I would suggest adding a new section to the OPNsense documentation under https://docs.opnsense.org/manual/how-tos/drop.html for the new default firewall rules.
The sections "Step 2 - Firewall Rules Inbound Traffic" and "Step 3 - Firewall Rules Outbound Traffic" currently do not appear to document the new rules that are now included by default (presumably since OPNsense 26.7).
In my case, I have configured it as follows using the new rules:
- Enabled: ✅
- Categories: Threat Intelligence
- Description: Block Spamhaus DROP
- Interface: LAN, WAN
- Quick: ✅
- Action: Block
- Direction: In
- Version: any
- Protocol: any
- Source: Spamhaus_DROPv4, Spamhaus_DROPv6
- Source Port: any
- Destination: any
- Destination port: any