OPNsense HA is not “two firewalls in a cluster” — it is a disciplined configuration of CARP, pfsync, XMLRPC, and per-service redundancy that together make a single virtual firewall. Drift between the two nodes, mismatched firmware, or a sync interface on a busy network are the usual ways an HA pair becomes an HA liability.
When to use
Use this checklist before the first HA deployment goes live, before any change that affects the sync interface or the XMLRPC sync password, and quarterly as a regression check. It is also the right checklist after any incident where HA failed to behave as expected, or after a node replacement.
How to use
Walk the list, then schedule a maintenance window for the failover drill. Disable master, observe backup take over VIPs, validate application traffic, then re-enable master. Capture the failover time and the failback time and file both with the change record.