Skip to main content
RunBook Academy

← All checklists in OPNsense

Before deploymentpre-upgrade

Pre-Upgrade Checklist

15 items ·10 critical ·4 warn ·1 info

An OPNsense firmware upgrade is a controlled reboot that touches the control plane of the network. A failed upgrade is recoverable if the rollback has been dry-run, the configuration is backed up off-box, and the change has been rehearsed on a staging firewall. This checklist covers the pre-upgrade work that turns a hopeful reboot into a planned one.

When to use

Use this checklist before every OPNsense firmware upgrade — minor, major, and security releases. It is the right checklist for the upgrade of an HA pair and for a single firewall; the HA sequencing is the only meaningful difference.

How to use

Walk the list, capture the release notes summary in the change record, take the off-box backup, schedule the maintenance window, dry-run the rollback in staging, and confirm go / no-go criteria. Anything with severity critical must be satisfied before the upgrade begins.

Critical10 items

  1. https://docs.opnsense.org/releases.html and the per-release notes.
  2. System > Configuration > Backups > Download configuration.
  3. System > Firmware > Plugins; cross-check with the plugin release notes.

Warning4 items

Info1 item

  1. pfctl -ss | wc -l; top -b -n 1; netstat -I.