Firewall / OPNsense

OPNsense

OPNsense as Site A's sole WAN, NAT, routed-VLAN, DHCP, WireGuard, DMZ, and stateful policy owner, with Site B unchanged.

At Site A, sa-fw-01 is the only Layer-3 owner. It terminates the ONT, exposes an explicit VLAN trunk to sa-sw-01, and owns .1 on every routed Site A network. The three switches remain Layer 2 only.

Bootstrap Remains Current

sa-fw-01 is live on its temporary seed path, but UCG Max still serves the production bootstrap network. Do not move the ONT until A4-A7 pass and every wired and wireless endpoint is already on its final 10.10.x network.

Site A Responsibilities

  • routed gateways on VLANs 10,20,30,40,50,70,80,90,100,110,120;
  • DHCP for VLANs 100, 110, and 120;
  • DNS forwarding during bootstrap;
  • stateful inter-VLAN and DMZ policy;
  • WAN NAT and default route;
  • future WireGuard termination.

VLANs 25 and 60 have no gateway. VLAN 65 is reserved and not carried. VLAN 999 has no interface. VLANs 253 and 4040 are absent at Site A.

VM and Host Boundary

sa-fw-01 remains pinned to sa-edge-01. Its WAN vNIC uses vmbr1; its LAN vNIC uses VLAN-aware vmbr2 and must explicitly allow 10;20;30;40;50;70;80;90;100;110;120. The Proxmox host has no IP on either bridge.

Site B

Site B remains a later, separate campaign. OPNsense owns its local routed VLANs and feeds the downstream USG Pro over VLAN 253. Do not copy Site A's VLAN 999 profiles or migration ports into Site B.

Pages