Network Map
Control network map
Every device on 192.168.30.0/24 has an EdgeRouter reservation, and each one is on the address the
device already had, whether that came from DHCP or is set on the unit. Checked live on 2026-09-25 by
a sweep from docker-server plus the switches’ forwarding tables. Two hosts are deliberately left on dynamic
leases until someone identifies them: .11 (lease name VIDEO-COLOR, a Belkin USB Ethernet
adapter) and .70 (a Windows PC named LAMPSTAND, AVoIP-DS 0/27). AMX panels are listed with
their NetLinx device number, which Telnet get device reports.
| Address | Device |
|---|---|
192.168.30.15 |
RackLink — rack room |
192.168.30.16 |
RackLink — wireless cam |
192.168.30.17 |
Stage camera 2 |
192.168.30.18 |
Stage camera 1 |
192.168.30.19 |
RackLink — control room |
192.168.30.20 |
RackLink — atrium |
192.168.30.21 |
RackLink — audio microphones |
192.168.30.22 |
RackLink — equipment room left |
192.168.30.23 |
RackLink RLNK-DS — server room signage rack, AVoIP-DS 0/25. Outlets 1–4 DS1–DS4, 5 the SVSI cage. Static address |
192.168.30.24 |
RackLink — FOH audio, control-switch gi9 |
192.168.30.25 |
RackLink RLNK-STAGE-RELAY (SW715R, Under-Stage-Right). Outlets 1–2 always-on; switched 3 = dLive Mix Rack, 4 = IP6, 5 = ME1; contacts 9/10 = Sub Amp 1/2. Web UI / OutletSubmit.cgi only (TCP 60000 refused) |
192.168.30.26 |
RackLink RLNK-M21-RELAY (SW715R, M21-left). Contacts 9–12 = main amplifiers; switched outlets numbered 3–7 |
192.168.30.29 |
STREAM-AUDIO-PC (Windows), Control Room 0/26 |
192.168.30.33 |
AMX MXT-700 LIGHTING-TOUCHSCREEN, device 10006, control-switch gi3 |
192.168.30.36 |
BSS BLU-100 ATRIUM-DSP |
192.168.30.44 |
AMX MST-701 SOUND-TOUCHSCREEN, device 10002, control-switch gi5 |
192.168.30.48 |
AMX EXB-REL8 ATRIUM-REL8, Atrium 0/3 |
192.168.30.50 |
SOUND-PC (Windows), control-switch gi15 |
192.168.30.51–.54 |
Audio-Technica IEM transmitters: .52 AT IEM 1, .51 2, .54 3, .53 4 |
192.168.30.55 |
Projection Mac Studio |
192.168.30.60 |
Global Caché iTach ITACH-RL01 |
192.168.30.65 |
AMX MXD-1000 LEGATO-TOUCHSCREEN, device 10301, Atrium 0/7 |
192.168.30.71 |
AMX MST-701 TOUCHSCREEN-LX, device 10007 |
192.168.30.72 |
AMX MST-701 TOUCHSCREEN-VIDEO, device 10004 |
192.168.30.73 |
AMX MXT-1000 ATRIUM-TOUCHSCREEN, device 10010 |
192.168.30.80 |
Lighting USB extender, receiver |
192.168.30.81 |
Lighting USB extender, transmitter |
192.168.30.100 |
nion audio processor, control-switch gi6 |
192.168.30.101 |
dLive MixRack |
192.168.30.119 |
LG multiview TV — switcher position (OLED55B2PUA), Control Room 0/22 |
192.168.30.120 |
LG multiview TV — shader position (OLED48C3PUA), Control Room 0/23 |
192.168.30.150 |
AMX NX4200 controller, control-switch gi24 |
192.168.30.151 |
AMX MXT-1900L PROJECTION-TOUCHSCREEN, device 10001, control-switch gi8 |
192.168.30.155 |
AMX MSD-431 BALCONY-TOUCHSCREEN, device 10005, control-switch gi4 |
192.168.30.156 |
AMX EXB-REL8 M21-REL8, control-switch gi2 |
192.168.30.180 |
Lighting PC (grandMA3 onPC) |
192.168.30.200 |
docker-server |
192.168.30.201 |
AV-CORE (M4250) |
192.168.30.202 |
M21-SWITCH (M4250) |
192.168.30.203 |
CONTROL-ROOM-SWITCH (M4250) |
192.168.30.204 |
AVoIP-DS-SWITCH (M4250) |
192.168.30.205 |
ATRIUM-SWITCH (M4250) |
192.168.30.206 |
control-switch (Cisco SG-300) |
192.168.30.208 |
STAGE-SWITCH (M4250) |
192.168.30.250 |
IT’s UniFi gateway (DHCP relay, see below) |
192.168.30.254 |
EdgeRouter (AV-ROUTER). Gateway and DNS for this VLAN. Internet through SPACnet only for the AMX controller (CONTROL_INTERNET). Its management address is 192.168.100.254 on VLAN 2, where it takes NTP from docker-server (192.168.100.200) and answers SNMP for docker-server only |
RackLink clocks. Every RackLink uses docker-server (192.168.30.200) for NTP. Their SNTP client
can stop polling and only restarts at boot or when the date/time form is saved, so check
docker exec ntp chronyc -n clients on docker-server. A RackLink whose Last column reads hours
rather than seconds needs its date/time form re-saved with the same settings. The two older relays:
.25uses docker-server first and1.north-america.pool.ntp.orgsecond; the second is now unreachable..26(RLNK-M21-RELAY) uses docker-server alone, on Mountain time. Its five outlets are kept OFF, since nothing should be powered from it. Both relays keep their time settings on the same form as their network settings (/settings/IPConfig.zhtml), and saving it reboots the unit..26took about 6 minutes to come back, with outlet states retained.
