Skip to main content
RunBook Academy

← All checklists in OPNsense

As neededchange-management

Post-Change Checklist

16 items ·9 critical ·5 warn ·2 info

The post-change window is where an OPNsense change becomes either a successful operational change or a quiet regression that will be rediscovered at the next incident. This checklist forces the operator to validate, document, and close the change — and to keep the rollback plan in reach for at least a week in case the change is implicated later.

When to use

Use this checklist immediately after any planned change to an OPNsense firewall, including the post-change validation phase of every pre-change entry. Use it for both service-affecting and non-service-affecting changes; the validation criteria differ but the discipline does not.

How to use

Walk the list, run the explicit validation tests from the pre-change checklist, capture the rule-counter and log evidence, close the change in the ticketing system, and file the post-change artefacts against the change record. Anything with severity critical must pass before the change is closed.

Critical9 items

  1. System > Configuration > History; `opnsense-configctl -c system check` from shell.
  2. Firewall > Log Files > Live View; filter by rule.
  3. System > Configuration > Backups; verify destination.
  4. Status > CARP; System > High Availability > Status.

Warning5 items

Info2 items

  1. pfctl -ss | wc -l; top -b -n 1; netstat -I.