Use of the OPNsense tool for unified threat management in a data center
Main Article Content
Abstract
The security of technological infrastructure in data centers requires robust frameworks that control access and protect critical services against external threats. Given the direct exposure of administration servers with public addresses and the lack of secure remote connections in an organization, the need arose to implement a unified threat management solution to centralize network traffic, hide internal equipment, and enable encrypted access for technical personnel.
The methodology was developed through a structured approach that encompassed the logical design of a segmented architecture and the subsequent installation of an open-source platform within a virtualized environment. Strict filtering rules were configured to isolate operational segments, one-to-one address translation was enabled to regulate outbound traffic to the external network, and independent virtual private network servers were created for remote access. Finally, connectivity tests and event auditing were executed to validate the effectiveness of the established policies before final deployment. One limitation of this study was the inability to empirically validate the geographic blocking feature, due to the lack of access to foreign-origin IP addresses during the testing phase.
The results demonstrated a total concealment of internal servers and precise control of outbound traffic. Unauthorized access attempts via remote administration protocols were automatically mitigated and logged for subsequent auditing, while the private network connections functioned stably across various operating systems. It was concluded that the adopted solution resolved the initial vulnerabilities by reducing the attack surface, recommending for the future the integration of deep inspection systems and the centralization of logs.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Este trabajo tiene la licencia CC BY-NC-ND 4.0
References
Huda, A. S., Prihantoro, C., y Pranata, M. (2023). Analisis perbandingan QoS pfSense dan OPNsense menggunakan metode load balancing [Comparative analysis of QoS in pfSense and OPNsense using the load balancing method]. Media Informatika, 22(2), 87–95. https://doi.org/10.37595/mediainfo.v22i2.196 DOI: https://doi.org/10.37595/mediainfo.v22i2.196
Majid, J. (2025). Building a firewall and intrusion detection system based network security system using OPNsense tools. Iraqi Journal of Intelligent Computing and Informatics (IJICI), 4(1), 66–76. https://doi.org/10.52940/ijici.v4i1.96 DOI: https://doi.org/10.52940/ijici.v4i1.96
Miller, J. (2025). Enhancing network security: Can geo-blocking be the answer? BitLyft. https://www.bitlyft.com/resources/enhancing-network-security-can-geo-blocking-be-the-answer
Purvant, S., y Sowmya, K. S. (2024). Advancements in network security. International Journal of Research Publication and Reviews, 5(1), 5122–5126. https://ijrpr.com/uploads/V5ISSUE1/IJRPR22156.pdf
Tymoshchuk, V., Pakhoda, V., Dolinskyi, A., y Karnaukhov, A. (2024). Modelling cyber threats and evaluating the performance of intrusion detection systems. Grail of Science, (46), 638–646. https://doi.org/10.36074/grail-of-science.29.11.2024.081 DOI: https://doi.org/10.36074/grail-of-science.29.11.2024.081
Veerasingam, P., Abd Razak, S., Abidin, A. F. A., Mohamed, M. A., y Mohd Satar, S. D. (2023). Intrusion detection and prevention system in SME's local network by using Suricata. Malaysian Journal of Computing and Applied Mathematics, 6(1), 21–30. https://doi.org/10.37231/myjcam.2023.6.1.88 DOI: https://doi.org/10.37231/myjcam.2023.6.1.88
Zscaler. (2024). What is unified threat management? https://www.zscaler.com/zpedia/what-unified-threat-management