Network Map

AVoIP network map

Live inventory of the SVSI fleet on 10.0.25.0/24, read from each endpoint’s getStatus (TCP 50002). A decoder subscribes to a stream number; an encoder produces one. This is a snapshot — re-run the enumeration to refresh it.

Only the stable fields are recorded here. DVIINPUT/DVISTATUS is deliberately not in these tables: it flips as gear is powered up and down for a service, so committing it guarantees the page reads as wrong most of the week. Read it live with getStatus when you need it.

54 endpoints: 32 decoders (31 × N1222A, 1 × N1233A), 19 encoders (12 × N1122A, 7 × N1115A) and 3 × N432A audio transceivers. The fleet is not uniformly N1122A/N1222A: the N1115A encoders and the single N1233A decoder are the same generation but different models.

Switch ports come from the switches’ forwarding tables, walked over SNMP from docker-server: the port where an endpoint’s MAC is the only one learned. Switches are abbreviated: AVoIP DS is the M4250 in the server room, AVoIP the SG-500X in the AV room, Core is AV-CORE, and Atrium, M21 and Control Room are the M4250s of those names. — means the endpoint was powered off when the tables were read, which outside services is most of the video system.

AVoIP DS switch (server room)

AVoIP-DS-SWITCH, 192.168.100.204. The signage encoders, the four content PCs, the rack’s RackLink and the home runs from eleven decoders all land here. Its config carries only the AV UI’s generic VID:25,AVoIP,Video port descriptions, so this table is the record of what is where.

Port Device Address VLAN Power
0/1 DS Atrium Auditorium R (decoder) 10.0.25.61 25 PoE
0/2 DS Atrium Doors South (decoder) 10.0.25.62 25 PoE
0/3 —   25  
0/4 DS Kids Min Elevator (decoder) 10.0.25.66 25 PoE
0/5 DS Atrium Auditorium L (decoder) 10.0.25.60 25 PoE
0/6 DS SCS (decoder), plus the SCS display 10.0.25.79, display 10.0.25.154 25 PoE
0/7 DS Kids Min Check-in Desk (decoder) 10.0.25.67 25 PoE
0/8 DS Kids Min Hallway (decoder) 10.0.25.68 25 PoE
0/9 DS Atrium - Legato (decoder) 10.0.25.63 25 PoE
0/10 DS Legato - Office Side (decoder) 10.0.25.65 25 PoE
0/11 DS Legato - Atrium Side (decoder) 10.0.25.64 25 PoE
0/12 —   25  
0/13 DS2 encoder 10.0.25.81 25 sled
0/14 DS1 encoder 10.0.25.80 25 sled
0/15 DS3 encoder 10.0.25.82 25 PoE (temporary; normally sled)
0/16 DS4 encoder 10.0.25.83 25 sled
0/17 DS5 encoder (no source) 10.0.25.84 25 sled
0/18 —   25  
0/19 Treehouse Preschool (decoder) 10.0.25.85 25 PoE
0/20 —   25  
0/21 DS2 content PC 192.168.1.157 5 RackLink
0/22 DS3 content PC 192.168.0.147 5 RackLink
0/23 DS1 content PC 192.168.0.115 5 RackLink
0/24 DS4 content PC 192.168.0.103 5 RackLink
0/25 RackLink RLNK-DS (RLNK-915R) 192.168.30.23 21  
0/26 EdgeRouter (AV-ROUTER); VLANs 2, 5, 21, 24, 25 tagged   trunk  
0/27 SPAC-SWT01-CORE (office network), 10 G   trunk  
0/28 AV-CORE 0/46, 10 G   trunk  

Only the decoders draw PoE — class 4, ~6.5 W each — so poe reset still cycles a decoder from here. The five encoders on 0/13–0/17 draw none: the SVSI sleds power them, and those ports read Searching at 0 mW. The sleds and the four PCs are on the RackLink instead — outlets 1–4 are DS1–DS4 and 5 is the SVSI cage — which is how the rack is power-cycled remotely; see Power-cycling an SVSi endpoint remotely.

