Networks

Networks

What hands out addresses on each network docker-server can reach. Two routers split the building:

  • The EdgeRouter (AV-ROUTER) serves Control, Comms and AVoIP.
  • IT’s UniFi gateway (MAC 68:d7:9a:59:8c:74, the office’s 192.168.0.1) serves SPACnet, Lighting and Video.

Each is the gateway as well as the DHCP server on its networks. Management and Dante A have no DHCP at all. The EdgeRouter also has an address on Management, 192.168.100.254, used only for its own SNMP and NTP; it routes nothing into or out of that VLAN.

Internet and office access

Network Internet How
Lighting, Video yes IT’s UniFi gateway, on the office’s public IP
Control only the AMX controller (192.168.30.150) EdgeRouter → SPACnet → IT’s gateway, allowlist CONTROL_INTERNET
Comms only the Green-Go BridgeX (10.0.24.1) EdgeRouter → SPACnet → IT’s gateway, allowlist COMMS_INTERNET
AVoIP no the EdgeRouter doesn’t let it out
Management, Dante A no no gateway

The EdgeRouter’s uplink is SPACnet. eth0.5 takes an ordinary DHCP lease from IT’s gateway, and the router translates outgoing traffic onto it. Its WAN_OUT firewall lets out only the devices in two address groups: CONTROL_INTERNET (today just the AMX controller) and COMMS_INTERNET (today just the Green-Go BridgeX). To give another device internet, give it a DHCP reservation and add its address to the group for its network. Nothing goes out to a private, CGNAT or link-local address, so neither network reaches the office, nor Lighting or Video through IT’s gateway. The router answers DNS on Control and Comms, forwarding to the resolvers SPACnet’s DHCP hands it. Devices without internet can still resolve names; they just can’t connect.

The router is invisible from the office. Nothing answers on its SPACnet address, over IPv4 or IPv6. It also ignores office traffic that reaches its Control address through IT’s .250 leg: CONTROL_LOCAL accepts only Control and the management network. Nothing from the office reaches Comms or AVoIP at all. IT’s DHCP client list shows the router as AV-ROUTER.

The office can reach docker-server at 192.168.30.200. IT’s gateway delivers the traffic through its Control leg, and docker-server answers on its own office interface. The office can’t reach other Control devices: their replies go through the EdgeRouter, which won’t send them to the office.

IT’s gateway routes office traffic into Lighting and Video. Lighting devices mostly don’t answer, because few have a gateway set, but nothing blocks the traffic on the way in. Video devices answer. Only IT’s firewall can close either.

DHCP by network

VLAN Network Subnet DHCP server Authoritative Lease Gateway handed out
2 Management 192.168.100.0/24 none — static addresses only — — —
5 SPACnet (office) 192.168.0.0/23 UniFi gateway, 192.168.0.1 yes 1 day 192.168.0.1
21 Control 192.168.30.0/24 EdgeRouter, 192.168.30.254 yes 1 day 192.168.30.254
22 Lighting 10.0.22.0/24 UniFi gateway, 10.0.22.254 yes 1 day 10.0.22.254
23 Video 10.0.23.0/24 UniFi gateway, 10.0.23.254 yes 1 day 10.0.23.254
24 Comms 10.0.24.0/24 EdgeRouter, 10.0.24.254 yes 7 days 10.0.24.254
25 AVoIP 10.0.25.0/24 EdgeRouter, 10.0.25.254 yes 7 days 10.0.25.254
26 Dante A 192.168.10.0/24 none — static addresses only — — —

Authoritative means the server refuses (NAKs) a request for an address that doesn’t belong on that network. A device moved from one network to another therefore gets a new lease straight away, instead of holding on to a dead address until its old lease runs out. Every server above does this; the UniFi’s refusal reads wrong network.

No network has more than one DHCP server. A discover from a made-up MAC gets a single offer on each network that has DHCP, and none on the other two. Two authoritative servers on one network would refuse each other’s clients, so keep it that way.

The EdgeRouter also carries scopes for Lighting, Video, Core (10.0.0.0/24), LAN1 and LAN2, but all five are disabled. Its Lighting and Video interfaces (eth0.22, eth0.23) are shut down, and they’re configured with the same .254 addresses the UniFi answers on. Turning either one back on would put two gateways and two DHCP servers on that VLAN.

Every DHCP reply on Control arrives twice. The UniFi gateway also has an address on Control (192.168.30.250), and it relays Control DHCP to the EdgeRouter. It then re-broadcasts the router’s answers, about 40 ms after the router’s own. Both copies carry server ID 192.168.30.254, so the second isn’t a rogue server. It’s harmless, and it’s configured on IT’s side.

On the static networks nothing answers DHCP, so every device on them needs an address set by hand. A Dante device left on automatic addressing falls back to a link-local 169.254.x.x address.

Not covered here, because docker-server has no interface on them:

  • Dante B (192.168.11.0/24), on its own pair of SG-300s;
  • SPAC’s wireless networks.

Checking a network

To see every DHCP server on a network, send a discover from a random MAC out of docker-server’s interface for it. The probe needs raw sockets, which a host-network container provides without root on the host:

docker run --rm --network host --cap-add NET_RAW --cap-add NET_ADMIN alpine:3 sh -c \
  "apk add -q nmap nmap-scripts && nmap -e <interface> --script broadcast-dhcp-discover \
   --script-args broadcast-dhcp-discover.mac=random"

The interfaces are ens9 (SPACnet), SPACmgmt, control, lighting, video, comms, avoip and danteprimary. More than one Server Identifier in the output means a second server. A server that only answers devices it already knows won’t show up this way.