2. Base install & interface assignment¶
Do this on both nodes. It is per-node and pre-dates HA config sync, so nothing here replicates automatically.
2.1 Install the OS¶
- Boot the OPNsense installer via BMC/KVM on each node.
- Install to the BOSS card (M.2 RAID1). Use ZFS (single disk / mirror as the BOSS presents it).
- Set hostname:
fw-01/fw-02. Domain per your infra convention. - Complete the install, reboot, remove the installer.
Leave the initial LAN/WAN as the installer guesses — you'll reassign everything next.
2.2 Identify the physical NICs¶
At the console (option 8, shell) run ifconfig and note the driver names:
- X710 SFP+ ports appear as
ixl0,ixl1, … (order follows PCIe slot/NUMA). - i350 1G ports appear as
igb0,igb1. - The USB NIC appears as
ue0(oraxge0/ure0depending on driver).
Map port ⇄ driver name physically
Unplug/replug one DAC at a time and watch ifconfig link state, or match by MAC.
Record the mapping — every later step refers to OPNsense interface names, and a
wrong assignment here propagates everywhere. Label both DAC ends per §8.
2.3 Assign interfaces¶
Interfaces ▸ Assignments. Add and name each interface. Suggested names (used throughout this runbook):
| OPNsense name | Device | Role |
|---|---|---|
WAN |
ixl? (combo) |
eBGP /31 → bdr-1 |
WAN2 |
ixl? (X710 #1) |
eBGP /31 → bdr-2 |
COREA |
ixl? (combo) |
eBGP /31 → CR-COLO-01 |
COREB |
ixl? (X710 #1) |
eBGP /31 → CR-COLO-02 |
SRVTRUNK |
lagg0 (built next page) |
LACP to VM MLAG (VLAN parent) |
PFSYNC |
lagg1 (built next page) |
pfSync bond |
OOB |
ue0 |
USB NIC → OOB switch |
LAGGs first, then assign
You can't assign SRVTRUNK/PFSYNC until the LAGGs exist. Either create the
LAGGs now (page 3 §3.1) then return here, or assign
the two core + two WAN + OOB physical ports now and add the LAGG-backed ones after
page 3. The order doesn't matter as long as both are done before addressing.
2.4 Address the point-to-point and OOB interfaces¶
Interfaces ▸ [each], set IPv4 = Static, enter the per-node address. These are per-node and unique — they are not CARP VIPs and are not synced.
| Interface | FW-01 address | FW-02 address |
|---|---|---|
WAN |
<FW01_BDR1_31> |
<FW02_BDR1_31> |
WAN2 |
<FW01_BDR2_31> |
<FW02_BDR2_31> |
COREA |
<FW01_CR1_31> |
<FW02_CR1_31> |
COREB |
<FW01_CR2_31> |
<FW02_CR2_31> |
OOB |
<OOB_FW01> |
<OOB_FW02> |
For each /31: set the mask to /31, no upstream gateway on the interface itself (BGP provides routing; the backup's default comes from a low-priority static — page 5 §5.6). MTU 1500 on WAN/core.
OOB gets no gateway and no VIP
Set OOB static, leave the gateway blank. Do not put a CARP VIP on it — a VIP
would follow the master and orphan the backup. Full reasoning + the firewall rules
are on page 8.
2.5 Get management onto OOB before you go further¶
Once OOB is addressed on both nodes, point your browser at https://<OOB_FW01> /
https://<OOB_FW02> (via the OOB VPN). From here on you manage each box over OOB,
independent of the data path — which is exactly what monitoring
needs too.
The one thing the GUI can't restore from a config.xml alone
Interface assignment (device ⇄ name) and these per-node /31 addresses live
in each node's config.xml and are not carried by XMLRPC sync. If you ever
rebuild a node from the other node's backup, you must redo §2.3–2.4 for that
node's unique ports. Keep each node's own config.xml backed up
(System ▸ Configuration ▸ Backups, and the Git backup target — page 11).