Networking Architecture¶
Overview¶
The network uses the private 10.0.0.0/8 address space.
Addresses follow this convention:
Xidentifies a logical segmentation that will eventually become VLANs.Yidentifies the site location:69— local network96— cloud networkZidentifies the host.
Currently, all local hosts share the 10.0.0.0/8 network and use 10.0.0.1 as their gateway. After VLAN implementation, 10.0.0.1 will remain the primary router, but each VLAN will use a logical interface with its own dedicated gateway address, i.e. 10.X.Y.1.
Segments¶
| ID | Name | Purpose |
|---|---|---|
| 0 | MGMT |
Network infrastructure only. VLAN ID 1000 |
| 22 | GUEST |
Untrusted guest devices and temporary access |
| 42 | HOME |
Trusted personal computers, phones, and general-purpose devices |
| 44 | IOT |
Smart-home and other Internet-of-Things devices |
| 69 | LAB |
Servers, virtual machines, containers, and development infrastructure |
| 169 | CSYNC |
Corosync cluster traffic and related cluster communication |
The segment identifier is represented by X in the address format 10.X.Y.Z. VLAN IDs will match the segment identifier with the exception of segment 0.
Local Network Addressing¶
Local networks use Y=69.
| Segment | Name | Subnet | Future gateway |
|---|---|---|---|
| 22 | GUEST |
10.22.69.0/24 |
10.22.69.1 |
| 42 | HOME |
10.42.69.0/24 |
10.42.69.1 |
| 44 | IOT |
10.44.69.0/24 |
10.44.69.1 |
| 69 | LAB |
10.69.69.0/24 |
10.69.69.1 |
| 169 | CSYNC |
10.169.69.0/24 |
10.169.69.1 |
Until VLANs are implemented, 10.0.0.1 is the gateway for all local addresses.
Local Address Allocation¶
The following allocation is in use:
| Range | Intended use |
|---|---|
.1 |
Gateway |
.2-.99 |
Static hosts |
.100-.254 |
DHCP pool |
All local segments use this allocation, regardless of whether any DHCP hosts currently exist or are expected.
Cloud Network Addressing¶
The cloud is an intentionally minimal environment to reduce costs.
| Network | Subnet | Gateway |
|---|---|---|
Cloud LAB |
10.69.96.0/24 |
10.69.96.1 |
Cloud hosts should use static addresses only, and thus no DHCP pool is reserved nor is DHCP service available.
No additional cloud VLANs are planned at this time. If additional cloud segmentation becomes necessary, it should use the same convention as local.
Firewall Policy¶
The firewall should use a default-deny policy for traffic between security zones. Rules should be evaluated from most specific to least specific.
Baseline Rules¶
| Source | ➡ | Destination | Action | Notes |
|---|---|---|---|---|
| Any | ➡ | Any | Allow established and related | Required for return traffic |
| Any | ➡ | Any | Drop invalid | |
| Any | ➡ | Any | Drop | Default deny |
| Any | ➡ | Firewall | Allow required management services | Restrict to only necessary hosts |
Inter-VLAN Rules¶
| Source | ➡ | Destination | Action | Notes |
|---|---|---|---|---|
HOME |
➡ | LAB |
Allow selected services | Prefer service-specific ports and hosts |
HOME |
➡ | IOT |
Allow selected control services | Permit only required device-management protocols |
HOME |
➡ | GUEST |
Deny | Guest devices are not trusted |
IOT |
➡ | HOME |
Deny | Prevent IoT devices from initiating access to trusted devices |
IOT |
➡ | LAB |
Deny by default | Permit only explicitly required services |
GUEST |
➡ | HOME |
Deny | Mandatory guest isolation |
GUEST |
➡ | IOT |
Deny | Mandatory guest isolation |
GUEST |
➡ | LAB |
Deny | Mandatory guest isolation |
LAB |
➡ | HOME |
Deny by default | Permit only documented administrative or application flows |
LAB |
➡ | IOT |
Deny by default | Permit only required automation or management flows |
LAB |
➡ | LAB |
Allow as required | Apply host-level firewalls and service restrictions |
CSYNC |
➡ | CSYNC |
Allow Corosync traffic | Restrict to cluster members only |
CSYNC |
➡ | Any other network | Deny | Corosync should not be routable to general-purpose networks |
Internet Egress¶
As a baseline policy, all hosts except those in CSYNC may initiate outbound internet connections unrestricted. This should likely be revisited later.
Local-to-Cloud and Cloud-to-Local Rules¶
Cloud resources are publicly routable and as such should be considered as external connections.
External-to-Local Rules¶
The local environment is treated as a restricted zone. The local firewall must never permit an externally initiated connection except as follows.
| Condition | Protocol | Destination port | Action |
|---|---|---|---|
Connection state is ESTABLISHED or RELATED |
Any | Any | Allow |
| New connection | TCP | 443 |
Allow, forward to Traefik |
| New connection | TCP | 22 |
Allow, forward to bastion-host |
| All other incoming connections | Any | Any | Deny |