0/25 is an untagged Control VLAN port. The RackLink is statically addressed at 192.168.30.23, so on any other VLAN it has no usable address at all.

AVoIP switch (AV room)

AVoIP-SWITCH, a Cisco SG500X-48MP at 10.0.25.207, in the AV room left rack. Every gigabit port is a VLAN 25 access port except the four in LAG Po1, PoE is enabled on gi1/1–gi1/24 only, and the config carries no port descriptions.

Port Device Address VLAN Power
gi1/1 LAG Po1 (“AVoIP Link”) member, unused   Po1  
gi1/2 Balcony TV 1 (decoder), plus the TV itself 10.0.25.2, TV 10.0.25.101 25 PoE
gi1/3 Balcony HDMI Out (decoder) 10.0.25.142 25 PoE
gi1/4 Balcony TV 2 (decoder), plus the TV itself 10.0.25.4, TV 10.0.25.100 25 PoE
gi1/5 Balcony In 1 (encoder) 10.0.25.5 25 PoE
gi1/6 Booth Laptop In 1 (encoder) 10.0.25.6 25 PoE
gi1/7 Booth Laptop In 2 (encoder) 10.0.25.7 25 PoE
gi1/8 —   25  
gi1/9 Portable Lap 2 (encoder) 10.0.25.130 25 PoE
gi1/10 Portable Encoder (encoder) 10.0.25.119 25 PoE
gi1/11 South Gym Projector (decoder) 10.0.25.127 25 PoE
gi1/12 —   25  
gi1/13 Fireside (decoder) 10.0.25.59 25  
gi1/14 —   25  
gi1/15 —   25  
gi1/16 —   25  
gi1/17 LAG Po1 (“AVoIP Link”) member, unused   Po1  
gi1/18 —   25  
gi1/19 —   25  
gi1/20 Nursing Mothers Room (decoder) 10.0.25.20 25 PoE
gi1/21 Green Room (decoder) 10.0.25.21 25 PoE
gi1/22 —   25  
gi1/23 —   25  
gi1/24 LAG Po1 (“AVoIP Link”) member, unused   Po1  
gi1/25 video-system decoder, off when read   25  
gi1/26 video-system decoder, off when read   25  
gi1/27 video-system decoder, off when read   25  
gi1/28 video-system encoder, off when read   25  
gi1/29 video-system encoder, off when read   25  
gi1/30 video-system encoder, off when read   25  
gi1/31 video-system decoder, off when read   25  
gi1/32 video-system decoder, off when read   25  
gi1/33 video-system decoder, off when read   25  
gi1/34 video-system decoder, off when read   25  
gi1/35 video-system encoder, off when read   25  
gi1/36 —   25  
gi1/37 video-system decoder, off when read   25  
gi1/38 —   25  
gi1/39 —   25  
gi1/40 —   25  
gi1/41 —   25  
gi1/42 —   25  
gi1/43 —   25  
gi1/44 —   25  
gi1/45 —   25  
gi1/46 LAG Po1 (“AVoIP Link”) member, unused   Po1  
gi1/47 FOH Audio PC (SOUND-PC) 10.0.25.102 25  
gi1/48 —   25  
te1/1 AV-CORE 0/48, 10 G   trunk  
te1/2 —      
te1/3 —      
te1/4 —      

Twelve ports carry the video system’s SVSI gear, which is powered with the video rack and was off when the table was read. By their traffic, gi1/28–gi1/30 and gi1/35 are encoders and the other eight are decoders: between them Corio 1–4, Ross 1 and 2, Rear LED Wall and [ Unassigned 2 ] (decoders), and Ross 01, Ross 02, Confidence Encoder and ProPres Video Overlay (encoders). Which one is on which port needs a read of the forwarding table during a service.

