CHG-0023: Internet Means Internet

CHG-0023: Internet Means Internet #

Date2026-09-23
Change typeConfiguration
ClassificationRoutine
StatusComplete, 2026-09-23. The router’s pf table deevnet_private holds the three ranges and seven internet rules negate it. From DVNTM-TD the edge router’s admin now times out and the internet still answers (21/21); from trusted and management it still answers.
Window2026-09-23 18:50 to 18:51 (apply); client verification afterwards
Sitemobile (the role and home inventory change too; home is not applied)
Systemsdv02cor002p01 (core router)
Automationdeevnet.net opnsense_firewall: make migration-opnsense-firewall, against ansible-inventory-deevnet/mobile
RiskLow. Seven existing pass rules get narrower; nothing is added or deleted. Most likely to go wrong: a zone that quietly depended on a private address upstream. None is known — nothing in inventory or the roles references one
Related changesCHG-0022 (found it), CHG-0007 (wrote the rule)
Related incidentsNone
Related runbooksNetwork Segmentation standard

Summary #

Every zone’s internet rule passed to !10.20.0.0/16: anything outside the site’s own space. That is not the internet. Guest, and every other internet zone, could reach 192.168.0.0/16 and 172.16.0.0/12 — confirmed from DVNTM-TD in CHG-0022, where the edge router’s admin at 192.168.8.1:80 answered. The standard says guest has internet access only.

The value was also hard-coded in the role, so the home site (10.10.0.0/16) carried mobile’s range, and its internet rule excluded none of its own segments.

After this change, the internet rule passes to not deevnet_private, an alias of 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 that the role manages. One rule negates one network, and a negated list in pf expands into rules that each match everything else; an alias is one table, and ! <table> negates the set.

Management and trusted keep the wider rule (!10.20.0.0/16), because upstream equipment such as the edge router is administered from the operator’s seats.

Goal #

  • Alias deevnet_private exists on the router with exactly the three ranges.
  • The internet rules of platform, iot, iot_vendor, iot_backend, guest, tenant_dev and tenant_transit pass to !deevnet_private; management and trusted are unchanged.
  • From DVNTM-TD: 192.168.8.1:80 times out, the internet still answers, and the CHG-0022 checks still pass.
  • From a trusted seat: 192.168.8.1:80 still answers.

Scope #

In scope: the role (configure_alias.yml, the internet rule, defaults), both sites' firewall.yml, one apply on mobile.

Out of scope: applying on home; 100.64.0.0/10 and link-local, which are not RFC 1918 and are not added here.

Procedure #

Step 1: Plan #

make migration-opnsense-firewall

Verify: alias deevnet_private: ADD 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and ADD 0, UPDATE 7 (each destination_net: 10.20.0.0/16 -> deevnet_private), DELETE 0.

Step 2: Apply #

make migration-opnsense-firewall EXTRA_ARGS="-e firewall_apply=true"

The alias is written and loaded first, then the rules. The post-apply checks roll the router back to the pre-run revision (alias included) if a required path stops answering.

Verify: all required paths answer; a re-plan shows the alias matching and 0 / 0 / 0.

Undo: revert the role and inventory PRs and apply again. The rules return to !10.20.0.0/16; the alias is left in place, unused.

Verification #

From DVNTM-TD, the CHG-0022 script (chg0022-verify.sh): 21 passes, and the edge router line now reads timeout. From a trusted seat: nc -vz 192.168.8.1 80 still succeeds.

Outcome #

Completed after the change has run.

WhenStepsWhat happened
before merge1Plan from the branch: alias ADD, ADD 0, UPDATE 7 (10.20.0.0/16 -> deevnet_private), DELETE 0
18:501The same plan again from main, after role #33 and inventory #53 merged
18:502Applied. The alias was saved and loaded with its own reconfigure, then the 7 rules were updated; all 6 required paths still answered, and there was no rollback
18:522pf’s table deevnet_private (alias_util/list): 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16. Re-plan: alias matches, 0 / 0 of 65 / 0
afterVerificationSee the table below
FromCheckResult
DVNTM-TD (MacBook)chg0022-verify.sh21 passed, 0 failed: API, state store, broker TLS and internet still answer, and all 12 internal targets are still blocked
DVNTM-TD192.168.8.1:80timeout. It was open before this change
Trusted (a laptop)edge router admin 192.168.8.1reachable (exempt)
Management (the Builder)192.168.8.1:80, https://example.comopen, 200 (exempt)

Departures from the plan #

  • None to the procedure. Only tenant_dev was tested from a client; guest, iot, iot_vendor, platform and tenant_transit carry the same rule change but weren’t tested from a client of their own.

Follow-ups #

  • Apply on home when that site is next built; its internet rules have been wrong since CHG-0007.
  • Home dock mode. Its “full visibility” between a docked mobile and home rested on the old internet rule. Resolved 2026-09-23 by dropping dock mode: the sites aren’t connected, and a link would be declared with its own policy when there is a reason for one ( Naming and Addressing).
Page last modified: September 23, 2026