Networks
Networks
What hands out addresses on each network docker-server can reach. Two routers split the building:
- The EdgeRouter (
AV-ROUTER) serves Control, Comms and AVoIP. - IT’s UniFi gateway (MAC
68:d7:9a:59:8c:74, the office’s192.168.0.1) serves SPACnet, Lighting and Video.
Each is the gateway as well as the DHCP server on its networks. Management and Dante A have no DHCP
at all. The EdgeRouter also has an address on Management, 192.168.100.254, used only for its own
SNMP and NTP; it routes nothing into or out of that VLAN.
Internet and office access
| Network | Internet | How |
|---|---|---|
| Lighting, Video | yes | IT’s UniFi gateway, on the office’s public IP |
| Control | only the AMX controller (192.168.30.150) |
EdgeRouter → SPACnet → IT’s gateway, allowlist CONTROL_INTERNET |
| Comms | only the Green-Go BridgeX (10.0.24.1) |
EdgeRouter → SPACnet → IT’s gateway, allowlist COMMS_INTERNET |
| AVoIP | no | the EdgeRouter doesn’t let it out |
| Management, Dante A | no | no gateway |
The EdgeRouter’s uplink is SPACnet. eth0.5 takes an ordinary DHCP lease from IT’s gateway, and
the router translates outgoing traffic onto it. Its WAN_OUT firewall lets out only the devices in
two address groups: CONTROL_INTERNET (today just the AMX controller) and COMMS_INTERNET (today
just the Green-Go BridgeX). To give another device internet, give it a DHCP reservation and add its
address to the group for its network. Nothing goes out to a private, CGNAT or link-local address, so neither network reaches the
office, nor Lighting or Video through IT’s gateway. The router answers DNS on Control and Comms,
forwarding to the resolvers SPACnet’s DHCP hands it. Devices without internet can still resolve
names; they just can’t connect.
The router is invisible from the office. Nothing answers on its SPACnet address, over IPv4 or
IPv6. It also ignores office traffic that reaches its Control address through IT’s .250 leg:
CONTROL_LOCAL accepts only Control and the management network. Nothing from the office reaches
Comms or AVoIP at all. IT’s DHCP client list shows the router as AV-ROUTER.
The office can reach docker-server at 192.168.30.200. IT’s gateway delivers the traffic through its
Control leg, and docker-server answers on its own office interface. The office can’t reach other
Control devices: their replies go through the EdgeRouter, which won’t send them to the office.
IT’s gateway routes office traffic into Lighting and Video. Lighting devices mostly don’t answer, because few have a gateway set, but nothing blocks the traffic on the way in. Video devices answer. Only IT’s firewall can close either.
DHCP by network
| VLAN | Network | Subnet | DHCP server | Authoritative | Lease | Gateway handed out |
|---|---|---|---|---|---|---|
| 2 | Management | 192.168.100.0/24 |
none — static addresses only | — | — | — |
| 5 | SPACnet (office) | 192.168.0.0/23 |
UniFi gateway, 192.168.0.1 |
yes | 1 day | 192.168.0.1 |
| 21 | Control | 192.168.30.0/24 |
EdgeRouter, 192.168.30.254 |
yes | 1 day | 192.168.30.254 |
| 22 | Lighting | 10.0.22.0/24 |
UniFi gateway, 10.0.22.254 |
yes | 1 day | 10.0.22.254 |
| 23 | Video | 10.0.23.0/24 |
UniFi gateway, 10.0.23.254 |
yes | 1 day | 10.0.23.254 |
| 24 | Comms | 10.0.24.0/24 |
EdgeRouter, 10.0.24.254 |
yes | 7 days | 10.0.24.254 |
| 25 | AVoIP | 10.0.25.0/24 |
EdgeRouter, 10.0.25.254 |
yes | 7 days | 10.0.25.254 |
| 26 | Dante A | 192.168.10.0/24 |
none — static addresses only | — | — | — |
Authoritative means the server refuses (NAKs) a request for an address that doesn’t belong on
that network. A device moved from one network to another therefore gets a new lease straight away,
instead of holding on to a dead address until its old lease runs out. Every server above does this;
the UniFi’s refusal reads wrong network.
No network has more than one DHCP server. A discover from a made-up MAC gets a single offer on each network that has DHCP, and none on the other two. Two authoritative servers on one network would refuse each other’s clients, so keep it that way.
The EdgeRouter also carries scopes for Lighting, Video, Core (10.0.0.0/24), LAN1 and LAN2,
but all five are disabled. Its Lighting and Video interfaces (eth0.22, eth0.23) are shut down,
and they’re configured with the same .254 addresses the UniFi answers on. Turning either one back
on would put two gateways and two DHCP servers on that VLAN.
Every DHCP reply on Control arrives twice. The UniFi gateway also has an address on Control
(192.168.30.250), and it relays Control DHCP to the EdgeRouter. It then re-broadcasts the router’s
answers, about 40 ms after the router’s own. Both copies carry server ID 192.168.30.254, so the
second isn’t a rogue server. It’s harmless, and it’s configured on IT’s side.
On the static networks nothing answers DHCP, so every device on them needs an address set by
hand. A Dante device left on automatic addressing falls back to a link-local 169.254.x.x address.
Not covered here, because docker-server has no interface on them:
- Dante B (
192.168.11.0/24), on its own pair of SG-300s; - SPAC’s wireless networks.
Checking a network
To see every DHCP server on a network, send a discover from a random MAC out of docker-server’s interface for it. The probe needs raw sockets, which a host-network container provides without root on the host:
docker run --rm --network host --cap-add NET_RAW --cap-add NET_ADMIN alpine:3 sh -c \
"apk add -q nmap nmap-scripts && nmap -e <interface> --script broadcast-dhcp-discover \
--script-args broadcast-dhcp-discover.mac=random"
The interfaces are ens9 (SPACnet), SPACmgmt, control, lighting, video, comms, avoip and
danteprimary. More than one Server Identifier in the output means a second server. A server that
only answers devices it already knows won’t show up this way.