OPN Admin
Manage OPNsense easy & secure
Free · In-App Purchases · Designed for iPad. Not verified for macOS.
The most advanced OPN admin client ever built. Experience full control over your firewall with a stunning Liquid Glass interface and real-time insights.
Pro-Grade Features
Everything you need to manage your network securely and efficiently.
Real-time Dashboard
Live traffic graphs, system health, and resource monitoring at a glance.
Firewall Management
Create, edit, and toggle rules. Manage NAT and inspect logs in real-time.
Advanced Diagnostics
Beautifully visualized Ping and Traceroute with timeline-based hop tracking.
DHCP & Static IP
Manage leases, view MAC addresses, and fix IPs with a single tap.
Secure by Design
Biometric authentication and secure credential storage protect your access.
Liquid Glass UI
A premium design language with smooth animations and dynamic dark mode.
more • HAProxy fixed and editable — the tab was calling API endpoints the plugin doesn't provide, so it always claimed the plugin wasn't installed. It now loads your real frontends, backends, and servers — and you can edit them (binds, mode, balancing algorithm, server membership, address/port/weight).
• OpenVPN instances can now be edited in place, and the add form no longer silently ignores your protocol, device type, and port choices.
• Unbound Query Forwarding — add, edit, and toggle domain forwards and DNS-over-TLS upstreams from the DNS tab.
• CrowdSec fixed — alert and ban lists were querying the wrong endpoints and always came up empty; lifting a ban now works too.
• ZeroTier reworked — join networks by ID, leave or forget them, with live status and assigned addresses.
• Dashboard cards can go half-width — pair two side by side via Customize.
• Light theme polish — several accents were unreadable on white; now theme-aware.
1.0.27 5 days ago
• Tailscale fixed — the tab was calling endpoints the Tailscale plugin doesn't provide, so peers never listed and Connect/Disconnect didn't work. It now shows connection state, your firewall's Tailscale IP, and all peers.
• CPU load now uses your firewall's real core count instead of assuming 4 cores — percentages were overstated on bigger CPUs and understated on smaller ones. Corrected on the dashboard, load bars, home-screen widgets, Siri shortcuts, and fleet view.
• Fixed the multi-firewall fleet view always showing 0% CPU regardless of actual load.
1.0.26 6 days ago
• Fixed certificate/CA expiry dates showing wrong far-future dates
• WireGuard: edit existing peers and instances, not just add/delete
• Fixed a rare phantom firewall rule that didn't actually exist
• Fixed HAProxy status sometimes showing enabled items as disabled
• Toggles (WireGuard, firewall, DNS, cron, syslog, captive portal) now update instantly
• Tablet/iPad layout fixes across several screens
1.0.25 14 Jul
The biggest update yet —
• Much faster startup — the dashboard loads while the splash screen shows
• New tools: packet capture, config backup history with rollback, ZFS boot snapshots, plugin manager, cron jobs, system tunables
• Firewall fixes: rule/NAT toggles no longer quietly revert, port forwards save completely, disabled rules stay disabled when
edited
• Redesigned Port Forward & Outbound NAT editors with clearer fields and validation
• Live alias table view (add/remove/flush entries, find referencing rules) and per-rule hit counters
• Gateways, VLANs, and Virtual IPs are now editable; interface review with reload
• VPN: IPsec tunnel start/stop and pre-shared keys, OpenVPN client export & disconnect, WireGuard service restart
• Captive portal vouchers
• DNS insights — recent queries, blocked status, totals
• Syslog remote destinations and more log sources
• Traffic shaper editing with live statistics
• IDS ruleset toggles, certificate details with PEM/PKCS#12 export, CA list
• New cards: NTP time sync, disk & swap usage
• Live Interface Load remembers your selection, pins WAN/LAN, raw or assigned names
• Cleaner unified lists with search and filters, dark theme polish
• Many more fixes: rules loading fully after switching firewalls, keyboard covering editors, overflowing rows
1.0.24 14 Jul
Fixed rule and NAT toggles quietly reverting — enabling or disabling a firewall or NAT rule from the app could silently undo itself about a minute later. Toggles now stick, while the firewall's built-in lockout safety net is preserved: if a change cuts off your access, it still rolls back automatically.
