Skip to content

Legacy WAN (AS 204258) — As-Built Survey

Date: 2026-07-06. Method: SSH sweep of CR01-LIV01…06 (discovery/collect.sh, raw output in discovery/raw/<router>/), plus AS01-LIV01 EdgeSwitch config and MAC table (info/er, info/er-mac-table.txt). All six routers now on the standard admin credential (LIV05 was reset during the survey).

This network is being replaced by WAN-DESIGN.md — everything here rides metro VPLS circuits in the target design. This document exists so we know what we have, where customers physically plug in, and what has to move. §10 is the migration mapping.


1. Device Inventory

Routers (surveyed)

Device Model ROS Loopback Site (best evidence)
CR01-LIV01 CCR2004-1G-12S+2XS 7.9 185.109.42.101 Colo, 18-20 Fleet St (roof switch AS01-LIV01 attached)
CR01-LIV02 RB4011iGS+ 6.48.1 .102 Charlotte St (CHARLOTTEL WAN SWITCH + RTR-CHARLOTTEST-001 adjacent)
CR01-LIV03 RB4011iGS+ 6.48.3 .103 PI ("JSM") building (serves the PI Fleet-St-roof breakout + Mulligans PPPoE; PtP "to Bling")
CR01-LIV04 RB4011iGS+ 6.48.1 .104 "Bling", Hanover St (EOIP-3 Hanover St breakout terminates here)
CR01-LIV05 RB4011iGS+ 6.48.1 .105 Colquitt St area (EOIP "LAGO to JSM Core"; Colquitt St breakout = pig-004)
CR01-LIV06 RB4011iGS+ 6.48.3 .106 Relay site (Fitzgeralds + Hatch circuits, both currently disabled)

Edge — Brocade CER2024s (configs: discovery/raw/brocade/edge{1,2}.txt)

Device Loopback Location Transit
pubinvest-edge001 185.109.42.1 / 2a06:4e80:1::1 LEVEL Night Club, 18-20 Fleet St A: e2/2, 37.122.249.37/31 + 2a00:7a40:10:25::2/64 (+ legacy 188.94.40.230/30, + 2a02:1648:0:feed::13/127 configured)
pubinvest-edge002 185.109.42.2 / 2a06:4e80:1::2 Mathew St, L2 6RE ✓ (confirms the WAN-DESIGN transit-B hub assumption) B: e1/1, 37.122.249.39/31 + 2a00:7a40:10:26::2/64 (+ legacy 188.94.41.234/30)

Both transits: "ConnetU via NoOne", AS 51945 (port-names say AS59145 — typo). Inter-CER: e2/1↔e2/1 via EAD Openreach fibre, 185.109.42.4/30, MTU 9000, OSPF v4+v6, MPLS RSVP-TE with FRR between the two, carrying a Brocade VPLS "JSM-LAN" (id 601) between edge1 e1/7 and edge2 e2/2 ("Link to rtr-core-001 in LEVEL"). JSM = Pub Invest — this is the corporate Mathew St ↔ LEVEL L2 riding the WAN's MPLS. It retires with the CERs and the relationship inverts: the PI metro runs its own MPLS/VPLS (../DESIGN.md) and the WAN business becomes the L2-circuit customer (WAN-DESIGN §2.1). Nothing JSM-LAN carries becomes the WAN's problem at cutover.

BGP as-built on the CERs (differs from folklore in two ways): - TE: edge1 transit-in weight 100, edge2 weight 10 (A primary); edge2 TRANSIT-OUT prepends ×1 (single prepend 204258 — not the remembered ×2). - edge2 announces 185.109.40.0/24 as a more-specific alongside the /22 — meaning inbound for the whole .40 /24 (PI's 40.8/29, PPPoE statics, Old Hall St) prefers the 1G transit B today. Decide deliberately at cutover: almost certainly drop the /24 and go aggregate-only per WAN-DESIGN §4.1. - v6 transit sessions run on the per-circuit /64s (2a00:7a40:10:25::1 / 10:26::1) — the :feed::12/127 on A is configured but not the BGP session address. Correct WAN-DESIGN's /127 assumption accordingly. - In: defaultonly; out: aggregate-only prefix lists (+ the /24 above); redistribute connected,static inside; no MD5, telnet enabled, mgmt ACLs include long-gone parties.

