Networking

Routing and Firewall Policy Matrix

Exact Site A zone outcomes, narrow required permits, mandatory denies, service objects, and the evidence required before a firewall rule is accepted.

Site A starts from deny-by-default between routed zones. Every permit identifies its ingress interface, named endpoints, protocol, ports, purpose, and adjacent negative test; an unspecified flow remains denied.

Target Policy, Not Live State

Site A remains at Phase A2. The final routed VLANs and rules are commissioned in A4. The historical broad LAN/transit allow in opnsense/config is obsolete and must not be applied at cutover; target automation still needs explicit interfaces, aliases, NAT, and rules.

Result Vocabulary

ResultMeaning
Allow — narrowA named source alias may reach a named destination alias on recorded protocols and ports only
Allow — client WANClient-initiated internet egress through OPNsense NAT; no unsolicited matching WAN ingress
DenyAn explicit block or the default deny applies
No routeThe traffic plane has no OPNsense interface, gateway, NAT, or static route
Closed until phaseNo rule exists until the workload phase defines endpoints and ports

An Allow — narrow cell never means source network → destination network: any. If aliases, protocol, and ports are missing, the flow is denied.

Site A Zone Matrix

SourceRequired allowsMandatory denies or closed paths
WANEstablished return traffic; approved published DMZ services through matching NAT and firewall rulesOPNsense admin, Proxmox, IPMI, UOS, OpenBao, and every unpublished internal service
VLAN 10 Network Mgmt / IPMIsa-uos-01; approved DNS, NTP, and update endpointsGeneral client access and direct WAN exposure
VLAN 20 Proxmox ManagementDNS, NTP, update repositories, and declared service dependenciesIoT, Guest, and undeclared service networks
VLAN 30 VM ServicesDeclared consumers and dependencies onlyPublication to an entire client or management subnet without a service rule
VLANs 40/50 KubernetesNone before A11Every pre-opened Kubernetes node or VIP flow before a cluster exists
VLAN 70 DMZDeclared internal dependencies only; approved WAN publication per serviceManagement, storage, and other internal networks by default
VLAN 80 MonitoringCollector aliases may poll explicit exporter targetsBroad monitored-node access back into monitoring and undeclared targets
VLAN 90 Backup / ReplicationDeclared host-to-PBS and PBS replication flows onlyGeneral management, client, and application traffic
VLAN 100 named admin aliasesRequired OPNsense, VLAN 10, and VLAN 20 management services; normal client WANBlanket access to every management endpoint or port
VLAN 100 other trusted clientsNormal client WAN and declared application servicesImplicit management access solely because the client is trusted
VLAN 110 IoTLocal DNS, NTP, client WAN, and explicit local controller or service exceptionsGeneral access to VLANs 10, 20, 30, 60, 70, 80, and 90
VLAN 120 Guest WiFiLocal DNS and client WANAll RFC1918/internal destinations, including management and storage
VLAN 25 CorosyncPeer traffic inside VLAN 25No route to OPNsense, WAN, or another VLAN
VLAN 60 StorageApproved consumers directly attached inside VLAN 60No route to OPNsense, WAN, VLAN 65, or another VLAN
VLAN 65 Ceph clusterNone at Site A; reserved and not carriedEvery Site A flow
VLAN 999 Native sinkNoneNo IP subnet, gateway, DHCP, clients, or OPNsense interface

Required Service Objects

Objects make repeated infrastructure flows explicit. Creating an object does not create an allow rule; the matrix decides which source may use it.

ObjectDestinationProtocol and portAllowed source class
Local DNSCurrent local OPNsense resolver; later 10.10.30.10/.11TCP/UDP 53Approved client and infrastructure zones
NTPApproved local or external time sourceUDP 123Approved infrastructure and client zones
OPNsense admin10.10.10.1HTTPS/API service onlyNamed admin and recovery aliases
Proxmox adminVLAN 20 host aliasesTCP 22 and 8006Named admin aliases
UOS admin10.10.10.40TCP 11443Named admin aliases
Monitoring exportersExplicit monitored-node aliasesExporter-specific port, such as TCP 9100 for node_exporterVLAN 80 collector aliases
Backup servicesExplicit host and PBS aliasesProtocol and port recorded with the backup serviceVLAN 90 aliases only

DHCP terminates on the local OPNsense client-VLAN interface and needs no inter-zone rule. UOS device traffic between VLAN 10 peers is same-subnet Layer 2 traffic.

Mandatory Negative Tests

Test sourceTest destinationExpected result
WANOPNsense admin, Proxmox, IPMI, UOS, and OpenBaoDenied; no matching inbound NAT
VLAN 110Representative VLAN 10 and VLAN 20 endpointsDenied at OPNsense
VLAN 120Representative RFC1918 address in each internal routed classDenied while public internet still works
VLAN 70Management and storage targetsDenied unless a named dependency exists
Non-admin VLAN 100 clientManagement service outside its aliasDenied
Any routed VLANVLAN 25 and VLAN 60 endpointsNo route through OPNsense; local peers remain unaffected
Any Site A sourceVLAN 65 or VLAN 999No routed path or addressable endpoint
VLANs 40/50 before A11Any dependencyDenied because phase rules do not exist

Rule Construction Contract

Every pass rule records the ingress interface, source alias, destination alias, protocol, destination port, service owner, positive probe, adjacent negative probe, and activation phase. OPNsense rules belong on the interface where traffic enters the firewall.

No Diagnostic Broad Allows

Never add a broad /16 pass, an any-to-any inter-zone rule, or a gateway on VLAN 25 or 60 to make a test succeed. Undefined flows stay denied until the service contract is approved.

Use the Network Validation Runbook to prove the matrix and Packet-Flow Troubleshooting to isolate a failed path.

Site B Boundary

Site B remains parked and unchanged. Do not copy Site A VLAN 999 or clean-slate rules into Site B; its OPNsense/Netgear/USG design retains VLAN 253.