OPNsense
OPNsense as Site A's sole WAN, NAT, routed-VLAN, DHCP, WireGuard, DMZ, and stateful policy owner, with Site B unchanged.
At Site A, sa-fw-01 is the only Layer-3 owner. It terminates the ONT, exposes
an explicit VLAN trunk to sa-sw-01, and owns .1 on every routed Site A
network. The three switches remain Layer 2 only.
Bootstrap Remains Current
sa-fw-01 is live on its temporary seed path, but UCG Max still serves the
production bootstrap network. Do not move the ONT until A4-A7 pass and every wired
and wireless endpoint is already on its final 10.10.x network.
Site A Responsibilities
- routed gateways on VLANs 10,20,30,40,50,70,80,90,100,110,120;
- DHCP for VLANs 100, 110, and 120;
- DNS forwarding during bootstrap;
- stateful inter-VLAN and DMZ policy;
- WAN NAT and default route;
- future WireGuard termination.
VLANs 25 and 60 have no gateway. VLAN 65 is reserved and not carried. VLAN 999 has no interface. VLANs 253 and 4040 are absent at Site A.
VM and Host Boundary
sa-fw-01 remains pinned to sa-edge-01. Its WAN vNIC uses vmbr1; its LAN
vNIC uses VLAN-aware vmbr2 and must explicitly allow
10;20;30;40;50;70;80;90;100;110;120. The Proxmox host has no IP on either
bridge.
Site B
Site B remains a later, separate campaign. OPNsense owns its local routed VLANs and feeds the downstream USG Pro over VLAN 253. Do not copy Site A's VLAN 999 profiles or migration ports into Site B.