Switching & Cabling
Switch Operations
Safe operating rules for Site A's UniFi L2 fabric and Site B's unchanged switching design.
All Site A UniFi switches and sa-ap-01 adopt to sa-uos-01 at
10.10.10.40. The controller is not in the forwarding path: existing
forwarding continues during controller loss, but adoption, telemetry, and
configuration stop.
Site A Rules
- Switches remain Layer 2 only: no SVIs, DHCP, or static routes.
- OPNsense owns all routed gateways and stateful policy.
A-FABRICuses native 999 with explicit tagged VLANs; neverAllow All.- VLAN 65 is not carried; VLANs 253/4040 are absent at Site A.
- RSTP priorities are 4096/8192/12288 for sw1/sw2/sw3.
- One healthy triangle path is expected to be alternate/blocking.
- Keep MTU 1500 and do not configure LACP, MLAG, or stacking.
- PoE stays off except on commissioned AP ports.
Safe Change Sequence
- Export UOS and OPNsense backups; capture current ports and RSTP state.
- Confirm local console access and a physical rollback path.
- Review the exact port/profile/VLAN diff.
- Change one endpoint or bounded cable group.
- Test management, DHCP, DNS, WAN, one allowed flow, and one denied flow.
- Roll back immediately if management or the expected policy path is lost.
For fabric activation, pull each DAC once and confirm reconvergence. That proves
link redundancy only; it does not make sa-fw-01 redundant.
Site B Boundary
Site B keeps the Netgear L2 core, UniFi access switch, OPNsense gateways, and downstream USG Pro on VLAN 253. Its forbidden-infrastructure-VLAN access rule remains intact.