This is a patch release for the major 2.0 release.
It changes the default OPNsense plugin configuration which controls the placement of Defguard-related firewall rules.
This configuration is now also available in advanced plugin options.
⚠️ Upgrade notes:
-
Reboot required. The new placement only applies after a filter reload. Reboot the firewall after upgrading, or open Services → Defguard Gateway and Save once (no changes needed) to force a reload.
-
Firewall behaviour changes. VPN traffic that previously bypassed OPNsense rules is now subject to them and may be blocked. Review any OPNsense rules touching your WireGuard interface/VPN subnets and test connectivity.
The 2.0 was a significant step up from version 1.x, featuring:
🎨 a completely redesigned UI,
📦 a new and easy deployment approach (and component communication security),
🛠️ and some other major architectural changes.
More details with videos in this blogpost.
⬆︎ If you will be upgrading from 1.x - here you can find relevant documentation about the upgrade.
🚅 If you would like to test Defguard - we offer a quick and easy One-line install script.
⚠️ Business features require free registration.
Previously, these features were available without registration (within certain limits).
Starting from 2.0, a free Business license registration is required to use them.
👉 https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance and enjoy access to Business functionality.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues