OPN Admin
Manage OPNsense easy & secure
Free · In-App Purchases · Designed for iPad. Not verified for macOS.
The most advanced OPN admin client ever built. Experience full control over your firewall with a stunning Liquid Glass interface and real-time insights.
Pro-Grade Features
Everything you need to manage your network securely and efficiently.
Real-time Dashboard
Live traffic graphs, system health, and resource monitoring at a glance.
Firewall Management
Create, edit, and toggle rules. Manage NAT and inspect logs in real-time.
Advanced Diagnostics
Beautifully visualized Ping and Traceroute with timeline-based hop tracking.
DHCP & Static IP
Manage leases, view MAC addresses, and fix IPs with a single tap.
Secure by Design
Biometric authentication and secure credential storage protect your access.
Liquid Glass UI
A premium design language with smooth animations and dynamic dark mode.
more • DHCP Leases now shows IPv6 as well as IPv4, with a filter per family, and names clients by DUID
when they have no MAC.
• Reservations and DHCP subnets/ranges cover IPv6 too — view, add, edit, delete.
• ARP Table is now Neighbors: IPv4 and IPv6 in one list.
• Gateways show which are IPv4 and which are IPv6.
• New: DHCP Subnets — see and edit your scopes, and control the DHCP service.
• Packet Filter & Kernel no longer says "Under pressure" for a counter that last moved months ago.
• WOL: Showing only when the WOL Plugin is installed
1.0.36 21 hrs ago
Small bump version for:
Bug fix: Disk Health sits properly on the Overview now - (had weird margins/paddings)
Bug fix: Filter chips read correctly in both themes
1.0.35 4d ago
New: Link Health — negotiated speed and duplex per interface, plus error, collision and drop
counters, in Labs → Insights.
New: Top Talkers — sample which hosts are using bandwidth right now. Opt-in, per interface, in Labs
→ Insights.
Static reservations now show whether each device is actually on the network, with a filter to find
the ones that are not.
Labs → Insights regrouped into Appliance Health, Physical Links, Traffic and History — and it loads
noticeably faster.
Quicker to open, and lighter on the firewall: live graphs pause when you are not looking at them or
the app is locked.
The offline banner is now confirmed against live traffic before it appears.
Splash screen quotes can be switched off in Settings → Look & Feel.
Consistent card styling, first-load placeholders, and better dark-mode contrast on the VPN screen.
Turning a port forward or outbound NAT rule on or off from the app now sticks — the switch was
asking the firewall for the opposite state.
Rules the firewall generates itself — anti-lockout and automatic NAT — are now marked and read-only,
instead of offering controls that could never work.
Fixed a case where switching a rule could leave an extra, unintended rule behind on the firewall.
Toggles are now written only to the section the rule belongs to, and the ruleset reloads once per
change instead of several times.
The rule list now always shows every rule on newer OPNsense builds — interface-bound rules could
drop out of the list after a refresh, leaving only the floating ones.
Threat feeds: URL list feeds can now be switched on and off, not just added and removed. Rulesets
that ship with the firmware no longer show a Remove button they cannot honour.
Switches use the app accent colour everywhere now, instead of green on some screens and blue on
others.
Thank you to everyone who sent feedback and reported issues — it shapes what gets built next. Keep
it coming.
1.0.34 6d ago
- New: Packet Filter & Kernel card in Deep Insights — how full the state table and the source-tracking table are against their limits, network buffer usage, connection churn per second, and any non-zero drop counters. These are the numbers that explain a firewall which is up and answering but quietly refusing new connections, and nothing in the app surfaced them before.
- New: Disk Health (S.M.A.R.T.) card in Deep Insights — per-drive health verdict, temperature, powered-on age, and wear, reading both SATA attributes and NVMe health logs. *Experimental*
- Time Sync card expanded — each time server now shows how many of its last eight polls were answered, how long ago it last replied, how often it's polled, and what it's synced to. A silent server used to look much like a healthy one. Firewalls with a GPS or other reference clock attached also get a lock status and satellite count.
- Background alerts narrowed to what's worth waking you for — certificate expiry, firmware updates, UPS power events, interfaces going up or down, gateways going up or down, and the firewall becoming unreachable.
- Far fewer false alarms when your phone changes network — moving between Wi-Fi, mobile data and VPN used to be able to produce alerts about interfaces or gateways going down when nothing had.
