Skip to content

ADR-0003: OPNsense is the active firewall

  • Status: Accepted
  • Date: 2026-06-22
  • Supersedes: pfSense VM 110

Context and decision

The recovered environment uses OPNsense VM 100 for routing, DHCP, NAT, gateway policy, and DNS enforcement. pfSense exports remain historical recovery evidence.

Alternatives

Restoring pfSense or moving routing to the upstream devices would preserve old patterns but conflict with the deployed VM and current policy work.

Consequences

Procedures must use OPNsense paths and Dnsmasq's live top-level configuration. Firewall changes require authenticated UI/API/SSH access and a fresh backup.

Validation evidence

VM 100 router was running on 2026-07-17. OPNsense interfaces and DHCP option 6 were last verified 2026-07-02; access failed on 2026-07-17 and is explicitly unverified.