← All project updates
network

Network automation: current boundary and roadmap

Guest private networking is validated separately from public IPv4 and firewall publication to keep changes controlled.

Current model

Customer guests connect through vmbr20 and receive private addressing from defined pools. Public IPv4 is mapped at the network edge instead of being configured directly inside guests.

Safety boundary

The primary OPNsense node is the configuration authority and HA synchronization handles its peer. The network worker remains stopped until guest provisioning and public inbound/outbound behavior can be proven together with the new address allocation.

Planned validation

• Confirm private guest address, prefix, and gateway from inside the operating system.

• Confirm outbound public translation and inbound mapped services.

• Verify firewall ordering, state behavior, and TCP/25 policy.

• Prove retry, rollback, termination, and address-release behavior.

This separation prevents a successful firewall compile from hiding an incorrectly configured guest.