Decoders — displays, projectors & signage TVs

IP Name Model Stream Switch port
10.0.25.2 Balcony TV 1 N1222A 11 AVoIP gi1/2
10.0.25.4 Balcony TV 2 N1222A 11 AVoIP gi1/4
10.0.25.10 Atrium Audio N1222A 19 Atrium 0/13
10.0.25.20 Nursing Mothers Room N1222A 11 AVoIP gi1/20
10.0.25.21 Green Room N1222A 26 AVoIP gi1/21
10.0.25.26 Corio 1 - s3i1 N1222A 18 —
10.0.25.27 Corio 2 - s3i2 N1222A 18 —
10.0.25.28 Corio 3 - s4i1 N1222A 18 —
10.0.25.29 Corio 4 - s4i2 N1222A 18 —
10.0.25.31 Ross 1 N1222A 22 —
10.0.25.32 Ross 2 N1222A 28 —
10.0.25.33 [ Unassigned 2 ] N1222A 26 —
10.0.25.55 LX Right Display N1222A 16 Core 0/35
10.0.25.58 LX Left Display N1222A 23 Core 0/33
10.0.25.59 Fireside N1222A 26 AVoIP gi1/13
10.0.25.60 DS Atrium Auditorium L N1222A 11 AVoIP DS 0/5
10.0.25.61 DS Atrium Auditorium R N1222A 11 AVoIP DS 0/1
10.0.25.62 DS Atrium Doors South N1222A 11 AVoIP DS 0/2
10.0.25.63 DS Atrium - Legato N1222A 11 AVoIP DS 0/9
10.0.25.64 DS Legato - Atrium Side N1222A 11 AVoIP DS 0/11
10.0.25.65 DS Legato - Office Side N1222A 11 AVoIP DS 0/10
10.0.25.66 DS Kids Min Elevator N1222A 12 AVoIP DS 0/4
10.0.25.67 DS Kids Min Check-in Desk N1222A 12 AVoIP DS 0/7
10.0.25.68 DS Kids Min Hallway N1222A 12 AVoIP DS 0/8
10.0.25.79 DS SCS N1222A 11 (13 once DS3 has a link) AVoIP DS 0/6
10.0.25.85 Treehouse Preschool N1222A 26 AVoIP DS 0/19
10.0.25.109 Rear LED Wall N1222A 28 —
10.0.25.118 Online Sound Display N1233A 21 Control Room 0/4
10.0.25.126 Atrium Projector N1222A 19 Atrium 0/17
10.0.25.127 South Gym Projector N1222A 29 AVoIP gi1/11
10.0.25.133 Legato Projector N1222A 26 Atrium 0/16
10.0.25.142 Balcony HDMI Out N1222A 26 AVoIP gi1/3

LX Right Display and LX Left Display have Settings Lock on (getStatus SLCK:1). The unit describes it as locking the IP settings and stream number against automated changes, and it ignores them: an IP change sent to either is dropped without an error. To change one, clear Settings Lock under Advanced Settings (command=setSettings&settingsLock=false), make the change, then set it again.

Encoders — sources

IP Name Model Stream Switch port
10.0.25.3 Legato Wall N1115A 25 Atrium 0/15
10.0.25.5 Balcony In 1 N1115A 24 AVoIP gi1/5
10.0.25.6 Booth Laptop In 1 N1115A 17 AVoIP gi1/6
10.0.25.7 Booth Laptop In 2 N1115A 18 AVoIP gi1/7
10.0.25.9 Atrium Encoder N1115A 19 Atrium 0/14
10.0.25.23 Ross 01 N1122A 26 —
10.0.25.24 Ross 02 N1122A 27 —
10.0.25.25 Confidence Encoder N1122A 28 —
10.0.25.30 ProPres Video Overlay N1122A 22 —
10.0.25.50 LX Left Display Encoder N1122A 23 M21 0/38
10.0.25.51 LX Right Display Encoder N1122A 16 M21 0/39
10.0.25.80 DS1 - General Slides N1122A 11 AVoIP DS 0/14
10.0.25.81 DS2 - Kids Min N1122A 12 AVoIP DS 0/13
10.0.25.82 DS3 - SCS N1122A 13 AVoIP DS 0/15
10.0.25.83 Digital Signage 4 N1122A 14 AVoIP DS 0/16
10.0.25.84 Digital Signage 5 N1122A 15 AVoIP DS 0/17
10.0.25.116 Audio Recording PC N1122A 21 Control Room 0/2
10.0.25.119 Portable Encoder N1115A 144 AVoIP gi1/10
10.0.25.130 Portable Lap 2 N1115A 20 AVoIP gi1/9

