Switching & Cabling

Switch Operations

Safe operating rules for Site A's UniFi L2 fabric and Site B's unchanged switching design.

All Site A UniFi switches and sa-ap-01 adopt to sa-uos-01 at 10.10.10.40. The controller is not in the forwarding path: existing forwarding continues during controller loss, but adoption, telemetry, and configuration stop.

Site A Rules

  • Switches remain Layer 2 only: no SVIs, DHCP, or static routes.
  • OPNsense owns all routed gateways and stateful policy.
  • A-FABRIC uses native 999 with explicit tagged VLANs; never Allow All.
  • VLAN 65 is not carried; VLANs 253/4040 are absent at Site A.
  • RSTP priorities are 4096/8192/12288 for sw1/sw2/sw3.
  • One healthy triangle path is expected to be alternate/blocking.
  • Keep MTU 1500 and do not configure LACP, MLAG, or stacking.
  • PoE stays off except on commissioned AP ports.

Safe Change Sequence

  1. Export UOS and OPNsense backups; capture current ports and RSTP state.
  2. Confirm local console access and a physical rollback path.
  3. Review the exact port/profile/VLAN diff.
  4. Change one endpoint or bounded cable group.
  5. Test management, DHCP, DNS, WAN, one allowed flow, and one denied flow.
  6. Roll back immediately if management or the expected policy path is lost.

For fabric activation, pull each DAC once and confirm reconvergence. That proves link redundancy only; it does not make sa-fw-01 redundant.

Site B Boundary

Site B keeps the Netgear L2 core, UniFi access switch, OPNsense gateways, and downstream USG Pro on VLAN 253. Its forbidden-infrastructure-VLAN access rule remains intact.