7. Firewall & zones¶
Configure on the primary only (rules + aliases sync). This box is the server-room zone firewall: every routed server VLAN gateways here, so venue→server and server→server east-west all cross a stateful, logged firewall (zero-trust, DESIGN §7.2, §10).
7.1 Principle — address-list-driven, default-drop¶
Follow the same discipline as the RouterOS estate (CONFIG-GUIDE §1):
- Aliases are the policy API. Rules reference aliases (
ad-servers,pos-backend,mgmt-hosts,trusted-inbound, …), never raw IPs. Changing policy = editing an alias. - Default-drop. Each interface's ruleset ends by dropping what isn't explicitly allowed. Fail toward the backup, never toward open.
- Log the drops you care about (send to Tier-2 syslog — page 9).
Firewall ▸ Aliases — build the alias set first, then write rules against it.
7.2 Zone model¶
Each routed VLAN is a zone. Default posture: deny inter-zone, permit only the explicitly-whitelisted flows. Sketch (tighten to your actual service map):
| From → To | Allow | Notes |
|---|---|---|
| Venue nets → Tier-1 (930) | only named services (AD, POS backend, payments) on named ports | strictest zone |
| Venue nets → Tier-2 (931) | RADIUS, UniFi, monitoring, DNS as needed | standard zone |
| Any → DMZ (932) | only published service ports | internet-exposed |
| DMZ → internal | deny by default | DMZ initiates nothing inward except whitelisted |
| Tier-1 ↔ Tier-2 | only named flows | east-west hairpins the trunk — keep it tight |
| Backup (910) | backup server ↔ agents only | |
| Hyp-mgmt (940) | mgmt-VPN sources only | not a general routed zone |
| Any → storage (920/921/922) | N/A | not on this box — L2-only, DESIGN §7.2 |
East-west costs double on the trunk
Because OPNsense gateways every routed VLAN, inter-zone traffic hairpins the server trunk (in and back out). That's the accepted firewall-on-a-stick trade for zero-trust (§4). Keep the heaviest same-zone server-to-server flows within a VLAN (switched, never routed) so they don't traverse OPNsense at all.
7.3 Self-protection¶
On WAN/WAN2/COREA/COREB, permit only what the box itself needs — BGP from the
configured neighbours, BFD, ICMP — and drop the rest inbound to the firewall. The BGP
pass rules are auto-added by FRR; confirm they're scoped to the neighbour addresses,
not any.
7.4 Scrub / advanced¶
Firewall ▸ Settings ▸ Advanced:
- Scrub/reassembly: on at the WAN edge (untrusted), off on internal fast paths if not needed — scrub costs CPU (§12c).
- Firewall Maximum States: raise to 3–5 million (128 GB RAM affords it; a busy edge blows past the default). See tunables.
- Do not
set skipon the server trunk — you want stateful inspection there.
7.5 Consuming NetBox security policy (optional, later)¶
Your NetBox runs the netbox-security plugin. If you later want firewall policy to originate in NetBox rather than the GUI, that's a separate tooling effort (there's no maintained Ansible collection for it) — out of scope for this GUI build. For now, author zones/rules here in the GUI; they're git-backed via config backup (page 11), which gives you the audit trail.