OPNsense VPN User Rights and Configuration SOP
Purpose
Provision and govern OPNsense VPN users, groups, certificates, routes and firewall permissions using least privilege.
Decision Summary
VPN authentication grants tunnel access only; firewall rules determine reachable resources. Default to per-group least privilege and split tunneling unless business requirements approve otherwise.
Use Cases
OpenVPN/IPsec/WireGuard remote users, office-LAN access, split tunnel, contractor access, certificate renewal and offboarding.
Hardware Requirements
Existing supported platform, secure management path, tested backup and adequate capacity.
Backup Strategy
Export configuration and permissions before changes; protect credentials, certificates and secrets.
Recovery Strategy
Use approved break-glass access or restore known-good configuration; revoke unintended access and validate.
Secure Boot Notes
Keep Secure Boot enabled where supported; rights configuration does not require disabling it.
Version History
v1.0 — 2026-08-04 — Initial controlled SOP.
Technology Register Metadata
- CSI Classification: Production Ready
- CSI Tech ID: 158
- Category: Field SOPs
- Client Approved: No
- Commercial Use: Allowed
- Current Version: 1.0 — 2026-08-04
- Documentation URL: https://docs.opnsense.org/manual/vpnet.html
- Evidence Complete: Yes
- Last Updated: August 4, 2026 3:19 AM
- Licence: CSI Internal SOP — underlying product and edition licence terms apply.
- Lifecycle Status: Done
- Risk Flag: High Risk
- Ventoy Compatibility: Not Applicable
Migration Record
Imported deterministically from the CSI Technology Register.
Source classifications, approval state, risk state, version information and testing status have been preserved. No additional approval or validation has been inferred during migration.
Cyber Space Infocom
Making Technology Work for You