Choose the image that matches your architecture and use case.
OPNsense is a FreeBSD-based firewall and routing platform with a web administration interface. It is a dedicated network appliance, not a Linux desktop. The official download selector offers different installation media; choose AMD64 and the image appropriate to the target hardware. The recorded version is the 26.7 installation release, not a claim about the newest installed-system patch level. Review network interface assignments and installation instructions before deploying it as a gateway.
OPNsense is primarily suited to servers, virtual machines and self-hosted services; authorized security testing, forensics and technical training; experienced Linux users who want detailed control over the system. Before choosing it, compare the current release lifecycle with the length of support required for the machine. This distribution is based on freebsd, which influences package formats, repositories and much of the available documentation. The best choice depends on hardware support, preferred software, update policy and the amount of system administration the user wants to perform.
Read the release notes and installation guide before downloading. Select an image that matches the processor architecture and intended use: desktop, server, live media, virtual machine or another published edition. Test Wi-Fi, graphics, audio, storage and suspend from live media when that option is available. Back up important files before repartitioning, encryption changes or dual-boot installation. Security distributions should only be used against systems and networks you own or are explicitly authorized to assess. For production deployment, verify application compatibility, upgrade paths, backup restoration and the project security-support policy in a non-production environment first. Download from an official project page or mirror, compare the published SHA-256 checksum, and verify a signed checksum when the project provides one. After installation, apply updates before adding third-party repositories or drivers.
Requirements depend on the target appliance, network interfaces, storage layout and deployment method. Consult the official hardware guide before installation.
The download button first records an anonymous aggregated download counter and then redirects to the official source.
A project-specific post-installation checklist. Commands are displayed for your own equipment; the website never runs them. Use an authorized administrator account when required.
Use the configuration backup page and store the export outside the firewall.
Before you continue: Exports contain sensitive configuration; encrypt and restrict access.
Read project documentation: Export the configurationCheck LAN, WAN and management mapping against the physical network before policy changes.
Before you continue: Keep console access; incorrect mapping can disconnect management.
Read project documentation: Confirm interface assignmentsConfirm each permit rule has an intended source, destination and service.
Before you continue: Avoid broad allow rules as a troubleshooting shortcut.
Read project documentation: Review rules by interfaceRead update notes and use the supported update interface during a maintenance window.
Before you continue: Expect connectivity interruptions; retain a configuration backup and console access.
Read project documentation: Use the firmware update workflowFrom networks you administer, confirm expected connectivity and blocking after changes.
Before you continue: Existing states may affect tests; do not clear all states casually.
Read project documentation: Test permitted and denied trafficDocument how to recover the saved configuration on compatible equipment.
Before you continue: Test recovery away from the live gateway to avoid address conflicts.
Read project documentation: Plan configuration restoration