You install OPNsense from an ISO image. This article describes the steps on our platform; the installation itself follows the usual OPNsense procedure.
Requirements
- at least one public IPv4 address
- at least one virtual network for the LAN side
Creating the virtual machine
- Under Create New Virtual Machine, choose the ISO Images tab and select OS OPNsense OpenSSL Dvd Amd64. The secondary ISO stays empty.
- Recommended sizing: 2 vCPU, 2048 MB RAM. 10 GB is enough for the boot disk; if you want to do a lot of logging, plan on 25 GB or more.
- Under Virtual Networks, add the network interfaces you need — typically one per zone, e.g. WAN, LAN and DMZ. The order of the NICs decides which interface OPNsense later sees as WAN.
Installation
Once it has been created, open the VNC Console. Log in to the installer with the user installer and the password opnsense and follow the steps: keyboard layout, installation type, target disk, then set a password and restart.
After the installation, remove the ISO image so that the VM boots from the disk.
The OPNsense documentation describes the details of the installer and the initial setup.
Secure access before the firewall is connected to the internet. In the Client Area, set firewall rules that limit access to the web interface to your own addresses, and change the default password when you first log in.