Move Plan — Old Network → New Core¶
Version: 1.0 — 2026-07-06 Sequences the physical and logical migration from the as-built network (DISCOVERY.md) to the target design (DESIGN.md). Strategy per agreed approach: interconnect old and new racks → move WAN → re-home links backups-first → decommission. IP network first (Stage 1); guest VPLS + PPPoE follow later (Stage 2, CONFIG-GUIDE §9) and appear here only as constraints.
Golden rule for every link move: the new core port adopts the old core-side /30 address. The far end (venue/metro router) needs zero config in the move window — light comes back, its existing static default still points at the same gateway IP, traffic flows. Routing modernisation (eBGP conversion) happens afterwards, remotely, per device.
1. Device fates¶
| Device | As-built | Fate |
|---|---|---|
| CR-LEVEL-01 (CCR1016, ROS6) | WAN NAT + public IPs + main hub | Decommission — WAN → OPNsense; links → CR-COLO-01/02 |
| CR-LEVEL-02 (CCR2004, ROS 6.48) | Second hub (Seel/Charlotte/Boston/L03/L04 + 3 venues) | Re-use as CR-HOLMES-01 — once drained (uplinks D2#1–3, venues D3), wipe → netinstall ROS 7.19 → target config (loopback .22) → replaces the Boston CCR1009 in the D2#4 window. No new CCR2004 purchase for Holmes |
| CR-LEVEL-03 (RB5009, 7.16) | Links Charlotte-01, LEVEL-02, Old Bank roof, Irish House | Re-role → CR-COLOROOF-01 (colo roof) — needs loopback assigned (has none!) |
| CR-LEVEL-04 (CCR2004, 7.16) | Only one uplink (LEVEL-02); WireGuard hub (12 peers), public /30, gre-bolton | Re-role as bdr-2 (WAN business border router 2 — WAN-DESIGN §4; not yet purchased otherwise). Blockers first: WireGuard peers → OPNsense (WIREGUARD.md §4), gre-bolton confirmed dead. Then wipe → ROS 7.19 → bdr-2 (AS 204258, loopback 100.64.0.2); its 2×25G XS ports become the bdr-1↔bdr-2 bond. .233 loopback returns to the pool |
| CR-BOSTON-01 (CCR1009, ROS 6.48) | Holmes hub, dual fibre to LEVEL-01+02 | Replace in place with the re-used LEVEL-02 CCR2004 (→ CR-HOLMES-01); CCR1009 retired to spares |
| CR-SEELSTREET-01 (CCR2004, 7.19.6) | Seel hub, 8 venues | Keep — re-home uplink; add 60 GHz to Holmes later |
| CR-CHARLOTTESTREET-002 (CCR2004, 7.19.4) | New Charlotte hub | Keep — becomes the only Charlotte router |
| CR-CHARLOTTESTREET-01 (RB5009UPr+S+) | Already the Charlotte roof RB5009 — PoE, powers the dishes; carries venue CAT6 backups (ROK/NFL/RBL), colo-roof dish, Irish House 2nd dish, LHGG segment. No link to -002 today — roof island uplinks only via 60 GHz | Keep — it is the target Charlotte roof PE (later rename CR-CHARLOTTEROOF-01, renumber into .50–.79). Build the 01↔02 link by repurposing one venue's CAT6 run — closes the site ring (colo→fibre→-002→roof→60 GHz→colo roof), so a fibre cut is survived at transport level by the whole site. The donor venue becomes single-homed to -002 (acceptable: the ring now covers it for fibre cuts; pick a non-POS-critical venue, and NOT Celtic Corner, which already loses its Celtic-roof path). Link config: OSPF p2p cost 100, L2MTU ≥1600, LDP. Celtic-roof links (ether4/7) die at Celtic removal; LHGG segment to untangle; confirm the Temple Court 60 GHz (design expects it on this roof — not seen in discovery) |
| CR-CELTICROOF-02 (RB5009) | Celtic roof; venue CEL (dual-homed already) | Remove (CEL already has a path via Charlotte-002 sfp-sfpplus4) |
| CR-LORDSTREETROOF-01 | Offline, loopback unreachable | Remove — confirm RTR-LOR-001 (10.151.14.4/30 via LEVEL-01 sfpplus1.4) has/gets another path first |
| CR-MATHEWSTREET-01 (CCR2004, 7.19.3) | Mathew hub via VLAN 601 L2 | Keep — 601-swap (§4) |
| CR-OLDBANKROOF-01 (RB5009, 7.16) | 60 GHz to LEVEL-01 + LEVEL-03; venues OLB, CAS | Keep — re-terminate colo-side 60 GHz on CR-COLOROOF-01; fibre to Fenwick later |
| SERVER-ROUTER (RB4011, 10.255.255.249) | Old server room gateway | Decommission — replaced by new server-room fabric + OPNsense zones (services renumber to 10.128/16 in Phase 7) |
| RTR-BNG-001 (RB4011, ROS6) | A venue, oddly attached via LEVEL-01 sfpplus1.4 | Re-home as normal venue on plain WAN/venue port; not the future BNG |
| Venue routers (RTR-*) | Mostly RB4011, ROS 7.1x–7.19 | Keep — far end untouched during moves; eBGP conversion after; ROS6 stragglers (YNK 6.47, RBL 6.39, FUS/EIN/OLB/CAS/WDS/SOH…) upgraded to ROS7 at conversion |
Known gaps (fill before their move windows): Temple Court and Fenwick St routers never appeared in discovery (they sit behind Mathew St, which we only have from export) — collect them once Mathew St's mgmt list admits us. Passwords unknown: CAS, LOR, MCC, BPL. 60 GHz antenna inventory (LEVEL_, ANT-) unverified.
