Documented deployment / infrastructure
Dexter + Sentinel
A Proxmox-hosted OPNsense firewall cutover, documented from topology changes through post-reboot verification.
The problem
Move the LAN behind a virtual firewall without losing hypervisor management or leaving an unintended physical bypass in place.
The approach
The recorded configuration separates the upstream and LAN broadcast domains, uses distinct bonded interfaces and bridges, and routes the LAN through the OPNsense virtual machine. A former direct switch-to-switch bypass was physically disconnected.
What the build log verifies
- Public-IP connectivity after the upgrade and reboot sequence.
- DNS resolution through the firewall.
- The workstation's active DNS configuration points to the firewall.
- The OPNsense update process reported no pending packages on the selected mirror.
What remains
Internal DNS suffix cleanup, guest-agent checks, backup planning, management refinements, and separate investigation of direct fiber handoff. Two 1GbE links aggregated with LACP do not make a single TCP flow 2Gbps.
Documentation: Based on the supplied September 28, 2026 build log. Network addresses and internal management endpoints have been omitted from this public summary.