Skip to content

pfSense and OPNsense: rules, aliases, NAT, backups and updates

How pfSense and OPNsense evaluate floating, group and interface rules, why interface rules filter inbound and stop at the first match, the default deny and the default WAN/LAN behaviour, aliases, port forwards and their linked rules, packages, configuration backups (config.xml, encryption, configuration history, AutoConfigBackup) and preparing for updates. Where the two projects differ, the course says so only where each project's documentation confirms it.

Level
Intermediate
Length
About 50 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026
  • pfSense / OPNsense · open source

Skills you'll practise

  • Predict which rule handles a packet from the processing order, interface direction and first match
  • Place block and pass rules on the correct interface tab and in the correct order
  • Use aliases and restrict port forward sources, and explain what the associated filter rule does
  • Take, protect and restore configuration backups, including from configuration history
  • Prepare a firewall for an update, including the steps each project's documentation recommends

Course outline

  1. 1.pfSense and OPNsense: rules, backups and updatesVideo · 2 min
  2. 2.How rules are processedLesson · 17 min
  3. 3.Aliases, port forwards and packagesLesson · 16 min
  4. 4.Backups, configuration history and updatesLesson · 17 min
  5. 5.pfSense and OPNsense: rules, aliases, NAT, backups and updates: knowledge checkKnowledge check · 18 questions
  6. 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.