- A notification that fails to display can no longer derail a monitoring round — previously it could abort the round before the new state was recorded, so the same alerts fired again on the next check.
Tailscale network check rewritten — it used to print the raw diagnostic output and leave you to interpret it. It now says what it found in plain language: whether direct connections between devices will work, whether the network's NAT gets in the way, which relay is nearest and how far away it is.
- Rating prompt — the app may ask you to rate it, at most once, after you have been using it for a while. You can also rate it at any time from the Rate button in Settings, and the Feedback option there is always available if you would rather tell us something directly.
1.0.32 Jul 29
New: interface assignment editing on OPNsense 26.7+ — add, rename, reassign, and remove assigned interfaces right from the app.
Firmware Check/Update fixed — no more stuck "Updating…", correct handling of major upgrades vs. regular updates, clearer errors.
Gateway monitoring fixed — accurate "no RTT data" signal, and gateways you add are now monitored by default.
Live Interface Load now includes WireGuard tunnels.
System Info card expanded (name, version, uptime, CPU, load, RAM, time, last config change) and customizable.
New: choose bits or bytes for traffic speeds (Mbps vs. MB/s) in Settings.
Fixed several popups sitting under the on-screen nav bar on some devices, and unified every "+" button into one consistent header icon.
Firewall Aliases: Add/Import are icon-only now, and fixed a dark-theme popup bug.
Firewall Shaper: fixed the Add popup rendering pitch black instead of following your theme.
Fixed the NAT tab's buttons overflowing off-screen on some devices.
Fixed search fields that could clip text at larger system font sizes.
Gateway Status card: removed a redundant "Online" label next to the status dot.
Certificates: create or import right from the Certs tab; trust-store certificates can now be deleted.
Fixed the share sheet crashing on iPad.
UPS fixed and expanded — full metrics, apcupsd support, and optional power alerts.
Tailscale moved to the VPN tab and is now editable.
New Fleet Overview on the Monitor tab for anyone with more than one firewall saved.
Fixed several firewall-switching and account bugs, plus Dynamic DNS, ZeroTier, and ACME renewal reporting.
Thank you to everyone who reported bugs and sent feedback this round — keep it coming, it's what drives these fixes.
1.0.31 Jul 24
• HAProxy fixed and editable — the tab was calling API endpoints the plugin doesn't provide, so it always claimed the plugin wasn't installed. It now loads your real frontends, backends, and servers — and you can edit them (binds, mode, balancing algorithm, server membership, address/port/weight).
• OpenVPN instances can now be edited in place, and the add form no longer silently ignores your protocol, device type, and port choices.
• Unbound Query Forwarding — add, edit, and toggle domain forwards and DNS-over-TLS upstreams from the DNS tab.
• CrowdSec fixed — alert and ban lists were querying the wrong endpoints and always came up empty; lifting a ban now works too.
• ZeroTier reworked — join networks by ID, leave or forget them, with live status and assigned addresses.
• Dashboard cards can go half-width — pair two side by side via Customize.
• Light theme polish — several accents were unreadable on white; now theme-aware.
1.0.27 Jul 16
• Tailscale fixed — the tab was calling endpoints the Tailscale plugin doesn't provide, so peers never listed and Connect/Disconnect didn't work. It now shows connection state, your firewall's Tailscale IP, and all peers.
• CPU load now uses your firewall's real core count instead of assuming 4 cores — percentages were overstated on bigger CPUs and understated on smaller ones. Corrected on the dashboard, load bars, home-screen widgets, Siri shortcuts, and fleet view.
• Fixed the multi-firewall fleet view always showing 0% CPU regardless of actual load.
