The release of the OPNsense 22.1 firewall distribution has occurred. This version is a branch of the pfSense project, aimed at creating a fully open distribution that can offer features comparable to commercial solutions for deploying firewalls and network gateways. Unlike pfSense, this project is positioned as independent of any single company, developed with community involvement, and features a completely transparent development process, allowing the use of its components in third-party products, including commercial ones. The source codes for the distribution components, along with the tools used for building, are distributed under the BSD license. Builds are available in the form of a LiveCD and an image for writing to USB drives (339 MB).
The basic filling of the distribution is based on the FreeBSD code. Among the features of OPNsense, one can highlight a fully open build toolset, the ability to install as packages on top of standard FreeBSD, load balancing tools, a web interface for organizing user connections to the network (Captive portal), mechanisms for connection state tracking (stateful firewall based on pf), setting bandwidth limits, traffic filtering, and creating VPN based on IPsec, OpenVPN, and PPTP, LDAP and RADIUS integration, DDNS (Dynamic DNS) support, and a system of visual reports and charts.
The distribution provides tools for creating fault-tolerant configurations based on the CARP protocol, allowing for the launch of a backup node alongside the primary firewall, which will be automatically synchronized at the configuration level and take over the load in case of a primary node failure. A modern and simple interface for configuring the firewall is offered to the administrator, built using the Bootstrap web framework.
Among the changes:
- Transition to the FreeBSD 13-STABLE branch has been completed (the previous version was based on HardenedBSD 12.1).
- Log information regarding the severity level of messages has been provided for filtering logs based on this value.
- The opnsense-log utility for inspecting logs has been included.
- Tools for overriding sysctl have been added to the tunables framework.
- The process of loading and configuring network interfaces has been accelerated. Transition to using the LUA boot loader has been completed.
- Updated versions of additional programs from the ports have been released, such as filterlog 0.6, hostapd 2.10, lighttpd 1.4.63, nss 3.74, openssl 1.1.1m, openvpn 2.5.5, php 7.4.27, sqlite 3.37.2, syslog-ng 3.35.1, unbound 1.14.0, wpa_supplicant 2.10.

Source: opennet.ru
