
This guide demonstrates how to deploy OPNsense on a Rad Web Hosting VPS. This guide is tailored specifically for Rad Web Hosting VPS infrastructure, including /32 IP addressing, KVM virtualization, and ISO-based installs.
What is OPNsense?
OPNsense is a free, open-source firewall and routing platform designed for network security, traffic control, and perimeter defense. It is based on FreeBSD and is widely used as a modern alternative to proprietary firewalls and legacy open-source solutions.
What Works Best on Rad Web Hosting
Rad Web Hosting VPS nodes provide:
- KVM virtualization
- Custom ISO boot
- VNC console access
- Static IPv4 (/32)
- Optional IPv6 /64
- High-performance NVMe storage
This makes Rad VPS well-suited for OPNsense when configured correctly.
Recommended VPS Plan (Minimum)
| Resource | Recommended |
|---|---|
| vCPU | 2 cores |
| RAM | 2β4 GB |
| Storage | 20+ GB NVMe |
| NICs | 1 (default) |
| IPv4 | 1Γ static /32 |
| IPv6 | Optional /64 |
Dual-NIC OPNsense is not required on Rad VPS. A single-NIC routed firewall model is preferred.
Network Model (Rad-Optimized)
β Single-NIC Routed Firewall (Recommended)
- Interface:
vtnet0 - WAN + LAN handled on same interface
- OPNsense acts as:
- Edge firewall
- VPN gateway
- Policy router
LAN is logical, not physical (VPNs, VLANs, or routed subnets).
How to Deploy OPNsense on a Rad Web Hosting VPS
-
Download OPNsense ISO
Collect the DVD ISOΒ download URL:
https://opnsense.org/download/
Select:
- Architecture:
amd64 - Image type:
dvd - File system:
UFS
Upload the ISO in the Rad Web Hosting VPS panel.
- Architecture:
-
Create the VPS (Rad Panel)
In the Rad VPS panel:
- Create a new VPS
- Choose Custom ISO
- Select the uploaded OPNsense ISO
- Enable VNC console
- Disable Rad-side firewall (temporarily)
Power on the VPS.
-
Install OPNsense
From the VNC console:
- Select Install (UFS)
- Accept defaults
- Select disk:
vtbd0 - Use Auto (UFS)
- Confirm install
- Set root password
- Reboot and detach ISO
-
Interface Assignment (Rad VPS)
From the console menu:
1) Assign interfaces
Assign:
- WAN β
vtnet0 - LAN β none (single-NIC setup)
Confirm and continue.
- WAN β
-
WAN IP Configuration (Critical for Rad VPS)
Rad Web Hosting uses static /32 addressing.
From console:
2) Set interface IP address
Example Configuration
Configure WAN via DHCP? β No IPv4 address β YOUR_ASSIGNED_IP Subnet mask β 32 Gateway β RAD_GATEWAY_IP IPv6 β Optional
β οΈ Gateway is mandatory on
/32IPs
Rad will provide the correct gateway in the VPS details panel. -
Access the Web UI
After configuration:
- Web UI:
https://YOUR_VPS_IP
- Username:
root - Password: (set during install)
If blocked:
Console β 11) Reload all services
-
Initial Web Setup Wizard
Complete:
- Hostname (example:
fw01) - Domain (example:
rad.local) - DNS servers
- Timezone
- Confirm WAN config
- Change admin password
- Hostname (example:
-
Firewall Rules (Rad-Safe Defaults)
WAN Rules (Highly Recommended)
Allow management access only from your IP:
Action: Pass Interface: WAN Source: Your_Public_IP Destination: This Firewall Port: 443
Optional:
- SSH (TCP 22) with key-only auth
β Do not allow WAN β Any
-
NAT Configuration (Rad Default)
Navigate:
Firewall β NAT β Outbound
Set:
- Automatic outbound NAT
This works perfectly for:
- VPN clients
- LAN subnets
- IPv6 NAT-less routing
-
Rad VPS Performance Tweaks
Disable Hardware Offloading
System β Settings β Networking
Disable:
- Hardware checksum offloading
- Hardware TCP segmentation
- Hardware large receive offloading
This prevents packet drops on virtual NICs.
Optional Rad VPS Enhancements
- WireGuard VPN gateway
- Site-to-site tunnels
- Bastion firewall
- IPv6-only LAN with NAT64
- HAProxy reverse proxy
- GeoIP blocking
- Suricata IDS (light ruleset)
What OPNsense Is Best Used for on Rad VPS
β Excellent:
- VPN concentrator
- Secure edge firewall
- Jump host protection
- Remote access hub
- Traffic filtering
- High-PPS DDoS mitigation
β Not ideal:
- Hardware offload use
- Multi-WAN CARP HA
Final Notes
OPNsense runs extremely well on Rad Web Hosting VPS when configured using:
- Single NIC
/32routing- Automatic NAT
- Tight WAN rules
Conclusion
You now know how to deploy OPNsense on a Rad Web Hosting VPS.









