Notes on installing OPNsense 26.7 (based on FreeBSD) as a Virtual Firewall
Subject: Notes on installing OPNsense 26.7 (based on FreeBSD) as a Virtual Firewall
Good day from Singapore,
Author: Mr. Turritopsis Dohrnii Teo En Ming
Date: 10 Oct 2026 Saturday 1.32 pm
Country: Singapore
Section 1 - Download OPNsense Firewall
==========================================
Download link:
https://opnsense.org/download/
Fast download selector:
System architecture: amd64
Select the image type: dvd
Mirror Location: Taiwan, Nantou County Education Network Center
Peak download speed: 44 MiB/s
Downloaded as OPNsense-26.7-dvd-amd64.iso.bz2
Use 7-zip to Extract Here.
Then you will get OPNsense-26.7-dvd-amd64.iso
Filesize: 1.95 GB
Section 2 - Installing OPNsense 26.7 as a Virtual Firewall in VMware Workstation Pro 26H1u1
================================================================================================
File > New Virtual Machine
New Virtual Machine Wizard
===========================
Welcome to the New Virtual Machine Wizard
Select Typical (recommended)
Click Next
Guest Operating System Installation:
Click Installer disc image file (iso):
D:\OPNsense-26.7-dvd-amd64.iso
Click Next
Name the Virtual Machine:
Virtual machine name:
OPNsense 26.7 Virtual Firewall
Location:
D:\Virtual Machines\OPNsense 26.7 Virtual Firewall
Click Next
Specify Disk Capacity:
Maximum disk size (GB): 64
Click Store virtual disk as a single file
Click Next
Ready to Create Virtual Machine:
Click Customize Hardware...
Memory: 8 GB
Processors: 4
Number of processors: 1
Number of cores per processor: 4
New CD/DVD (IDE):
Click Connect at power on
Click Use ISO image file: D:\OPNsense-26.7-dvd-amd64.iso
Network Adapter 1:
Click Connect at power on
Click Bridged: Connected directly to the physical network
USB Controller: Present
Sound Card: Auto detect
Display: Auto detect
Click Add...
Select Network Adapter
Click Finish
Network Adapter 2:
Click Connect at power on
Click Host-only: A private network shared with the host
Click Add...
Select Network Adapter
Click Finish
Network Adapter 3:
Click Connect at power on
Click Host-only: A private network shared with the host
Click Close
Click Power on this virtual machine after creation
Click Finish
Booting up OPNsense 26.7 virtual firewall...
Option 1 Boot Multi User is automatically selected
Press any key to start the manual interface assignment
Do you want to configure LAGGs now? N
Do you want to configure VLANs now? N
Enter the WAN interface name or 'a' for auto-detection: em0
Enter the LAN interface name or 'a' for auto-detection
NOTE: this enables full Firewalling/NAT mode.
(or nothing if finished): em1
Enter the Option interface 1 name or 'a' for auto-detection
(or nothing if finished): em2
Enter the Optional interface 2 name or 'a' for auto-detection
(or nothing if finished): Press Enter
The interfaces will be assigned as follows:
WAN -> em0
LAN -> em1
OPT1 -> em2
Do you want to proceed? y
Welcome! OPNsense is running in live mode from install media. Please
login as 'root' to continue in live mode, or as 'installer' to start the
installation. Use the default or previously-imported root password for
both accounts. Remote login via SSH is also enabled.
FreeBSD/amd64 (OPNsense.internal) (ttyv0)
login: installer
Password: opnsense
FreeBSD Installer
==================
Keymap Selection
=================
Continue with default keymap
OPNsense Installer
===================
OPNsense 26.7
==============
Install (ZFS) ZFS GPT/UEFI Hybrid
FreeBSD Installer
==================
ZFS Configuration
===================
Select Virtual Device type:
stripe Stripe - No Redundancy
Please select one or more disks to create a pool:
Select da0 VMware, VMware Virtual S
Last Chance! Are you sure you want to destroy
the current contents of the following disks:
da0
YES
OPNsense Installer
===================
Shows installation progress...
