The OPNsense firewall is on the critical path of nearly every service, so a planned change without a tested rollback is not a change — it is a hopeful experiment. The pre-change checklist captures the discipline that lets a change window be short, the rollback predictable, and the stakeholders confident.
When to use
Use this checklist before any planned change to an OPNsense firewall: rule set changes, NAT changes, firmware upgrades, plugin installs, interface changes, VPN changes, and HA configuration. Use it for both service-affecting and non-service-affecting changes; the latter still need a change record and a backup.
How to use
Open the change record, walk the list, capture artefacts (configuration export, baseline metrics, rollback plan) against the record, and close the pre-change review with the change authority. Anything with severity critical must be satisfied before the change window opens.