Every encoder runs with MPC on. MPC (Minimal Proprietary Compression, under Advanced Settings in the web UI) picks which FPGA image the encoder loads, and it matters most on the N1115As. With it off, an N1115A runs N1115_Encoder_RAW.bit, which sends a 76-byte frame with a random source address alongside every audio packet, 187.5 a second. Every switch on the VLAN learns those addresses: about 1,700 at a time on the SG-500X, and about 2,600 on the M4250s, which keep an address for 50 minutes rather than 5. AMX keeps the option for legacy pre-MPC N1000 decoders and for scaling at the encoder. Neither applies here: every decoder is an N1222A or N1233A, and every encoder that has been checked bypasses its scaler.

getStatus doesn’t report MPC. Read <mpcEnable> from https://<ip>/nseriesGetParams.php, which needs no login, or look at FPGAVER: an N1115A reads 8/25/2016 with MPC on and 8/31/2016 with it off. To turn it on, send setSettings:mpcEnable:on on TCP 50002. The encoder reloads its FPGA in about 30 seconds without rebooting (under a minute on an N1122A), and the setting persists. An N1122A reads the same FPGAVER either way, so check its stream instead: MPC line packets are type 0x98 and 1454 bytes. The encoders that were off when this was checked are Portable Encoder (.119) and the four in the video rack (.23, .24, .25, .30).

Audio transceivers

IP Name Model Stream Switch port
10.0.25.52 Audio Transceiver 1 N432A 31 M21 0/35
10.0.25.53 Audio Transceiver 2 N432A 32 M21 0/37
10.0.25.54 Audio Transceiver 3 N432A 33 M21 0/36

Projectors and displays on the VLAN

IP Device MAC Switch port
10.0.25.134 Legato projector, NEC NP-V300W 00:25:5c:cb:01:b7 Atrium 0/16, through the Legato Projector decoder’s second jack
10.0.25.154 SCS display, NEC V321 00:25:5c:48:f0:0e AVoIP DS 0/6, through the DS SCS decoder’s second jack
10.0.25.100 Balcony stairs TV, Sharp (reports LC70LExx1) 80:38:96:90:7b:71 AVoIP gi1/4, through the Balcony TV 2 decoder’s second jack
10.0.25.101 Balcony pillar TV, Sharp (reports LC70LExx1) 80:38:96:90:7b:80 AVoIP gi1/2, through the Balcony TV 1 decoder’s second jack
10.0.25.141 Green Room TV, Sharp (reports LC70LExx1) 80:38:96:a3:66:e4 AVoIP gi1/21, through the Green Room decoder’s second jack

The Legato projector is controlled on TCP 7142; see Legato projector. It never transmits unprompted and ignores ARP from other subnets, so it shows up in neither the forwarding tables nor a sweep unless something talks to it first.

The SCS display takes DHCP, with a router reservation (AVoIP-DS-SCS-TV). It answers NEC’s display protocol on TCP 7142, one connection at a time; see Signage displays. Like the projector, it’s silent until spoken to.

The three Sharp TVs speak Sharp’s AQUOS protocol on TCP 10002: 8-character commands, space-padded, with ???? for queries (POWR???? power, IAVD???? input, where HDMI 1 is 1). The balcony pair have static addresses and the Green Room TV takes DHCP; all three have router reservations. The Green Room TV has a login turned on, and nobody here has the credentials. It greets a connection with Username:, answers the first command sent anyway, then asks for a password, so one query per connection still works.

Uptime Kuma watches the SCS display and the three Sharps (AVoIP group: Balcony Stairs TV, Balcony Pillar TV, Green Room TV), through the display_check service. It only reads power and input, and pushes up when a display is on and on the expected input, down with the reason otherwise. None of these monitors has a notification attached, so a TV that’s off just shows red. To add a display, add it to Automation/server/scripts/display-check.json with a new push monitor’s token.

