services:networking
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:networking [2021/05/25 19:19] – [Hardware] djgalloway | services:networking [2026/09/05 00:52] (current) – [Table] djgalloway | ||
|---|---|---|---|
| Line 3: | Line 3: | ||
| ===== Networks ===== | ===== Networks ===== | ||
| - | The Sepia internal LANs are divided up into four /20 networks (netmask 255.255.240.0) described below. | + | ^ Name ^ Purpose |
| - | | ^ front.sepia.ceph.com | + | | RDU Front Copy | Created to make lab migration easy | 172.21.0.0/20 | 100 | front.sepia.ceph.com |
| - | ^ Available IP Range | 172.21.0.1 - 172.21.15.250 | 172.21.16.1 - 172.21.31.250 | 172.21.32.1 - 172.21.47.250 | 172.21.48.1 - 172.21.63.250 | | + | | RDU IPMI Copy | Created to make lab migration easy | 172.21.32.0/20 | 102 | ipmi.sepia.ceph.com |
| - | ^ Gateway | + | | New Front | Server uplinks |
| - | ^ VLAN ID | 100 | 101 | + | | New IPMI | New server BMC | 10.20.208.0/ |
| - | ^ Use | Main Network interface | + | | VPN Clients |
| + | | LRC | Ceph Cluster Backend Storage Traffic | ||
| + | | Openshift Cluster | ||
| + | | Openshift Provision | ||
| + | | Openshift Clients | ||
| + | | ODF Public | ||
| + | | ODF Storage | ||
| + | | Public | ||
| + | | vlan104 | ||
| + | | vlan105 | ||
| + | | vlan106 | ||
| + | | vlan107 | ||
| - | In January 2020, 4 new small subnets were created for the [[hardware: | + | The first IP of each is the gateway and the first 5 IPs should not be used (.0 through .4) |
| ==== Officinalis ==== | ==== Officinalis ==== | ||
| + | In January 2020, 4 new small subnets were created for the [[hardware: | ||
| [[services: | [[services: | ||
| - | | ^ vlan104.sepia.ceph.com | + | ===== Firewall Rules ===== |
| - | ^ Available IP Range | + | |
| - | ^ Gateway | + | IBM OneIT manages the Juniper SRX in front of the lab. |
| - | ^ VLAN ID | 104 | + | |
| + | ^ Application Name ^ Inbound/ | ||
| + | | OpenVPN | ||
| + | | nginx / file share (e.g., https:// | ||
| + | | GitWeb | ||
| + | | githelper (https:// | ||
| + | | Etherpad (pad.ceph.com) | Inbound | ||
| + | | Pulpito (https:// | ||
| + | | qa-proxy.ceph.com | ||
| + | | sentry.ceph.com | ||
| + | | teuthology-api.ceph.com | ||
| + | | Dokuwiki (wiki.sepia.ceph.com) | Inbound | ||
| + | | Postorius & Hyperkitty | ||
| + | | Postfix (Ceph project mailing lists) | ||
| + | | telemetry.ceph.com (apache2) | ||
| + | | telemetry-public.ceph.com (nginx serving grafana) | ||
| + | | chacra.ceph.com (nginx) | ||
| + | | quay.ceph.io | ||
| + | | INBOUND OKAY TO BLOCK: 20,21, | ||
| + | | Outbound web traffic | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | Jenkins agent SSH to Jenkins controller | ||
| + | | rsync unsigned packages from chacra.ceph.com | Outbound | ||
| + | | rsync signed packages to download.ceph.com | ||
| + | | OUTBOUND OKAY TO BLOCK: 20,21, | ||
| + | | All non-blocklisted ports | ||
| + | | All, unrestricted | ||
| + | |||
| + | Firewall rules can be updated by following https:// | ||
| + | |||
| + | IES keeps [[https:// | ||
| ===== Hardware ===== | ===== Hardware ===== | ||
| Line 25: | Line 67: | ||
| * A [[https:// | * A [[https:// | ||
| * A QFX5200 in A09 for the Officinalis nodes | * A QFX5200 in A09 for the Officinalis nodes | ||
| - | * A QFX5120 in B12 for the All Flash (name TBD) systems | + | * An uplinked |
| + | * A NON-uplinked [[https:// | ||
| **The Sepia Networking core is === OUT === of 40G ports. | **The Sepia Networking core is === OUT === of 40G ports. | ||
services/networking.1621970359.txt.gz · Last modified: by djgalloway
