Site A Port Map
Bootstrap handoffs and final assignments for all 36 ports on Site A's three UniFi Switch Pro XG 10 PoE switches.
The XG6 remains the separate UCG-side bootstrap/recovery switch. All three XG10s use only final VLAN-10 management behind OPNsense and never connect to UCG Max or XG6. Every XG10 port has a final role or an explicit disabled state; PoE stays off except on commissioned AP ports.
XG10 Never Connects to UCG/XG6
XG6 p4 serves one host/BMC at a time; p5/p6 stay disconnected. Every XG10 is commissioned and adopted only on the isolated OPNsense-backed target plane.
Physical Picture
No cable ever joins UCG Max or XG6 to an XG10, including during adoption.
UCG Max and XG6 Ports
| Port | Endpoint | Phase role |
|---|---|---|
| UCG WAN | Fios ONT | live ISP termination through A7 |
| UCG LAN 1 | XG6 p1 | bootstrap LAN uplink |
| XG6 p2 | sa-ap-01 | bootstrap Wi-Fi through A6; AP moves in A7 |
| XG6 p3 | sa-edge-01 nic3 / vmbr1 | staged OPNsense WAN through A7 |
| XG6 p4 | one endpoint at a time; sa-edge-01 nic0 during A2-A4 | service/recovery lead |
| XG6 p5 | none | disconnected; never attach an XG10 |
| XG6 p6 | none | disconnected; never attach an XG10 |
Cabling Order
- A3: bring up OPNsense VLAN 10 and UOS's target interface, connect edge
nic2to sw1 p1, then add sw2 through sw1 p11 and sw3 through sw1 p12. Adopt each at its final address using a temporary target-only native-VLAN-10 commissioning profile. If discovery requires DHCP, remove the short-lived VLAN-10 scope after adoption. - A4: commission and prove the remaining VLANs and policy on the A3 tree.
- A5: move every host and BMC directly to its final port and address.
- A6: add sw2 p12 to sw3 p11 as the third DAC, then failure-test RSTP.
- A7/A8: move the AP to sw3 p6, then move only the ONT feed to edge
nic3.
A5 Control-Plane Cable Moves
| Order | Endpoint | From | Final port | Final address/state |
|---|---|---|---|---|
| 1 | sa-uos-01 bootstrap vNIC | dual-homed in A3: bootstrap vmbr0 + PVE tag 10 | remove bootstrap vNIC after target proof | retain 10.10.10.40 on tag 10 |
| 2 | sa-bao-01 vNIC | bootstrap vmbr0 | PVE tag 30 | 10.10.30.40 |
| 3 | sa-edge-01 IPMI | disconnected after XG6 p4 first contact | sw2 p5 | 10.10.10.10 |
| 4 | sa-edge-01 nic0 | XG6 p4 | sw3 p5 | 10.10.20.10 |
| 5 | sa-stor-01 IPMI | disconnected after XG6 p4 first contact | sw3 p2 | 10.10.10.20 |
| 6 | sa-stor-01 i210 | disconnected after bootstrap | sw2 p2 | 10.10.20.20 |
| 7 | sa-cmp-01 built-in NIC | disconnected after bootstrap | sw3 p3 | 10.10.20.11 |
| 8 | sa-cmp-02 built-in NIC | disconnected after bootstrap | sw1 p6 | 10.10.20.12 |
Fabric Links
| Link | End A | End B |
|---|---|---|
| A | sa-sw-01 p11 | sa-sw-02 p11 |
| B | sa-sw-02 p12 | sa-sw-03 p11 |
| C | sa-sw-03 p12 | sa-sw-01 p12 |
All three use A-FABRIC: native VLAN 999; tagged
10,20,25,30,40,50,60,70,80,90,100,110,120.
sa-sw-01: L2 Root and Router Attachment
Management 10.10.10.2; RSTP priority 4096.
| Port | Endpoint | Configuration |
|---|---|---|
| 1 | sa-edge-01 nic2 / vmbr2 | A-EDGE-ROUTER: native 999; tagged 10,20,30,40,50,70,80,90,100,110,120 |
| 2 | sa-edge-01 nic1 / vmbr3 | access 25; Corosync |
| 3 | sa-stor-01 XL710 p1 | native 999; tagged 25,30,70,80 |
| 4 | sa-stor-01 XL710 p4 | access 90 |
| 5 | sa-cmp-01 X550 p2 | native 999; tagged 60,90 |
| 6 | sa-cmp-02 built-in NIC | access 20 |
| 7-9 | unused | quarantine; disabled |
| 10 | emergency admin | access 10; normally disabled |
| 11 | sa-sw-02 p11 | A-FABRIC |
| 12 | sa-sw-03 p12 | A-FABRIC |
sa-sw-02: L2 Secondary and Data Attachment
Management 10.10.10.3; RSTP priority 8192.
| Port | Endpoint | Configuration |
|---|---|---|
| 1 | sa-stor-01 XL710 p2 | native 999; tagged 40,50,100 |
| 2 | sa-stor-01 i210 | access 20 |
| 3 | sa-cmp-01 X550 p1 | native 999; tagged 25,30,40,50,70,80,100 |
| 4 | sa-cmp-02 X550 p2 | native 999; tagged 60,90 |
| 5 | sa-edge-01 IPMI | access 10 |
| 6-9 | unused | quarantine; disabled |
| 10 | emergency admin | access 10; normally disabled |
| 11 | sa-sw-01 p11 | A-FABRIC |
| 12 | sa-sw-03 p11 | A-FABRIC |
sa-sw-03: L2 Tertiary and Client/AP Attachment
Management 10.10.10.4; RSTP priority 12288.
| Port | Endpoint | Configuration |
|---|---|---|
| 1 | sa-stor-01 XL710 p3 | access 60 |
| 2 | sa-stor-01 IPMI | access 10 |
| 3 | sa-cmp-01 built-in NIC | access 20 |
| 4 | sa-cmp-02 X550 p1 | native 999; tagged 25,30,40,50,70,80,100 |
| 5 | sa-edge-01 nic0 / vmbr0 | access 20 |
| 6 | sa-ap-01 U7 Pro XGS | native 10; tagged 100,110,120; PoE++ |
| 7 | future AP | quarantine; disabled |
| 8 | unused | quarantine; disabled |
| 9 | unused | quarantine; disabled |
| 10 | emergency admin | access 10; normally disabled |
| 11 | sa-sw-02 p12 | A-FABRIC |
| 12 | sa-sw-01 p12 | A-FABRIC |
Endpoint Rules
- Infrastructure trunks use native VLAN 999 plus explicit tagged allow-lists.
- VLANs 25 and 60 have no gateway. VLAN 65 is reserved and not carried.
- The switches have no SVIs, DHCP, or static routes.
sa-uos-01ends on VLAN 10;sa-bao-01ends on VLAN 30.- The OPNsense LAN vNIC is a real Proxmox trunk, not a single tagged vNIC.
See Site A L2 Fabric and Migration Phases.
Site A L2 Fabric
Clean-slate Site A target: three UniFi Switch Pro XG 10 PoE switches at Layer 2, OPNsense-owned routing, explicit trunks, RSTP, and failure domains.
Site B Port Map
Site B port assignments for sb-sw-01 and sb-sw-02, with NIC-to-VLAN wiring for the five compute nodes and the edge device.