Switches

Device Model Mgmt Where / role
AS01-LIV01 EdgePoint S16 (1.9.2, up 406 days) 185.109.41.10/30 (gw .9 on LIV01 sfp-sfpplus2.2 — that gateway address is currently disabled on LIV01) Colo roof. Customer + core ports, see §7
AS01-LIV02 ("CHARLOTTEL WAN SWITCH") CRS318-16P-2S+ 185.109.42.206 (LIV02 bridge-vlan-2 .205/30 disabled) Charlotte St, PI breakout hand-off
AS01-LIV04 CRS318-16P-2S+ 185.109.41.62 Bling/Hanover St access
(unnamed) CRS318-16P-2S+ 185.109.41.6 LIV06 site access (ether1)
(unnamed ×2) CRS318-16P-2S+ 10.222.2.3 / 10.0.0.2 LIV03 site — JSM + PPPoE access
Link Radio pair (identity, mgmt IP) ROS
LIV01 ↔ LIV02 ANT-LIV01-LIV02 (185.109.41.42) / ANT-LIV02-LIV01 (185.109.41.43) 6.49.17
LIV01 ↔ LIV06 ANT01-LIV08 (10.6.248.10) / ANT01-LIV09 (10.14.248.10) 6.44.3
LIV05 ↔ LIV06 ANT02-LIV08 (10.6.248.11) / ANT01-LIV02 (10.7.90.2) ← misnamed 6.45.2
LIV03 ↔ LIV04 ANT-LIV01-LIV04 (192.168.88.2) / ANT-LIV04-LIV01 (192.168.88.3) ← misnamed 6.47.7
(inside PI Hanover L2, pig-003) unnamed pair 48:8F:5A:67:BA:D3/:F5 (192.168.88.2/.3) 6.45.8

Radio firmware is ancient (6.44–6.49) and management addressing is chaos (public /30s, 10.x, 192.168.88.x with duplicate IPs across pairs). They all go with the migration.


2. Topology

graph TB
    TA[Transit A 10G] --- EDGE1[edge01 CER2024<br/>42.1 - colo]
    TB2[Transit B 1G] --- EDGE2[edge02 CER2024<br/>42.2 - remote hub]
    EDGE1 --- EDGE2
    EDGE1 ---|42.8/30| LIV01[CR01-LIV01 CCR2004<br/>42.101 - colo Fleet St]
    LIV01 ---|"40.0/30 (PI transit hand-off)"| LEVEL04[CR-LEVEL-04<br/>corporate colo CCR]
    LIV01 ---|"43.88/30 + breakout VLANs 10G"| LEVEL001[CR-LEVEL-001<br/>PI CCR1016-12S-1S+]
    LIV01 -.60GHz 42.80/30.- LIV02[CR01-LIV02 RB4011<br/>42.102 - Charlotte St]
    LIV01 ---|"PtP 42.84/30 (medium unconfirmed)"| LIV03[CR01-LIV03 RB4011<br/>42.103 - JSM]
    LIV01 -.60GHz 42.88/30.- LIV06[CR01-LIV06 RB4011<br/>42.106 - relay]
    LIV03 -.60GHz 42.72/30.- LIV04[CR01-LIV04 RB4011<br/>42.104 - Bling/Hanover]
    LIV06 -.60GHz 42.44/30.- LIV05[CR01-LIV05 RB4011<br/>42.105 - Colquitt]
    LIV01 --- AS01[AS01-LIV01 EdgeSwitch<br/>colo roof - customers]

Dashed = 60 GHz. Chain topology: LIV04 and LIV05 are two radio hops from the colo; no ring anywhere — any mid-chain failure strands everything behind it.

Link Interfaces Subnet Medium
LIV01 ↔ edge01 sfp-sfpplus6 "CORE:: Edge CER LEVEL" ↔ CER 185.109.42.8/30 (.9/.10) fibre
LIV01 ↔ LIV02 sfp-sfpplus2.3 (VLAN 3 via roof switch port 0/16) ↔ ether10 185.109.42.80/30 60 GHz, MTU 2000
LIV01 ↔ LIV03 sfp-sfpplus5 (comment wrongly says "CR01-LIV04") ↔ sfp-sfpplus1 185.109.42.84/30 PtP 1G MTU 2000 — medium unconfirmed
LIV01 ↔ LIV06 sfp-sfpplus3 ↔ ether1.2 (VLAN 2) 185.109.42.88/30 60 GHz
LIV03 ↔ LIV04 ether10.2 (VLAN 2) ↔ ether10 185.109.42.72/30 60 GHz
LIV05 ↔ LIV06 ether10 ↔ ether10 185.109.42.44/30 60 GHz
LIV05 ↔ (dead) sfp-sfpplus1 "ER01-MAN03 Connection (SSE)" — disabled, 185.109.42.96/30 + 188.94.40.84/30 — retired Manchester/SSE circuit