Reading these tables

Several AVoIP endpoints are switched on only when wanted — most of the video system, for one — so a sweep records the power state as much as the inventory. Do not read absence as a fault on its own. The five DS encoders are the exception: they run 24/7.

The Stream column is AMX’s routing when the endpoints were read, not a fixed property. SVSi.axi’s set_digital_signage_to_stream() moves Balcony TV 1 and 2 (among others) onto Ross01, stream 26, and the slides routine puts them back on 11. Read it live when it matters.

Settings every endpoint shares

  • Static address with gateway 10.0.25.254, interleaveMC off, VLAN tagging off.
  • Encoders: MPC on (see above). Stream encryption is on for all but DS4 (.83).
  • N1115A encoders: analog input set to Unbalanced (setSettings:inputType:unbal). That’s the front 3.5 mm jack, meant for a phone on an aux cable.
  • Decoders: fixed 1080p60 output (modeset:1080p60 on TCP 50002; unmute and getStatus are on the same port — printf "help\r\n" | nc <ip> 50002 lists them). Atrium Audio (.10) and Kids Min Hallway (.68) had nothing attached when this was set, so their displays haven’t been seen at 1080p.
  • Force HTTPS off. Logging into the web UI over HTTPS turns it back on: the firmware’s login does it. That includes the login needed to enable maintenance mode. For maintenance mode, use Automation/server/scripts/svsi-maintenance-mode.sh <ip>, which turns it back off in the same login (--close <ip> closes maintenance mode again). After any other HTTPS login, POST TakeSecurity=1&forceHTTPS=false to /security.php while still logged in. TCP 50002 doesn’t accept the setting.
  • Decoders unmuted, except the Atrium Projector’s (.126), which hasn’t been decided.
  • DS and projector decoders (.60–.68, .79, .126, .127, .133): media output on the second jack off (MEDIAPORT1:off, set with setSettings:mediaPort1:off on TCP 50002). A decoder otherwise sends its whole stream out the second jack as well. On the Legato Projector decoder that pinned the NEC’s 100 Mb/s port at line rate with a ~780 Mb/s stream. The decoder’s own video comes in on the uplink, so turning it off doesn’t affect the picture. Encoders keep it on: DS1–DS3 go black without it. Online Sound Display (.118) also has it off. The other decoders haven’t been decided.
  • Firmware 2/11/2025 (N432A: 9/14/2023). Three decoders are stuck on older images: .20, .61 and .68.

Grafana alerts slack-av-alerts when a unit drifts from this. svsi-matrix (http://192.168.30.200:18642/) reads every unit on each discovery beacon. It exports each setting as svsi_device_setting{id,key,value}, keeping an offline unit’s last values, and Prometheus scrapes it as the svsi_matrix job. The “svsi” group in Grafana’s AV Alerts folder holds three rules:

  • SVSi setting drifted from baseline: any setting above that differs. Its query holds the exceptions: DS4’s encryption, the Atrium Projector’s mute, and the firmware of .20, .61 and .68. MEDIAPORT1 is checked only on the DS and projector decoders listed above. A unit that’s meant to differ needs a line there, and the rule’s export in Automation/server/backups/grafana/alerting/ needs updating.
  • SVSi unit has an unconfirmed change: UPDATE, UPDFAILED or IPTRIAL not 0 for 10 minutes. A power cycle or reboot would undo the change or break the unit.
  • svsi-matrix not reporting: while it’s down, the other two can’t fire. It runs as the svsi-matrix systemd service, which starts at boot and restarts after a crash — see Automation/server/README.md.

Deliberate exceptions:

  • The LX encoders and displays (.50, .51, .55, .58) have Settings Lock on.
  • The LX displays, Fireside (.59) and Online Sound Display (.118) turn their video off when their stream stops.
  • Atrium Audio (.10) has its video muted and takes stream 19’s audio.

To read a unit’s full settings without logging in:

  • getStatus-1 and getStatus-2 on TCP 50002. Plain getStatus stops at 1400 bytes on 2/11/2025 firmware.
  • https://<ip>/nseriesGetParams.php, the web UI’s parameter dump, which needs no login.

