Skip to main content
RunBook Academy

← All checklists in OPNsense

Before deploymentchange-management

Pre-Change Checklist

16 items ·10 critical ·5 warn ·1 info

The OPNsense firewall is on the critical path of nearly every service, so a planned change without a tested rollback is not a change — it is a hopeful experiment. The pre-change checklist captures the discipline that lets a change window be short, the rollback predictable, and the stakeholders confident.

When to use

Use this checklist before any planned change to an OPNsense firewall: rule set changes, NAT changes, firmware upgrades, plugin installs, interface changes, VPN changes, and HA configuration. Use it for both service-affecting and non-service-affecting changes; the latter still need a change record and a backup.

How to use

Open the change record, walk the list, capture artefacts (configuration export, baseline metrics, rollback plan) against the record, and close the pre-change review with the change authority. Anything with severity critical must be satisfied before the change window opens.

Critical10 items

  1. System > Configuration > Backups; export a copy to the change record.
  2. System > Configuration > Backups > "Download configuration".

Warning5 items

  1. System > High Availability > Settings; "Persistent maintenance" mode.

Info1 item

  1. pfctl -ss | wc -l; top -b -n 1; netstat -I.