RackLink relay ports. The two relays (RLNK-SW715R, Rabbit MAC 00:90:c2:*) sit on STAGE-SWITCH
0/26 (.25) and M21-SWITCH 0/31 (.26). Both ports are forced to speed 100 full-duplex
with no auto-negotiate:
- Both relays autonegotiate to 100 Full, but they have failed to link after a power cycle in the past, so autonegotiation stays off.
- With autonegotiation off, the relays fall back to full duplex. Don’t force these ports to
half duplex:
10 half-duplexproduced late collisions, FCS errors and 1.26 million output discards on0/31, and about 9% ping loss on.25.
The relays have a slow CPU and stop answering while the VLAN carries a few hundred broadcasts a
second, whatever the port speed. An arp-scan wider than the /24 is enough to do it. Storm
control on the relays’ own ports doesn’t help, because it only limits traffic coming in on a
port. Keep scans on Control to 192.168.30.0/24.
DHCP. The EdgeRouter’s Control scope is authoritative: it refuses (NAKs) a request for an
address that doesn’t belong on VLAN 21, so a device moved here gets a lease straight away. It is
the only DHCP server on the VLAN, but not the only path to it. The IT gateway at 192.168.30.250
(MAC 68:d7:9a:59:8c:74) relays Control DHCP to it too, so every client gets each reply twice:
once from .254 and, about 40 ms later, from .250. Both carry server ID 192.168.30.254. That’s
harmless, and it’s configured on IT’s side. Every network’s DHCP server is listed on
Networks.
Corrected 2026-09-17. This table previously read .204 as Stage and .205 as M21, and listed
the AVoIP SG-500X at .207. Each M4250 holds the same last octet on every VLAN it carries, so
the mapping is the one above and matches Networking/*/startup-config.cfg; .204 was confirmed
live as AVoIP-DS-SWITCH. Nothing answers .207 — the SG-500X’s static address is
192.168.10.207 on the Dante VLAN, and it is reachable at 10.0.25.207 on AVoIP. There is no
.207 here.
Only .203, .204 and .206 answer SNMP from this VLAN. That is not a fault: the M4250s’
snmp-server community line is source-restricted, and only Control Room and AVoIP-DS use
ipmask 255.255.0.0 — wide enough to include 192.168.30.200. The rest use 255.255.255.0 and
answer on the management VLAN only. Poll them at 192.168.100.20x.
Inter-switch topology (LLDP-verified)
Read live from the M4250s via LLDP. A 10 G star from AV-CORE:
| AV-CORE port | Neighbour | Link |
|---|---|---|
| 42 | Atrium switch (M4250) | 10 G |
| 43 | Control-Room switch (M4250) | 10 G |
| 44 | M21 switch (M4250) | 10 G |
| 46 | AVoIP-DS switch (M4250) | 10 G |
| 47 | Stage switch (M4250) | 10 G |
| 48 | AVoIP switch (SG-500X) | 10 G |
| 40 | Control switch (SG-300) | 1 G |
| 30 | Dante-A switch | 1 G |
| 33, 35 | video endpoints | 1 G |
- SPACnet joins through the AVoIP-DS switch (server room) — its port 27
neighbours
SPAC-SWT01-CORE, and port 28 goes back to AV-CORE. - M21 additionally links (×3) to the AMX N4321 audio transceivers (these report as “N4000” over LLDP — they are transceivers, not a switch), plus video endpoints.
