services:networking
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:networking [2021/03/12 15:54] – djgalloway | services:networking [2026/09/05 00:52] (current) – [Table] djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Networking ====== | ====== Networking ====== | ||
| - | ==== Networks ==== | + | ===== Networks |
| - | The Sepia internal LANs are divided up into four /20 networks (netmask 255.255.240.0) described below. | + | ^ Name ^ Purpose |
| - | | ^ front.sepia.ceph.com | + | | RDU Front Copy | Created to make lab migration easy | 172.21.0.0/20 | 100 | front.sepia.ceph.com |
| - | ^ Available IP Range | 172.21.0.1 - 172.21.15.250 | 172.21.16.1 - 172.21.31.250 | 172.21.32.1 - 172.21.47.250 | 172.21.48.1 - 172.21.63.250 | | + | | RDU IPMI Copy | Created to make lab migration easy | 172.21.32.0/20 | 102 | ipmi.sepia.ceph.com |
| - | ^ Gateway | + | | New Front | Server uplinks |
| - | ^ VLAN ID | 100 | 101 | + | | New IPMI | New server BMC | 10.20.208.0/ |
| - | ^ Use | Main Network interface | + | | VPN Clients |
| + | | LRC | Ceph Cluster Backend Storage Traffic | ||
| + | | Openshift Cluster | ||
| + | | Openshift Provision | ||
| + | | Openshift Clients | ||
| + | | ODF Public | ||
| + | | ODF Storage | ||
| + | | Public | ||
| + | | vlan104 | ||
| + | | vlan105 | ||
| + | | vlan106 | ||
| + | | vlan107 | ||
| + | The first IP of each is the gateway and the first 5 IPs should not be used (.0 through .4) | ||
| + | |||
| + | ==== Officinalis ==== | ||
| In January 2020, 4 new small subnets were created for the [[hardware: | In January 2020, 4 new small subnets were created for the [[hardware: | ||
| [[services: | [[services: | ||
| - | | ^ vlan104.sepia.ceph.com | + | ===== Firewall Rules ===== |
| - | ^ Available IP Range | + | |
| - | ^ Gateway | + | IBM OneIT manages the Juniper SRX in front of the lab. |
| - | ^ VLAN ID | 104 | + | |
| + | ^ Application Name ^ Inbound/ | ||
| + | | OpenVPN | ||
| + | | nginx / file share (e.g., https:// | ||
| + | | GitWeb | ||
| + | | githelper (https:// | ||
| + | | Etherpad (pad.ceph.com) | Inbound | ||
| + | | Pulpito (https:// | ||
| + | | qa-proxy.ceph.com | ||
| + | | sentry.ceph.com | ||
| + | | teuthology-api.ceph.com | ||
| + | | Dokuwiki (wiki.sepia.ceph.com) | Inbound | ||
| + | | Postorius & Hyperkitty | ||
| + | | Postfix (Ceph project mailing lists) | ||
| + | | telemetry.ceph.com (apache2) | ||
| + | | telemetry-public.ceph.com (nginx serving grafana) | ||
| + | | chacra.ceph.com (nginx) | ||
| + | | quay.ceph.io | ||
| + | | INBOUND OKAY TO BLOCK: 20,21, | ||
| + | | Outbound web traffic | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | rsync unsigned packages from chacra.ceph.com | Outbound | ||
| + | | rsync signed packages to download.ceph.com | ||
| + | | OUTBOUND OKAY TO BLOCK: 20,21, | ||
| + | | All non-blocklisted ports | ||
| + | | All, unrestricted | ||
| + | |||
| + | Firewall rules can be updated by following https:// | ||
| + | |||
| + | IES keeps [[https:// | ||
| - | ==== Hardware ==== | + | ===== Hardware |
| All the switches in the Sepia lab are either Juniper EX4300 1Gb or QFX5100 10Gb (SFP+) except: | All the switches in the Sepia lab are either Juniper EX4300 1Gb or QFX5100 10Gb (SFP+) except: | ||
| * A [[https:// | * A [[https:// | ||
| * A QFX5200 in A09 for the Officinalis nodes | * A QFX5200 in A09 for the Officinalis nodes | ||
| + | * An uplinked QFX5120 in B12 for the All Flash (name TBD) systems | ||
| + | * A NON-uplinked [[https:// | ||
| **The Sepia Networking core is === OUT === of 40G ports. | **The Sepia Networking core is === OUT === of 40G ports. | ||
| - | ==== Typical Switch config ==== | + | ===== Typical Switch config |
| In racks that only have 1Gb networking (e.g., [[hardware: | In racks that only have 1Gb networking (e.g., [[hardware: | ||
| * Ports 0-23 assigned to VLAN 100 (front) | * Ports 0-23 assigned to VLAN 100 (front) | ||
| Line 35: | Line 81: | ||
| The infra rack (houses RHEV, teuthology, gitbuilder.ceph.com), | The infra rack (houses RHEV, teuthology, gitbuilder.ceph.com), | ||
| - | ==== Switch Port Config Changes ==== | + | ===== Switch Port Config Changes |
| Red Hat IT manages all switches in the Sepia lab and switch port configuration changes should be submitted to [[servicedesk@redhat.com]]. | Red Hat IT manages all switches in the Sepia lab and switch port configuration changes should be submitted to [[servicedesk@redhat.com]]. | ||
| Line 54: | Line 100: | ||
| </ | </ | ||
| - | ==== Public IPs ==== | + | ===== Public IPs ===== |
| The Community Cage has a block of public IPs dedicated to it. Ceph's usable IPs are 8.43.84.129 - 8.43.84.186. | The Community Cage has a block of public IPs dedicated to it. Ceph's usable IPs are 8.43.84.129 - 8.43.84.186. | ||
| Line 72: | Line 118: | ||
| | 8.43.84.141 | | 8.43.84.141 | ||
| - | ==== IPv6 ==== | + | ===== IPv6 ===== |
| IPv6 was enabled on 12/11/2018. | IPv6 was enabled on 12/11/2018. | ||
| Our subnet is '' | Our subnet is '' | ||
| Our default gw is '' | Our default gw is '' | ||
services/networking.1615564465.txt.gz · Last modified: by djgalloway
