OPNexus Deutsch Install
Free · Source available · self-hosted

All your OPNsense firewalls.
One console.

OPNexus manages rules, NAT, VPN, certificates and updates across your OPNsense firewalls from one place – and pushes them out over the API with preview, confirmation and automatic rollback. On desktop, tablet and phone.

  • Mobile first
  • Light & dark
  • English & German
  • No cloud
  • No tracking
  • 6areas: rules, NAT, VPN, certificates, monitoring, updates
  • 3VPN types: IPsec, OpenVPN, WireGuard
  • 2languages and 2 colour schemes
  • 0cookies, trackers or cloud requirements
The safe way

Changes you can trust yourself to make

One wrong firewall rule can lock you out in seconds. So every change goes through three steps – nothing is just shoved onto the box.

  1. Review

    The preview shows, per target firewall and field by field, what would change before anything touches the firewall.

  2. Deploy

    The change goes over the OPNsense API to individual hosts or whole device groups, and is applied on probation first.

  3. Confirm

    If you do not confirm within the time window (3 minutes by default), OPNexus rolls back automatically.

The preview before deploying

The preview before deploying

Features in detail

From the whole fleet down to a single package

One tool for running a firewall fleet day to day – from an HA pair to a branch office. Pick an area:

Keep the overview, even with many firewalls

The dashboard shows what needs attention right now. HA pairs are grouped into clusters automatically.

  • Live status of every host with its CARP role
  • MASTER and BACKUP side by side, including drift indicators
  • Event history and alerts for split-brain or a missing MASTER
  • Maintenance mode with an auto-revert timer (15/30/60 minutes)
Dashboard
Cluster
Dashboard
Cluster

See all screenshots

Mobile first

Your data center in your pocket

OPNexus is built for small screens from the ground up: check an incident from the sofa, prepare an update on the train. Every view works from 375 pixels wide.

  • Dashboard
  • Rules
  • Cluster
  • Update Center
  • Big touch targets

    Buttons and menus are made for thumbs – no tiny links in dense tables.

  • Compact navigation

    Main areas as an icon bar, sub-pages beneath. The quick search (Ctrl/⌘+K) jumps anywhere.

  • Light and dark

    The colour scheme follows your system or your choice – readable in a dark server room, too.

  • Accessible

    Automatically checked with axe-core on all 18 pages (WCAG 2.2 AA), fully keyboard operable.

Light or dark

Both colour schemes, the same clarity

Drag the handle: dark design on the left, light on the right. This site follows your system, too.

Dashboard compared: dark and light design
Everything at a glance

The complete feature set

More than a rule editor: OPNexus covers the day-to-day running of a firewall fleet.

Fleet & high availability

Central host list

Live status, CARP role, cluster and policy membership; “Open in OPNsense” in one click.

Cluster view

HA pairs are grouped automatically by cluster name; MASTER and BACKUP side by side.

CARP event history

Every role change is recorded; alert on split-brain or a missing MASTER.

CARP maintenance mode

Optionally with an auto-revert timer (15, 30, 60 minutes or permanent).

Resource history

CPU load, memory and disk for the last 24 hours per host.

Service control

List a firewall’s services and start, stop or restart them.

Dashboard

Pending actions, fleet health, security and expiry warnings, and an activity feed.

Rulebase

Central firewall rules

Maintain once, deploy to chosen hosts or device groups.

Preview → deploy → confirm

With a time window and automatic rollback if confirmation never comes.

Hierarchical policies

Pre/post rulebases with inheritance down group trees, in the right order.

Device groups

Bundle hosts: one target, many firewalls.

Aliases

Network objects (host, network, port, group, MAC, ASN) with the same flow as rules.

Per-rule history

Review earlier versions and restore them.

Drift detection

Differences between managed and actually active configuration are flagged.

Lockout protection

Every deploy starts on probation – if you lock yourself out, it is rolled back when the time is up.

NAT & VPN

Port forward

Define and deploy port forwards centrally.

1:1 and outbound NAT

With a live view of the rules actually active on the firewall.

NAT drift

Differences between the nodes of a cluster are detected.

IPsec site-to-site

Manage tunnels with pre-shared key centrally.

OpenVPN

Server and client instances, optional TLS-Crypt, certificate and CA per host.

WireGuard

Servers and peers including optional pre-shared key.

Certificates

Live overview

All certificates and CAs in the fleet with remaining lifetime and status.

Trust store

Import certificates centrally and distribute them to firewalls.

ACME / Let’s Encrypt

Issue directly from OPNexus – with a warning before any contact with a real CA.

Monitoring & notifications

Central log search

Firewall logs are ingested, searchable and filterable.

Log dashboards

Top sources, top destination ports and the pass/block split.

Size limit & retention

Maximum size and retention period of the logs are configurable.

Audit history

Complete, with JSON export; survives deleting rules or hosts.

Webhook & email

Signed webhooks and SMTP email for host offline, certificate expiry, drift, split-brain and failed rollback.

Updates & maintenance

Update Center

Stable updates and major upgrades for the whole fleet, with reboot hints.

Guided HA flow

Update the BACKUP first, CARP switch-over with confirmation.

