Book Image

OPNsense Beginner to Professional

By : Julio Cesar Bueno de Camargo
5 (1)
Book Image

OPNsense Beginner to Professional

5 (1)
By: Julio Cesar Bueno de Camargo

Overview of this book

OPNsense is one of the most powerful open source firewalls and routing platforms available. With OPNsense, you can now protect networks using features that were only previously available to closed source commercial firewalls. This book is a practical guide to building a comprehensive network defense strategy using OPNsense. You’ll start with the basics, understanding how to install, configure, and protect network resources using native features and additional OPNsense plugins. Next, you’ll explore real-world examples to gain in-depth knowledge of firewalls and network defense. You’ll then focus on boosting your network defense, preventing cyber threats, and improving your knowledge of firewalling using this open source security platform. By the end of this OPNsense book, you’ll be able to install, configure, and manage the OPNsense firewall by making the most of its features.
Table of Contents (25 chapters)
1
Section 1: Initial Configuration
6
Section 2: Securing the Network
13
Section 3: Going beyond the Firewall

Advanced customization

The OPNsense webGUI is a powerful configuration tool, and you rarely need to change or customize the OPNsense configuration while using the CLI. Still, it can happen, and it is essential to know which tools we can count on for doing this task.

The config.xml file is the webGUI's generated XML configuration file, it is where the OPNsense configuration file resides.

Customizing the XML configuration file

All configurations generated by webGUI through the OPNsense framework are saved in /conf/config.xml.

Note

Before modifying the config.xml file, always make a backup copy! Editing this file can crash your OPNsense installation, so take caution!

The following is an example where the manual editing of the config.xml file could help.

This is an example showing the substitution of OPNsense hardware. Let's suppose that you need to replace the OPNsense hardware, and the new one uses a different network card, which means changing the Network...