Skip to content

2. Base install & interface assignment

Do this on both nodes. It is per-node and pre-dates HA config sync, so nothing here replicates automatically.

2.1 Install the OS

  1. Boot the OPNsense installer via BMC/KVM on each node.
  2. Install to the BOSS card (M.2 RAID1). Use ZFS (single disk / mirror as the BOSS presents it).
  3. Set hostname: fw-01 / fw-02. Domain per your infra convention.
  4. Complete the install, reboot, remove the installer.

Leave the initial LAN/WAN as the installer guesses — you'll reassign everything next.

2.2 Identify the physical NICs

At the console (option 8, shell) run ifconfig and note the driver names:

  • X710 SFP+ ports appear as ixl0, ixl1, … (order follows PCIe slot/NUMA).
  • i350 1G ports appear as igb0, igb1.
  • The USB NIC appears as ue0 (or axge0/ure0 depending on driver).

Map port ⇄ driver name physically

Unplug/replug one DAC at a time and watch ifconfig link state, or match by MAC. Record the mapping — every later step refers to OPNsense interface names, and a wrong assignment here propagates everywhere. Label both DAC ends per §8.

2.3 Assign interfaces

Interfaces ▸ Assignments. Add and name each interface. Suggested names (used throughout this runbook):

OPNsense name Device Role
WAN ixl? (combo) eBGP /31 → bdr-1
WAN2 ixl? (X710 #1) eBGP /31 → bdr-2
COREA ixl? (combo) eBGP /31 → CR-COLO-01
COREB ixl? (X710 #1) eBGP /31 → CR-COLO-02
SRVTRUNK lagg0 (built next page) LACP to VM MLAG (VLAN parent)
PFSYNC lagg1 (built next page) pfSync bond
OOB ue0 USB NIC → OOB switch

LAGGs first, then assign

You can't assign SRVTRUNK/PFSYNC until the LAGGs exist. Either create the LAGGs now (page 3 §3.1) then return here, or assign the two core + two WAN + OOB physical ports now and add the LAGG-backed ones after page 3. The order doesn't matter as long as both are done before addressing.

2.4 Address the point-to-point and OOB interfaces

Interfaces ▸ [each], set IPv4 = Static, enter the per-node address. These are per-node and unique — they are not CARP VIPs and are not synced.

Interface FW-01 address FW-02 address
WAN <FW01_BDR1_31> <FW02_BDR1_31>
WAN2 <FW01_BDR2_31> <FW02_BDR2_31>
COREA <FW01_CR1_31> <FW02_CR1_31>
COREB <FW01_CR2_31> <FW02_CR2_31>
OOB <OOB_FW01> <OOB_FW02>

For each /31: set the mask to /31, no upstream gateway on the interface itself (BGP provides routing; the backup's default comes from a low-priority static — page 5 §5.6). MTU 1500 on WAN/core.

OOB gets no gateway and no VIP

Set OOB static, leave the gateway blank. Do not put a CARP VIP on it — a VIP would follow the master and orphan the backup. Full reasoning + the firewall rules are on page 8.

2.5 Get management onto OOB before you go further

Once OOB is addressed on both nodes, point your browser at https://<OOB_FW01> / https://<OOB_FW02> (via the OOB VPN). From here on you manage each box over OOB, independent of the data path — which is exactly what monitoring needs too.

The one thing the GUI can't restore from a config.xml alone

Interface assignment (device ⇄ name) and these per-node /31 addresses live in each node's config.xml and are not carried by XMLRPC sync. If you ever rebuild a node from the other node's backup, you must redo §2.3–2.4 for that node's unique ports. Keep each node's own config.xml backed up (System ▸ Configuration ▸ Backups, and the Git backup target — page 11).