Category:Network: Difference between revisions

From Nottinghack Wiki
Jump to navigation Jump to search
C
 
(76 intermediate revisions by 4 users not shown)
Line 1: Line 1:
{{TOC right}}
{{info|Information about the space's network has moved to the [[Network]] page.|date=December 2018}}
The hackspace network and servers are look after by the [[Team:Network_and_Servers|Network and Servers group]]
This category is for pages relating to the Hackspace [[network]]. For general network related pages see [[:Category:Network (other)]].
=Network Layout=
This page will show the network topology & proposals for network expansion / modification.<br/>
 
[[File:Hackspace_network_26-02.jpg|800px|thumb|none|alt=A |Hackspace Network]]
 
External IP address 79.77.188.139.
 
External domain address [http://lspace.nottinghack.org.uk lspace.nottinghack.org.uk] (DNS record looked after by [[User:Lwk|'RepRap' Matt]])<br/>
 
== Static & Reserved IP's ==
There are a few VLANs:
 
{| class="wikitable"
|-
! VLAN
! Network
! Description
|-
| [[#VLAN 1|1]] || 192.168.1.0/24 || Default
|-
| [[#VLAN 2|2]] || 10.0.0.0/24 || Main Hackspace network
|-
| [[#VLAN 3|3]] || 192.168.0.0/24 || [[HackSpace_Instrumentation|Instrumentation projects]]
|-
| [[#VLAN 4|4]] || - || Able / ADSL Modem (PPPoE)
|-
| [[#VLAN 5|5]] || 192.168.0.0/24 || Instrumentation ''test'' (Rommie)
|-
| [[#VLAN 6|6]] || 192.168.6.0/24 || [[Collective#Unimatrix|Unimatrix]]<->[[Collective#Locutus|Locutus]] direct network
|-
| [[#VLAN 7|7]] || 192.168.7.0/24 || [[Collective#Queen|Queen]]<->[[Collective#Unimatrix|Unimatrix]] direct network
|-
| [[#VLAN 8|8]] || 192.168.8.0/24 || [[Collective#Queen|Queen]]<->[[Collective#Locutus|Locutus]] direct network
|}
 
The following ranges are reserved for there given purpose:
 
{| class="wikitable"
|-
! Start
! End
! Purpose
|-
| 10.0.0.1 || 10.0.0.1 || [[#Kryten|kryten]] The Main Router
|-
| 10.0.0.2 || 10.0.0.79 || Static things
|-
| 10.0.0.80 || 10.0.0.89 || openVPN DHCP pool
|-
| 10.0.0.90 || 10.0.0.99 || Static Printers
|-
| 10.0.0.100 || 10.0.0.254 || DHCP Range
|-
| 10.0.0.255 || 10.0.0.255 || Broadcast
|-
| 192.168.0.1 || 192.168.0.100 || Static [[HackSpace_Instrumentation|HackSpace Instrumentation]]
|}
 
 
===VLAN 1===
These are all statically assigned.
{| class="wikitable"
|-
! VLAN
! IP
! DNS Name
! Notes
|-
| 1 || 192.168.1.1 || [[Holly|HollyVM]] || Our primary server hosing hms and instrumentation things
|-
| 1 || 192.168.1.2 || ws-switch|| Workshop switch
|-
| 1 || 192.168.1.3 || Lore || Workshop Wifi AP
|-
| 1 || 192.168.1.4 || st-switch || Studio/BlueRoom switch
|-
| 1 || 192.168.1.5 || Data || Studio/BlueRoom Wifi AP
|-
| 1 || 192.168.1.6 || [[#Gibson|Gibson]] || Wifi RADIUS Server
|-
| 1 || 192.168.1.7 || studio-gbit || Dell PowerConnect 2724 (24x gbit)
|-
| 1 || 192.168.1.8 || [[Queeg]] || Hollys backup
|-
| 1 || 192.168.1.9 || [[Collective#Unimatrix|Unimatrix]] ||
|-
| 1 || 192.168.1.10 || [[Collective#Locutus|Locutus]] ||
|-
| 1 || 192.168.1.11 || [[Collective#Queen|Queen]] ||
|-
| 1 || 192.168.1.12 || Holly (on Unimatrix)] ||
|}
 