Backup check

A local configuration backup as a prerequisite; restore preview for saved backups.

Scheduled maintenance

Queue reboots and updates for a maintenance window.

Updating OPNexus itself

Release images and opnexus update / opnexus rollback; optional new-version notice.

Security & operations

HTTPS proxy

Bundled Caddy with an internal CA – also for bare IP addresses.

Pinned firewall certificates

OPNexus trusts exactly the stored certificate of each firewall.

Two-factor sign-in

TOTP with recovery codes.

Roles

Admin and read-only; user management with password reset.

Login info

Last sign-in and failed attempts since the previous login.

Self-hosted

Docker Compose on your server; your data never leaves it.

Usability

Mobile first

Fully usable from 375 pixels wide.

Quick search

Ctrl/⌘+K jumps to pages, hosts and settings.

Light, dark, system

Colour scheme per user.

English and German

The entire interface, switchable per user.

Accessible

Keyboard operation, focus ring, screen-reader labels, WCAG AA contrast.

Security & privacy

Built for firewalls – so, careful by design

A tool that may change firewalls has to treat credentials and changes with particular care.

Nothing without a way back

A deploy starts on probation. Without confirmation it is rolled back; if the rollback itself fails, that stays visible.

Encrypted and pinned

Browser and OPNexus talk over HTTPS. Firewall certificates are pinned instead of clicking through warnings.

Two-factor and roles

TOTP sign-in, a read-only role for observers and audit accounts.

Complete audit

Every request and every deploy result is recorded permanently.

No telemetry

OPNexus phones nothing home. The update notice is off by default and sends only a version query.

Source available

Read the code, audit it and adapt it for your own use – with no licence fees.

Development

Regular releases with bird-of-prey names

OPNexus follows semantic versioning. Every minor version gets a codename – the latest milestones:

  1. 1.10.0 „Lanner“5 Oct 2026

    Updatability: release images, opnexus update and rollback, optional new-version notice.

  2. 1.9.0 „Kite“4 Oct 2026

    Versioned schema migrations – upgrades without hand-editing the database.

  3. 1.8.0 „Harris“4 Oct 2026

    Accessibility: WCAG 2.2 AA contrast, keyboard operation, screen-reader labels.

  4. 1.7.0 „Goshawk“4 Oct 2026

    Secure transport: HTTPS proxy, pinned firewall certificates, two-factor sign-in.

  5. 1.6.0 „Peregrine“4 Oct 2026

    A calmer interface: hints as tooltips, log size limit.

  6. 1.5.0 „Osprey“19 Sep 2026

    Multilingual: the entire interface in German and English.

All versions in the changelog →

Frequently asked questions

Do I have to install anything on the firewalls?

No. OPNexus uses the OPNsense core REST API. The filter and alias API is available without an extra plugin. You store an API key per firewall.

What if a rule locks me out?

Every change is applied on probation. If you do not confirm within the time window (default: 3 minutes), OPNexus restores the previous state automatically. If that fails, the error stays visible and is reported.

Where is my data?

On your own server (Docker Compose with PostgreSQL). There is no cloud and no account with us. The version notice is off by default; if you enable it, at most one request every 12 hours goes to updates.opnexus.dev – with no instance or user data.

Who is OPNexus for?

Anyone who runs several OPNsense firewalls of their own – from a homelab to a mid-sized company. Multi-tenancy for service providers with many customers is deliberately not a goal.

Does OPNexus support high availability?

Yes. CARP pairs are shown as clusters, role changes are logged, and updates run in a guided flow that starts with the BACKUP.

What does OPNexus cost?

Nothing. Downloading, reading the source, adapting and using it – including commercially for your own firewalls – is free. Not allowed: reselling OPNexus or derivatives, or offering them as a competing product or service. Licence: PolyForm Shield 1.0.0 (source-available, not an open-source licence).

Is there any connection to OPNsense or Deciso?

No. OPNexus is an independent project and is not affiliated with Deciso B.V. or the OPNsense® project. OPNsense® is a trademark of Deciso B.V.

How do I update OPNexus?

With opnexus update: the tool pulls the new images, waits for “healthy” and rolls back automatically on problems; opnexus rollback also restores the database from the pre-upgrade backup. Ready-made release images arrive with the first public release.

Get started

Installation

OPNexus runs as a Docker Compose stack on your own server – your firewall data stays with you.

# Requires Docker with the Compose plugin
git clone https://git.opnexus.dev/opnexus/opnexus.git
cd OPNexus
cp .env.example .env     # set POSTGRES_PASSWORD
docker compose up -d --build

The UI is then reachable locally at http://localhost:3100. For access from other machines and production use with TLS, the handbook (in German) describes the bundled HTTPS proxy.

Ready-made release images including opnexus update and opnexus rollback are prepared and arrive with the first public release.

Good to know

  • Self-hosted. No cloud, no account with us.
  • Version notice on request only. Off by default; otherwise at most one request every 12 hours to updates.opnexus.dev.
  • Source available. Free to use under the PolyForm Shield License 1.0.0 – only reselling and competing products are excluded.
  • Developed against real OPNsense instances and backed by an extensive test suite.

Ready to run your firewalls from one place?

Free, open and set up in a few minutes.