IP Addressing & VLANs¶
All corporate IPv4 lives inside 10.0.0.0/8; guest WiFi uses 172.16.0.0/12.
NetBox is the source of truth — the tables below are the plan
that the registry encodes.
Top-level allocation¶
| Block | Purpose |
|---|---|
10.1.0.0/16 – 10.127.0.0/16 |
One /16 per venue (10.V.0.0/16). Existing venue numbers kept (10.10–10.13, 10.23, 10.25, 10.32, 10.44, 10.90, …). 10.1 is a venue (The Level). |
10.128.0.0/16 |
Colo / server room (new build; legacy 10.1.x services migrate here) |
10.201.201.0/24 |
OOB management / management VPN |
10.254.0.0/16 |
Infra point-to-point: 10.254.Y.0/24 per hub for its /30s; 10.254.254.0/24 for core inter-hub links |
10.255.255.0/24 |
Router loopbacks, one /32 each |
172.16.0.0/12 |
Guest WiFi only — served by the guest firewall; venue V gets the Vth /20 (~4,094 leases) |
Per-venue VLAN standard¶
Every venue 10.V.0.0/16 follows the same VLAN layout:
| VLAN | Name | Subnet | Lease | Notes |
|---|---|---|---|---|
| 10 | Office / Corporate | 10.V.0.0/24 |
1w | AD-joined machines |
| 30 | POS | 10.V.1.0/24 |
1w | PXE options 66/67 for till imaging |
| 40 | Staff WiFi (untrusted) | 10.V.8.0/22 |
10m | Internet-only |
| 20 | Guest WiFi | (no local L3) | — | Bridged into the guest VPLS; guest FW serves the /20 from 172.16/12 |
| 99 | Network mgmt (UniFi, switches, APs) | 10.V.248.0/24 |
1w | Tagged — stop using untagged native |
| — | Loopback | 10.V.255.255/32 |
— | Router ID + mgmt target |
Venue uplinks take a /30 (or /31) from the hub's 10.254.Y.0/24 range;
dual-homed venues get a second from the backup hub.
Loopback registry¶
One /32 loopback per transport router = its router-id. Venue routers do not
take a 10.255.255.x loopback — they use 10.V.255.255 inside their own /16.
New-device bands:
| Band | Use | Examples |
|---|---|---|
.1–.19 |
Colo core | .1 CR-COLO-01, .2 CR-COLO-02, .3 CR-COLOROOF-01 |
.20–.49 |
Metro hub CCRs | .20 CR-TEMPLECT-01, .21 CR-FENWICK-01, .22 CR-HOLMES-01 |
.50–.79 |
Roof / backup RB5009s | .50 CR-TEMPLECTROOF-01 |
.80–.100 |
Service appliances / spare | — |
Cleanup items
CR-MATHEWSTREET-01currently has two loopbacks (.246and.222) — collapse to one.CR-COLOROOF-01(ex-LEVEL-03) andCR-LEVEL-04have no loopback yet — assign.- RR loopbacks appear as
.255/.254in the design and.1/.2in the worked config example — the automation uses.1/.2forCR-COLO-01/02.
Autonomous system numbers¶
| ASN | Who |
|---|---|
65500 |
Core iBGP (route reflectors + all transport clients) |
64512 + venue_id |
Venue CE eBGP (e.g. venue 23 → 64535, The Level venue 1 → 64513) |
65510 |
OPNsense edge pair |
65502 |
Starlink backup gateway |
204258 |
Retail ISP business (separate — see WAN) |
MTU policy¶
Three distinct MTUs, all treated as design constants (the NetBox interface-MTU field is ignored):
| Where | L2MTU | MPLS MTU | IP MTU |
|---|---|---|---|
| Fibre transport links (colo-rr, metro-pe) | 9000 | 1600 | 1500 |
| eBGP peer / venue hand-off / mgmt | default | — | 1500 |
| Venue CE / Starlink | default | — | 1500 |
| CRS server-room fabric | 9092 | — | 9092 |
| 60 GHz radios (unmanaged) | ≥ 1600 (verify per radio) | — | — |
1600 is the MPLS floor, set uniformly fleet-wide so any reroute over a 60 GHz
hop (which caps around 1600 L2) stays reroute-safe. Storage VLANs run jumbo 9000
end-to-end but never traverse MPLS. Order of operations on a link: raise L2MTU
both ends → set mpls-mtu=1600 → build VPLS. Verify with
/ping <loopback> size=1580 do-not-fragment.
(The design doc quotes a 1596 minimum; the automation standardises on 1600 — treat 1600 as authoritative.)