Can anyone at OPNsense create a guide to setup Surfshark VPN?

Started by Sonicmixmaster, August 30, 2026, 04:26:34 PM

Previous topic - Next topic
August 30, 2026, 04:26:34 PM Last Edit: August 30, 2026, 04:51:42 PM by Sonicmixmaster
I am having PFSense issues where the config page no longer functions after updating to 9.0 so I switched to OPNsense but Surfshark has an outdated guide to set up their service to work with OPNsense. I looked everywhere to see if I could install an outdated version of OPNsense like 22.x and then gradually update to the current version after I confirm that Surfshark works, but I cannot find an old OPNsense iso to download and try. So here I am with 26.7.3_8 and I cannot get Surfshark to work with it even with many hours chatting with their support. Help please.

Surfshark is like any other VPN-Provider, so probably no. Maybe use a desktop-client if *Sense is to hard for you.

I want a dedicated router so I don't have to install software anytime I connect the device. That is the whole point of this post. I would not be here if I wanted to install client software on devices. I am mainly looking for a way to install old OPNsense like version 22 or so.

So you now expect OpnSense CE (which is free) to invest in interoperability for Surfshark (which you presumably pay for)?
Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, Leox LXT-010H-D

1100 down / 450 up, Bufferbloat A+

I mean, you can configure OPNsense as a WireGuard client using a configuration provided by Surfshark:

Surfshark: How to set up a manual WireGuard connection

Then, follow the appropriate guide to configure your firewall as a WireGuard client:

OPNsense: 
WireGuard Selective Routing to an External VPN Endpoint

pfSense: 
WireGuard VPN Client Configuration Example

However, this will only create a standard VPN tunnel. I'm not sure what additional features Surfshark offers, but with this setup, you would only be using the VPN connection itself.

I just create an instance for surfshark using wireguard, same setup for it.

Create instance and peer (from manual setup file),
Create interface,
Create Source NAT,
Create Gateway, 10.14.0.1

Added in my vpn group as tear1 for test - working well.