagement summary
Questions we’re usually asked
Open-source firewall in a bank — seriously?
It is a fair question and we will not oversell it. OPNsense is built on the same packet-filtering lineage as the commercial appliances most institutions already run, and its filtering, IPS and VPN capability is mature and in production use in regulated environments. Where your policy, your insurer or an existing support contract requires a named commercial vendor, that is a legitimate constraint — tell us during scoping and we will work within it rather than argue the point.
How does it compare to what we have?
That is an assessment question, not a brochure question. We look at your throughput, feature use, support obligations and renewal costs, and give you a written comparison — including the cases where replacing what you have is not worth doing.
OPNsense in use