2. Stage A — Build the new colo (no impact on live network)¶
- Rack + cable per DESIGN §5.1: CR-COLO-01/02 (CCR2004), 2×25G bonded inter-core, OPNsense pair (CARP), OOB CRS326-24G + gateway + console server (serial to everything), server-room CRS fabrics.
- Deploy config via Terraform (TERRAFORM-PLAN §8 step order): baseline + transport + RR modules. Loopbacks from registry (new: CR-COLO-01
.245? — assign from free space; do not reuse .255/.250 until their owners are dead). - New core runs target routing from day one: OSPF area 0 between the pair, iBGP RR templates ready, input filters on,
bgp-networksempty. - Burn-in: 48h idle with monitoring/syslog attached; btest across the bond.
3. Stage B — Interconnect old ↔ new racks¶
- Run 2× fibre LEVEL rack ↔ colo: one to CR-COLO-01, one to CR-COLO-02.
- Each is a hybrid port: routed /30 (new allocations from 10.254.9.x free space) + tagged VLANs for L2 stretch (WAN hand-off VLAN, and anything else that must ride between racks during transition).
- Enable OSPF (cost 10) on both /30s: old LEVEL-01/02 ↔ new CR-COLO-01/02 become one OSPF domain; also add both new CCRs to the old iBGP mesh (two more peers on LEVEL-01/02 only — venues/metros don't change). New core now learns every prefix; old network learns nothing new (new core originates nothing yet).
- Verify: from CR-COLO-01, traceroute to a venue loopback in every hub (via old paths).
Rollback: disable the two OSPF interfaces. Nothing depends on them yet.
4. Stage C — Move the WAN (the 601-swap)¶
Current: upstream fibre lands at Mathew St; WAN + VLAN 601 (metro L2 to LEVEL-01 sfp2.601 ↔ CR-MATHEWSTREET-01 sfp-sfpplus1, 10.254.254.0/30) are delivered over it to LEVEL-01, which does NAT and holds the public IPs (185.109.x on the CCR1016).
Target: your fibre runs the metro natively (jumbo-capable); WAN rides it as a tagged VLAN to the colo OPNsense.
- Prep (remote): inventory everything on LEVEL-01 that touches WAN: NAT rules, public IP bindings, dst-nat forwards, the CR01-LIV0x upstream sessions on
sfpplus1.x, Starlink policy, hotspot walled-garden IPs (185.109.40.8/9 — the portal lives in public space today). Recreate all of it, disabled, on OPNsense. We hold LEVEL-01's raw state indiscovery/raw/— do a fresh/exporttoo. - Parallel WAN path: upstream hand-off VLAN extended: Mathew St → (601-path) → LEVEL rack → (interconnect trunk VLAN) → OPNsense WAN port. OPNsense comes up with a secondary public IP; test outbound + BGP/static with upstream while LEVEL-01 still carries production.
- Cutover window (morning, ~1h): upstream moves the routed subnets/default to OPNsense (BGP announce or gateway swap); OPNsense NAT enabled; LEVEL-01 default route replaced by static toward CR-COLO (which now originates default from OPNsense); venue traffic hairpins old→new→OPNsense. Confirm: venue POS test transaction, hotspot login, public dst-nat services.
- Rollback: upstream re-points to LEVEL-01 VIP; re-enable its NAT. Keep the rollback path warm for a week.
