OPSense Configuartion
OPNsense® is an open source, feature rich firewall and routing platform, offering cutting-edge network protection.
Defguard Gateway Configuration
This instruction helps configuring Defguard Gateway in OPNsense. This is based on WireGuard Road Warrior Setup from OPNsense documentation.
Configure Defguard Gateway plugin
Go to VPN → Defguard Gateway
Fill out the approriate values in the form
Eventually, Start/Restart the service.

Assign a network interface to Defguard
Go to Interfaces → Assignments
Under Assign a new interface, select the Defgaurd Gateway network interface (e.g. wg0)
Add a descrption, for example ParisOfficeVPN
Click Add

Select the newly create interface by clicking on its name (in this example [ParisOfficeVPN]).
Select Enable Interface
Select Prevent interface removal
Click Save, and then Apply changes
Create an outbound NAT rule
Go to Firewall → NAT → Outbound
Make sure the selected Mode is Hybrid outbound NAT rule generation; if it wasn't selected, click Save and then Apply changes
Under Manual rules, add a new rule by clicking +.
Select Interface – this should be either WAN or LAN, depending on the needs.
Select TCP/IP version – either IPv4 or IPv6.
Select Source address – this should be interface name assigned above plus net, e.g. ParisOfficeVPN net.
Click Save, and then Apply changes

Add firewall rules to allow WireGuard traffic in
Go to Firewall → Rules → WAN
Click + (plus) to add a new rule
The rule should Pass the traffic in with quick option enabled
Select WAN interface
Choose TCP/IP version of your desire
Select UDP protocol.
Set Destination to WAN address and port to the port number provided in Defaurd Core: Location configuration → Gateway port
Click Save, and then Apply changes

Last updated
Was this helpful?