Switches on the VLAN

Each M4250 holds the same last octet on every VLAN it carries, so the AVoIP-VLAN address is its management address with 192.168.100. swapped for 10.0.25.:

AVoIP VLAN Switch Management address
10.0.25.201 AV-CORE (M4250) 192.168.100.201
10.0.25.202 M21-SWITCH (M4250) 192.168.100.202
10.0.25.203 CONTROL-ROOM-SWITCH (M4250) 192.168.100.203
10.0.25.204 AVoIP-DS-SWITCH (M4250) 192.168.100.204
10.0.25.205 ATRIUM-SWITCH (M4250) 192.168.100.205
10.0.25.208 STAGE-SWITCH (M4250) 192.168.100.208
10.0.25.207 AVoIP Switch (Cisco SG-500X) 10.0.25.207
10.0.25.254 AV-ROUTER (EdgeRouter) 192.168.100.254

10.0.25.201 is also the IGMP querier for the AVoIP VLAN, which is what the decoders report as ND_MRRQ.

Gateway. The gateway is 10.0.25.254, the EdgeRouter’s address on eth0.25 — the same .254 as every other AV VLAN. Every SVSi endpoint in the tables above is statically addressed, with the gateway set on the device, so none of them depends on the router’s DHCP to come up. That matters most for the ones switched on only when wanted.

The router also holds a DHCP reservation for each of them, which records the unit’s MAC and address. EdgeOS leaves reserved addresses out of the scope’s dynamic ranges, so the router can’t lease a static endpoint’s address to another device.

Two SVSi units that aren’t in the tables took dynamic leases on 2026-09-18 and were off when the rest were checked: .149 (00:19:0b:8b:63:d3) and .150, an N2135A KVM encoder.

The scope is authoritative: the router refuses (NAKs) a request for an address that doesn’t belong on VLAN 25, so a device moved here from another VLAN gets a lease straight away rather than holding on to its old address. The EdgeRouter is the only DHCP server on the VLAN.

To check an endpoint, read GW from getStatus, or ping it from docker-server’s Control interface (ping -I control <ip>). The reply only comes back if the endpoint routes through .254. To change one, use the web UI’s Network settings: Trial Save applies the change, and Confirm keeps it. getStatus reads IPTRIAL:1 until it’s confirmed, and a reboot before then undoes it. Watch the trial with that ping, not by polling getStatus: polling port 50002 during a trial can hang the control port until the unit is power-cycled.

To make a DHCP device static, choose Static and enter the address, netmask and gateway it already has. That ping can’t show the trial took, because the device answered it before. Instead, check that the Network page and getStatus both read STATIC before confirming.

What the gateway reaches. The EdgeRouter routes between Control (VLAN 21), Comms (24) and AVoIP (25), and filters what Comms and AVoIP can start:

From To Control To Comms To AVoIP
Control — open open
Comms replies only — blocked
AVoIP replies, plus ICSP (TCP 1319) to the AMX controller 192.168.30.150 blocked —

The rules are the router’s COMMS_IN and AVOIP_IN firewalls, applied inbound on eth0.24 and eth0.25, and blocked traffic is logged. Office, Lighting and Video are routed by the office’s UniFi gateway rather than this router, so nothing here reaches them.

AVoIP has no internet, by design. The EdgeRouter reaches the internet through SPACnet, but its WAN_OUT lets only Control and Comms out; see Networks. Firmware fetches and syslog that need the internet don’t work from this VLAN.

The router itself answers only DHCP, NTP and ping from this VLAN (AVOIP_LOCAL; over IPv6, AVOIP_LOCAL6 allows only ICMPv6). Comms gets the same, plus DNS, which its scope hands out. SSH, the web UI and SNMP are closed to both, and attempts are logged. The router is managed from Control (192.168.30.254) or anywhere on the management network (192.168.100.254); SNMP answers docker-server only. It keeps time from docker-server, so an endpoint that needs NTP can use 10.0.25.254.