- Control-Room carries the SKAARHOJ Blue Pill and an SVSI encoder; Atrium carries an SVSI decoder.
Far-end ports, from lldpRemPortId:
| AV-CORE port | Neighbour | Far-end port |
|---|---|---|
| 42 | ATRIUM-SWITCH | 0/30 |
| 43 | CONTROL-ROOM-SWITCH | 0/30 |
| 44 | M21-SWITCH | 0/48 |
| 46 | AVoIP-DS-SWITCH | 0/28 |
| 47 | STAGE-SWITCH | 0/30 |
| 48 | AVoIP switch (SG-500X) | te1/1 |
| 40 | control-switch (SG-300) | gi27 |
| 30 | dante-switch-a | gi8 |
The switches’ LLDP doesn’t expose the far-end (remote) port numbers. They do — the earlier
attempt read lldpRemSysName (1.0.8802.1.1.2.1.4.1.1.9) without also walking lldpRemPortId
(…1.1.7). Supersedes the (stale) Uplink Map in the network workbook.
Trunk consistency
Audited 2026-09-17 by comparing each VLAN’s dot1qVlanStaticEgressPorts bitmap at both ends of
every inter-switch link. Worth re-running after any VLAN change: a trunk configured at one end only
passes broadcast traffic and silently drops the unicast reply, which is how the comms VLAN went
unusable for as long as it did (see Digital Signage).
| Link | Status |
|---|---|
M21 0/48 ↔ AV-CORE 0/44 |
consistent |
CONTROL-ROOM 0/30 ↔ AV-CORE 0/43 |
consistent |
AVoIP-DS 0/28 ↔ AV-CORE 0/46 |
consistent (VLAN 24 added 2026-09-17) |
ATRIUM 0/30 ↔ AV-CORE 0/42 |
VLANs 24, 26 on AV-CORE only |
STAGE 0/30 ↔ AV-CORE 0/47 |
VLANs 5, 24, 26 on AV-CORE only |
The last two are not faults. Atrium and Stage have zero ports in those VLANs — no egress, no access members — so the leaf switches are correctly pruned and it is AV-CORE that carries VLANs toward ports where they will be dropped. Untidy, harmless, and the safe direction: the dangerous asymmetry is a VLAN present on a leaf but missing from the uplink, which is what broke VLAN 24.
The management VLAN 2 is consistent everywhere — present on every uplink (AV-CORE
39, 41–44, 46, 47; M21 40, 48; CONTROL-ROOM 30; AVoIP-DS 26, 27, 28; ATRIUM 30;
STAGE 30) with no mismatch on any link.
Nothing routes to 192.168.100.0/24, by the way. The EdgeRouter has an address there
(192.168.100.254) for its own SNMP and NTP, but its MGMT_IN and MGMT_OUT firewalls drop anything
it would route into or out of the VLAN, and the switches have no working default gateway — Core’s points at 192.168.100.1, which does not
exist on that VLAN. Management access works because docker-server is on the VLAN at .200, so
reaching it means going through that box. Given 192.168.100.0/24 is also in use on the IT side,
that is the right answer rather than a gap to close.
The switches do not need a default gateway
Two of the six carry a dead one — Core 192.168.100.1, Atrium 10.0.0.1 — and neither address
exists. The other four have none at all and run fine, which is the answer: delete the two lines
rather than repointing them.
The only off-box service any M4250 references is ntp server 192.168.100.200 — docker-server, on
their own management VLAN. No syslog host, no ip name-server, no SNMP trap destination. SNMP
polling is inbound. Firmware is uploaded to the switch, not fetched by it. Nothing needs to leave
the subnet.
Routing the default out SPACnet (VLAN 5) is the obvious thought, since that is where the internet is — but it is a project, not a line:
- All six run
no ip routing, so a switch’s own traffic has exactly one L3 presence, the management interface on VLAN 2. A next hop has to be on a directly connected subnet, and a SPACnet address is not one from192.168.100.0/24. Management would have to move, or routing be re-enabled — and routing was deliberately turned off on these leaf switches. - Only M21 has any VLAN 5 address at all (
ip address dhcp). The others would each need one. - Stage has no VLAN 5 at all — it is not trunked there, so SPACnet is not even universally available.
- SPACnet is IT’s network, so it crosses the ownership boundary.
Worth revisiting only if something concrete needs it — cloud management, or firmware the switch fetches itself. Nothing does today.