Skip to content

starlink — Starlink failover gateway

The payments-only backup WAN. Worked example: CR-STARLINK-1.

Model RB4011 + Starlink dish
NetBox role starlink
Key custom field bgp_asn=65502 (read by the colo-side eBGP peer)
Ansible playbook starlink.yml (backup, baseline, bgp_instance, starlink)
OOB 172.16.201.24/24 on ether8

Function

  • AS 65502, one eBGP session to each colo RR over routed /31s; NAT egress out the dish.
  • Advertises whatever the route-control / break-glass app puts in the starlink-announce list (tagged 65500:911, accepted by the RRs at local-pref 50) — the payments failover.

Interfaces

Port Role Address
loopback mgmt /32 (advertised via announce list) 10.255.255.3/32
ether1 core-link 10.254.96.13/31 → CR-COLO-01 sfp-sfpplus3 (routed /31, no OSPF)
ether2 core-link 10.254.96.15/31 → CR-COLO-02
ether5 starlink-wan DHCP client → dish (default route + masquerade)

BGP

  • as=65502 router-id=loopback.
  • to-core chain tags 65500:911 and accepts; from-core accepts the 10.0.0.0/8 return path and rejects the rest — never a default from the core.
  • eBGP to both colos with output.network=starlink-announce.
  • Forward chain: established → source → payment-prefixes → drop.

Hands-off lists

Both starlink-announce (app-written; the role only adds its loopback /32, never sweeps) and payment-prefixes (contents never managed) are owned outside Ansible. Advertise-only-when-healthy is enforced with check-gateway routes. Test the failover quarterly.