Notes on installing OPNsense 26.7 (based on FreeBSD) as a Virtual Firewall

Subject: Notes on installing OPNsense 26.7 (based on FreeBSD) as a Virtual Firewall


Good day from Singapore,


Author: Mr. Turritopsis Dohrnii Teo En Ming

Date: 10 Oct 2026 Saturday 1.32 pm

Country: Singapore


Section 1 - Download OPNsense Firewall

==========================================


Download link: 


https://opnsense.org/download/


Fast download selector:


System architecture: amd64


Select the image type: dvd


Mirror Location: Taiwan, Nantou County Education Network Center


Peak download speed: 44 MiB/s


Downloaded as OPNsense-26.7-dvd-amd64.iso.bz2


Use 7-zip to Extract Here.


Then you will get OPNsense-26.7-dvd-amd64.iso


Filesize: 1.95 GB


Section 2 - Installing OPNsense 26.7 as a Virtual Firewall in VMware Workstation Pro 26H1u1

================================================================================================


File > New Virtual Machine


New Virtual Machine Wizard

===========================


Welcome to the New Virtual Machine Wizard


Select Typical (recommended)


Click Next


Guest Operating System Installation:


Click Installer disc image file (iso):


D:\OPNsense-26.7-dvd-amd64.iso


Click Next


Name the Virtual Machine:


Virtual machine name:


OPNsense 26.7 Virtual Firewall


Location:


D:\Virtual Machines\OPNsense 26.7 Virtual Firewall


Click Next


Specify Disk Capacity:


Maximum disk size (GB): 64


Click Store virtual disk as a single file


Click Next


Ready to Create Virtual Machine:


Click Customize Hardware...


Memory: 8 GB


Processors: 4


Number of processors: 1

Number of cores per processor: 4


New CD/DVD (IDE): 


Click Connect at power on

Click Use ISO image file: D:\OPNsense-26.7-dvd-amd64.iso


Network Adapter 1:


Click Connect at power on


Click Bridged: Connected directly to the physical network


USB Controller: Present


Sound Card: Auto detect


Display: Auto detect


Click Add...


Select Network Adapter


Click Finish


Network Adapter 2:

 

Click Connect at power on


Click Host-only: A private network shared with the host


Click Add...


Select Network Adapter


Click Finish


Network Adapter 3:


Click Connect at power on


Click Host-only: A private network shared with the host


Click Close


Click Power on this virtual machine after creation


Click Finish


Booting up OPNsense 26.7 virtual firewall...


Option 1 Boot Multi User is automatically selected


Press any key to start the manual interface assignment


Do you want to configure LAGGs now? N


Do you want to configure VLANs now? N 


Enter the WAN interface name or 'a' for auto-detection: em0


Enter the LAN interface name or 'a' for auto-detection

NOTE: this enables full Firewalling/NAT mode.

(or nothing if finished): em1


Enter the Option interface 1 name or 'a' for auto-detection

(or nothing if finished): em2


Enter the Optional interface 2 name or 'a' for auto-detection

(or nothing if finished): Press Enter


The interfaces will be assigned as follows:


WAN -> em0

LAN -> em1

OPT1 -> em2


Do you want to proceed? y


Welcome! OPNsense is running in live mode from install media. Please

login as 'root' to continue in live mode, or as 'installer' to start the

installation. Use the default or previously-imported root password for

both accounts. Remote login via SSH is also enabled.


FreeBSD/amd64 (OPNsense.internal) (ttyv0)


login: installer

Password: opnsense


FreeBSD Installer

==================


Keymap Selection

=================


Continue with default keymap


OPNsense Installer

===================


OPNsense 26.7

==============


Install (ZFS) ZFS GPT/UEFI Hybrid


FreeBSD Installer

==================


ZFS Configuration

===================


Select Virtual Device type:


stripe Stripe - No Redundancy


Please select one or more disks to create a pool:


Select da0 VMware, VMware Virtual S


Last Chance! Are you sure you want to destroy

the current contents of the following disks:


da0


YES


OPNsense Installer

===================


Shows installation progress...


