Network

From Sequoia Fabrica

Our Internet drop is from Monkeybrains and lands in the mezzanine lounge. Monkeybrains generally reaches the rest of the Internet via SFMIX, Cogent, Wave, Hurricane Electric

This Monkeybrains uplinks physically lands into switch1 a Juniper EX2200C-12P (fanless, low power 12 ports PoE, 2 ports non-PoE managed switch).

Next to this switch is a server (soil) running Proxmox hosting VMs.

A VM on soil is a VyOS router, the-trunk with VLAN-plumbed interfaces on the General, Security, and Monkeybrains LANs. the-trunk provides NAT, firewalling, dynamic DNS and DHCP services.

Another VM running on soil, nursery, is an Ubuntu VM running Docker engine and hosting a few apps as containers.

Ansible for defining what runs on soil and nursery is on github.

HomeAssistant runs on a HomeAssistant Green computer running in the front network closet.

For general access there is WiFi based on Aruba IAP-225 access points, and a couple spare network ports. WiFi networks are Sequoia Fabrica and Sequoia Fabrica 24.

The space was wired with Cat6/6a and Cat5e at some point; by the appearance of labels and cables there were probably a couple separate projects, each with slightly different (but apparently unique) numbering schemes. Cable outlets in the walls around the space are labeled with some characters, and in the front network closet cables are labeled towards their ends with labels showing

Networks and VLANs[edit | edit source]

VLAN Name/ID IP space DNS Zone Name
Monkeybrains / 5
General / 100 192.168.88.0/23 xylem.sequoiafabrica.org
Security / 110 192.168.44.0/23 jasmonic.sequoiafabrica.org
Guest / 200 172.17.16.0/23 migratory.sequoiafabrica.org
General LAN[edit | edit source]

There is a single flat IP network and broadcast domain for this modestly-sized space: 192.168.88.0/23

The VyOS router acts as a DHCP server and hands out addresses between 192.168.88.100 - 192.168.89.254

ip device web admin notes
192.168.88.1 the-trunk VyOS VM on soil
192.168.88.2 switch1 Juniper EX2200-C (always-on PoE switch)
192.168.88.3 ap1 Aruba IAP-225/APIN0225
192.168.88.4 ap2 Aruba IAP-225/APIN0225
192.168.88.5 soil Proxmox Virtual Machine Host
192.168.88.6 nursery Ubuntu VM for hosting in-space applications
192.168.88.7 wifi Aruba Virtual Controller IP
192.168.88.8 soil (IPMI) IPMI Interface of soil server
192.168.88.88 laser xTool P2 Laser
192.168.88.254 homeassistant Home Assistant Green with Zigbee module
Security LAN[edit | edit source]

There are some security devices in use inside the space. Currently, this is just PoE IP cameras with no microphones attached.

This uses IP space 192.168.44.0/23 (which is currently only reachable via Tailscale and Nursery)

Frigate is running at http://nursery.xylem.sequoiafabrica.org:5000/

IP Name Description
192.168.44.1 the-trunk (eth0.110) Router for the LAN
192.168.44.2 nursery (ens19) Application-hosting VM (on soil), runs Frigate
192.168.44.100 cam-1 Floating Amcrest Bullet-shape Cam. Currently watching prusa-2 or the rollup door
192.168.44.101 cam-2 Amcrest Bullet-shape Cam. Watching the inside of the vestibule door.
Guest LAN[edit | edit source]

The Guest LAN exists to provide Internet access to guests in a way that is firewall-protected away from internal network resources.

Only Internet access should be accessible from this LAN.

Telephone Network[edit | edit source]

There are two red analog telephones in the space. These are driven by Grandstream HT801 ATAs to put them on the network.

An asterisk instance is running on nursery, to which the telephones are registered.

Currently, only calling between the telephones is supported. One uses extension "100" and the other is "101"

Available Equipment[edit | edit source]

  • Juniper EX-2200
    • 48x ports GigE copper, 4x ports GigE SFP
    • Idle Power Draw: 20 - 27 Watts
  • Cisco SG300-28PP
    • 48 ports of PoE+ GigE copper. RS232 port seems unhappy.
  • Juniper EX-2200-C
    • 12x ports GigE copper (PoE+ / 802.3at), 2x ports GigE combo Copper/SFP
    • Idle Power Draw: 15 Watts