Network Map

Control network map

Every device on 192.168.30.0/24 has an EdgeRouter reservation, and each one is on the address the device already had, whether that came from DHCP or is set on the unit. Checked live on 2026-09-25 by a sweep from docker-server plus the switches’ forwarding tables. Two hosts are deliberately left on dynamic leases until someone identifies them: .11 (lease name VIDEO-COLOR, a Belkin USB Ethernet adapter) and .70 (a Windows PC named LAMPSTAND, AVoIP-DS 0/27). AMX panels are listed with their NetLinx device number, which Telnet get device reports.

Address Device
192.168.30.15 RackLink — rack room
192.168.30.16 RackLink — wireless cam
192.168.30.17 Stage camera 2
192.168.30.18 Stage camera 1
192.168.30.19 RackLink — control room
192.168.30.20 RackLink — atrium
192.168.30.21 RackLink — audio microphones
192.168.30.22 RackLink — equipment room left
192.168.30.23 RackLink RLNK-DS — server room signage rack, AVoIP-DS 0/25. Outlets 1–4 DS1–DS4, 5 the SVSI cage. Static address
192.168.30.24 RackLink — FOH audio, control-switch gi9
192.168.30.25 RackLink RLNK-STAGE-RELAY (SW715R, Under-Stage-Right). Outlets 1–2 always-on; switched 3 = dLive Mix Rack, 4 = IP6, 5 = ME1; contacts 9/10 = Sub Amp 1/2. Web UI / OutletSubmit.cgi only (TCP 60000 refused)
192.168.30.26 RackLink RLNK-M21-RELAY (SW715R, M21-left). Contacts 9–12 = main amplifiers; switched outlets numbered 3–7
192.168.30.29 STREAM-AUDIO-PC (Windows), Control Room 0/26
192.168.30.33 AMX MXT-700 LIGHTING-TOUCHSCREEN, device 10006, control-switch gi3
192.168.30.36 BSS BLU-100 ATRIUM-DSP
192.168.30.44 AMX MST-701 SOUND-TOUCHSCREEN, device 10002, control-switch gi5
192.168.30.48 AMX EXB-REL8 ATRIUM-REL8, Atrium 0/3
192.168.30.50 SOUND-PC (Windows), control-switch gi15
192.168.30.51–.54 Audio-Technica IEM transmitters: .52 AT IEM 1, .51 2, .54 3, .53 4
192.168.30.55 Projection Mac Studio
192.168.30.60 Global Caché iTach ITACH-RL01
192.168.30.65 AMX MXD-1000 LEGATO-TOUCHSCREEN, device 10301, Atrium 0/7
192.168.30.71 AMX MST-701 TOUCHSCREEN-LX, device 10007
192.168.30.72 AMX MST-701 TOUCHSCREEN-VIDEO, device 10004
192.168.30.73 AMX MXT-1000 ATRIUM-TOUCHSCREEN, device 10010
192.168.30.80 Lighting USB extender, receiver
192.168.30.81 Lighting USB extender, transmitter
192.168.30.100 nion audio processor, control-switch gi6
192.168.30.101 dLive MixRack
192.168.30.119 LG multiview TV — switcher position (OLED55B2PUA), Control Room 0/22
192.168.30.120 LG multiview TV — shader position (OLED48C3PUA), Control Room 0/23
192.168.30.150 AMX NX4200 controller, control-switch gi24
192.168.30.151 AMX MXT-1900L PROJECTION-TOUCHSCREEN, device 10001, control-switch gi8
192.168.30.155 AMX MSD-431 BALCONY-TOUCHSCREEN, device 10005, control-switch gi4
192.168.30.156 AMX EXB-REL8 M21-REL8, control-switch gi2
192.168.30.180 Lighting PC (grandMA3 onPC)
192.168.30.200 docker-server
192.168.30.201 AV-CORE (M4250)
192.168.30.202 M21-SWITCH (M4250)
192.168.30.203 CONTROL-ROOM-SWITCH (M4250)
192.168.30.204 AVoIP-DS-SWITCH (M4250)
192.168.30.205 ATRIUM-SWITCH (M4250)
192.168.30.206 control-switch (Cisco SG-300)
192.168.30.208 STAGE-SWITCH (M4250)
192.168.30.250 IT’s UniFi gateway (DHCP relay, see below)
192.168.30.254 EdgeRouter (AV-ROUTER). Gateway and DNS for this VLAN. Internet through SPACnet only for the AMX controller (CONTROL_INTERNET). Its management address is 192.168.100.254 on VLAN 2, where it takes NTP from docker-server (192.168.100.200) and answers SNMP for docker-server only

