Skip to content

venue-ce — Venue CE router

The in-venue L3 gateway. Worked example: rtr-lvl-1 (The Level, venue_id=1).

Model RB5009UG+S+IN (1G venue) or CCR2004-16G-2S+ (10G colo-fed venue)
NetBox role venue-ce, site slug = venue trigram (lvl)
Key custom field venue_id=1 — immutable key → /16, AS, VPLS site-id, DHCP
Ansible playbook venue-ce.yml (backup, baseline, bgp_instance, venue_ce)

Function

  • L3 gateway + DHCP for the venue VLANs.
  • eBGP CE in private AS 64512 + venue_id = 64513.
  • Guest VLAN 20 bridged transparently to the uplink (no local L3 — the guest FW serves it over VPLS).
  • No OSPF / LDP / VPLS.

Interfaces

Port Role Address
loopback router-id (inside its own /16) 10.1.255.255/32
sfp-sfpplus1 uplink (uplink_primary=true) 10.254.97.1/31 → PE venue-handoff, eBGP + tagged guest VLAN 20
ether1 lan-trunk 10.1.248.1/24 (VLAN 99 mgmt gateway)
ether2… access / lan-trunk APs / POS / office

BGP

  • as=64513 router-id=10.1.255.255.
  • eBGP uplink input.filter=default-only (accepts only 0.0.0.0/0), blackhole anchor 10.1.0.0/16 + bgp-networks (only statics allowed). A backup uplink is de-preferred with local-pref 50.
  • Per-uplink BFD (2026-07). Each uplink's NetBox bfd_enabled custom field (default on) decides BFD — it is no longer a flat fleet use-bfd=yes. A /routing bfd configuration is built only for the BFD-enabled uplink /31s, at 200 ms × 3 (sub-second detection on optics/PE failure), and BFD is switched on per session.
    • Fibre primary — BFD on.
    • 60 GHz dish backup — BFD off. Its Ethernet port keeps carrier UP through RF fades so link-down can't see the outage, and aggressive BFD would flap on brief fades. Instead the BGP session's timers are tightened to hold 9s / keepalive 3s, so a real outage is still caught in seconds. Set the matching bfd_enabled=false on the PE's venue-handoff port for the dish path.
    • venue_use_bfd: false is a master kill-switch that disables BFD fleet-wide.

VLAN / DHCP template

Driven by venue_id = V (here V=1):

VLAN Name Subnet DHCP range
10 office 10.V.0.0/24 .0.10 – .0.254
30 pos 10.V.1.0/24 .1.10 – .1.254
40 staff 10.V.8.0/22 .8.10 – .11.254
99 mgmt 10.V.248.0/24 .248.10 – .248.254
20 guest (bridged to uplink, no local L3) —

The UniFi controller (from the site's unifi_controller field) is pushed as DHCP option 43 and a unifi firewall list. /ip dhcp-server lease is hands-off — static reservations are hand-managed on the device and excluded from drift checks.

Firewall zones

The forward filter is a zone jump-chain model. Each venue L3 zone is a NetBox-authoritative interface tagged ros_role=venue-<zone> — either a VLAN child (parent = the LAN trunk → a /interface vlan is built) or a bare port (addressed directly). The forward chain jumps per VLAN/port to a per-zone chain; the jump target, DNS, lease and UniFi option for each zone live in venue_zone_policy (group_vars), not per venue.

Forward chain order: established/related accept, invalid drop, trusted-inbound → LAN, per-zone jumps, default drop.

Zone (VLAN) Chain Allowed out
office (10) trusted internet (wan) + UniFi controller + AD
pos (30) pos internet (wan) + AD — destination whitelist removed 2026-07
staff (40) wan internet only (blocks 10/8)
mgmt (99) mgmt UniFi controller + DNS + NTP to AD — no internet

Tight mgmt chain (2026-07). VLAN 99 previously jumped to trusted (full internet); it now has its own locked-down chain: (i) any port to the UniFi controller IP (the unifi list — one trusted host, covers inform/STUN/discovery, controller-cached firmware pulls, speed test and future features), (ii) DNS udp/tcp 53 → ad-servers, (iii) NTP udp 123 → ad-servers (AD DCs are the time source — APs need correct time or TLS/adoption fails), then return → default-drop. No internet — UniFi firmware is served from the controller's cache (a device→controller flow, allowed), so mgmt needs no direct path out. DHCP and router management (Winbox/SSH) from VLAN 99 ride the INPUT chain (baseline), so the tight forward chain does not lock the box out.