===VLAN 2===
These are assigned via DHCP/MAC using [[#Kryten|Kryten]] or set statically on the device
{| class="wikitable"
|-
! VLAN
! IP
! DNS Name
! Notes
|-
| 2 || 10.0.0.1 || [[#Kryten|Kryten]] || pfSense router on [[Collective]]
|-
| 2 || 10.0.0.2 || [[Holly|HollyVM]] || Our primary server hosing hms and instrumentation things (Squeeze under KVM)
|-
| 2 || 10.0.0.4 || [[JARVIS]] || Sandbox Debian VM open for all members
|-
| 2 || 10.0.0.5 || [[Rommie]] || HMS Development VM
|-
| 2 || <s>10.0.0.6</s> || <s>Workshop</s> || <s>Workshop Wifi AP (channel 11)</s>
|-
| <s>2</s> || <s>10.0.0.7</s> || <s>Zyxel</s> || <s>Additional Wifi AP (channel 1)</s>
|-
| 2 || 10.0.0.10 || [[Collective]] || ESXi Management Server
|-
| 2 || 10.0.0.11 || [[Samaritan]] || Monitoring server
|-
| 2  || 10.0.0.12  || [[Queeg]] || Hollys backup
|-
| 2 || 10.0.0.14 || [[Holly]] || Our primary server hosing hms and instrumentation things (Jessie under KVM)
|-
| 2 || 10.0.0.15 || [[#Gibson|Gibson]] || Wifi RADIUS Server
|-
| 2 || 10.0.0.17 || [[Collective#Unimatrix|Unimatrix]]  ||
|-
| 2 || 10.0.0.18 || [[Collective#Locutus|Locutus]] ||
|-
| 2 || 10.0.0.19 || [[Collective#Queen|Queen]] ||
|-
| <s>2</s> || <s>10.0.0.21</s> || <s>[[YooCNC|yoocnc]]</s> || <s>YooCNC desktop</s>
|-
| 2 || 10.0.0.22 || [[Quorra]] || Quorra
|-
| 2 || 10.0.0.23 || Kiosk || Kiosk PC (under 50" screen in blueroom). WIP.
|-
| 2 || 10.0.0.24 || [[Bishop]] || Laptop for 3D printer
|-
| 2 || 10.0.0.25 || BarBot || Pi in [[Project:BarBot]]
|-
| 2 || 10.0.0.27 || pbx || Asterisk on bare metal
|-
| 2 || 10.0.0.28 || payphone || RaspberryPi in the Payphone
|-
| 2 || 10.0.0.40 || [[Webcams|studiocam]] || Pan/Tilt Studio webcam
|-
| 2 ||<s>10.0.0.90</s> || <s>[[#Marvin|marvin]]</s> || <s>A4 Laser Printer</s>
|-
| 2 ||<s>10.0.0.91</s> || <s>[[#Clank|Clank]]</s> || <s>A3 Laser Printer</s>
|-
| 2 || <s>10.0.0.92</s> || <s>[[#B4|B4]]</s> || <s>A4 InkJet with Scanner</s>
|-
| 2 || 10.0.0.93 || [[Signmaker|Vinyl]] || [[Signmaker|Vinyl]]
|-
| 2 || 10.0.0.94 || [[Rosey]] || Epson WF-7610DWF
|-
| 2 || 10.0.0.95 || [[Bender]] || HP5550
|-
| 2 || 10.0.0.96 || Zebra_2844 || Label printer 
|-
| 2 || 10.0.0.97 ||[[Plotter]] || Plotter (HP DesignJet 600)
|}(''coming soon...'') <br />
 