Fixed port forwards saving incomplete — new port forwards created from the app could end up without their external port and description. They now save exactly what you entered.
Fixed editing a disabled rule turning it back on — saving changes to a disabled rule no longer re-enables it; a new Enabled switch in the editor puts that under your control.
Redesigned Port Forward and Outbound NAT editors — the fields that define a port forward (external port → internal host : internal port) now lead the form, filter-only options no longer clutter NAT rules, and advanced matching (source restrictions, IP version, inverts) lives in a collapsible section.
Rule editor polish — clearer invert-match toggles, validation errors highlight the exact field, and the on-screen keyboard no longer covers the fields or the Save button.
Fixed rules not loading fully after switching firewalls — with multiple saved firewalls, the rules list could come up incomplete after a switch.
Live Interface Load remembers your selection — the interfaces you've checked on the traffic graph now persist across launches instead of resetting to "all interfaces" every time. WAN and LAN are also pinned first for quick scanning.
Raw vs. assigned interface names — a new toggle on Live Interface Load switches between OPNsense's raw interface ids (opt1, opt2...) and your own assigned names.
Fixed assigned names not showing for OPT interfaces on Live Interface Load — it was falling back to the raw id instead of the name you gave it.
UPS Status card restyled to match the other at-a-glance dashboard cards, with the same tap-through to full details.
Dark theme polish — the traffic graph, ping tool, DNS resolver cache card, and a few other spots now follow your theme instead of showing hardcoded colors.
1.0.22 9 Jul
DHCP leases fixed on Kea networks — the Leases screen could keep showing "ISC DHCP" and old lease data after a firewall migrated to Kea, because the legacy ISC lease endpoint stays reachable and kept answering with stale data. The app now checks which DHCP service is actually running and shows its real leases.
Kill active connections by IP — drop all firewall states from a device directly from its DHCP lease, no need to hunt it down in the States screen.
Customizable dashboard — reorder or hide any section on the main dashboard to match how you actually use it. New at-a-glance cards for system health (uptime, CPU, RAM), DHCP lease count, active firewall states, VPN tunnel status, certificate expiry warnings, and pending firmware updates — each one tap away from its full detail screen, and each only shows up when it's actually relevant (no clutter from features you don't use).
More at-a-glance cards — CARP/HA status, security alerts (CrowdSec/IDS), HAProxy health, and firewall rule/alias counts, each appearing only when relevant to your setup. The VPN Tunnels card now shows per-tunnel online/offline counts instead of just a peer count.
Dashboard polish — the Customize/Deep Insights controls now sit inline with whichever card is on top instead of taking their own row, reordering sections is smoother (no more long-press delay, bigger drag handles, a clear lift animation), and the floating nav bar is slimmer and no longer lets the last card peek out from underneath it.
Refreshed dark theme — a deeper, more blackish-blue palette for a more premium feel at night.
Firmware status fixes — the Firmware card no longer reports "update available" when a firmware mirror check simply fails to reach the mirror, and the Firmware section on the System tab no longer mislabels itself "OPN Admin" instead of OPNsense.
Stability fixes — resolved a crash that could hit first-time users if a settings toggle couldn't immediately save, a rare crash on cold start caused by an internal data-refresh race, and a crash that could interrupt an in-progress firmware update if the app was backgrounded while the firewall rebooted.
1.0.21 6 Jul
• DHCP: Potential KEA DHCP fix
• Widget: long-press to pick each widget's primary metric — CPU, memory, or interfaces
• More hands-free status checks: certificate expiry & interface traffic
• Accessibility: every button now announces its action to screen readers
• Cleaner internals: diagnostic logs stripped from release builds, better network timeout handling
• Found a bug or want a feature? In-app feedback is in Settings — send a note anytime
1.0.20 3 Jul
Fixed a dashboard crash
Light-theme polish — resolved the remaining tap-highlight glitches
1.0.18 19 Jun
New Features:
- Light theme — yes, it exists now. Added a light/white theme for when you
want your retinas to suffer in broad daylight. Flip it on in Settings (a few
screens are still getting their tan — bear with us).
