The post-change window is where an OPNsense change becomes either a successful operational change or a quiet regression that will be rediscovered at the next incident. This checklist forces the operator to validate, document, and close the change — and to keep the rollback plan in reach for at least a week in case the change is implicated later.
When to use
Use this checklist immediately after any planned change to an OPNsense firewall, including the post-change validation phase of every pre-change entry. Use it for both service-affecting and non-service-affecting changes; the validation criteria differ but the discipline does not.
How to use
Walk the list, run the explicit validation tests from the pre-change checklist, capture the rule-counter and log evidence, close the change in the ticketing system, and file the post-change artefacts against the change record. Anything with severity critical must pass before the change is closed.