venue-ce — Venue CE router¶
The in-venue L3 gateway. Worked example: rtr-lvl-1 (The Level, venue_id=1).
| Model | RB5009UG+S+IN (1G venue) or CCR2004-16G-2S+ (10G colo-fed venue) |
| NetBox role | venue-ce, site slug = venue trigram (lvl) |
| Key custom field | venue_id=1 — immutable key → /16, AS, VPLS site-id, DHCP |
| Ansible playbook | venue-ce.yml (backup, baseline, bgp_instance, venue_ce) |
Function¶
- L3 gateway + DHCP for the venue VLANs.
- eBGP CE in private AS
64512 + venue_id= 64513. - Guest VLAN 20 bridged transparently to the uplink (no local L3 — the guest FW serves it over VPLS).
- No OSPF / LDP / VPLS.
Interfaces¶
| Port | Role | Address |
|---|---|---|
loopback |
router-id (inside its own /16) | 10.1.255.255/32 |
sfp-sfpplus1 |
uplink (uplink_primary=true) |
10.254.97.1/31 → PE venue-handoff, eBGP + tagged guest VLAN 20 |
ether1 |
lan-trunk | 10.1.248.1/24 (VLAN 99 mgmt gateway) |
ether2… |
access / lan-trunk | APs / POS / office |
BGP¶
as=64513 router-id=10.1.255.255.- eBGP uplink
input.filter=default-only(accepts only0.0.0.0/0), blackhole anchor10.1.0.0/16+bgp-networks(only statics allowed). A backup uplink is de-preferred withlocal-pref 50. - Per-uplink BFD (2026-07). Each uplink's NetBox
bfd_enabledcustom field (default on) decides BFD — it is no longer a flat fleetuse-bfd=yes. A/routing bfd configurationis built only for the BFD-enabled uplink /31s, at 200 ms × 3 (sub-second detection on optics/PE failure), and BFD is switched on per session.- Fibre primary — BFD on.
- 60 GHz dish backup — BFD off. Its Ethernet port keeps carrier UP through
RF fades so link-down can't see the outage, and aggressive BFD would flap on
brief fades. Instead the BGP session's timers are tightened to hold 9s /
keepalive 3s, so a real outage is still caught in seconds. Set the matching
bfd_enabled=falseon the PE's venue-handoff port for the dish path. venue_use_bfd: falseis a master kill-switch that disables BFD fleet-wide.
VLAN / DHCP template¶
Driven by venue_id = V (here V=1):
| VLAN | Name | Subnet | DHCP range |
|---|---|---|---|
| 10 | office | 10.V.0.0/24 |
.0.10 – .0.254 |
| 30 | pos | 10.V.1.0/24 |
.1.10 – .1.254 |
| 40 | staff | 10.V.8.0/22 |
.8.10 – .11.254 |
| 99 | mgmt | 10.V.248.0/24 |
.248.10 – .248.254 |
| 20 | guest | (bridged to uplink, no local L3) | — |
The UniFi controller (from the site's unifi_controller field) is pushed as DHCP
option 43 and a unifi firewall list. /ip dhcp-server lease is hands-off —
static reservations are hand-managed on the device and excluded from drift checks.
Firewall zones¶
The forward filter is a zone jump-chain model. Each venue L3 zone is a
NetBox-authoritative interface tagged ros_role=venue-<zone> — either a VLAN
child (parent = the LAN trunk → a /interface vlan is built) or a bare port
(addressed directly). The forward chain jumps per VLAN/port to a per-zone chain;
the jump target, DNS, lease and UniFi option for each zone live in
venue_zone_policy (group_vars), not per venue.
Forward chain order: established/related accept, invalid drop, trusted-inbound →
LAN, per-zone jumps, default drop.
| Zone (VLAN) | Chain | Allowed out |
|---|---|---|
| office (10) | trusted |
internet (wan) + UniFi controller + AD |
| pos (30) | pos |
internet (wan) + AD — destination whitelist removed 2026-07 |
| staff (40) | wan |
internet only (blocks 10/8) |
| mgmt (99) | mgmt |
UniFi controller + DNS + NTP to AD — no internet |
Tight mgmt chain (2026-07). VLAN 99 previously jumped to trusted (full
internet); it now has its own locked-down chain: (i) any port to the UniFi
controller IP (the unifi list — one trusted host, covers inform/STUN/discovery,
controller-cached firmware pulls, speed test and future features), (ii) DNS
udp/tcp 53 → ad-servers, (iii) NTP udp 123 → ad-servers (AD DCs are the time
source — APs need correct time or TLS/adoption fails), then return → default-drop.
No internet — UniFi firmware is served from the controller's cache (a
device→controller flow, allowed), so mgmt needs no direct path out. DHCP and
router management (Winbox/SSH) from VLAN 99 ride the INPUT chain (baseline), so the
tight forward chain does not lock the box out.