RackLink clocks. Every RackLink uses docker-server (192.168.30.200) for NTP. Their SNTP client can stop polling and only restarts at boot or when the date/time form is saved, so check docker exec ntp chronyc -n clients on docker-server. A RackLink whose Last column reads hours rather than seconds needs its date/time form re-saved with the same settings. The two older relays:

  • .25 uses docker-server first and 1.north-america.pool.ntp.org second; the second is now unreachable.
  • .26 (RLNK-M21-RELAY) uses docker-server alone, on Mountain time. Its five outlets are kept OFF, since nothing should be powered from it. Both relays keep their time settings on the same form as their network settings (/settings/IPConfig.zhtml), and saving it reboots the unit. .26 took about 6 minutes to come back, with outlet states retained.

RackLink relay ports. The two relays (RLNK-SW715R, Rabbit MAC 00:90:c2:*) sit on STAGE-SWITCH 0/26 (.25) and M21-SWITCH 0/31 (.26). Both ports are forced to speed 100 full-duplex with no auto-negotiate:

  • Both relays autonegotiate to 100 Full, but they have failed to link after a power cycle in the past, so autonegotiation stays off.
  • With autonegotiation off, the relays fall back to full duplex. Don’t force these ports to half duplex: 10 half-duplex produced late collisions, FCS errors and 1.26 million output discards on 0/31, and about 9% ping loss on .25.

The relays have a slow CPU and stop answering while the VLAN carries a few hundred broadcasts a second, whatever the port speed. An arp-scan wider than the /24 is enough to do it. Storm control on the relays’ own ports doesn’t help, because it only limits traffic coming in on a port. Keep scans on Control to 192.168.30.0/24.

DHCP. The EdgeRouter’s Control scope is authoritative: it refuses (NAKs) a request for an address that doesn’t belong on VLAN 21, so a device moved here gets a lease straight away. It is the only DHCP server on the VLAN, but not the only path to it. The IT gateway at 192.168.30.250 (MAC 68:d7:9a:59:8c:74) relays Control DHCP to it too, so every client gets each reply twice: once from .254 and, about 40 ms later, from .250. Both carry server ID 192.168.30.254. That’s harmless, and it’s configured on IT’s side. Every network’s DHCP server is listed on Networks.

Corrected 2026-09-17. This table previously read .204 as Stage and .205 as M21, and listed the AVoIP SG-500X at .207. Each M4250 holds the same last octet on every VLAN it carries, so the mapping is the one above and matches Networking/*/startup-config.cfg; .204 was confirmed live as AVoIP-DS-SWITCH. Nothing answers .207 — the SG-500X’s static address is 192.168.10.207 on the Dante VLAN, and it is reachable at 10.0.25.207 on AVoIP. There is no .207 here.

Only .203, .204 and .206 answer SNMP from this VLAN. That is not a fault: the M4250s’ snmp-server community line is source-restricted, and only Control Room and AVoIP-DS use ipmask 255.255.0.0 — wide enough to include 192.168.30.200. The rest use 255.255.255.0 and answer on the management VLAN only. Poll them at 192.168.100.20x.

Inter-switch topology (LLDP-verified)

Read live from the M4250s via LLDP. A 10 G star from AV-CORE:

AV-CORE port Neighbour Link
42 Atrium switch (M4250) 10 G
43 Control-Room switch (M4250) 10 G
44 M21 switch (M4250) 10 G
46 AVoIP-DS switch (M4250) 10 G
47 Stage switch (M4250) 10 G
48 AVoIP switch (SG-500X) 10 G
40 Control switch (SG-300) 1 G
30 Dante-A switch 1 G
33, 35 video endpoints 1 G
  • SPACnet joins through the AVoIP-DS switch (server room) — its port 27 neighbours SPAC-SWT01-CORE, and port 28 goes back to AV-CORE.
  • M21 additionally links (×3) to the AMX N4321 audio transceivers (these report as “N4000” over LLDP — they are transceivers, not a switch), plus video endpoints.
  • Control-Room carries the SKAARHOJ Blue Pill and an SVSI encoder; Atrium carries an SVSI decoder.