Final Configuration

====================


Complete Install Confirm and exit


OK


Installation Complete

========================


The system may boot back into

the installation media when not ejected properly.


Reboot now. Reboot system


OK


Section 3 - Allow OPNsense WebGUI on WAN Interface

====================================================


login: root


Password: opnsense


Select 8) Shell


pfctl -d

pf disabled


ifconfig | less


em0: 192.168.88.32


Open https://192.168.88.32 in Google Chrome web browser


Username: root


Password: opnsense


System: Configuration: Wizard

==================================


Welcome

=========


This wizard will guide you through the initial system configuration. The wizard may be stopped at any time by clicking the logo image at the top of the screen.


Click Next


General Information

====================


Hostname: OPNsense


Domain: teo-en-ming-corp.com


Language: English


Timezone: Asia/Singapore


DNS Servers: 8.8.8.8, 8.8.4.4


Override DNS: Leave checked


Enable Resolver: Leave checked


Enable DNSSEC Support: Not checked


Harden DNSSEC data: Not checked


Click Next


Network [WAN]

==============


Disable WAN: No


Type: DHCP


MAC (spoofed): Leave empty


MTU: Leave empty


MSS: Leave empty


DHCP hostname: Leave empty


Block RFC1918 Private Networks: UNCHECKED


Block bogon networks: Checked


Click Next


Network [LAN]

================


Disable LAN: No


IP Address: 192.168.26.1/24


Configure DHCP server: Checked


Click Next


Deployment type

===================


Optimize for Multiwan: Checked


Automatic DHCP/DNS registration: Checked


Optimize for IPsec: UNCHECKED


Click Next


Set initial password

=====================


Root Password:


Root Password Confirmation:


Click Next


Finish

=======


This is the last step in the wizard, click apply to reconfigure the firewall.


Click Apply.


Finished initial configuration!


Congratulations! OPNsense is now configured.


Please consider donating to the project to help us with our overhead costs. See our website to donate or purchase available OPNsense support services.


Click to continue to the dashboard. Or click to check for updates.


NOTE: OPNsense WebGUI is NOT accessible again.


pfctl -d

pf disabled


Can access OPNsense WebGUI again.


Once logged in, go to Firewall → Rules


Select the WAN interface


Click the red + (Add):


Edit rule

===========


Enabled: YES


Categories: Nothing selected


Description: Allow OPNsense WebGUI on WAN


Invert interface: No


Interface: WAN


Quick: Checked


Action: Pass


Direction: In


Version: IPv4


Protocol: TCP


Invert Source: No


Source: Single host or Network: 192.168.88.101


Source Port: any


Invert Destination: No


Destination: This Firewall


Destination Port: HTTPS (443)


Log: CHECKED


Gateway: None


Click Save


After changing settings, please remember to apply them.


Click Apply


Click Apply


Click Apply


Apply will show a tick.


Go to Interfaces → WAN


Block private networks: No


Click Save.


Click Apply changes


Click Apply changes


Click Apply changes


FINALLY

========


pfctl -e

pfctl: pf already enabled


Final Expected Result

=======================


OPNsense 26.7 Virtual Firewall WebGUI is still accessible from the WAN interface after enabling packet filter.


Regards,


Mr. Turritopsis Dohrnii Teo En Ming

Republic of Singapore

10 Oct 2026 Saturday 2.54 pm Singapore Time





REFERENCES

=============


[1] https://lists.freebsd.org/archives/freebsd-amd64/2026-October/000259.html


[2] mail-archive.com - NIL


[3] https://marc.info/?l=freebsd-amd64&m=179161753165508&w=2


[4] https://lists.freebsd.org/archives/freebsd-chat/2026-October/000089.html


[5] mail-archive.com - NIL


[6] https://marc.info/?l=freebsd-chat&m=179161776565649&w=2


Comments

Popular posts from this blog

Estimated Total Expenses in Taiwan from 6 Aug 2025 to 12 Aug 2025 (Version 15 Aug 2025)

Linux 6.18 Released With Many New Features, Likely This Year's LTS Kernel

Linux 6.19 Kernel Benchmarks With X86_NATIVE_CPU Optimization