An OPNsense firmware upgrade is not complete when the box reboots: it is complete when every service, interface, VPN tunnel, rule, IDS instance, and log path is back to a known-good state. This checklist forces that validation to be explicit and traceable so a regression is caught inside the maintenance window, not three days later by a downstream team.
When to use
Use this checklist after every OPNsense firmware upgrade — minor, major, and security releases. Use it on both nodes of an HA pair after each node upgrade. Use it after a plugin upgrade that triggers a service restart.
How to use
Walk the list, run the explicit validation tests, capture rule counters and log samples as evidence, and close the change record. Anything with severity critical must pass before the maintenance window closes. If a critical item cannot be validated within the rollback time budget, initiate the documented rollback.