OPNsense 19.7, codenamed “Jazzy Jaguar”, has been released and brings numerous improvements to the popular open-source firewall distribution.
Release Highlights
New Firmware Upgrade System
The firmware upgrade system has been completely redesigned. Updates can now be applied more reliably and faster. The new system is based on improved package management and ensures smooth updates.
Multi-WAN Improvements
Multi-WAN functionality has been significantly improved:
- Gateway groups with more flexible weighting
- Improved failover detection
- Optimized load balancing algorithms
- Faster switchover times during connection failures
Firewall Improvements
- Improved alias management with new types
- Optimized NAT rule management
- Extended logging options
- Improved ruleset for IPv6
VPN Updates
- WireGuard support available as a plugin
- Updated OpenVPN with security fixes
- Improved IPsec configuration
- Extended VPN status overview
Web Interface
The user interface has been further modernized:
- Faster loading times
- Improved dashboard with customizable widgets
- Redesigned navigation
- Responsive design improvements
Security Updates
OPNsense 19.7 includes numerous security updates:
- Updated FreeBSD kernel with security patches
- OpenSSL updates
- Suricata IDS/IPS update
- Various CVE fixes
Migration from 19.1
The upgrade from OPNsense 19.1 to 19.7 can be performed directly via the web interface. It is recommended to create a backup of the configuration beforehand.
Conclusion
OPNsense 19.7 is a solid release with many practically relevant improvements. The Multi-WAN optimizations and WireGuard support in particular make the update attractive. As an experienced OPNsense integrator, we are happy to advise you on planning and implementing your firewall infrastructure.
More on these topics:
More articles
Vaultwarden: Self-Hosted Password Manager for Teams
Run Vaultwarden as a self-hosted password manager: Docker deployment, reverse proxy, SMTP, 2FA enforcement, and backup strategy — the complete guide for teams.
Fail2ban: Automating Brute-Force Protection for Linux Servers
Install and configure Fail2ban: log parsing, jail.local, protecting SSH, Nginx, Postfix, and Dovecot, whitelists, email alerts, and a comparison with CrowdSec, sshguard, and CSF.
TrueNAS Dataset Encryption: ZFS Encryption in Practice
Understanding and implementing TrueNAS ZFS Encryption: dataset vs. pool encryption, passphrase vs. key file, key management, and performance impact with AES-NI.