3. Routing As-Built

  • OSPF single area (area-1/default), router-id = loopback, on all core links above. edge01 participates (router-id 185.109.42.1).
  • iBGP AS 204258 full mesh: every LIV router peers with every other + edge01 + edge02 (loopback-to-loopback, no MD5, no BFD). ~8 nodes ≈ 28 sessions.
  • redistribute connected + static on every router (ROS6 instances and LIV01's v7 templates alike; LIV01 templates also default-originate=if-installed toward the RB4011s). This is exactly the pattern the new design eliminates.
  • Stale config: every RB4011 still carries an ER01-MAN03v4 iBGP peer pointing at 185.109.40.2 — which is now corporate CR-LEVEL-04's address on the PI transit hand-off. Sessions are down/idle, but it's a confusing landmine: delete on sight.

4. Customers — where they physically plug in

4.1 Static / routed customers (live)

Customer Block Attachment Move plan
54 Degrees (100M, q disabled) 185.109.43.128/30 (LIV01 sfp-sfpplus2.102) AS01-LIV01 roof port 0/5 (VLAN 102, 24V PoE). CPE MACs 48:8F:5A:22:49:FC/.FD/.4A:14, F4:92:BF:7D:FE:B6 Immovable for now — the §3.1 divestment long pole is its neighbour block; this one keeps its /30
Seven Stay Bold Street (aka q-clockworks, 100M) 185.109.43.84/30 (LIV01 sfp-sfpplus2.101) AS01-LIV01 roof port 0/6 (VLAN 101, PoE). MACs 04:CE:14:F9:DF:57, 18:FD:74:87:9C:E4, 18:FD:74:88:76:7C, 74:83:C2:FB:C6:B8 → PPPoE candidate
Old Hall St Router 185.109.40.16/31 (CPE) + 185.109.40.18/31 (clients, static via .17) edge1 e1/8 (1G) Keep (per plan) — re-home to a POP circuit before edge1 dies
Cavern Walks 185.109.40.20/31 edge2 e1/3 Re-home to Mathew St POP circuit before edge2 dies
Pub Invest backup internet ("JSM Backup") 185.109.43.145/30 edge1 e1/6 PI's fallback feed — folds into the corporate transit arrangement at cutover (see §4.3)
Unnamed 185.109.43.36/30 LIV05 ether3 (no comment on port) Identify, then → PPPoE or static range
Unnamed 185.109.43.168/30 LIV03 ether3 (no comment on port) Identify, then → PPPoE or static range
WatchGuard VPN solution 185.109.43.108/30 + static 185.109.40.100/32 via .110 LIV01 sfp-sfpplus7 (MAC 00:01:21:2E:76:C1 = WatchGuard OUI) Can go soon — or retained as the future OOB VPN termination (WAN-DESIGN §8); decide before cutover

4.2 PPPoE customers (live, realm @citybeam)

User Password IP BNG today Caller MAC Physical entry
zodiac.lounge@citybeam kAxN&!XjLmVT 185.109.41.122 LIV01 (sfp-sfpplus2.90) 24:5A:4C:15:82:EC AS01-LIV01 port 0/8 (VLAN 90) — Zodiac Lounge
ink@citybeam Ink123456 185.109.41.124 LIV01 (sfp-sfpplus2.90) 24:5A:4C:15:83:98 AS01-LIV01 port 0/10 (VLAN 90) — Ink (+ FC:EC:DA:* Ubiquiti CPEs)
mulligans@citybeam 4riuxi 185.109.40.130 LIV03 (ether10.3) 24:5A:4C:15:71:0E LIV03 site CRS318, PPPoE VLAN 3
tun-lewis-home (l2tp, disabled) Swen8cu1 185.109.40.92 LIV01 — legacy, delete

PPPoE infra today: LIV01 server on sfp-sfpplus2.90 (MTU/MRU 1492, local pool pppoe-pool = 185.109.41.101–120), LIV03 server on ether10.3 (pap/chap). All secrets local — no RADIUS anywhere (/radius empty on all six). These three users seed the new FreeRADIUS DB; new static-PPPoE range is 185.109.40.192–.223 per WAN-DESIGN §3.1.

4.3 Pub Invest Group (the corporate network as a customer)

PI is the biggest customer of the legacy WAN, delivered as a mess of EoIP + VLANs (the "badly" L2):

Circuit Path today Contents seen
Transit hand-off LIV01 sfp-sfpplus1 "CUST: Pub Invest Group LEVEL", 185.109.40.0/30 → CR-LEVEL-04 (corporate colo CCR2004) Corporate internet feed
10G trunk LIV01 sfp-sfpplus4 "CUST::Pub Invest Group [10Gb]" → CR-LEVEL-001 (PI CCR1016-12S-1S+), routed on 185.109.43.88/30; carries all breakout VLANs below Routed to PI: 185.109.40.8/29, 43.52/30, 43.64/30, 43.251/32 via .90
EOIP-1 Charlotte St breakout sfp-sfpplus4.10 (VLAN10 "Ruby Roof") bridged with eoip-pig-002 → LIV02 + dark-art-test (QinQ VLAN5 over the same 60 GHz) → CHARLOTTEL WAN SWITCH → RTR-CHARLOTTEST-001 / RTR-CELTICROOF-01 Two parallel L2 paths bridged together — loop kept at bay only by the EoIP MTU mismatch/luck. Fragile
EOIP-3 Hanover St breakout sfp-sfpplus4.4 bridged with eoip-pig-003 → LIV04 ether1.101 RTR-LOR-001, RTR-BNG-001, a PI LHGG-60ad pair, corporate 10.x
EOIP-3 Colquitt St breakout sfp-sfpplus4.5 bridged with eoip-pig-004 → LIV05 ether1 ("LAGO to JSM Core") RTR-LAG-001 (CCR1009)
Fleet St Roof breakout sfp-sfpplus4.6 bridged with sfp-sfpplus5.101 (VLAN101 over the LIV03 PtP; eoip-pig-005 now disabled) → LIV03 ether10.101 "JSM Network" RTR-CHR-001, CRS318s, corporate 10.222.2.x
Boston Pool breakout sfp-sfpplus4.7 bridged with sfp-sfpplus2.103 (roof switch port 0/7 VLAN 103, MTU 2000) Pure local L2 to Boston building
Hatch (disabled) sfp-sfpplus4.8 + eoip-pig-006 → LIV06 ether1.102 — all disabled dormant
Fitzgeralds (disabled) LIV06 ether1.101, 185.109.43.0/30, 110M queue — disabled dormant

These all dissolve in the migration: PI breakouts become native metro links inside the corporate network (they already exist in ../DESIGN.md), and the transit hand-off is replaced by whatever the corporate edge buys from the new WAN business.

4.4 WireGuard (on LIV01, wg_liv01, port 18492, subnet 185.109.40.104/29)

Peer Tunnel IP Routed via tunnel Note
(uncommented — third party) .107 185.109.40.90/32, 185.109.41.88/29 The "third-party WG routed block". Blocks the .41 PPPoE pool carve until moved
FSN-1 .108 185.109.42.240/28 Hetzner Falkenstein by the name — blocks the .42 divestment /23 until moved
Lewis Laptop (disabled) .106 — delete

5. AS01-LIV01 roof switch port map (colo)

Port Use VLAN
0/5 CUST 54 Degrees, PoE 24V 102
0/6 CUST Seven Stay Bold Street, PoE 101
0/7 CUST PI Group → Boston 103
0/8 CUST Zodiac Lounge (PPPoE), PoE 90
0/10 CUST Ink (PPPoE), PoE 90
0/16 CORE 60 GHz → CR01-LIV02, MTU 2000, PoE 3
0/17 CORE uplink → LIV01 sfp-sfpplus2, MTU 9000, trunk all 2,3,90,101–104
0/18 trunk (unlabelled, same VLANs minus 90) —

Mgmt VLAN 2 (185.109.41.10; its LIV01-side gateway .9 is disabled — the switch is managed L2-adjacent only). VLAN 104 tagged on all customer ports but terminates nowhere visible — legacy. SNMP community and admin/oxidized users are in info/er. Uptime 406 days.


6. EoIP register

Tunnel Endpoints ID MTU State
eoip-pig-002 LIV01 ↔ LIV02 2 1450 R — PI Charlotte
eoip-pig-003 LIV01 ↔ LIV04 3 1958 R — PI Hanover
eoip-pig-004 LIV01 ↔ LIV05 4 1958 R — PI Colquitt/Lago
eoip-pig-005 LIV03 → LIV01 5 1958 LIV03 end R, LIV01 end disabled (superseded by VLAN101 on the PtP)
eoip-pig-006 LIV06 ↔ LIV01 6 1450 disabled both ends (Hatch)
eoip-management LIV01 & LIV02 → 185.109.41.68 60101/60102 1458 down — headend at .68 unidentified

The 1450/1458-MTU tunnels mean PI traffic through Charlotte is sub-1500 today — one of the "badly" symptoms; VPLS at ≥1520 fixes this class of problem wholesale.


7. Oddities / cleanup found (delete-on-sight during migration)

  1. Stale ER01-MAN03v4 iBGP peers on every RB4011 → 185.109.40.2 (now CR-LEVEL-04). LIV05 keeps the dead SSE/Manchester circuit config + 188.94.40.84/30.
  2. dark-art-test QinQ (service-tag VLAN 5) bridged in parallel with eoip-pig-002 — an experiment left in production, bridging two L2 paths between the same routers.
  3. Radio names lie (ANT-LIV01-LIV04 serves LIV03↔LIV04; ANT01-LIV02 serves LIV05↔LIV06); duplicate 192.168.88.2/.3 on two different radio pairs.
  4. LIV01 sfp-sfpplus5 comment says LIV04, connects LIV03.
  5. AS01-LIV01 mgmt gateway (sfp-sfpplus2.2, 185.109.41.9) disabled on LIV01; switch NTP unsynced, 406-day uptime.
  6. LIV02 bridge-vlan-2 address 185.109.42.205/30 disabled; LIV01 43.165/29 (old VLAN 90 L3 — pre-PPPoE Zodiac/Ink addressing) disabled.
  7. q-clockworks/q-54degrees/Q-FITZGERALDS queues all disabled — nothing is actually rate-limiting the static customers.
  8. No RADIUS, no BFD, no MD5 on any BGP session; PPPoE secrets local on two different routers.

8. Open questions

(Resolved: sfp-sfpplus7 = WatchGuard VPN — keep-or-kill decision only; edge02 = Mathew St, confirmed from config; ER01-MAN03 = gone, confirmed — delete the stale peers.)

  1. LIV03 ether3 (43.168/30) and LIV05 ether3 (43.36/30) — which customers?
  2. eoip-management headend 185.109.41.68 — what was it?
  3. LIV01↔LIV03 PtP medium (radio model/fibre?) — matters for its retirement plan.
  4. Who is WG peer .107 (41.88/29 third party)? Needed for the .41 pool carve.
  5. edge2 e1/24 (185.109.42.213/30) — unlabelled live interface, what's on it?
  6. edge2 pins 41.122/32, 41.124/32, 43.128/30 statics via edge1 — die naturally at cutover. (JSM = Pub Invest throughout the legacy configs; JSM-LAN VPLS and the JSM backup feed fold into the corporate migration, not this one.)

9. What the 42.x survey changes in WAN-DESIGN §3.1

Confirmed in use (beyond the user-known list): loopbacks 42.101–.106 (die with these routers), core /30s 42.8, 42.44, 42.72, 42.80, 42.84, 42.88 (all die), disabled 42.96/30 + 42.204/30 (dead already), 42.240/28 (WG FSN-1 — must move before divestment). PI routed block is announced/routed as 40.8/29 (not /28 as remembered) — check RIPE assignment vs reality before renumbering anything onto 40.8–.15.

10. Migration mapping (old → WAN-DESIGN target)

Today Target
CR01-LIV01 (CCR2004) + edge01/edge02 CERs bdr-1 + bdr-2 (LIV01's chassis is redeployable as one of them after cutover)
LIV01/LIV03 PPPoE servers, local secrets bng-1 (CCR1016) + FreeRADIUS; seed the 3 users from §4.2, static IPs → 40.192–.223
AS01-LIV01 roof switch + customer ports Becomes (or is replaced by) pop-fleetst-1; customer ports keep VLANs, VLANs ride metro VPLS to the colo hand-off
LIV02 site (Charlotte customers/PI) PI circuits → native corporate metro. Any retail customers → pop-charlotte-1 VPLS
LIV03/LIV04/LIV05/LIV06 + all 60 GHz chain Retire routers + radios entirely; each site with retained retail customers gets a pop--1 access switch on a metro VPLS circuit; PI breakouts dissolve into the corporate metro
EoIP everything Gone — metro BGP-VPLS with DF multihoming (WAN-DESIGN §2.1)
iBGP mesh + redistribute connected/static bdr-1/2 iBGP pair only; BNG eBGP leaf; §3.4 community tagging
RB4011 ×5 Recovered — usable as corporate venue-refresh stock or spares