Skip to content

Networking Architecture

Overview

The network uses the private 10.0.0.0/8 address space.

Addresses follow this convention:

10.X.Y.Z
  • X identifies a logical segmentation that will eventually become VLANs.
  • Y identifies the site location:
  • 69 — local network
  • 96 — cloud network
  • Z identifies the host.

Currently, all local hosts share the 10.0.0.0/8 network and use 10.0.0.1 as their gateway. After VLAN implementation, 10.0.0.1 will remain the primary router, but each VLAN will use a logical interface with its own dedicated gateway address, i.e. 10.X.Y.1.

Segments

ID Name Purpose
0 MGMT Network infrastructure only. VLAN ID 1000
22 GUEST Untrusted guest devices and temporary access
42 HOME Trusted personal computers, phones, and general-purpose devices
44 IOT Smart-home and other Internet-of-Things devices
69 LAB Servers, virtual machines, containers, and development infrastructure
169 CSYNC Corosync cluster traffic and related cluster communication

The segment identifier is represented by X in the address format 10.X.Y.Z. VLAN IDs will match the segment identifier with the exception of segment 0.

Local Network Addressing

Local networks use Y=69.

Segment Name Subnet Future gateway
22 GUEST 10.22.69.0/24 10.22.69.1
42 HOME 10.42.69.0/24 10.42.69.1
44 IOT 10.44.69.0/24 10.44.69.1
69 LAB 10.69.69.0/24 10.69.69.1
169 CSYNC 10.169.69.0/24 10.169.69.1

Until VLANs are implemented, 10.0.0.1 is the gateway for all local addresses.

Local Address Allocation

The following allocation is in use:

Range Intended use
.1 Gateway
.2-.99 Static hosts
.100-.254 DHCP pool

All local segments use this allocation, regardless of whether any DHCP hosts currently exist or are expected.

Cloud Network Addressing

The cloud is an intentionally minimal environment to reduce costs.

Network Subnet Gateway
Cloud LAB 10.69.96.0/24 10.69.96.1

Cloud hosts should use static addresses only, and thus no DHCP pool is reserved nor is DHCP service available.

No additional cloud VLANs are planned at this time. If additional cloud segmentation becomes necessary, it should use the same convention as local.

Firewall Policy

The firewall should use a default-deny policy for traffic between security zones. Rules should be evaluated from most specific to least specific.

Baseline Rules

Source ➡ Destination Action Notes
Any ➡ Any Allow established and related Required for return traffic
Any ➡ Any Drop invalid
Any ➡ Any Drop Default deny
Any ➡ Firewall Allow required management services Restrict to only necessary hosts

Inter-VLAN Rules

Source ➡ Destination Action Notes
HOME ➡ LAB Allow selected services Prefer service-specific ports and hosts
HOME ➡ IOT Allow selected control services Permit only required device-management protocols
HOME ➡ GUEST Deny Guest devices are not trusted
IOT ➡ HOME Deny Prevent IoT devices from initiating access to trusted devices
IOT ➡ LAB Deny by default Permit only explicitly required services
GUEST ➡ HOME Deny Mandatory guest isolation
GUEST ➡ IOT Deny Mandatory guest isolation
GUEST ➡ LAB Deny Mandatory guest isolation
LAB ➡ HOME Deny by default Permit only documented administrative or application flows
LAB ➡ IOT Deny by default Permit only required automation or management flows
LAB ➡ LAB Allow as required Apply host-level firewalls and service restrictions
CSYNC ➡ CSYNC Allow Corosync traffic Restrict to cluster members only
CSYNC ➡ Any other network Deny Corosync should not be routable to general-purpose networks

Internet Egress

As a baseline policy, all hosts except those in CSYNC may initiate outbound internet connections unrestricted. This should likely be revisited later.

Local-to-Cloud and Cloud-to-Local Rules

Cloud resources are publicly routable and as such should be considered as external connections.

External-to-Local Rules

The local environment is treated as a restricted zone. The local firewall must never permit an externally initiated connection except as follows.

Condition Protocol Destination port Action
Connection state is ESTABLISHED or RELATED Any Any Allow
New connection TCP 443 Allow, forward to Traefik
New connection TCP 22 Allow, forward to bastion-host
All other incoming connections Any Any Deny