- Unified look — cards and surfaces across the app now share one softer,
consistent style instead of a patchwork of greys and blues.
- Supporter badge no longer shoves your firewall name off-screen — it now sits
neatly under the title where it belongs.
- Removed the firewall traffic digest — it never delivered reliably
(especially on iOS) and the underlying data couldn't back a real daily/weekly
summary, so it's gone rather than left half-working.
- Feedback was quietly broken — through a mistake on my end, any in-app
feedback sent over the last ~4 days never reached me. It's fixed now. If you
wrote in during that window, please re-send it — and sorry!
- Assorted stability and polish fixes under the hood.
1.0.17 18 Jun
Fixed a bug a user mentioned
Remote wake-up pushes — background monitoring gains a far more reliable wake source, so alerts stay timely even when iOS defers background refresh.
Monitoring reliability — fixed monitoring silently pausing after launch for some multi-account setups.
User management — group members now appear instantly after saving.
Newest OPNsense compatibility — interface monitoring understands the latest OPNsense response format.
iOS 26 app icons — dark and tinted variants, plus polish fixes throughout.
1.0.15 13 Jun
New features:
Multi-account switching
Command palette
Wake-on-LAN
Push notifications
Unread alert badge
CARP & Unbound DNS cards
Expanded Backup History
Faster hedged-request login
Widget improvements
Security & stability hardening
1.0.14 7 Jun
Major release:
(Notifications hopefully work), of course keep in mind that I have made the app to compare a baseline to the next one and therefore we get updates if something is down or not.
If sketchy connection or no connection (wifi or vpn) you may face wrong alerts/notifications, therefore the "alpha" version.
Security
TOFU certificate pinning for TLS, with a verification workflow and cert‑rejection tracking;
Session lifecycle management that invalidates state on logout
Improved host validation on the operations screen
Notifications & background monitoring
Push notifications
Time‑sensitive notification support and iOS 14+ foreground presentation, plus refined iOS background refresh intervals
Unread alert indicators; updated background task scheduling and monitoring diagnostics
Notification logging and more accessible background storage
Login & networking
Hedged‑request login strategy with better error messaging and cache eviction
Network request deduplication and endpoint caching
More robust API response parsing and error handling
Persistent firewall/network stats providers; new DNS, Certificate, and Firewall Alias monitoring providers
UI
Central AppSnackbar widget and unified global snackbar theming
Chart animations and smoother line/area gradients; optimized LiquidGlass rendering
RRD time‑range selection and configurable ping counts
Reordered dashboard navigation and tab index mapping; unified Captive Portal styling
Fixed ScaffoldMessenger errors on cold boot
1.0.13 1 Jun
New graph line for gateway
New approach on the Background Notification Service
Visual Firewall Adjustments. & Inclusion of Aliases
Support for Unbound DNS Host Override
Certificate Viewer
Optimized LiquidGlass
1.0.11 14 May
• HAProxy fixed and editable — the tab was calling API endpoints the plugin doesn't provide, so it always claimed the plugin wasn't installed. It now loads your real frontends, backends, and servers — and you can edit them (binds, mode, balancing algorithm, server membership, address/port/weight).
• OpenVPN instances can now be edited in place, and the add form no longer silently ignores your protocol, device type, and port choices.
• Unbound Query Forwarding — add, edit, and toggle domain forwards and DNS-over-TLS upstreams from the DNS tab.
• CrowdSec fixed — alert and ban lists were querying the wrong endpoints and always came up empty; lifting a ban now works too.
• ZeroTier reworked — join networks by ID, leave or forget them, with live status and assigned addresses.
• Dashboard cards can go half-width — pair two side by side via Customize.
• Light theme polish — several accents were unreadable on white; now theme-aware.
more Version 1.0.27 5 days ago
Data Linked to You The following data may be collected and linked to your identity:
Data Not Linked to You The following data may be collected but it is not linked to your identity: