<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.skullspace.ca/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sean</id>
	<title>SkullSpace Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.skullspace.ca/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sean"/>
	<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php/Special:Contributions/Sean"/>
	<updated>2026-05-05T15:35:26Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.32.2</generator>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4927</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4927"/>
		<updated>2020-03-15T15:59:49Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Network hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |                 +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           ge1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2960g      +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (ge24)|       |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |     Cisco 2960g       +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |      172.30.6.3       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] old graphical shell service on [[vmsrv]] (to be retired)&lt;br /&gt;
*172.30.6.31 [[sksp-virt3|sksp-virt3-mgr]]&lt;br /&gt;
*172.30.6.32 [[sksp-virt3|sksp-virt3-1]]&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Sean's pihole&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 tftp server for [[IPXE boot option]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) static LAN (no DHCP, reserve here)&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 available&lt;br /&gt;
**172.30.8.3 available&lt;br /&gt;
**172.30.8.4 [[whonix.skull.space]] ssh login portal for TCP forwarding (port 1887 on whonix.skull.space forwarded to 172.30.8.4:22)&lt;br /&gt;
**172.30.8.5 [[outbound commercial vpn]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*10.2.0.0/24 [[whonix.skull.space]] gateway WAN side on [[vmsrv]]&lt;br /&gt;
**10.2.0.1 [[vmsrv]]&lt;br /&gt;
**10.2.0.15 [[whonix.skull.space]] gateway&lt;br /&gt;
&lt;br /&gt;
*10.152.152.0/24 [[whonix.skull.space]] LAN side behind Whonix gateway (isolated network virbr2 on [[vmsrv]]&lt;br /&gt;
**10.152.152.10 Whonix gateway, a full KVM vm on [[vmsrv]], acts as gateway/default route and nameserver&lt;br /&gt;
**10.152.152.51 Whonix ssh login portal for TCP port forwarding (also present as 172.30.8.4)&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| tmp.skullspace.ca&lt;br /&gt;
| Temporary address&lt;br /&gt;
| Open to anyone&lt;br /&gt;
| &lt;br /&gt;
| Check before use, use briefly. Example use, migration of skullspace.ca website on [[skullhost]] when [[vmsrv]] is being serviced.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
| (domain name pending)&lt;br /&gt;
| For handling migration of skullspace websites by way of DNS&lt;br /&gt;
| Mark Jenkins &amp;lt;mark@parit.ca&amp;gt; &lt;br /&gt;
| Ubuntu 18.04 vm hosted on [[sksp-virt3-1]]&lt;br /&gt;
| Website hosting, on separate physical host from vmsrv.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
| irc.skull.space (not set up yet)&lt;br /&gt;
| IRC server - /knock #admin&lt;br /&gt;
| Abuse: alexwebr@gmail.com or mark@parit.ca (not owned by Alex/Mark though) &lt;br /&gt;
| members &amp;amp; the public&lt;br /&gt;
| Running an ircd - not easy to proxy to a private address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca &lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
| lab.intarweb.ca &lt;br /&gt;
| lab.intarweb.ca &lt;br /&gt;
| sean AT tinfoilhat.ca &lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
| tmp.intarweb.ca&lt;br /&gt;
| tmp.intarweb.ca  Temporary rsync issues test.&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Main_Page&amp;diff=4920</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Main_Page&amp;diff=4920"/>
		<updated>2020-02-26T05:33:50Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* What is SkullSpace? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;(Back to [http://skullspace.ca Skullspace.ca])&lt;br /&gt;
&lt;br /&gt;
'''''EDITING''''' - if you want to edit this wiki, you'll need an account to be created by the [[Wikigods]]&lt;br /&gt;
&lt;br /&gt;
==What is [http://www.skullspace.ca SkullSpace]?==&lt;br /&gt;
SkullSpace is a [http://hackerspaces.org hackerspace] in Winnipeg. It is a place for hackers, builders, programmers, artists and anybody interested in how stuff works to gather in a common place and help focus and share their knowledge and creativity. Whether members are interested in individual or group projects, and whether they're tackling hardware, software, mathematical, design or any other problems, it's our goal to provide the space, tools, freedom, and education to make it happen.&lt;br /&gt;
&lt;br /&gt;
Our physical presence is 2500 sq. ft. of space on the 2nd floor of 374 Donald Street, right across from the Burton Cummings Theatre in the heart of the Exchange District.&lt;br /&gt;
&lt;br /&gt;
Our legal entity is a non-profit corporation within the province of Manitoba. We have a member-elected Board of Directors who also act as Officers consisting of:&lt;br /&gt;
&lt;br /&gt;
* Chris Johnson&lt;br /&gt;
* Kyle Martin&lt;br /&gt;
* Mark Campbell&lt;br /&gt;
* Michael Kozakewich&lt;br /&gt;
* Nate Wild&lt;br /&gt;
&lt;br /&gt;
All Directors can be reached by email at firstname.lastname @ skullspace.ca.&lt;br /&gt;
Actually, Thor can be reached without his last name, because his first is just that powerful.&lt;br /&gt;
&lt;br /&gt;
In practice our membership operates as a collective, with members being as involved as much as they want to be in the decision making process.  See our [[Bylaws]] for more information.&lt;br /&gt;
&lt;br /&gt;
Also see our [[Press]] coverage.&lt;br /&gt;
&lt;br /&gt;
If you're still unsure what SkullSpace is about, KQED has published a great [http://www.youtube.com/watch?v=wamwklXWK4M short video] on what hackerspaces offer to the community.&lt;br /&gt;
&lt;br /&gt;
==Visiting SkullSpace==&lt;br /&gt;
&lt;br /&gt;
We are located on the second floor of 374 Donald Street in Winnipeg. ([https://www.google.com/maps/place/374+Donald+St/@49.8960111,-97.144483,17z/data=!3m1!4b1!4m2!3m1!1s0x52ea715dcf0040b3:0x83cc84d524e1bcfb Google Maps link])&lt;br /&gt;
&lt;br /&gt;
Meetings, which are open to the public, happen every Tuesday at 6pm. You can browse our previous [[Meeting notes]] archive to stay updated on what we discuss. '''Non-members are welcome to drop in'''!&lt;br /&gt;
&lt;br /&gt;
We also have a variety of events during the week and weekends - see our [[Community_Events|Calendar]] for a complete listing!&lt;br /&gt;
&lt;br /&gt;
==Contact us/Connect with SkullSpace==&lt;br /&gt;
We have lots of ways to get in touch us!&lt;br /&gt;
&lt;br /&gt;
The best way to stay informed is by joining our [[Mailing List|mailing lists]]. We have two primary lists - announce@ and discuss@. All members and people interested should join announce@ - it's low traffic, with only a couple emails a week about our important events. If you're more interested in the community, join discuss@, which is high volume. Instructions are on the [[Mailing List]] wiki page.&lt;br /&gt;
&lt;br /&gt;
Our primary social media outlet is our [https://twitter.com/SkullSpaceWpg/ Twitter] page. You can also find SkullSpace on [https://www.facebook.com/SkullSpaceWpg Facebook].&lt;br /&gt;
&lt;br /&gt;
The other online place where you can find us is in our [irc://irc.freenode.net/#SkullSpace irc channel], #SkullSpace on irc.freenode.net. You'll find constant traffic/discussion there. Freenode also offers a webchat client [https://webchat.freenode.net/?channels=%23skullspace&amp;amp;uio=d4 here].&lt;br /&gt;
&lt;br /&gt;
SkullSpace also has a [http://www.meetup.com/Skullspace-Winnipegs-hackerspace/ Meetup] page and a [https://secure.flickr.com/photos/skullspace Flickr] page.&lt;br /&gt;
&lt;br /&gt;
==How do I join?==&lt;br /&gt;
Easy! First you should show some interest showing up either online or physically as discussed above. If you like what you see, browse the [[:Category:Required Reading]] category on the wiki, which is the information that every member should know.&lt;br /&gt;
&lt;br /&gt;
Once you've done that, you can apply to become a member! Our membership dues are pay-what-you-can, with a minimum cost of $40/month ($20/month if you're a student). This gets you 24/7 access to the space along with everything else listed on the [[Member Benefits]] page. To apply, fill out the [[Media:Membership Agreement.doc|membership agreement]] and, if you choose, [[Media:SkullSpace PAD.pdf|pre-authorized debit form]]. Bring those forms (and a void cheque if you'd like to use pre-authorized debit) to a Tuesday meeting, if you can; otherwise, email info at skullspace.ca to make other arrangements.&lt;br /&gt;
&lt;br /&gt;
Your name will be emailed to the announce@ mailing list, and if nobody objects to your membership after two weeks you'll be handed a key.&lt;br /&gt;
&lt;br /&gt;
==Can I host events at your space?==&lt;br /&gt;
The short answer: Absolutely!&lt;br /&gt;
&lt;br /&gt;
If you're hosting an event at the space, you'll need to coordinate with at least one SkullSpace member, for access. We generally don't give keys to non-members. Of course, becoming a member is easy, so you can simply become a member and have full access! See above for info!&lt;br /&gt;
&lt;br /&gt;
As early as possible, the event needs to be put in the [[Community Events|calendar]] and emailed to the discuss@ mailing list (discuss at skullspace.ca). If it's open to the public, you may also advertise it on the announce@ mailing list, both when it's planned and again shortly before the event as a reminder.&lt;br /&gt;
&lt;br /&gt;
We request that all events at the space be open to SkullSpace members, as the space belongs to us. We also request that you solicit donations for non-members who use our space. We currently don't charge to use our space, but if it becomes popular, and we don't make enough donations to be worth our while, we may start charging non-members.&lt;br /&gt;
&lt;br /&gt;
==Important Links==&lt;br /&gt;
===Community===&lt;br /&gt;
* [http://www.skullspace.ca/blog/ Blog]&lt;br /&gt;
* [[Mailing List]]&lt;br /&gt;
* [irc://irc.freenode.net/#SkullSpace #SkullSpace on irc.freenode.net] (or visit [http://webchat.freenode.net/?channels=SkullSpace Freenode Webchat])&lt;br /&gt;
* [[Community_Events|Community events Calendar]]&lt;br /&gt;
* [[Members]]&lt;br /&gt;
&lt;br /&gt;
===Social networking===&lt;br /&gt;
* [https://www.facebook.com/pages/SkullSpace/127670240630811 SkullSpace] (Facebook)&lt;br /&gt;
* [https://twitter.com/SkullSpaceWpg/ @SkullSpaceWpg] (Twitter)&lt;br /&gt;
* [http://vimeo.com/skullspace Videos] (Vimeo)&lt;br /&gt;
* [http://www.skullspace.ca/wiki/index.php/Flickr Photos] (Flickr)&lt;br /&gt;
* [https://github.com/skullspace Code] (GitHub)&lt;br /&gt;
* [http://www.meetup.com/Skullspace-Winnipegs-hackerspace/ Events Calendar] (Meetup)&lt;br /&gt;
* [http://www.strava.com/clubs/skullSpace Trip/Fitness Tracking] (Strava)&lt;br /&gt;
* [http://plug.dj/skullspace/ Web Radio] (Plug.DJ)&lt;br /&gt;
* [https://www.fundscrip.com/ Giftcard Fundraising] (Invitation code: SS5BMZ)&lt;br /&gt;
* [https://trello.com/b/YhudmLje/eventstrikeforce Event Planning and Organization] (Trello; Invite required)&lt;br /&gt;
* [http://steamcommunity.com/groups/skullspace Gaming] (Steam)&lt;br /&gt;
&lt;br /&gt;
===Projects===&lt;br /&gt;
* [[Wishlist]]&lt;br /&gt;
* [[:category:Renovations|Renovations]] - (currently none are planned)&lt;br /&gt;
* [[Parts Database]]&lt;br /&gt;
* [[Game Collection]]&lt;br /&gt;
* [[:Category:Projects|More...]]&lt;br /&gt;
&lt;br /&gt;
===Miscellaneous Resources===&lt;br /&gt;
* [[MemberAgreement|Member Agreement]]&lt;br /&gt;
* [[Member Benefits]]&lt;br /&gt;
* [[Cleaning]]&lt;br /&gt;
* [[Equipment]]&lt;br /&gt;
* [[:Category:Required Reading|Required Reading]]&lt;br /&gt;
* [[Networking]]&lt;br /&gt;
* [[Too cool for Skullspace]]&lt;br /&gt;
* [[IPXE boot option]]&lt;br /&gt;
* [[:Category:Archives|Archived Wiki Documents]]&lt;br /&gt;
&lt;br /&gt;
===Pages for Members===&lt;br /&gt;
* [[Meeting notes]]&lt;br /&gt;
* [[Strikeforces]]&lt;br /&gt;
* [[Wiki_Tips_and_Tricks]]&lt;br /&gt;
&lt;br /&gt;
== Recent Changes==&lt;br /&gt;
&lt;br /&gt;
{{Special:RecentChanges}}&lt;br /&gt;
&lt;br /&gt;
==Sandbox==&lt;br /&gt;
Want to play with wiki markup? Play in the [[sandbox]].&lt;br /&gt;
&lt;br /&gt;
[[Category: Required Reading]]&lt;br /&gt;
[[Category: Wiki]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4918</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4918"/>
		<updated>2020-02-19T00:59:57Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* IP Usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |                 +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           ge1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2960g      +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (ge24)|       |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |     Cisco 2960g       +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |      172.30.6.3       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] old graphical shell service on [[vmsrv]] (to be retired)&lt;br /&gt;
*172.30.6.31 [[sksp-virt3|sksp-virt3-mgr]]&lt;br /&gt;
*172.30.6.32 [[sksp-virt3|sksp-virt3-1]]&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Sean's pihole&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 tftp server for [[IPXE boot option]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) static LAN (no DHCP, reserve here)&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 available&lt;br /&gt;
**172.30.8.3 available&lt;br /&gt;
**172.30.8.4 [[whonix.skull.space]] ssh login portal for TCP forwarding (port 1887 on whonix.skull.space forwarded to 172.30.8.4:22)&lt;br /&gt;
**172.30.8.5 [[outbound commercial vpn]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*10.2.0.0/24 [[whonix.skull.space]] gateway WAN side on [[vmsrv]]&lt;br /&gt;
**10.2.0.1 [[vmsrv]]&lt;br /&gt;
**10.2.0.15 [[whonix.skull.space]] gateway&lt;br /&gt;
&lt;br /&gt;
*10.152.152.0/24 [[whonix.skull.space]] LAN side behind Whonix gateway (isolated network virbr2 on [[vmsrv]]&lt;br /&gt;
**10.152.152.10 Whonix gateway, a full KVM vm on [[vmsrv]], acts as gateway/default route and nameserver&lt;br /&gt;
**10.152.152.51 Whonix ssh login portal for TCP port forwarding (also present as 172.30.8.4)&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| tmp.skullspace.ca&lt;br /&gt;
| Temporary address&lt;br /&gt;
| Open to anyone&lt;br /&gt;
| &lt;br /&gt;
| Check before use, use briefly. Example use, migration of skullspace.ca website on [[skullhost]] when [[vmsrv]] is being serviced.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
| tmpskspproxy.parit.ca&lt;br /&gt;
| Temporary, proxies some traffic for https://parit.ca&lt;br /&gt;
| Mark Jenkins &amp;lt;mark@markjenkins.ca&amp;gt; &lt;br /&gt;
| Ubuntu 16.04 vm hosted on [[vmsrv]]&lt;br /&gt;
| Will some TCP proxying on ports used by vmsrv host OS&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
| irc.skull.space (not set up yet)&lt;br /&gt;
| IRC server - /knock #admin&lt;br /&gt;
| Abuse: alexwebr@gmail.com or mark@parit.ca (not owned by Alex/Mark though) &lt;br /&gt;
| members &amp;amp; the public&lt;br /&gt;
| Running an ircd - not easy to proxy to a private address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca &lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
| lab.intarweb.ca &lt;br /&gt;
| lab.intarweb.ca &lt;br /&gt;
| sean AT tinfoilhat.ca &lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
| tmp.intarweb.ca&lt;br /&gt;
| tmp.intarweb.ca  Temporary rsync issues test.&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4866</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4866"/>
		<updated>2019-04-30T22:50:41Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |                 +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           ge1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2960g      +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (ge24)|       |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |     Cisco 2960g       +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |      172.30.6.3       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31 [[sksp-virt3|sksp-virt3-mgr]]&lt;br /&gt;
*172.30.6.32 [[sksp-virt3|sksp-virt3-1]]&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 tftp server for [[IPXE boot option]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| tmp.skullspace.ca&lt;br /&gt;
| Temporary address&lt;br /&gt;
| Open to anyone&lt;br /&gt;
| &lt;br /&gt;
| Check before use, use briefly. Example use, migration of skullspace.ca website on [[skullhost]] when [[vmsrv]] is being serviced.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
| tmpskspproxy.parit.ca&lt;br /&gt;
| Temporary, proxies some traffic for https://parit.ca&lt;br /&gt;
| Mark Jenkins &amp;lt;mark@markjenkins.ca&amp;gt; &lt;br /&gt;
| Ubuntu 16.04 vm hosted on [[vmsrv]]&lt;br /&gt;
| Will some TCP proxying on ports used by vmsrv host OS&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
| irc.skull.space (not set up yet)&lt;br /&gt;
| IRC server - /knock #admin&lt;br /&gt;
| Abuse: alexwebr@gmail.com or mark@parit.ca (not owned by Alex/Mark though) &lt;br /&gt;
| members &amp;amp; the public&lt;br /&gt;
| Running an ircd - not easy to proxy to a private address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| lab.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
| tmp.intarweb.ca&lt;br /&gt;
| tmp.intarweb.ca  Temporary rsync issues test.&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4820</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4820"/>
		<updated>2018-08-15T03:11:27Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |                 +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           ge1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2960g      +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (ge24)|       |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |     Cisco 2960g       +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |      172.30.6.3       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31 [[sksp-virt3|sksp-virt3-mgr]]&lt;br /&gt;
*172.30.6.32 [[sksp-virt3|sksp-virt3-1]]&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
| irc.skull.space (not set up yet)&lt;br /&gt;
| IRC server - /knock #admin&lt;br /&gt;
| Abuse: alexwebr@gmail.com or mark@parit.ca (not owned by Alex/Mark though) &lt;br /&gt;
| members &amp;amp; the public&lt;br /&gt;
| Running an ircd - not easy to proxy to a private address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4819</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4819"/>
		<updated>2018-08-15T03:10:46Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |                 +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           ge1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2950g      +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (ge24)|       |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |     Cisco 2960g       +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |      172.30.6.3       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31 [[sksp-virt3|sksp-virt3-mgr]]&lt;br /&gt;
*172.30.6.32 [[sksp-virt3|sksp-virt3-1]]&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
| irc.skull.space (not set up yet)&lt;br /&gt;
| IRC server - /knock #admin&lt;br /&gt;
| Abuse: alexwebr@gmail.com or mark@parit.ca (not owned by Alex/Mark though) &lt;br /&gt;
| members &amp;amp; the public&lt;br /&gt;
| Running an ircd - not easy to proxy to a private address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4818</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4818"/>
		<updated>2018-08-15T03:09:43Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |                 +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           ge1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2950g      +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (ge24)| ge24  |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |     Cisco 2960g       +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |      172.30.6.3       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31 [[sksp-virt3|sksp-virt3-mgr]]&lt;br /&gt;
*172.30.6.32 [[sksp-virt3|sksp-virt3-1]]&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
| irc.skull.space (not set up yet)&lt;br /&gt;
| IRC server - /knock #admin&lt;br /&gt;
| Abuse: alexwebr@gmail.com or mark@parit.ca (not owned by Alex/Mark though) &lt;br /&gt;
| members &amp;amp; the public&lt;br /&gt;
| Running an ircd - not easy to proxy to a private address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4800</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4800"/>
		<updated>2018-04-14T16:00:13Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* IP Usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   | fa20            +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           fa1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2850       +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  Temporarily in use by Mark, to host edit.solidarityeconomy.us&lt;br /&gt;
|  Mark Jenkins mark@markjenkins.ca&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Sean Cody&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4799</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4799"/>
		<updated>2018-04-14T15:58:30Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   | fa20            +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           fa1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2850       +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  Temporarily in use by Mark, to host edit.solidarityeconomy.us&lt;br /&gt;
|  Mark Jenkins mark@markjenkins.ca&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
| | TBD&lt;br /&gt;
| ips.intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4798</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4798"/>
		<updated>2018-04-14T15:57:26Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   | fa20            +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           fa1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2850       +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.14 (new, ask Alex W about this) UniFI AP Controller - VM on vmsrv.skullspace.ca&lt;br /&gt;
*172.30.6.15 esx.intarweb.ca&lt;br /&gt;
*172.30.6.16 ips.intarweb.ca&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
| mail.skull.space&lt;br /&gt;
| [[SkullMail]] email forwarding service&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
| nessus.skullspace.ca&lt;br /&gt;
| SkullSpace Nessus scanner &lt;br /&gt;
| alexwebr at gmail dot com&lt;br /&gt;
| &lt;br /&gt;
| If it shared an IP with other infrastructure, tools like Fail2Ban could block more than intended&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
| broot.ca &lt;br /&gt;
| Personal webserver, Git, DNS, mail&lt;br /&gt;
| Alex Weber &amp;lt;alexwebr@gmail.com&amp;gt;&lt;br /&gt;
| Nothing. Can be moved elsewhere if we need IP space back.&lt;br /&gt;
| Makes life easier if it has its own IP. If Sksp infrastructure needs an IP, this can go.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  library.skullspace.ca&lt;br /&gt;
|  The Evergreen server for the (experimental) SkullSpace library&lt;br /&gt;
|  Alex (alexwebr@gmail.com)&lt;br /&gt;
| SkullSpace&lt;br /&gt;
| Uses Websockets, and Websockets need a legitimate SSL certificate? &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  Temporarily in use by Mark, to host edit.solidarityeconomy.us&lt;br /&gt;
|  Mark Jenkins mark@markjenkins.ca&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4367</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4367"/>
		<updated>2016-05-12T06:38:40Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              |     The Tubes     |&lt;br /&gt;
                              |    On The Roof    |&lt;br /&gt;
                              |                   |&lt;br /&gt;
                              +-- ------+---------+&lt;br /&gt;
                                        |&lt;br /&gt;
                                        |&lt;br /&gt;
                              +-- ------+-----------+&lt;br /&gt;
                              |     LES.net         |&lt;br /&gt;
                              |                     |&lt;br /&gt;
                              |   208.81.6.224/27   |&lt;br /&gt;
                              +----+----------------+&lt;br /&gt;
                                   |&lt;br /&gt;
                                   |&lt;br /&gt;
                                   | fa20            +---------------------+&lt;br /&gt;
                     +-------------+---------+       |  Skullspace+Router  |&lt;br /&gt;
           fa1+19    |  Skullspace+External  | ether1|       RB450G        |&lt;br /&gt;
          +----------+      Cisco 2850       +-------+                     |&lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |&lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |&lt;br /&gt;
          |                                 |        +---------------------+&lt;br /&gt;
+---------+-----------+                     |                  |ether2&lt;br /&gt;
|                     |                     |                  |&lt;br /&gt;
|  Rest of External   |                     |                  |&lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|   208.81.6.224/27   |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|                     |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
+---------------------+                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
                                                         |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |&lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+&lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |&lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |&lt;br /&gt;
                                         |             |  |             |  |             |&lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4366</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4366"/>
		<updated>2016-05-12T06:35:12Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* VOI IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;s&amp;gt;B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;/s&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.38 Jarred's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.39 Ben's VM on [[vmsrv]]&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
| vmsrv.skullspace.ca&lt;br /&gt;
| Virtual Machine Server [[vmsrv]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| VM server open to all members.&lt;br /&gt;
| Running an http proxy to allow this one IP address to host many web servers, and doing TCP port forwarding to allow many different virtual servers to share this one IP address&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
| shell.skull.space&lt;br /&gt;
| [[shell.skull.space]]&lt;br /&gt;
| mark AT markjenkins DOT ca&lt;br /&gt;
| Shell accounts for all members.&lt;br /&gt;
| Being able to bind to port 22 vs having some other port forwarded by vmsrv.skullspace.ca will make this much easier to get users for. Plus, Mak has brought with him a many users from his own system where he used to have his own users with shell accounts. They're already used to port 22 and a different hostname pointing here. Leaving that alone will help keep them. That old system was taking up it's own IP address anyway.&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  loki.madcowlabs.com&lt;br /&gt;
|  [[loki.madcowlabs.com]]&lt;br /&gt;
|  cotto at ieee point org&lt;br /&gt;
| Chris's Server &lt;br /&gt;
| Experimental development project server&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  amsler.ca&lt;br /&gt;
|  Production Appserver / Personal Webspace&lt;br /&gt;
|  edwinguy_gmail&lt;br /&gt;
|  Skullspace LAN&lt;br /&gt;
|  Edwin Amsler&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
&amp;lt;strike&amp;gt;&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4317</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4317"/>
		<updated>2016-01-03T06:24:20Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv4&lt;br /&gt;
Allocation 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
IPv6&lt;br /&gt;
Allocation 2605:e200:c212::/48&lt;br /&gt;
2605:e200:c201:2::4 Gateway&lt;br /&gt;
DNS1:  2605:e200:53:2::&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
| Mark's test router &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4316</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4316"/>
		<updated>2016-01-03T06:20:36Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
LES allocated 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| porting AT les DOT net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
| Mark's test router &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4308</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4308"/>
		<updated>2015-12-30T00:15:25Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
LES allocated 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
| Mark's test router &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
| ripe.skullspace.ca&lt;br /&gt;
| RIPE Probe &lt;br /&gt;
| colin AT insecure DASH complexity DOT ca&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4307</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4307"/>
		<updated>2015-11-15T04:35:51Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* VOI IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
LES allocated 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
| Mark's test router &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4291</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4291"/>
		<updated>2015-10-26T04:58:22Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.81.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
LES allocated 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
| Mark's test router &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4290</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4290"/>
		<updated>2015-10-26T04:05:50Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.2 (fa23)| fa21  |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
*172.30.6.41 Mark's test router&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
LES allocated 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
| Mark's test router &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4285</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4285"/>
		<updated>2015-09-15T22:51:19Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3 (fa23)| fa21  |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
LES allocated 208.81.6.224/27 (255.255.255.224).&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4284</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4284"/>
		<updated>2015-09-15T22:44:40Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              |     The Tubes     |                                                     &lt;br /&gt;
                              |    On The Roof    |                                                     &lt;br /&gt;
                              |                   |                                                     &lt;br /&gt;
                              +--+--------------+-+                                                     &lt;br /&gt;
                                 |              |                                                       &lt;br /&gt;
                                 |              | port1                                               &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                   &lt;br /&gt;
             |     LES.net         |    port2 |       VOI           |                                   &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                   &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                   &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                   &lt;br /&gt;
                               |       |                   | port3(SKSP)                                           &lt;br /&gt;
                               |       |                   | ether3                                     &lt;br /&gt;
                               | fa20  | fa24        +-----+---------------+                            &lt;br /&gt;
                     +---------+-------+-----+       |  Skullspace+Router  |                            &lt;br /&gt;
           fa1-19    |  Skullspace+External  | ether1|       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +-------+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3 (fa23)| fa21  |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++       |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |        +---------+-----------+                            &lt;br /&gt;
+---------+-----------+                     |                  |ether2                                  &lt;br /&gt;
|                     |                     |                  |                                         &lt;br /&gt;
|  Rest of External   |                     |                  |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |        +---------+-------------+      +------------------+&lt;br /&gt;
|                     |                     +--------+  Skullspace+Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                              |  3+Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                              |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                              +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                                  |       |       |          |                  |&lt;br /&gt;
                                                +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                                |                |                |                     &lt;br /&gt;
                                         +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                         |    WAP+A    |  |    WAP+B    |  |    WAP+C    |              &lt;br /&gt;
                                         | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                         |             |  |             |  |             |              &lt;br /&gt;
                                         +-------------+  +-------------+  +-------------+  &amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4283</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4283"/>
		<updated>2015-09-15T22:25:29Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Internet feeds */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity, tested 94.83mbit down, 96.22mbit up to Speedtest.net Winnipeg)&amp;lt;br&amp;gt;&lt;br /&gt;
B: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4282</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4282"/>
		<updated>2015-09-15T18:33:17Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Internet feeds */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&amp;lt;BR&amp;gt;&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4281</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4281"/>
		<updated>2015-09-15T18:32:17Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |                     |   +------+     CPE/Router      |                                &lt;br /&gt;
             |   208.81.6.224/27   |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4280</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4280"/>
		<updated>2015-09-15T18:28:14Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2850       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4279</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4279"/>
		<updated>2015-09-15T18:17:47Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2950       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| ns1.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4278</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4278"/>
		<updated>2015-09-15T18:14:23Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2950       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.224&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Network&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| dns.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4277</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4277"/>
		<updated>2015-09-15T18:13:42Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* LES IP Delegation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2950       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| dns.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.230&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.231&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.232&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.233&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.234&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.235&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.236&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.237&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.238&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.239&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.240&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.241&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.242&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.243&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.244&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.245&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.246&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.247&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.248&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.249&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.250&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.251&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.252&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.254&lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.255&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Broadcast&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4276</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4276"/>
		<updated>2015-09-15T18:09:39Z</updated>

		<summary type="html">&lt;p&gt;Sean: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2950       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
== IP Usage ==&lt;br /&gt;
&lt;br /&gt;
=== LES IP Delegation ===&lt;br /&gt;
LES allocated 208.81.6.224/27.&lt;br /&gt;
208.81.6.225 Gateway&lt;br /&gt;
208.81.6.226, 208.81.6.227 RESERVED for LES.net usage.&lt;br /&gt;
DNS1: 208.81.7.10&lt;br /&gt;
DNS2: 208.81.7.14&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.225&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net Gateway&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.226&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.227&lt;br /&gt;
| TBD&lt;br /&gt;
| LES.net RESERVED&lt;br /&gt;
| LES.net&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.228&lt;br /&gt;
| TBD&lt;br /&gt;
| Skullspace Router&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.229&lt;br /&gt;
| TBD&lt;br /&gt;
| dns.skullspace.ca&lt;br /&gt;
| it AT skullspace.ca&lt;br /&gt;
| Skullspace DNS&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 208.81.6.253&lt;br /&gt;
| TBD&lt;br /&gt;
| intarweb.ca&lt;br /&gt;
| sean AT tinfoilhat.ca&lt;br /&gt;
| Skullspace LAN&lt;br /&gt;
| Sean Cody &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== VOI IP Delegation ===&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4275</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4275"/>
		<updated>2015-09-15T18:00:21Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Internet feeds */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2950       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
A: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
B: Internet from LES.net (wifi-based Ubiquity)&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4274</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4274"/>
		<updated>2015-09-15T17:59:39Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                              +-------------------+                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              |     The Tubes     |                                                  &lt;br /&gt;
                              |    On The Roof    |                                                  &lt;br /&gt;
                              |                   |                                                  &lt;br /&gt;
                              +--+--------------+-+                                                  &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
                                 |              |                                                    &lt;br /&gt;
             +-------------------+-+          +-+-------------------+                                &lt;br /&gt;
             |     LES.net         |          |       VOI           |                                &lt;br /&gt;
             |  208.81.6.224/27    |   +------+     CPE/Router      |                                &lt;br /&gt;
             |                     |   |      |   206.220.196.49    |                                &lt;br /&gt;
             +-----------------+---+   |      +------------+--------+                                &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |                   |                                         &lt;br /&gt;
                               |       |          +--------+------------+                            &lt;br /&gt;
                     +---------+-------+-----+    |  Skullspace-Router  |                            &lt;br /&gt;
                     |  Skullspace-External  |    |       RB450G        |                            &lt;br /&gt;
          +----------+      Cisco 2950       +----+  206.220.196.50     |                            &lt;br /&gt;
          |          |      172.30.6.3       |    |  208.61.6.228       |                            &lt;br /&gt;
          |          +----------------------++    |  172.30.6.1         |                            &lt;br /&gt;
          |                                 |     +--------+------------+                            &lt;br /&gt;
+---------+-----------+                     |              |                                         &lt;br /&gt;
|                     |                     |              |                                         &lt;br /&gt;
|  Rest of External   |                     |              |                                         &lt;br /&gt;
|     PUBLIC/LAN      |                     |     +--------+--------------+      +------------------+&lt;br /&gt;
|                     |                     +-----+  Skullspace-Internal  |      |                  |&lt;br /&gt;
|  206.220.196.48/28  |                           |  3-Com L2 Old Junk    +------+ Rest of Internal |&lt;br /&gt;
|  206.220.193.64/29  |                           |                       |      |   INTERNAL/LAN   |&lt;br /&gt;
|  208.61.6.224/27    |                           +---+-------+-------+---+      |   172.30.6.0/24  |&lt;br /&gt;
+---------------------+                               |       |       |          |                  |&lt;br /&gt;
                                             +--------+       |       +--------+ +------------------+&lt;br /&gt;
                                             |                |                |                     &lt;br /&gt;
                                      +------+------+  +------+------+  +------+------+              &lt;br /&gt;
                                      |    WAP-A    |  |    WAP-B    |  |    WAP-C    |              &lt;br /&gt;
                                      | 172.30.6.10 |  | 172.30.6.11 |  | 172.30.6.12 |              &lt;br /&gt;
                                      |             |  |             |  |             |              &lt;br /&gt;
                                      +-------------+  +-------------+  +-------------+              &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4272</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4272"/>
		<updated>2015-08-10T15:37:54Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* VOI IP usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::81 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4271</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4271"/>
		<updated>2015-08-10T15:37:14Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* VOI IP usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4270</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4270"/>
		<updated>2015-08-10T15:36:34Z</updated>

		<summary type="html">&lt;p&gt;Sean: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
-&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4269</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4269"/>
		<updated>2015-08-10T15:35:30Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* VOI IP usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4268</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4268"/>
		<updated>2015-08-10T15:33:07Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* VOI IP usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.34 Jay Bots (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
*172.30.8.0/24 Virtual Machine Server ([[vmsrv]]) LAN&lt;br /&gt;
**172.30.8.1 [[vmsrv]]&lt;br /&gt;
**172.30.8.2 Mark private ubuntu vpn&lt;br /&gt;
**172.30.8.3 Mark private project ubuntu (Container on [[vmsrv]])&lt;br /&gt;
&lt;br /&gt;
*10.50.31.0/24 TheLEDSign LAN&lt;br /&gt;
**10.50.31.16 The Sign&lt;br /&gt;
**10.50.31.17 The controlling container ([[vmsrv]])&lt;br /&gt;
*10.50.32.0/30 Mark project private Point to Point link LAN&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Mark&lt;br /&gt;
| temporary use&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for www.skullspace.ca  (testing)&lt;br /&gt;
| 2604:4280:1:c0de::80 - Relay/Proxy v6 to v4 for wiki.skullspace.ca (testing)&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4167</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4167"/>
		<updated>2015-03-26T03:58:55Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Stupid-High Level Diagram */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4166</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4166"/>
		<updated>2015-03-26T03:29:49Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
**172.30.6.245 - sean VPN IP (sean cody)&lt;br /&gt;
**172.30.6.247 - cchilds VPN IP&lt;br /&gt;
**172.30.6.248 - jordansamulaitis VPN IP&lt;br /&gt;
**172.30.6.249 - gygar VPN IP&lt;br /&gt;
**172.30.6.250 - nwild VPN IP&lt;br /&gt;
**172.30.6.251 - cstanners-router VPN IP&lt;br /&gt;
**172.30.6.252 - odin VPN IP&lt;br /&gt;
**172.30.6.254 - cstanners VPN IP&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4165</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4165"/>
		<updated>2015-03-26T02:38:56Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC = 0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4164</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4164"/>
		<updated>2015-03-26T02:38:47Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC =0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4163</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4163"/>
		<updated>2015-03-26T02:38:36Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC -=0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 UniFI AP Controller (Container on [[vmsrv]])&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4162</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4162"/>
		<updated>2015-03-26T02:21:07Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP) - MAC = 0418D64E8BDE&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP) - MAC -=0418D64E8AED&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP) - MAC = 0418D64E8AE4&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4158</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4158"/>
		<updated>2015-03-26T00:56:12Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.13 intarweb.ca (Sean's server, inside interface)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4157</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4157"/>
		<updated>2015-03-26T00:55:29Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Legacy IPs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  Micro-tik Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4156</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4156"/>
		<updated>2015-03-26T00:55:11Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Legacy IPs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  SkullSpace-Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9 noel, alex's linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10 kyle, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11 stefen, a linux container on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4155</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4155"/>
		<updated>2015-03-26T00:54:41Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Legacy IPs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  SkullSpace-Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9&amp;lt;/strike&amp;gt;  noel, alex's linux container on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10&amp;lt;/strike&amp;gt; kyle, a linux container on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11&amp;lt;/strike&amp;gt; stefen, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.15 Cisco 2950 switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4154</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4154"/>
		<updated>2015-03-26T00:54:13Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Legacy IPs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  SkullSpace-Router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9&amp;lt;/strike&amp;gt;  noel, alex's linux container on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10&amp;lt;/strike&amp;gt; kyle, a linux container on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11&amp;lt;/strike&amp;gt; stefen, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*192.168.1.15 Cisco 2950 switch&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4153</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4153"/>
		<updated>2015-03-26T00:53:44Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Internal IP usage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.1&amp;lt;/strike&amp;gt;  main Linksys/Netgear router&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.9&amp;lt;/strike&amp;gt;  noel, alex's linux container on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.10&amp;lt;/strike&amp;gt; kyle, a linux container on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.11&amp;lt;/strike&amp;gt; stefen, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*192.168.1.15 Cisco 2950 switch&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.17 Cisco 4924 Switch-1 (main)&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.18 Cisco 4924 Switch-2&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.22 DES-3224&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.27 Who took this and didn't document?&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.31 not in use, but don't use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.33 iscsi server on [[vmsrv]]&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.34-35 Kenny servers&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.38 [[Driftnet]] laptop&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.39 open for use&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4152</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4152"/>
		<updated>2015-03-26T00:39:58Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Legacy IPs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  main Linksys/Netgear router&lt;br /&gt;
*192.168.1.9  noel, alex's linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.10 kyle, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.11 stefen, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*192.168.1.15 Cisco 2950 switch&lt;br /&gt;
*&amp;lt;strike&amp;gt;192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.17 Cisco 4924 Switch-1 (main)&lt;br /&gt;
*192.168.1.18 Cisco 4924 Switch-2&lt;br /&gt;
*192.168.1.22 DES-3224&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*192.168.1.27 Who took this and didn't document?&lt;br /&gt;
*192.168.1.31 not in use, but don't use&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*192.168.1.33 iscsi server on [[vmsrv]]&lt;br /&gt;
*192.168.1.34-35 Kenny servers&lt;br /&gt;
*192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*192.168.1.38 [[Driftnet]] laptop&lt;br /&gt;
*192.168.1.39 open for use&lt;br /&gt;
*192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4151</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4151"/>
		<updated>2015-03-26T00:39:34Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Legacy IPs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  main Linksys/Netgear router&lt;br /&gt;
*192.168.1.9  noel, alex's linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.10 kyle, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.11 stefen, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*192.168.1.15 Cisco 2950 switch&lt;br /&gt;
&amp;lt;strike&amp;gt;*192.168.1.16 Netgear GS108T workshop switch&amp;lt;/strike&amp;gt;&lt;br /&gt;
*192.168.1.17 Cisco 4924 Switch-1 (main)&lt;br /&gt;
*192.168.1.18 Cisco 4924 Switch-2&lt;br /&gt;
*192.168.1.22 DES-3224&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*192.168.1.27 Who took this and didn't document?&lt;br /&gt;
*192.168.1.31 not in use, but don't use&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*192.168.1.33 iscsi server on [[vmsrv]]&lt;br /&gt;
*192.168.1.34-35 Kenny servers&lt;br /&gt;
*192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*192.168.1.38 [[Driftnet]] laptop&lt;br /&gt;
*192.168.1.39 open for use&lt;br /&gt;
*192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
	<entry>
		<id>https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4150</id>
		<title>Networking</title>
		<link rel="alternate" type="text/html" href="https://wiki.skullspace.ca/index.php?title=Networking&amp;diff=4150"/>
		<updated>2015-03-26T00:38:58Z</updated>

		<summary type="html">&lt;p&gt;Sean: /* Current 172.30/16 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*Please keep an updated copy of this page printed out and posted in the server room, so there is access to documentation even if the network / internet is down&lt;br /&gt;
*Also see [[IT Policies]]&lt;br /&gt;
*We have many people working with the equipment, remember to attach or tie down anything that could get unplugged/fall/etc. We twice lost internet - first time the router fell and power switch got pressed, second time the power plug was pulled out of main internet switch.&lt;br /&gt;
*this page is finally being updated for Sksp2, old page is at [[Networking/Old]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== High-level description ==&lt;br /&gt;
&amp;lt;strike&amp;gt;The main router is a RB450G, connected to the main switch (port 2), security switch (4, later), internet feed (3), and other networks later. Main internal switch is a 3Com4924 in the server rack, feeds a GS108T at the lounge PC and a 5-port GigE switch near the meeting table. The main HP AP has SSID skullspace and is mounted on the roof in the middle of the space.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Stupid-High Level Diagram ==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
                                 +---------------------+                                        &lt;br /&gt;
                                 |    The Internet     |                                        &lt;br /&gt;
                                 | External CPE/Router |                                        &lt;br /&gt;
                                 |   206.220.196.49    |                  +--------------------+&lt;br /&gt;
                                 +---------^-----------+                  |                    |&lt;br /&gt;
                                           |                              |  dns.skullspace.ca |&lt;br /&gt;
                               +-----------v-----------+                  |   206.220.196.53   |&lt;br /&gt;
                               |   206.220.194.90/30   |                  +--^-----------------+&lt;br /&gt;
                               |  Skullspace+Router    &amp;lt;---------------+     |                  &lt;br /&gt;
                               | 172.30.6.1 172.30.7.1 |               |     |                  &lt;br /&gt;
                               +-----------^-----------+               |     |                  &lt;br /&gt;
                           Trunk Port      |                           |     |                  &lt;br /&gt;
+--------------------+          +----------v----------+     +----------v-----v----+             &lt;br /&gt;
|                    |          |                     |     |                     |             &lt;br /&gt;
|   Rest of the      &amp;lt;----------&amp;gt; Skullspace+Internal &amp;lt;-----&amp;gt; Skullspace+External |             &lt;br /&gt;
|   Internal LAN     |          |      172.30.6.2     |     |      172.30.6.3     |             &lt;br /&gt;
|                    |          +------^----^----^----+     +----------^----------+             &lt;br /&gt;
+--------------------+                 |    |    |                     |                        &lt;br /&gt;
                           Trunk Ports |    |    |               +-----v--------------+         &lt;br /&gt;
                                       |    |    |               |                    |         &lt;br /&gt;
                                       |    |    |               |   Rest of the      |         &lt;br /&gt;
                           +-----------+    |    +-----------+   |   External/PUBLIC  |         &lt;br /&gt;
                           |                |                |   |   LAN              |         &lt;br /&gt;
                           |                |                |   |                    |         &lt;br /&gt;
                           |                |                |   +--------------------+         &lt;br /&gt;
                           |                |                |                                  &lt;br /&gt;
                   +-------v-----+   +------v------+  +------v------+                           &lt;br /&gt;
                   | 172.30.6.10 |   | 172.30.6.11 |  | 172.30.6.12 |                           &lt;br /&gt;
                   |    WAP+A    |   |    WAP+B    |  |    WAP+C    |                           &lt;br /&gt;
                   | 172.30.7.10 |   | 172.30.7.11 |  | 172.30.7.12 |                           &lt;br /&gt;
                   +------+------+   +-------------+  +------+------+                           &lt;br /&gt;
                          |                                  |                                  &lt;br /&gt;
                   +------+------+                    +------+-----+                            &lt;br /&gt;
                   | 172.30.7.X  |                    | 172.30.7.Y |                            &lt;br /&gt;
                   |  client+X   |                    |  client+Y  |                            &lt;br /&gt;
                   |             |                    |            |                            &lt;br /&gt;
                   +-------------+                    +------------+                            &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Built using ASCIIFlow - http://http://asciiflow.com/&lt;br /&gt;
&lt;br /&gt;
== Internet feeds ==&lt;br /&gt;
Primary: Internet from VOI (wifi-based Ubiquity NB5, tested 60mbit down 40mbit up to Speedtest.net Winnipeg).&lt;br /&gt;
&lt;br /&gt;
== Network hardware ==&lt;br /&gt;
*Mikrotik Routerboard 450G as main router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Netgear WNDR3700 router, donated by [http://projectbismark.net Project Bismark]. It had a problem (routed packets fine but services like DHCP/DNS/web server didn't work) so was taken out of the network to test.&amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G2 v1.5 as spare. WAN port may sometime have packet loss. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT350N with DD-WRT v24SP2 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Linksys WRT54G v2 with tomato 1.28 firmware as a spare. Lent by Stef. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:A0) as the main switch, by default everything connects here.  &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;A 3Com 4924 (:??) a spare switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;2 D-Link DWL-810+ bridges. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Netgear GS108T as the lounge switch.&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DWL-7100AP AP. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;D-Link DES-3224 as a public IP switch, set to management only on port 7 (Telnet, username &amp;quot;D-Link&amp;quot;).&lt;br /&gt;
*&amp;lt;strike&amp;gt;A Belkin F5D8236 wireless-N router as spare &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;3 Cisco Aironet 1100 APs with .B cards and one (:90) with a .G card as spares. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*&amp;lt;strike&amp;gt;Belkin F5D5141-5 switch. &amp;lt;/strike&amp;gt;&lt;br /&gt;
*Cisco 2950 switches #1 and #2.&lt;br /&gt;
*Mikrotik RB750 (small white box) VOI's router&lt;br /&gt;
*&amp;lt;strike&amp;gt;Western Multiplex Tsunami 100 5.8ghz - two links (4x IDU, 2x high ODU, 2x low ODU) unused. Panel antenna loaned from Seccuris. &amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Wiring ==&lt;br /&gt;
Runs&lt;br /&gt;
A1+B1: from rack to wiring area on top of bathrooms, A2+B2 from wiring area on top of bathrooms to pole in front of classroom. One will be used to feed wifi AP.&lt;br /&gt;
C+D: from rack to next to a couch in lounge area. A wire goes under the nearby door to the wiring area of the space next door and above a window for the temporary garbage-cam.&lt;br /&gt;
E+F+G: from rack to area behind rear black desk.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tasks ==&lt;br /&gt;
*terminate ethernet lines correctly in a panel once we're sure server room is stable&lt;br /&gt;
*label networking equipment (IPs etc) and servers, update this page for the latter&lt;br /&gt;
*put read-only and full-access passwords on devices&lt;br /&gt;
&lt;br /&gt;
== Wireless Networks ==&lt;br /&gt;
skullspace = main SSID, usual password&lt;br /&gt;
&amp;lt;strike&amp;gt;skullspace_rear: linksys G router in the server rack, as a backup.&amp;lt;/strike&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
New IP Ranges&lt;br /&gt;
*172.30.4.x = testing/reserved for later use&lt;br /&gt;
*172.30.5.x = half Security/Management network  half VPNs&lt;br /&gt;
*172.30.6.x = Main network   DHCP  .100-.240  router .1  network gear .10-.29   printers .30-.39   VMs, servers .40-.99  VPNs .241-254&lt;br /&gt;
*172.30.7.x = CTF Network   DHCP ???   router .1&lt;br /&gt;
&lt;br /&gt;
== Internal IP usage ==&lt;br /&gt;
Check these&lt;br /&gt;
=== Legacy IPs ===&lt;br /&gt;
*192.168.1.1  main Linksys/Netgear router&lt;br /&gt;
*192.168.1.9  noel, alex's linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.10 kyle, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.11 stefen, a linux container on [[vmsrv]]&lt;br /&gt;
*192.168.1.12 Samsung CLP-310N printer&lt;br /&gt;
*192.168.1.15 Cisco 2950 switch&lt;br /&gt;
*192.168.1.16 Netgear GS108T workshop switch&lt;br /&gt;
*192.168.1.17 Cisco 4924 Switch-1 (main)&lt;br /&gt;
*192.168.1.18 Cisco 4924 Switch-2&lt;br /&gt;
*192.168.1.22 DES-3224&lt;br /&gt;
*192.168.1.26 [[vmsrv]]&lt;br /&gt;
*192.168.1.27 Who took this and didn't document?&lt;br /&gt;
*192.168.1.31 not in use, but don't use&lt;br /&gt;
*192.168.1.32 [[Skullhost]] on [[vmsrv]]&lt;br /&gt;
*192.168.1.33 iscsi server on [[vmsrv]]&lt;br /&gt;
*192.168.1.34-35 Kenny servers&lt;br /&gt;
*192.168.1.36 VPN server on [[vmsrv]] - contact Jay or Alex&lt;br /&gt;
*192.168.1.37 Ben's server&lt;br /&gt;
*192.168.1.38 [[Driftnet]] laptop&lt;br /&gt;
*192.168.1.39 open for use&lt;br /&gt;
*192.168.1.40 Pablodraw VM - http://picoe.ca/pablodraw/ for the client.&lt;br /&gt;
&lt;br /&gt;
=== Current 172.30/16 ===&lt;br /&gt;
*172.30.6.1  Micro-tik Router&lt;br /&gt;
*172.30.6.2  SkullSpace-External (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.3  SkullSpace-Internal (Cisco 2850 Switch)&lt;br /&gt;
*172.30.6.10 WAP-A (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.11 WAP-B (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.12 WAP-C (UniFI AP Management IP)&lt;br /&gt;
*172.30.6.16 Netgear GS108T&lt;br /&gt;
&lt;br /&gt;
*172.30.6.30 [[mumd|latest Ubuntu]] graphical shell service on [[vmsrv]]&lt;br /&gt;
*172.30.6.31-32 Mark's temporary project ips&lt;br /&gt;
*172.30.6.33 Wifi config app host&lt;br /&gt;
*172.30.6.40 [[vmsrv]]&lt;br /&gt;
&lt;br /&gt;
*172.30.6.50-53 Chris Otto Servers&lt;br /&gt;
*172.30.6.100-240  Main router DHCP space&lt;br /&gt;
*172.30.6.241-254  VPN IPs&lt;br /&gt;
&lt;br /&gt;
*172.30.7.1  Micro-tik Router (WIFI VLAN)&lt;br /&gt;
&lt;br /&gt;
== VOI IP usage ==&lt;br /&gt;
VOI gave us 206.220.196.48/28 (mask 255.255.255.240), 206.220.193.64/29 (mask 255.255.255.248) as well as 2604:4280:1:c0de::/64, you must reserve IPs here before using them. You'll need to plug into the new VOI-Static switch, currently a Cisco in the 'top' rack.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! IP&lt;br /&gt;
! DNS&lt;br /&gt;
! Use&lt;br /&gt;
! Contact&lt;br /&gt;
! used by?&lt;br /&gt;
! reason for public IP and notes&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.65&lt;br /&gt;
| TBD&lt;br /&gt;
| VOI router&lt;br /&gt;
| VOI&lt;br /&gt;
| all machines&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.66&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Mark temporary&lt;br /&gt;
| mark@markjenkins.ca&lt;br /&gt;
| Mark&lt;br /&gt;
| temporary ipsec test&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.67&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.68&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.69&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Richard's Server&lt;br /&gt;
| rjr point work at gmail&lt;br /&gt;
| &lt;br /&gt;
| development server, potentially Starbound server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.193.70&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  &lt;br /&gt;
|-&lt;br /&gt;
| Rev:  &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Chris's Server&lt;br /&gt;
| cotto at ieee point org&lt;br /&gt;
| &lt;br /&gt;
| development server, occasionally Terraria server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.49&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
| Rev:  h49-skullspace.winnipeg.voinetworks.net.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| VOI Mikrotik RB750? router&lt;br /&gt;
| VOI Networks&lt;br /&gt;
| now&lt;br /&gt;
| required by network design&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.50&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sksp Main Router&lt;br /&gt;
| CStanners a gmail.com or Sksp admins&lt;br /&gt;
| &lt;br /&gt;
|  &lt;br /&gt;
|-&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 206.220.196.51]&lt;br /&gt;
|[http://wiki.skullspace.ca/index.php?title=SKSP_DNS 2604:4280:1:c0de::53]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ns1.skullspace.ca (Pending)&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[SKSP DNS]]&lt;br /&gt;
| it@skullspace.ca&lt;br /&gt;
| 2014-10-08&lt;br /&gt;
| Skullspace Primary DNS Server&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.52&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.nepharia.org&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster Nepharia Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, OpenVPN, Asterisk, SSH &amp;amp; IRC, and HTTP for Nepharia and its associated domains.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.53&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &amp;lt;several&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev: mail.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster SkullSpace Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2012-02-17&lt;br /&gt;
| Runs DNS, SMTP/IMAP, SSH &amp;amp; IRC, and HTTP for SkullSpace.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.54&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: ctf.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Vobster CTF Services&lt;br /&gt;
| mak@kolybabi.com and dave@ysarro.com&lt;br /&gt;
| 2013-04-09&lt;br /&gt;
| Runs SSH-related services, for now.|&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.55&lt;br /&gt;
|| &lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Edwin Amsler&lt;br /&gt;
| edwinguy at gmail dot calm&lt;br /&gt;
| 2015-02-23&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.56&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin / Jeremy FreeBSD server&lt;br /&gt;
| phoul@insecure-complexity.com&lt;br /&gt;
| 2013-10-01&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.57&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| [[vmsrv]]&lt;br /&gt;
| mark@parit.ca&lt;br /&gt;
| 2012-08-27&lt;br /&gt;
| VM server open to all members, will run an http proxy to allow this one ip to host many web servers&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.58&lt;br /&gt;
| 2604:4280:1:c0de::314&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: intarweb.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Sean's server.&lt;br /&gt;
| sean _at_ tinfoilhat _dot_ ca&lt;br /&gt;
| 2013-09-27&lt;br /&gt;
| L2TP etc.&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.59&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ron's server&lt;br /&gt;
| ron @ skullsecurity.net&lt;br /&gt;
| Now&lt;br /&gt;
| Websites and stuff&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.60&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Colin's project server&lt;br /&gt;
| CStanners @ gmail&lt;br /&gt;
| Occasional&lt;br /&gt;
| IPv6, VPN services and testing&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.61&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: &lt;br /&gt;
|-&lt;br /&gt;
| Rev: &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| Ben's server&lt;br /&gt;
| ben@benbergman.ca&lt;br /&gt;
| 2012-12-18&lt;br /&gt;
| http/ssh/vpn/other&lt;br /&gt;
|-&lt;br /&gt;
| 206.220.196.62&lt;br /&gt;
|&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Fwd: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
| Rev: dangerzone.skullspace.ca&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
| The Danger Zone&lt;br /&gt;
| ctfadmin@&lt;br /&gt;
| 2012-06-01&lt;br /&gt;
| The home of the SkullSpace Teaching CTF.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Access ==&lt;br /&gt;
All members currently have full access to all devices. Later it may be a good idea to have different full-access passwords for all devices restricted to NetOps and by request, and the read-only password being publically known among our members.&lt;br /&gt;
&lt;br /&gt;
[[Category:Space]]&lt;br /&gt;
[[Category:Networking]]&lt;br /&gt;
[[Category:Required Reading]]&lt;/div&gt;</summary>
		<author><name>Sean</name></author>
		
	</entry>
</feed>