- Physical 601-swap (separate window, after §5 Mathew re-home): when the Mathew St fibre is re-patched as your native link into CR-COLO-01, the WAN VLAN moves onto it and the upstream's L2 601 service is cancelled. MTU on the native fibre → 9092; verify with DF pings before any Stage-2 VPLS work.
- Starlink: RB4011 moves to the colo (eBGP to both CR-COLOs per design §2.4/§4.4) in this stage too — it's currently useless if LEVEL-01 dies.
5. Stage D — Re-home links, backups first¶
Principle: move the backup path to the new core first; prove it; then move the primary while the proven backup carries traffic. New-core port adopts the old core-side /30 address in every case. One link per window; verify (far-end ping, OSPF/BGP state, POS traceroute) before the next.
D1 — 60 GHz backups → CR-COLOROOF-01 (ex-LEVEL-03)¶
| # | Link (as-built) | Move | New termination |
|---|---|---|---|
| 1 | Old Bank roof ether3 ↔ LEVEL-01 sfp11 (10.254.5.28/30) |
Colo-side antenna feed re-patches from LEVEL-01 to CR-COLOROOF-01 | CR-COLOROOF-01 (keeps 10.254.5.29) |
| 2 | Old Bank roof ether1 ↔ LEVEL-03 ether6 (10.254.8.24/30) |
Already on the RB5009 being re-roled — renumber identity/loopback only | stays |
| 3 | Charlotte roof chain (Charlotte-01 ether4/ether7 ↔ Celtic roof) |
Do not move — dies with Celtic roof removal (§6) after Charlotte venues re-home | — |
| 4 | Irish House 60 GHz (10.254.8.28/30 on LEVEL-03) | Stays on CR-COLOROOF-01 | stays |
Also in D1: give CR-COLOROOF-01 and CR-LEVEL-04 loopbacks (neither has one), upgrade CR-COLOROOF-01 to 7.19.x, wire it to both CR-COLO CCRs per design.
D2 — Metro hub fibres (one hub per window; hub's 60 GHz backup must be green first)¶
| # | Hub | As-built port | New port | /30 carried over | Notes |
|---|---|---|---|---|---|
| 1 | Seel St | LEVEL-02 sfp-sfpplus8 |
CR-COLO-02 | 10.254.70.0/30 | First — cleanest hub, ROS7 already. Backup: a Boston↔Seel 60 GHz dish pair already exists but is offline (creds/WIRELESS-60G) — revive it before this move and Seel is no longer single-homed. Investigate why it's dormant first. |
| 2 | Charlotte | LEVEL-02 sfp-sfpplus9 |
CR-COLO-01 | 10.254.70.4/30 | Backup via Celtic-roof chain still alive at this point |
| 3 | Holmes/Boston link A | LEVEL-02 sfp-sfpplus2 |
CR-COLO-02 | 10.254.8.12/30 | Move A while B carries |
| 4 | Holmes/Boston link B + router swap | LEVEL-01 sfp5 |
CR-COLO-01 | 10.254.8.4/30 | Same window: CCR1009 → re-used LEVEL-02 CCR2004 (CR-HOLMES-01, ROS 7.19, target config, pre-staged); venues MCC/BPL(/BLR) re-patch like-for-like, /30s preserved. Dependency: LEVEL-02 must be fully drained first (D2#1–3 + its D3 venues KEL/WDS/SOH) — so this is the LAST D2 window |
| 5 | Mathew St (fibre swap) | LEVEL-01 sfp2.601 |
CR-COLO-01 (native, jumbo) | 10.254.254.0/30 | The 601-swap physical step (§4.5). Backup for its venues = Temple Court 60 GHz — verify Temple Court state first (discovery gap) |
| 6 | LEVEL-04 | LEVEL-02 sfp-sfpplus7 |
(link decommissions) | 10.254.9.4/30 | Resolved: LEVEL-04 → bdr-2 (WAN business). No re-home — after its WireGuard peers move to OPNsense, the box is pulled, wiped and rebuilt as bdr-2; this /30 dies with it |
D3 — Colo-fed venue fibres (LEVEL-01/02 SFP ports → CR-COLO-01/02)¶
Batch 2–3 per morning window; far end untouched; new port adopts the old address. Port assignments per DESIGN §5.1 budget (new venues default to CR-COLO-02).
