Firewall / OPNsense

Site A Migration Phases

Decision-gated A0-A8 migration from the UCG Max bootstrap island to OPNsense and the three-switch UniFi L2 fabric.

Site A builds the complete final-addressed LAN behind OPNsense while the UCG remains its temporary WAN upstream. The final cutover changes only the WAN feed.

Physical Presence Required

Do not apply a switch, Proxmox bridge, OPNsense, or WAN-path change without console access, exported backups, documented rollback cabling, and local hands.

PhaseOutcomeGate
A0current bootstrap exported, labeled, and recoverablerollback can be executed from the written map
A1four hosts and two BMCs proven one at a time through XG6 p4every NIC identity is observed and recorded
A2OPNsense, UOS, and Bao staged behind UCGall edge services healthy without moving the ONT
A3UOS dual-homed to final VLAN 10; all three XG10s adopted there in a final-addressed loop-free target treeunique identities at .2/.3/.4; no UCG/XG6 connection
A4remaining target VLANs and policy commissioned on the A3 treeDHCP/DNS/NAT and allowed/denied zone tests pass
A5UOS bootstrap vNIC retired; secrets, management, and IPMI migratedUOS/Bao/management remain reachable after each move
A6third DAC added and RSTP triangle validatedevery single-DAC pull passes
A7AP, SSIDs, and clients migratedcomplete final LAN passes while UCG still feeds OPNsense WAN
A8ONT feed moved to OPNsensepublic WAN and policy pass twice; no UCG/XG6 dependency remains

Critical Order

  1. Add the final UOS tag-10 vNIC while retaining bootstrap; prove target VLAN 10 before cabling any XG10.
  2. Connect edge nic2→sw1, then add sw2 and sw3 through sw1. Adopt each at its final VLAN-10 address using target-only commissioning profiles. Never connect an XG10 to UCG Max or XG6.
  3. Prove UOS through the target tree, retire its bootstrap vNIC, then move Bao.
  4. Move each BMC and host-management cable directly to its final port and address.
  5. Connect sw2 p12 -> sw3 p11 as the third DAC and failure-test the triangle.
  6. Move the AP to sw3 p6 and prove all SSIDs/clients while UCG still feeds WAN.
  7. Freeze every LAN setting.
  8. Move only the ONT feed to edge nic3, then validate twice.

Rollback

If WAN service cannot be restored inside the maintenance window, reconnect ONT -> UCG Max and edge nic3 -> XG6 p3. The same final LAN returns through temporary double NAT; do not readdress hosts or move the AP.

Site B is outside this campaign and remains unchanged.