1.0.26 Jul 15
• Fixed certificate/CA expiry dates showing wrong far-future dates
• WireGuard: edit existing peers and instances, not just add/delete
• Fixed a rare phantom firewall rule that didn't actually exist
• Fixed HAProxy status sometimes showing enabled items as disabled
• Toggles (WireGuard, firewall, DNS, cron, syslog, captive portal) now update instantly
• Tablet/iPad layout fixes across several screens
1.0.25 Jul 14
The biggest update yet —
• Much faster startup — the dashboard loads while the splash screen shows
• New tools: packet capture, config backup history with rollback, ZFS boot snapshots, plugin manager, cron jobs, system tunables
• Firewall fixes: rule/NAT toggles no longer quietly revert, port forwards save completely, disabled rules stay disabled when
edited
• Redesigned Port Forward & Outbound NAT editors with clearer fields and validation
• Live alias table view (add/remove/flush entries, find referencing rules) and per-rule hit counters
• Gateways, VLANs, and Virtual IPs are now editable; interface review with reload
• VPN: IPsec tunnel start/stop and pre-shared keys, OpenVPN client export & disconnect, WireGuard service restart
• Captive portal vouchers
• DNS insights — recent queries, blocked status, totals
• Syslog remote destinations and more log sources
• Traffic shaper editing with live statistics
• IDS ruleset toggles, certificate details with PEM/PKCS#12 export, CA list
• New cards: NTP time sync, disk & swap usage
• Live Interface Load remembers your selection, pins WAN/LAN, raw or assigned names
• Cleaner unified lists with search and filters, dark theme polish
• Many more fixes: rules loading fully after switching firewalls, keyboard covering editors, overflowing rows
1.0.24 Jul 14
Fixed rule and NAT toggles quietly reverting — enabling or disabling a firewall or NAT rule from the app could silently undo itself about a minute later. Toggles now stick, while the firewall's built-in lockout safety net is preserved: if a change cuts off your access, it still rolls back automatically.
Fixed port forwards saving incomplete — new port forwards created from the app could end up without their external port and description. They now save exactly what you entered.
Fixed editing a disabled rule turning it back on — saving changes to a disabled rule no longer re-enables it; a new Enabled switch in the editor puts that under your control.
Redesigned Port Forward and Outbound NAT editors — the fields that define a port forward (external port → internal host : internal port) now lead the form, filter-only options no longer clutter NAT rules, and advanced matching (source restrictions, IP version, inverts) lives in a collapsible section.
Rule editor polish — clearer invert-match toggles, validation errors highlight the exact field, and the on-screen keyboard no longer covers the fields or the Save button.
Fixed rules not loading fully after switching firewalls — with multiple saved firewalls, the rules list could come up incomplete after a switch.
Live Interface Load remembers your selection — the interfaces you've checked on the traffic graph now persist across launches instead of resetting to "all interfaces" every time. WAN and LAN are also pinned first for quick scanning.
Raw vs. assigned interface names — a new toggle on Live Interface Load switches between OPNsense's raw interface ids (opt1, opt2...) and your own assigned names.
Fixed assigned names not showing for OPT interfaces on Live Interface Load — it was falling back to the raw id instead of the name you gave it.
UPS Status card restyled to match the other at-a-glance dashboard cards, with the same tap-through to full details.
Dark theme polish — the traffic graph, ping tool, DNS resolver cache card, and a few other spots now follow your theme instead of showing hardcoded colors.
1.0.22 Jul 9
DHCP leases fixed on Kea networks — the Leases screen could keep showing "ISC DHCP" and old lease data after a firewall migrated to Kea, because the legacy ISC lease endpoint stays reachable and kept answering with stale data. The app now checks which DHCP service is actually running and shows its real leases.
Kill active connections by IP — drop all firewall states from a device directly from its DHCP lease, no need to hunt it down in the States screen.
Customizable dashboard — reorder or hide any section on the main dashboard to match how you actually use it. New at-a-glance cards for system health (uptime, CPU, RAM), DHCP lease count, active firewall states, VPN tunnel status, certificate expiry warnings, and pending firmware updates — each one tap away from its full detail screen, and each only shows up when it's actually relevant (no clutter from features you don't use).
More at-a-glance cards — CARP/HA status, security alerts (CrowdSec/IDS), HAProxy health, and firewall rule/alias counts, each appearing only when relevant to your setup. The VPN Tunnels card now shows per-tunnel online/offline counts instead of just a peer count.
Dashboard polish — the Customize/Deep Insights controls now sit inline with whichever card is on top instead of taking their own row, reordering sections is smoother (no more long-press delay, bigger drag handles, a clear lift animation), and the floating nav bar is slimmer and no longer lets the last card peek out from underneath it.
Refreshed dark theme — a deeper, more blackish-blue palette for a more premium feel at night.
Firmware status fixes — the Firmware card no longer reports "update available" when a firmware mirror check simply fails to reach the mirror, and the Firmware section on the System tab no longer mislabels itself "OPN Admin" instead of OPNsense.
Stability fixes — resolved a crash that could hit first-time users if a settings toggle couldn't immediately save, a rare crash on cold start caused by an internal data-refresh race, and a crash that could interrupt an in-progress firmware update if the app was backgrounded while the firewall rebooted.
