Skip to content

7. Firewall & zones

Configure on the primary only (rules + aliases sync). This box is the server-room zone firewall: every routed server VLAN gateways here, so venue→server and server→server east-west all cross a stateful, logged firewall (zero-trust, DESIGN §7.2, §10).

7.1 Principle — address-list-driven, default-drop

Follow the same discipline as the RouterOS estate (CONFIG-GUIDE §1):

  • Aliases are the policy API. Rules reference aliases (ad-servers, pos-backend, mgmt-hosts, trusted-inbound, …), never raw IPs. Changing policy = editing an alias.
  • Default-drop. Each interface's ruleset ends by dropping what isn't explicitly allowed. Fail toward the backup, never toward open.
  • Log the drops you care about (send to Tier-2 syslog — page 9).

Firewall ▸ Aliases — build the alias set first, then write rules against it.

7.2 Zone model

Each routed VLAN is a zone. Default posture: deny inter-zone, permit only the explicitly-whitelisted flows. Sketch (tighten to your actual service map):

From → To Allow Notes
Venue nets → Tier-1 (930) only named services (AD, POS backend, payments) on named ports strictest zone
Venue nets → Tier-2 (931) RADIUS, UniFi, monitoring, DNS as needed standard zone
Any → DMZ (932) only published service ports internet-exposed
DMZ → internal deny by default DMZ initiates nothing inward except whitelisted
Tier-1 ↔ Tier-2 only named flows east-west hairpins the trunk — keep it tight
Backup (910) backup server ↔ agents only
Hyp-mgmt (940) mgmt-VPN sources only not a general routed zone
Any → storage (920/921/922) N/A not on this box — L2-only, DESIGN §7.2

East-west costs double on the trunk

Because OPNsense gateways every routed VLAN, inter-zone traffic hairpins the server trunk (in and back out). That's the accepted firewall-on-a-stick trade for zero-trust (§4). Keep the heaviest same-zone server-to-server flows within a VLAN (switched, never routed) so they don't traverse OPNsense at all.

7.3 Self-protection

On WAN/WAN2/COREA/COREB, permit only what the box itself needs — BGP from the configured neighbours, BFD, ICMP — and drop the rest inbound to the firewall. The BGP pass rules are auto-added by FRR; confirm they're scoped to the neighbour addresses, not any.

7.4 Scrub / advanced

Firewall ▸ Settings ▸ Advanced:

  • Scrub/reassembly: on at the WAN edge (untrusted), off on internal fast paths if not needed — scrub costs CPU (§12c).
  • Firewall Maximum States: raise to 3–5 million (128 GB RAM affords it; a busy edge blows past the default). See tunables.
  • Do not set skip on the server trunk — you want stateful inspection there.

7.5 Consuming NetBox security policy (optional, later)

Your NetBox runs the netbox-security plugin. If you later want firewall policy to originate in NetBox rather than the GUI, that's a separate tooling effort (there's no maintained Ansible collection for it) — out of scope for this GUI build. For now, author zones/rules here in the GUI; they're git-backed via config backup (page 11), which gives you the audit trail.