| Venue | As-built | /30 | Venue router (state) |
|---|---|---|---|
| Fusion | LEVEL-01 sfp1 |
10.254.4.4/30 | RTR-FUS CCR1009 ROS6 — needs ROS7/refresh at eBGP conversion |
| Yankees (YNK) | LEVEL-01 sfp3 |
10.254.4.0/30 | RTR-YNK 6.47 |
| Einstein | LEVEL-01 sfp4 |
10.254.4.12/30 | RTR-EIN CCR1009 ROS6 |
| LEVEL venue | LEVEL-01 sfp9 |
10.254.0.20/30 | RTR-LVL 7.11 |
| Kells | LEVEL-02 sfp-sfpplus3 |
10.254.5.64/30 | RTR-KEL 7.15 |
| Wood Street (WDS) | LEVEL-02 sfp-sfpplus4 |
10.254.7.0/30 | RTR-WDS ROS6 |
| SOHO | LEVEL-02 sfp-sfpplus5 |
10.254.4.8/30 | RTR-SOH 6.44 |
| Lord St venue | LEVEL-01 sfpplus1.4 (L2 via upstream!) |
10.151.14.4/30 | RTR-LOR — rides an upstream L2 leg; needs its own path decided before Lord St roof removal |
| RTR-BNG-001 (venue) | LEVEL-01 sfpplus1.4 |
10.254.6.8/30 | re-home to plain venue port / WAN per its needs |
| Cheers (RTR-CHR) — currently a flat 10.222.2.0/24 on the Vive trunk | LEVEL-01 sfpplus1.6 |
n/a (flat L2) | untangle: give it a proper /30 + port at re-home |
| SERVER-ROUTER | LEVEL-01 sfp8 |
10.199.199.0/30 | stays until Phase 7 server migration, then decom |
D4 — Routing modernisation (remote, after each site's cable move)¶
Per venue, in any order, no site visit: ROS7 if needed → eBGP CE conversion (CONFIG-GUIDE §2.3b: blackhole anchor, sessions to metro PE/colo, default-only in-filter, BFD) → remove its static routes from old and new cores → Terraform import + venue module (TERRAFORM-PLAN). When the last venue /16 static is gone from the new core, enable RR default-originate and drop the temporary mesh sessions to LEVEL-01/02.
6. Stage E — Decommission (only when its column is empty)¶
Order: Celtic roof (after Charlotte venues confirmed on -002 paths; CEL loses one of two uplinks — verify its Charlotte-002 path first) → Lord St roof (already offline; confirm RTR-LOR re-homed) → Boston CCR1009 (leaves in D2#4) → LEVEL-02 (drained, re-deployed as CR-HOLMES-01) → LEVEL-04 (WireGuard migrated, re-deployed as bdr-2) → LEVEL-01 (last: it holds the public IPs until §4 is proven stable) → SERVER-ROUTER (after Phase 7 renumbering) → cancel upstream 601 L2 service. (CR-CHARLOTTESTREET-01 is NOT decommissioned — it stays as the Charlotte roof PE.)
For each: final /export archived, licence/hardware recorded, loopback returned to registry, monitoring/Oxidized/NetBox updated, old iBGP mesh entries removed fleet-wide (Terraform makes this a one-file change once the registry drives peers).
7. Window discipline & verification¶
- Windows: venue-impacting moves Mon–Thu mornings; WAN cutover Sunday early AM; never Fri/Sat (trade nights).
- Before any move: fresh
/exportof both ends; backup path proven by disabling primary for 60s (where one exists); rollback = re-patch, old port config left disabled-not-deleted for 1 week. - After every move: far-end loopback ping; OSPF neighbour count restored;
routes_summarycount matches pre-move; POS venue: test transaction; hotspot venue: portal login. - Stage gates: C complete before D2 (WAN must not depend on LEVEL-01 while its links drain); D2 hub complete before that hub's D3 venues; D4 fleet-complete + 601 native MTU verified = Stage 1 done → Stage 2 (VPLS/PPPoE) may begin.
8. Open decisions / actions for Lewis¶
- ~~CR-LEVEL-04's role~~ Resolved: LEVEL-04 → bdr-2; LEVEL-02 → CR-HOLMES-01. Remaining action: schedule the WireGuard migration (blocks bdr-2) and drain LEVEL-02 before the Holmes swap.
- Seel St ordering — the Seel↔Holmes backup dish already exists but is offline; revive it (find why it's dormant) before moving Seel, rather than "build new" or "accept risk". Cheapest of the three options.
- Confirm Temple Court / Fenwick reachability + mgmt access (blocks D2#5 verification).
- Passwords for CAS/LOR/MCC/BPL; mgmt-list fix for the nine firewalled venue routers (can be done at their D4 conversion).
- New loopback assignments: CR-COLO-01/02, CR-COLOROOF-01, CR-HOLMES-01 — allocate in registry.
- Rotate the legacy credential everywhere it survives (it's burned).