Completed - 02-07-26 |
Migrate routing, firewall, and SD-WAN from OPNsense to UniFI.
We're going to split this shit up into multiple segments, because spitting this all into one paragraph just sounds like a terrible idea.
Routing:
First off, new public IP is probably going to happen, although, not sure, gateway may 8am-sticky it.
Second, need to make sure WAN failover still works, order SFP+ module for WAN interface for AT&T connection, use ethernet for T-Mobile Backup.
Third, Setup Router-on-a-stick interVLAN routing. UniFi's network-magic bullshit should take care of this, but this also ties into firewall rules.
Firewall Rules:
Totally re-write this shit, current in-place rules are really dodgy, like, we're talking allowing traffic from multiple different subnets to LITERALLY ANY OTHER HOST. total nightmare, base off NOCIX firewall setup, neat and tidy.
SD-WAN (WireGuard Site to Site)
Reconfigure WireGuard Site to Site Routing, this should work nicely by copying settings from parents' UDR, but ymmv.
Ensure both link to NOCIX, and link to WITTNET are both functional.
Traffic Inspection:
This needs to remain anonymous, but also readable, kind of like analytics, I'm not singling anyone out, I just wanna know how much Tiktok traffic we're rolling, or how much data I'm pumping out to NOCIX for internet ingest/outward traffic.