Final Configuration
====================
Complete Install Confirm and exit
OK
Installation Complete
========================
The system may boot back into
the installation media when not ejected properly.
Reboot now. Reboot system
OK
Section 3 - Allow OPNsense WebGUI on WAN Interface
====================================================
login: root
Password: opnsense
Select 8) Shell
pfctl -d
pf disabled
ifconfig | less
em0: 192.168.88.32
Open https://192.168.88.32 in Google Chrome web browser
Username: root
Password: opnsense
System: Configuration: Wizard
==================================
Welcome
=========
This wizard will guide you through the initial system configuration. The wizard may be stopped at any time by clicking the logo image at the top of the screen.
Click Next
General Information
====================
Hostname: OPNsense
Domain: teo-en-ming-corp.com
Language: English
Timezone: Asia/Singapore
DNS Servers: 8.8.8.8, 8.8.4.4
Override DNS: Leave checked
Enable Resolver: Leave checked
Enable DNSSEC Support: Not checked
Harden DNSSEC data: Not checked
Click Next
Network [WAN]
==============
Disable WAN: No
Type: DHCP
MAC (spoofed): Leave empty
MTU: Leave empty
MSS: Leave empty
DHCP hostname: Leave empty
Block RFC1918 Private Networks: UNCHECKED
Block bogon networks: Checked
Click Next
Network [LAN]
================
Disable LAN: No
IP Address: 192.168.26.1/24
Configure DHCP server: Checked
Click Next
Deployment type
===================
Optimize for Multiwan: Checked
Automatic DHCP/DNS registration: Checked
Optimize for IPsec: UNCHECKED
Click Next
Set initial password
=====================
Root Password:
Root Password Confirmation:
Click Next
Finish
=======
This is the last step in the wizard, click apply to reconfigure the firewall.
Click Apply.
Finished initial configuration!
Congratulations! OPNsense is now configured.
Please consider donating to the project to help us with our overhead costs. See our website to donate or purchase available OPNsense support services.
Click to continue to the dashboard. Or click to check for updates.
NOTE: OPNsense WebGUI is NOT accessible again.
pfctl -d
pf disabled
Can access OPNsense WebGUI again.
Once logged in, go to Firewall → Rules
Select the WAN interface
Click the red + (Add):
Edit rule
===========
Enabled: YES
Categories: Nothing selected
Description: Allow OPNsense WebGUI on WAN
Invert interface: No
Interface: WAN
Quick: Checked
Action: Pass
Direction: In
Version: IPv4
Protocol: TCP
Invert Source: No
Source: Single host or Network: 192.168.88.101
Source Port: any
Invert Destination: No
Destination: This Firewall
Destination Port: HTTPS (443)
Log: CHECKED
Gateway: None
Click Save
After changing settings, please remember to apply them.
Click Apply
Click Apply
Click Apply
Apply will show a tick.
Go to Interfaces → WAN
Block private networks: No
Click Save.
Click Apply changes
Click Apply changes
Click Apply changes
FINALLY
========
pfctl -e
pfctl: pf already enabled
Final Expected Result
=======================
OPNsense 26.7 Virtual Firewall WebGUI is still accessible from the WAN interface after enabling packet filter.
Regards,
Mr. Turritopsis Dohrnii Teo En Ming
Republic of Singapore
10 Oct 2026 Saturday 2.54 pm Singapore Time
REFERENCES
=============
[1] https://lists.freebsd.org/archives/freebsd-amd64/2026-October/000259.html
[2] mail-archive.com - NIL
[3] https://marc.info/?l=freebsd-amd64&m=179161753165508&w=2
[4] https://lists.freebsd.org/archives/freebsd-chat/2026-October/000089.html
[5] mail-archive.com - NIL
[6] https://marc.info/?l=freebsd-chat&m=179161776565649&w=2
Comments
Post a Comment