Far-end ports, from lldpRemPortId:

AV-CORE port Neighbour Far-end port
42 ATRIUM-SWITCH 0/30
43 CONTROL-ROOM-SWITCH 0/30
44 M21-SWITCH 0/48
46 AVoIP-DS-SWITCH 0/28
47 STAGE-SWITCH 0/30
48 AVoIP switch (SG-500X) te1/1
40 control-switch (SG-300) gi27
30 dante-switch-a gi8

The switches’ LLDP doesn’t expose the far-end (remote) port numbers. They do — the earlier attempt read lldpRemSysName (1.0.8802.1.1.2.1.4.1.1.9) without also walking lldpRemPortId (…1.1.7). Supersedes the (stale) Uplink Map in the network workbook.

Trunk consistency

Audited 2026-09-17 by comparing each VLAN’s dot1qVlanStaticEgressPorts bitmap at both ends of every inter-switch link. Worth re-running after any VLAN change: a trunk configured at one end only passes broadcast traffic and silently drops the unicast reply, which is how the comms VLAN went unusable for as long as it did (see Digital Signage).

Link Status
M21 0/48 ↔ AV-CORE 0/44 consistent
CONTROL-ROOM 0/30 ↔ AV-CORE 0/43 consistent
AVoIP-DS 0/28 ↔ AV-CORE 0/46 consistent (VLAN 24 added 2026-09-17)
ATRIUM 0/30 ↔ AV-CORE 0/42 VLANs 24, 26 on AV-CORE only
STAGE 0/30 ↔ AV-CORE 0/47 VLANs 5, 24, 26 on AV-CORE only

The last two are not faults. Atrium and Stage have zero ports in those VLANs — no egress, no access members — so the leaf switches are correctly pruned and it is AV-CORE that carries VLANs toward ports where they will be dropped. Untidy, harmless, and the safe direction: the dangerous asymmetry is a VLAN present on a leaf but missing from the uplink, which is what broke VLAN 24.

The management VLAN 2 is consistent everywhere — present on every uplink (AV-CORE 39, 41–44, 46, 47; M21 40, 48; CONTROL-ROOM 30; AVoIP-DS 26, 27, 28; ATRIUM 30; STAGE 30) with no mismatch on any link.

Nothing routes to 192.168.100.0/24, by the way. The EdgeRouter has an address there (192.168.100.254) for its own SNMP and NTP, but its MGMT_IN and MGMT_OUT firewalls drop anything it would route into or out of the VLAN, and the switches have no working default gateway — Core’s points at 192.168.100.1, which does not exist on that VLAN. Management access works because docker-server is on the VLAN at .200, so reaching it means going through that box. Given 192.168.100.0/24 is also in use on the IT side, that is the right answer rather than a gap to close.

The switches do not need a default gateway

Two of the six carry a dead one — Core 192.168.100.1, Atrium 10.0.0.1 — and neither address exists. The other four have none at all and run fine, which is the answer: delete the two lines rather than repointing them.

The only off-box service any M4250 references is ntp server 192.168.100.200 — docker-server, on their own management VLAN. No syslog host, no ip name-server, no SNMP trap destination. SNMP polling is inbound. Firmware is uploaded to the switch, not fetched by it. Nothing needs to leave the subnet.

Routing the default out SPACnet (VLAN 5) is the obvious thought, since that is where the internet is — but it is a project, not a line:

  • All six run no ip routing, so a switch’s own traffic has exactly one L3 presence, the management interface on VLAN 2. A next hop has to be on a directly connected subnet, and a SPACnet address is not one from 192.168.100.0/24. Management would have to move, or routing be re-enabled — and routing was deliberately turned off on these leaf switches.
  • Only M21 has any VLAN 5 address at all (ip address dhcp). The others would each need one.
  • Stage has no VLAN 5 at all — it is not trunked there, so SPACnet is not even universally available.
  • SPACnet is IT’s network, so it crosses the ownership boundary.

Worth revisiting only if something concrete needs it — cloud management, or firmware the switch fetches itself. Nothing does today.