===VLAN 3===
These are all statically assigned.
{| class="wikitable"
|-
! VLAN
! IP
! DNS Name
! Notes
|-
| 3 || 192.168.0.1 || [[Holly|HollyVM]] || Our primary server hosing hms and instrumentation things
|-
| 3 || 192.168.0.2 || [[Collective#Unimatrix|Unimatrix]] || Bridge interface
|-
| 3 || 192.168.0.3 || [[Collective#Locutus|Locutus]] || Bridge interface
|-
| 3 || 192.168.0.4 || [[Collective#Queen|Queen]] || Bridge interface
|-
| 3 || 192.168.0.10 || [[Gatekeeper|gatekeeper]] || Access Control Arduino
|-
| 3 || 192.168.0.11 || [[LED_Matrix|MatrixMQTT]] || BIG LED Matrix Display Arduino
|-
| 3 || 192.168.0.12 || [[Vending_Machine|Vending Machine]] || RFID cashless payment nanode
|-
| 3 || 192.168.0.13 || [[Mini-matrix|Mini-matrix]] || Blue room mini-matrix display nanode
|-
| <s>3</s> || <s>''192.168.0.14''</s> || <s>[[Wall of Faces]]</s> || <s>''Wall of members faces''</s>
|-
| 3 || ''192.168.0.15'' || [[Lighting Automation|Studio Controller]] || ''Lighting Controller (Studio)''
|-
| 3 || ''192.168.0.16'' || [[Lighting Automation|Workshop Controller]] || ''Lighting Controller (Workshop)''
|-
| 3 || ''192.168.0.17'' || [[Lighting Automation|Studio Switch Panel]] || ''Lighting Switch's (Studio)''
|-
| 3 || ''192.168.0.18'' || [[Lighting Automation|Workshop Switch Panel]] || ''Lighting Switch's (Workshop)''
|-
| 3 || 192.168.0.19 || WorkshopMQTT || Workshop Bell and Temp Node
|-
| 3 || 192.168.0.21 || [[NoteAcceptor]] || Note acceptor for [[Snackspace]] / [[Vending_Machine|Vending Machine]] payments
|-
| 3 || 192.168.0.22 || [[Laser_cutter|laser]] ||[[Nhtools|Laser RFID]]
|-
| 3 || 192.168.0.23 || [[3D Printer]] ||[[Nhtools|3D Printer RFID]]
|-
| 3 || 192.168.0.24 || [[Laser Display]] || LED display near laser cutter
|-
| 3 || 192.168.0.25 || [[Queeg]] || Hollys backup
|-
| 3 || 192.168.0.26 || [[Embroidery Machine]] || [[Nhtools|Embroidery machine RIFD]]
|}(''coming soon...'')
 
===VLAN 6===
Direct network between Unimatrix and Locutus used for HDD replication<br/>
These are all statically assigned.
{| class="wikitable"
|-
! VLAN
! IP
! DNS Name
! Notes
|-
| 6 || 192.168.6.1 || [[Collective#Unimatrix|Unimatrix]] ||
|-
| 6 || 192.168.6.2 || [[Collective#Locutus|Locutus]] ||
|-
<!--
| 8 || 192.168.6.3 || [[Collective#Queen|Queen]] || Reserved Not connected
|-
-->
|}
 
===VLAN 7===
Direct network between Unimatrix and Queen used for VM Backups<br/>
These are all statically assigned.
{| class="wikitable"
|-
! VLAN
! IP
! DNS Name
! Notes
|-
| 7 || 192.168.7.1 || [[Collective#Unimatrix|Unimatrix]] ||
|-
<!--
| 7 || 192.168.7.2 || [[Collective#Locutus|Locutus]] || Reserved Not connected
|-
-->
| 7 || 192.168.7.3 || [[Collective#Queen|Queen]] ||
|}
 
===VLAN 8===
Direct network between Locutus and Queen used for VM Backups<br/>
These are all statically assigned.
{| class="wikitable"
|-
! VLAN
! IP
! DNS Name
! Notes
|-
<!--
| 8 || 192.168.8.1 || [[Collective#Unimatrix|Unimatrix]] || Reserved Not connected
|-
-->
| 8 || 192.168.8.2 || [[Collective#Locutus|Locutus]] ||
|-
| 8 || 192.168.8.3 || [[Collective#Queen|Queen]] ||
|}
 
== External Port Routing ==
{| class="wikitable"
|-
! Service
! External Port
! Internal Port
! Internal IP
! Notes
|-
| HTTP || 80 || 80 || 10.0.0.14 || Webserver on [[Holly]]
|-
| HTTPS || 443 || 443 || 10.0.0.14 || HMS SSL Webserver on [[Holly]]
|-
| SSH || 1921 || 22 || 10.0.0.2 || SSH on [[Holly]]
|-
| SSH || 1922 || 22 || 10.0.0.12 || SSH on [[Holly#HollyVM|HollyVM]]
|-
| SSH || 3000 || 22 || 10.0.0.4 || SSH on [[JARVIS]]
|-
| SSH || 3045 || 22 || 10.0.0.5 || SSH on [[Rommie]]
|-
| RTP || 10000-20000 || 10000-20000  || 10.0.0.27 || Asterisk/RTP on PBX
|-
| SIP || 5060 || 5060  || 10.0.0.27 || Asterisk/SIP on PBX
|}
 
== Switch port assignments ==
=== Netgear Prosafe FS728x ===
The switch in the members storage room is a Netgear FS728TP (24x 100mbit with [http://en.wikipedia.org/wiki/Power_over_Ethernet POE] + 4x gbit ports), the switch in the workshop is FS728TS (same, but with no POE). As far as possible, both switches should have identical configuration; I.e. if the studio switch fails, the workshop switch should be a drop in replacement.
{| class="wikitable"
|-
! Port
! VLAN
! Comments
|-
| e1-e6 || 3 || [[HackSpace_Instrumentation|Instrumentation projects]]
|-
| e7 || 4 || Able (VDSL Modem)
|-
| e8|| 1,2 || Data/Lore (WAP)
|-
| e9-e10 || 3 || [[HackSpace_Instrumentation|Instrumentation projects]]
|-
| e11 || all || [[Queeg]]
|-
| e12 || 2 ||  Thomson ST2020 SIP phone in blue room
|-
| e13+ || 2 || Main hackspace network
|-
| g1 || all || [[Collective]]
|-
| g2 || 2 || Gigabit switch on Blue room table
|-
| g3 || 1,2,3,5 || Dell PowerConnect 2724
|-
| g4 || all || ''other'' switch (FS728TP or FS728TS)
|}
 
=== Dell PowerConnect 2724 ===
The Dell switch is in the members storage room, just above collective. It is connected to the Netgear FS728TP and to most of the Studio network sockets.
{| class="wikitable"
|-
! Port
! VLAN
! Comments
|-
| e1-e23 || 2 || Main hackspace network
|-
| e24 || 1,2,3,5 || Netgear FS728TP
|}
 
== Server Naming ==
See [[Network/Naming|here]] for our naming convention
 
= Network Devices=
=== Able ===
Able is Kryten's brother the BT Openreach VDSL modem that talks to the outside world. <br/>
 
=== [http://en.wikipedia.org/wiki/Kryten Kryten] ===
 
Kryten is VM on [[Collective]] running [http://www.pfsense.org pfSense], it handles all our DHCP and routing from the external world.<br/>
It is connected to VLAN 4 for access to Able, and 2 for the main hackspace network.
 
The Nottinghack VLAN has access to local resources - e.g. a samba file-share on [[JARVIS]], a future local dropbox server for projects & collaborations, a backup of all Web / Wiki files (to allow a remote restore in the event of moving hosts / outage of services) and anything else we don't want to be web facing.<br/>
 
The VPN (when enabled) would allow remote management of the VLANS, which could come in handy in the event of issues with the client WiFi access point.<br/>
 
Router management username & password for Authorised members only. If there something you need changing ask on the google group or speak to [[User:Lwk|'RepRap' Matt]] or [[User:Daniel|Daniel]] directly<br/>
 
Usual rules apply, as to any tool - if you don't know how to use it / don't do anything :)
 
====OpenVPN====
 
'''Not currently running and not for member access'''<br/>
Kryten runs our openVPN server for access to the hackspace network from the outside world.<br/>
 
For more details see the [[Network/VPN|VPN]] page
 
=== WiFi ===
There are three WiFi networks:
 
==== HSNOTTS ====
WiFi for Hackspace SSID: '''HSNOTTS''' passcode uses WPA2 protocol AES encryption. Members only, passcode on request, changes to the passcode will be emailed to members only.<br/>
 
==== HSNOTTS_GUEST ====
WiFi for guests is setup as '''HSNOTTS_GUEST''' and passcode can be provided and this will (possibly at some point) run on a separate VLAN. <br/>
 
==== [https://spacefed.net/wiki/index.php/Spacenet spacenet] ====
Cross-hackspace wireless network, using WPA2 Enterprise. Login using: <br />
Username: ''&lt;[[HMS]]-username&gt;''@nottinghack.org.uk <br />
Password: ''&lt;[[HMS]]-password&gt;'' <br />
 
For more details, see [[spacenet]].
 
=Servers=
===[[Holly]]===
See [[Holly]]
===[[Collective]]===
See [[Collective]]
===[[Andromeda]]===
See [[Andromeda]]
 
=== [http://en.wikipedia.org/wiki/WOPR Joshua] ===
Joshua loves to play games, Tic Tac Toe, Chess, Global Thermonuclear War... all the family favourites. 
We've co-opted him into running Quake II, Open Arena, Unreal Tournament & Counter Strike 1.5.  <br/>
The aim is to have a games server running games suitable for clients running low powered netbooks & laptops.  This allows us to run LAN parties & have more people join in, without having to bring gaming rigs from home.  Also QII & Open Arena have open source install paths available, with Unreal & Counter Strike available at low cost.<br/>
Joshua is running Windows XP Pro on a 1GHz PIII with 512MB RAM & a RIVA TNT2 graphics card. <br/>
Impressive I know.<br/>
 
There are 2 user accounts -<br/>
"David" - not password protected, but limited access - suitable for web browsing / printing etc.<br/>
"Falken" - admin account - speak to [[User:Tony_S|Tony_S]] if you need the password.<br/>
 
=Genral Use PC=
===[[Quorra]]===
A workstation with dual heads, Quorra is available for all members to use.
 
===[[WOPR]]===
Another general-use PC in the blue room, by the window
 
=Printers=
For more details, see [[Printers]].
 
=== Bender ===
The HP Color Laserjet HP5550 is set up on 10.0.0.95 as Bender.<br/>
The printer feeds A4 paper from tray 2 and A3 paper from tray 3.<br/>
A duplexer is installed enabling double-sided printing.<br/>
Bender is shared on [[JARVIS]], so should be auto-detected by Linux machines.
 
=== Rosey ===
An Epson WF-7610DWF printer/scanner set up on 10.0.0.94. The scanner/printer should be auto-detected by most Linux/Mac machines, and is known to work from [[Quorra]] using Xsane.
 
=== Plotter ===
HP DesignJet 600
Not networked, but connected via serial or parallel interface to [[quorra]]
 
=Websites=
 
=== [http://nottinghack.org.uk Nottinghack.org.uk] ===
 
The main Nottinghack websites are run form [[Andromeda]].
 
This hosts the [http://nottinghack.org.uk Wordpress blog], [http://wiki.nottinghack.org.uk this wiki], [http://planet.nottinghack.org.uk the Nottinghack Planet]
 
The [[Twitterbot]] for @HSNOTTS is also hosted on on this server.
 
===[http://lspace.nottinghack.org.uk lspace.nottinghack.org.uk]===
 
Hosted locally at the space on [[Holly]] <br/>
 
Includes:
* [https://lspace.nottinghack.org.uk/hms/ Hackspace Management System] - see [[HMS]]
* [http://lspace.nottinghack.org.uk/addr_graphs/ Graph] showing connected network device count
 
DNS record looked after by [[User:Lwk|'RepRap' Matt]]
 
===[http://cacti.nottinghack.org.uk/graph_view.php cacti.nottinghack.org.uk]===
 
Also hosted locally on [[Holly]] this provides graphing of various stats and info (mostly temperature graphs) from the hackspace instrumentation
 
===http://hollyvm/===
 
Our intranet, only accessible from the hackspace network
 
= HackSpace Instrumentation =
The Network and [[Holly]] provide the backbone to our [[HackSpace Instrumentation]] projects.
 
=Other Info=
== ADSL Connection Reboot Procedure ==
If for some reason the internet connection is not responding!<br/>
Then Able is located on the Internet shelf on the Members Storage room<br/>
On Able check if the 'DSL' and 'Internet' lights are green<br/>
If not on then reboot Able by cycling power using the power switch on the back,<br/>
If two minutes after doing this the 'DSL' light does not come back on then you need to get in touch with either [[User:Lwk|&#39;RepRap&#39; Matt]] or [[User:Daniel|Daniel]] who can check on Kryten<br/>
If there's still no look, it could well be an outside issue with talktalk.
 
== Extra Equipment ==
See [[Network/Equipment|here]] for a list of our other network gear


[[Category:Infrastructure]]
[[Category:Infrastructure]]

Latest revision as of 13:53, 2 April 2019

This category is for pages relating to the Hackspace network. For general network related pages see Category:Network (other).

Subcategories

This category has the following 3 subcategories, out of 3 total.

Media in category "Network"

The following 5 files are in this category, out of 5 total.