Best practice for managing my two (prime and backup) Routers

I thought I had a good solution for this but I think I might have missed something.

The goal is to have two Chino-Special (Qotom Denverton) OpnSense routers for my firewall router. Failover does NOT need to be seamless so if I need to swap cables and restart that is fine. I just want to get back up and running during a hardware failure.

In the most bare bones case I can just build two machines side-by-side. The problem there is that I would always need to go update and edit the second machine to match exactly what I did with the first machine. I am lazy and that always falls off the priority list.

I am/was using ProxMox but am thinking of going to XCP-NG, but this option is likely the same for both…. I also tried to run ProxMox (or maybe XCP-NG) on both machines and hopefully be able to move the OpnSense VM back and forth and use VM backups to keep everything cool. I had high hopes for this.

The problem is that my Chino-Special router has four SFP+ network ports, four 2.5g ports and an admin LAN. When I tried to move my OpnSense VM from one machine to the other, the network interface mappings didn’t work. I am pretty confident I set up each machine in the exact same way taking care to name all the interfaces the same and do them all in the same order. Alas, it failed.

Anyone have similar challenges?

My network initial design. The Qotom on the lower-right is what I actually have two of. Trying to figure out how to easily keep both up to date and be able to swap them if needed.

1 Like