1.0.21 Jul 6
• DHCP: Potential KEA DHCP fix
• Widget: long-press to pick each widget's primary metric — CPU, memory, or interfaces
• More hands-free status checks: certificate expiry & interface traffic
• Accessibility: every button now announces its action to screen readers
• Cleaner internals: diagnostic logs stripped from release builds, better network timeout handling
• Found a bug or want a feature? In-app feedback is in Settings — send a note anytime
1.0.20 Jul 3
Fixed a dashboard crash
Light-theme polish — resolved the remaining tap-highlight glitches
1.0.18 Jun 19
New Features:
- Light theme — yes, it exists now. Added a light/white theme for when you
want your retinas to suffer in broad daylight. Flip it on in Settings (a few
screens are still getting their tan — bear with us).
- Unified look — cards and surfaces across the app now share one softer,
consistent style instead of a patchwork of greys and blues.
- Supporter badge no longer shoves your firewall name off-screen — it now sits
neatly under the title where it belongs.
- Removed the firewall traffic digest — it never delivered reliably
(especially on iOS) and the underlying data couldn't back a real daily/weekly
summary, so it's gone rather than left half-working.
- Feedback was quietly broken — through a mistake on my end, any in-app
feedback sent over the last ~4 days never reached me. It's fixed now. If you
wrote in during that window, please re-send it — and sorry!
- Assorted stability and polish fixes under the hood.
1.0.17 Jun 18
Fixed a bug a user mentioned
Remote wake-up pushes — background monitoring gains a far more reliable wake source, so alerts stay timely even when iOS defers background refresh.
Monitoring reliability — fixed monitoring silently pausing after launch for some multi-account setups.
User management — group members now appear instantly after saving.
Newest OPNsense compatibility — interface monitoring understands the latest OPNsense response format.
iOS 26 app icons — dark and tinted variants, plus polish fixes throughout.
1.0.15 Jun 13
New features:
Multi-account switching
Command palette
Wake-on-LAN
Push notifications
Unread alert badge
CARP & Unbound DNS cards
Expanded Backup History
Faster hedged-request login
Widget improvements
Security & stability hardening
1.0.14 Jun 7
Major release:
(Notifications hopefully work), of course keep in mind that I have made the app to compare a baseline to the next one and therefore we get updates if something is down or not.
If sketchy connection or no connection (wifi or vpn) you may face wrong alerts/notifications, therefore the "alpha" version.
Security
TOFU certificate pinning for TLS, with a verification workflow and cert‑rejection tracking;
Session lifecycle management that invalidates state on logout
Improved host validation on the operations screen
Notifications & background monitoring
Push notifications
Time‑sensitive notification support and iOS 14+ foreground presentation, plus refined iOS background refresh intervals
Unread alert indicators; updated background task scheduling and monitoring diagnostics
Notification logging and more accessible background storage
Login & networking
Hedged‑request login strategy with better error messaging and cache eviction
Network request deduplication and endpoint caching
More robust API response parsing and error handling
Persistent firewall/network stats providers; new DNS, Certificate, and Firewall Alias monitoring providers
UI
Central AppSnackbar widget and unified global snackbar theming
Chart animations and smoother line/area gradients; optimized LiquidGlass rendering
RRD time‑range selection and configurable ping counts
Reordered dashboard navigation and tab index mapping; unified Captive Portal styling
Fixed ScaffoldMessenger errors on cold boot
1.0.13 Jun 1
New graph line for gateway
New approach on the Background Notification Service
Visual Firewall Adjustments. & Inclusion of Aliases
Support for Unbound DNS Host Override
Certificate Viewer
Optimized LiquidGlass
1.0.11 May 14
• DHCP Leases now shows IPv6 as well as IPv4, with a filter per family, and names clients by DUID
when they have no MAC.
• Reservations and DHCP subnets/ranges cover IPv6 too — view, add, edit, delete.
• ARP Table is now Neighbors: IPv4 and IPv6 in one list.
• Gateways show which are IPv4 and which are IPv6.
• New: DHCP Subnets — see and edit your scopes, and control the DHCP service.
• Packet Filter & Kernel no longer says "Under pressure" for a counter that last moved months ago.
• WOL: Showing only when the WOL Plugin is installed
more Version 1.0.36 21 hrs ago
Data Linked to You The following data may be collected and linked to your identity:
Data Not Linked to You The following data may be collected but it is not linked to your identity: