From Nottinghack Wiki
Revision as of 20:04, 23 October 2018 by Lwk (talk | contribs) (Dell PowerConnect 2724)
Jump to navigation Jump to search

The hackspace network and servers are look after by the Network and Servers group

Network Layout

This page will show the network topology & proposals for network expansion / modification.

Hackspace Network

Note: This diagram is very out of date and needs updating

External IP address

External domain address (DNS record looked after by 'RepRap' Matt)

Static & Reserved IP's

There are a few VLANs:

VLAN Network Description
1 Default (management network)
2 Main Hackspace network
3 Instrumentation projects
4 - Able / ADSL Modem (PPPoE)
5 Instrumentation test (Rommie)
6 Unimatrix<->Locutus direct network
7 Queen<->Unimatrix direct network
8 Queen<->Locutus direct network

The following ranges are reserved for there given purpose:

Start End Purpose kryten The Main Router Static things openVPN DHCP pool Static Printers DHCP Range Broadcast Static HackSpace Instrumentation


These are all statically assigned.

VLAN IP DNS Name Notes
1 HollyVM Our primary server hosing hms and instrumentation things
1 ws-switch Workshop switch
1 Lore Workshop Wifi AP
1 st-switch Studio/BlueRoom switch
1 Data Studio/BlueRoom Wifi AP
1 Gibson Wifi RADIUS Server
1 studio-gbit Dell PowerConnect 2724 (24x gbit)
1 Queeg Hollys backup
1 Unimatrix
1 Locutus
1 Queen
1 Holly (on Unimatrix)
1 1of3 (APC UPS) Upstairs members storage
1 1of9 (HP 2650-48)
1 2of3 (APC UPS) Team storgare
1 2of9 (HP 2650-48)
1 Dorian Raspberry Pi UniFi controller
1 3of3 (APC UPS) Downstairs members storage
1 3of9 (HP 2650-48)
1 4of9 (HP 2650-48)


These are assigned via DHCP/MAC using Kryten or set statically on the device

VLAN IP DNS Name Notes
2 Kryten pfSense router on Collective
2 HollyVM Our primary server hosing hms and instrumentation things (Squeeze under KVM)
2 JARVIS Sandbox Debian VM open for all members
2 Rommie HMS Development VM
2 Workshop Workshop Wifi AP (channel 11)
2 Zyxel Additional Wifi AP (channel 1)
2 Collective ESXi Management Server
2 Samaritan Monitoring server
2 Queeg Hollys backup
2 Holly Our primary server hosing hms and instrumentation things (Jessie under KVM)
2 Gibson Wifi RADIUS Server
2 Unimatrix
2 Locutus
2 Queen
2 yoocnc YooCNC desktop
2 Quorra Quorra
2 Kiosk Kiosk PC (under 50" screen in blueroom). WIP.
2 Bishop Laptop for 3D printer
2 BarBot Pi in Project:BarBot
2 pbx Asterisk on bare metal
2 payphone RaspberryPi in the Payphone
2 Ziggy Git work shop vm
2 Dorian RaspberryPi based Unifi controller
2 studiocam Pan/Tilt Studio webcam
2 marvin A4 Laser Printer
2 Clank A3 Laser Printer
2 B4 A4 InkJet with Scanner
2 Vinyl Vinyl
2 Rosey Epson WF-7610DWF
2 Bender HP5550
2 Zebra_2844 Label printer
2 Plotter Plotter (HP DesignJet 600)

(coming soon...)


These are all statically assigned.

VLAN IP DNS Name Notes
3 Holly Our primary server hosing hms and instrumentation things
3 HollyVM OLD server.
3 gatekeeper Access Control Arduino for upstairs inner (studio) door
3 MatrixMQTT BIG LED Matrix Display Arduino
3 Vending Machine RFID cashless payment nanode in snack vending machine
3 Mini-matrix Blue room mini-matrix display nanode
3 Wall of Faces Wall of members faces
3 Studio Controller Lighting Controller (Studio)
3 Workshop Controller Lighting Controller (Workshop)
3 Studio Switch Panel Lighting Switch's (Studio)
3 Workshop Switch Panel Lighting Switch's (Workshop)
3 WorkshopMQTT Workshop Bell and Temp Node
3 CoinAcceptor Coin acceptor for Snackspace / Vending Machine payments
3 NoteAcceptor Note acceptor for Snackspace / Vending Machine payments
3 laser Laser RFID
3 3D Printer 3D Printer RFID
3 Laser Display LED display near laser cutter
3 Queeg Hollys backup
3 Embroidery Machine Embroidery machine RIFD
3 CNCRoomController Lighting Controller (CNCRoomController)
3 Gatekeeper-4 CNC Corridor Access (1C:E3:0D:02:6A:4D)
3 Gatekeeper-6 Communal door (L) / blue room (1C:E3:0D:02:6A:4E)
3 Can machine Can vending machine in studio (DE:ED:BA:FE:FE:11)
3 Gatekeeper-3 Workshop (upstairs backdoor) (1C:E3:0D:02:6A:4F)
3 G5 Doorbell Doorbell/temperature node (DE:ED:BA:FE:62:12)
3 (129-254) Queen Docker instrumentation network pool

(coming soon...)


Direct network between Unimatrix and Locutus used for HDD replication
These are all statically assigned.

VLAN IP DNS Name Notes
6 Unimatrix
6 Locutus


Direct network between Unimatrix and Queen used for VM Backups
These are all statically assigned.

VLAN IP DNS Name Notes
7 Unimatrix
7 Queen


Direct network between Locutus and Queen used for VM Backups
These are all statically assigned.

VLAN IP DNS Name Notes
8 Locutus
8 Queen

External Port Routing

Service External Port Internal Port Internal IP Notes
HTTP 80 80 Webserver on Holly
HTTPS 443 443 HMS SSL Webserver on Holly
SSH 1922 22 SSH on Unimatrix
SSH 3000 22 SSH on JARVIS
SSH 3045 22 SSH on Rommie
RTP 10000-20000 10000-20000 Asterisk/RTP on PBX
SIP 5060 5060 Asterisk/SIP on PBX

Switch port assignments

Netgear Prosafe FS728x

The switch in the members storage room is a Netgear FS728TP (24x 100mbit with POE + 4x gbit ports), the switch in the workshop is FS728TS (same, but with no POE). As far as possible, both switches should have identical configuration; I.e. if the studio switch fails, the workshop switch should be a drop in replacement.

Port VLAN Comments
e1-e6 3 Instrumentation projects
e7 4 Able (VDSL Modem)
e8 1,2,3 Data/Lore (WAP)
e9-e10 3 Instrumentation projects
e11 all Queeg
e12 2 Thomson ST2020 SIP phone in blue room
e13-e14 2 Main hackspace network
e15 N Do Not Use
e16-19 3 Instrumentation projects
e20+ 2 Main hackspace network
g1 all Collective
g2 2 Gigabit switch on Blue room table
g3 1,2,3,5 Dell PowerConnect 2724
g4 all other switch (FS728TP or FS728TS)

Dell PowerConnect 2724

The Dell switch is in the members storage room, just above collective. It is connected to the Netgear FS728TP and to most of the Studio network sockets.

Port VLAN Comments
e1-e23 2 Main hackspace network
e5 U1,2,3,5 Locutus/Queen?
e9 U1,2,3,5 Locutus/Queen?
e24 1,2,3,5 Netgear FS728TP

1of9 ProCurve 2650-48 (J4899B)

2of9 ProCurve 2650-48 (J4899B)

Located in the CNC room cabinet, this switch servers the Blue room, CNC room and Team storage

3of9 ProCurve 2650-48 (J4899B)

4of9 ProCurve 2650-48 (J4899C)

Port VLAN Comments
e1-e32 2u Main hackspace network
e33-e40 3u Instrumentation
e41-e42 1u, 2t Wifi
e43 3u Instrumentation
e44 4u Modem
e45 5u Instrumentation test
e46 6t Unimatrix<->Locutus direct network
e47 7t Queen<->Unimatrix direct network
e48 8t Queen<->Locutus direct network
g49 1u, 2t, 3t, 4t , 5t, 6t, 7t, 8t Uplink trunk
g50 1u, 2t, 3t, 4t , 5t, 6t, 7t, 8t Server trunk

Patch Panels

Name Location Area served
Network/Patch_Panel_A Upstairs Member Storage Upstairs: Comfy Area, Studio, Blue Room, Kitchen, Members Storage
Network/Patch_Panel_B CNC Room Cabinet Down stairs: Blue Room, CNC room, CNC corridor, Team Storage

Patch cable colour coding

Colour Vlan Tagging Notes
Purple 2u Main hackspace network
Green 3u Instrumentation
Blue 1u, 2t Wifi
Pink 4u Modem
Yellow 5u Instrumentation test
White 1u, 2t, 3t, 4t , 5t, 6t, 7t, 8t Trunk

Server Naming

See here for our naming convention

UPS Power

The important infrastructure runs off 3 UPS's, each one is an APC Dell Smart UPS 5000 DL5000RMI5U.

Name Management IP Location Equipment served Notes
One of Three
Upstairs Member Storage Unimatrix, Queen (temporary), Locutus (temporary), Queeg,
1of9, studio-gbit, st-switch, Data, Able,
HS2.0 Gatekeeper, MatrixMQTT, Mini-matrix, CoinAcceptor,
In service since ~03/13
Batteries replaced 4/12/14
Cacti Graphs
Two of Three
00:C0 B7:66:65:99
Team Storage Queen (Once relocated),
2of9, 3of9 (temporary), 4of9 (temporary), 1of9 (temporary),
CNCRoom lighting automation, CNC corridor Gatekeeper, Blue room Gatekeeper, Team storage Gatekeeper
In service since 24/11/17
New Batteries fitted 24/11/17
Cacti Graphs
Three of Three
Downstairs Members Storage Locutus (Once relocated),
3of9, 4of9,
Corridor lighting automation, Metalworking lighting automation, Corridor Gatekeeper, Front door Gatekeeper, Members storage Gatekeeper
Not yet in service
New Batteries fitted xx/xx/xx
ip until I can get the login details

Network Devices


Able is Kryten's brother the BT Openreach VDSL modem that talks to the outside world.


Kryten is VM on Collective running pfSense, it handles all our DHCP and routing from the external world.
It is connected to VLAN 4 for access to Able, and 2 for the main hackspace network.

The Nottinghack VLAN has access to local resources - e.g. a samba file-share on JARVIS, a future local dropbox server for projects & collaborations, a backup of all Web / Wiki files (to allow a remote restore in the event of moving hosts / outage of services) and anything else we don't want to be web facing.

The VPN (when enabled) would allow remote management of the VLANS, which could come in handy in the event of issues with the client WiFi access point.

Router management username & password for Authorised members only. If there something you need changing ask on the google group or speak to 'RepRap' Matt or Daniel directly

Usual rules apply, as to any tool - if you don't know how to use it / don't do anything :)


Not currently running and not for member access
Kryten runs our openVPN server for access to the hackspace network from the outside world.

For more details see the VPN page


There are three WiFi networks:


WiFi for Hackspace SSID: HSNOTTS passcode uses WPA2 protocol AES encryption. Members only, passcode on request, changes to the passcode will be emailed to members only.


WiFi for guests is setup as HSNOTTS_GUEST and passcode can be provided and this will (possibly at some point) run on a separate VLAN.


Cross-hackspace wireless network, using WPA2 Enterprise. Login using:
Username: <HMS-username>
Password: <HMS-password>

For more details, see spacenet.



See Holly


See Collective


See Andromeda


Joshua loves to play games, Tic Tac Toe, Chess, Global Thermonuclear War... all the family favourites. We've co-opted him into running Quake II, Open Arena, Unreal Tournament & Counter Strike 1.5.
The aim is to have a games server running games suitable for clients running low powered netbooks & laptops. This allows us to run LAN parties & have more people join in, without having to bring gaming rigs from home. Also QII & Open Arena have open source install paths available, with Unreal & Counter Strike available at low cost.
Joshua is running Windows XP Pro on a 1GHz PIII with 512MB RAM & a RIVA TNT2 graphics card.
Impressive I know.

There are 2 user accounts -
"David" - not password protected, but limited access - suitable for web browsing / printing etc.
"Falken" - admin account - speak to Tony_S if you need the password.

Genral Use PC


A workstation with dual heads, Quorra is available for all members to use.


General-use windows PC in the blue room,aimed at CAD work and anything else requiring a reasonably beefy GPU.


Another general-use PC in the blue room, by the window


For more details, see Printers.


The HP Color Laserjet HP5550 is set up on as Bender.
The printer feeds A4 paper from tray 2 and A3 paper from tray 3.
A duplexer is installed enabling double-sided printing.
Bender is shared on JARVIS, so should be auto-detected by Linux machines.


An Epson WF-7610DWF printer/scanner set up on The scanner/printer should be auto-detected by most Linux/Mac machines, and is known to work from Quorra using Xsane.


HP DesignJet 600 Not networked, but connected via serial or parallel interface to quorra


DNS record looked after by 'RepRap' Matt

The main Nottinghack websites are run form Andromeda.

This hosts the Wordpress blog, this wiki, the Nottinghack Planet

The Twitterbot for @HSNOTTS is also hosted on on this server.

Hosted locally at the space on Holly


  • Graph showing connected network device count

Hackspace Management System

The Hackspace Management System
Hosted locally at the space on Holly
see HMS

Also hosted locally on Holly this provides graphing of various stats and info (mostly temperature graphs) from the hackspace instrumentation


Our intranet, only accessible from the hackspace network

HackSpace Instrumentation

The Network and Holly provide the backbone to our HackSpace Instrumentation projects.

Other Info

ADSL Connection Reboot Procedure

If for some reason the internet connection is not responding!
Then Able is located on the Internet shelf on the Members Storage room
On Able check if the 'DSL' and 'Internet' lights are green
If not on then reboot Able by cycling power using the power switch on the back,
If two minutes after doing this the 'DSL' light does not come back on then you need to get in touch with either 'RepRap' Matt or Daniel who can check on Kryten
If there's still no look, it could well be an outside issue with talktalk.

Extra Equipment

See here for a list of our other network gear


This category has the following 3 subcategories, out of 3 total.

Media in category "Network"

The following 5 files are in this category, out of 5 total.