OPNsense WireGuard Setup Guide
OPNsense is a FreeBSD-based firewall with native WireGuard since 21.7. It does not use wg-quick — all NAT and routing is done through the OPNsense firewall UI.
Create a tunnel in ProxyLink
Go to Devices → + Add → Router / LAN site, select Router / Gateway, enter your LAN subnet, and note all values from the downloaded config. On the gateway page, switch the download picker to 🌐 Router (MikroTik / pfSense / OpenWRT) before clicking Activate, otherwise you get a RouterOS .rsc script instead of a .conf file.
Create a WireGuard local instance
In OPNsense: VPN → WireGuard → Local → Add
- Name:
ProxyLink - Private Key: from your config
- Listen Port: leave default or pick one
- Tunnel Address: your VPN IP with
/16
Add the ProxyLink server as a peer
VPN → WireGuard → Peers → Add
- Public Key: server public key from your config
- Endpoint Address + Port: from your config
- Allowed IPs:
10.100.0.0/16 - Keepalive:
25
Assign this peer to your local instance.
Assign the WireGuard device as an interface
Go to Interfaces → Assignments. Assign wg1 (or your WG device) as a new interface. Enable it and give it a name like PROXYLINK.
Configure outbound NAT
Go to Firewall → NAT → Outbound. Switch to Hybrid mode.
Add a rule: Source = 10.100.0.0/16, Interface = PROXYLINK, Translation = Interface address.
Add firewall rules
Go to Firewall → Rules → PROXYLINK. Add a rule to allow all traffic from the WireGuard interface to your LAN.
Good to know
Reaching more than one VLAN
One LAN needs nothing beyond this guide. If the site has several VLANs (a camera VLAN, a PBX VLAN, a guest network), there is one more thing to know.
ProxyLink gives every gateway its own private address range and translates between that
range and your real LAN addresses. That is what lets two different clients both use
192.168.1.0/24
without colliding. The translation rules live in the
PostUp and
PostDown
lines of the config we generate.
OPNsense cannot run those rules for itself, so extra VLANs are routed directly instead of being translated. Two consequences worth knowing:
- Add the VLAN under your gateway → VLAN subnets as normal, then add the equivalent forwarding rules for that VLAN on the device yourself.
- Because the range is not translated, ProxyLink checks it does not collide with another customer's. A very common range that is already in use elsewhere may be refused.
If a site has several VLANs and you would rather not maintain that by hand, put a small Linux box (a Raspberry Pi is plenty) or a MikroTik beside the router and use it as the gateway. Both are managed, so every VLAN is handled automatically and the existing router is left alone. See the Linux and MikroTik guides.
What you get once the tunnel is up
- Browser RDP, VNC, and SSH — open a terminal or remote desktop to any device behind the tunnel straight from the ProxyLink dashboard. No client software, no open ports on your side.
- Proxy links — share an HTTPS URL that forwards to any internal web interface (NAS, NVR cameras, PBX admin panels, router UIs) with ProxyLink login in front of it.
- No public exposure — the device keeps zero open ports and needs no static IP. The tunnel is outbound-only WireGuard to EU-hosted infrastructure. Read more about agentless remote access and NIS2 compliance.
Ready to connect?
Create a free account and set up your first tunnel in minutes. Free during early access — no card required.