Network

From Sequoia Fabrica

Our Internet drop is from Monkeybrains and lands in the mezzanine lounge. Monkeybrains generally reaches the rest of the Internet via SFMIX, Cogent, Wave, Hurricane Electric

This Monkeybrains uplinks physically lands into switch1 a Juniper EX2200C-12P (fanless, low power 12 ports PoE, 2 ports non-PoE managed switch).

Next to this switch is a server (soil) running Proxmox hosting VMs.

A VM on soil is a VyOS router, the-trunk with VLAN-plumbed interfaces on the General, Security, and Monkeybrains LANs. the-trunk provides NAT, firewalling, dynamic DNS and DHCP services.

Another VM running on soil, nursery, is an Ubuntu VM running Docker engine and hosting a few apps as containers.

Ansible for defining what runs on soil and nursery is on github.

HomeAssistant runs on a HomeAssistant Green computer running in the front network closet.

For general access there is WiFi based on Aruba IAP-225 access points, and a couple spare network ports. WiFi networks are Sequoia Fabrica and Sequoia Fabrica 24.

The space was wired with Cat6/6a and Cat5e at some point; by the appearance of labels and cables there were probably a couple separate projects, each with slightly different (but apparently unique) numbering schemes. Cable outlets in the walls around the space are labeled with some characters, and in the front network closet cables are labeled towards their ends with labels showing

Networks and VLANs[edit | edit source]

VLAN Name/ID IP space DNS Zone Name
Monkeybrains / 5
General / 100 192.168.88.0/23 xylem.sequoiafabrica.org
Security / 110 192.168.44.0/23 jasmonic.sequoiafabrica.org
Guest / 200 172.17.16.0/23 migratory.sequoiafabrica.org
General LAN[edit | edit source]

There is a single flat IP network and broadcast domain for this modestly-sized space: 192.168.88.0/23

The VyOS router acts as a DHCP server and hands out addresses between 192.168.88.100 - 192.168.89.254

ip device web admin notes
192.168.88.1 the-trunk VyOS VM on soil
192.168.88.2 switch1 Juniper EX2200-C (always-on PoE switch)
192.168.88.3 ap1 Aruba IAP-225/APIN0225
192.168.88.4 ap2 Aruba IAP-225/APIN0225
192.168.88.5 soil Proxmox Virtual Machine Host
192.168.88.6 nursery Ubuntu VM for hosting in-space applications
192.168.88.7 wifi Aruba Virtual Controller IP
192.168.88.8 soil (IPMI) IPMI Interface of soil server
192.168.88.9 line100 http://192.168.88.9/ Analog Telephone Adapter for Line 100
192.168.88.10 line101 http://192.168.88.10/ Analog Telephone Adapter for Line 101
192.168.88.20 seq-tel http://seq-tel.xylem.sequoiafabrica.org/admin/ FreePBX
192.168.88.100 kimberly (The Pink Power Printer) http://kimberly.xylem.sequoiafabrica.org/ The Pink Prusa 3.9 Printer (the eponymous Power Ranger)
192.168.88.101 tommy (The Green Power Printer) http://tommy.xylem.sequoiafabrica.org/ The Green Prusa 3.9 Printer (the eponymous Power Ranger)
192.168.88.88 laser xTool P2 Laser
192.168.88.254 homeassistant Home Assistant Green with Zigbee module
Security LAN[edit | edit source]

There are some security devices in use inside the space. Currently, this is just PoE IP cameras with no microphones attached.

This uses IP space 192.168.44.0/23 (which is currently only reachable via Tailscale and Nursery)

Frigate is running at http://nursery.xylem.sequoiafabrica.org:5000/

IP Name Description
192.168.44.1 the-trunk (eth0.110) Router for the LAN
192.168.44.2 nursery (ens19) Application-hosting VM (on soil), runs Frigate
192.168.44.100 cam-1 Floating Amcrest Bullet-shape Cam. Currently watching prusa-2 or the rollup door
192.168.44.101 cam-2 Amcrest Bullet-shape Cam. Watching the inside of the vestibule door.
Guest LAN[edit | edit source]

The Guest LAN exists to provide Internet access to guests in a way that is firewall-protected away from internal network resources.

Only Internet access should be accessible from this LAN.

Telephone Network[edit | edit source]

There are two red analog telephones in the space. These are driven by Grandstream HT801 ATAs to put them on the network.

There is a cordless SIP/WiFi phone in the mezzanine.

An asterisk instance is running on a VM, seq-tel, to which the telephones are registered.

Currently, only calling between the telephones is supported, along with some interesting recordings. Dial "0" for the "operator".

There is a Twilio number that still needs to be set up, but could provide in- and out-bound trunking. The number is +1-415-873-3339 (415-TRE-EEEZ)