Primary IT Infrastructure: Difference between revisions

From HackRVA
Jump to navigation Jump to search
(Page needs updates.)
 
(50 intermediate revisions by 5 users not shown)
Line 1: Line 1:
Please check back with this page, as we are in the process of populating good information, relating to how to get the most out of your HackRVA data experience.
Hack.rva provides community wifi and lan drops in all rooms, as well as a few in house hosted services. All traffic is monitored by a snorby server that checks for illegal torrents, bots and other malware.


= The primary network architecture =
At HackRVA we utilize a switched network with vlans and VoIP support.
We have a dedicated smart-switch, a router and a Virtulization Server which runs our web services, and groupware.
== Network Topology ==
=== Network Diagram ===
[[File:HRVA_topology.jpg]]


----
----


===Layer 2 and Layer 3===
==== VLANs (802.1q tags) ====
At HackRVA we have a segmented network using vlans for segregation of traffic.
;VLAN-1
:*the management vlan
:*houses the management end-points for primary services.
;VLAN-100
:*the voip vlan, specifically intended to have all voip traffic.
;VLAN-200
:*the vlan for hackrva-wireless, and is the vlan which you will be assigned to, if access the hackrva-wireless ssid.
;VLAN-300
:*the vlan for all wired network infrastructure, and is also the vlan for network services such as email, and dns, as well as network printers.


===TCP/IP Layer and 802.1q label assignment===
[[File:serverrack.jpg]]
====Address Space (IPv4)====
At HackRVA we have subneting that is assigned to specific vlans.
;VLAN-1 : subnet 192.168.10.0/24
;VLAN-100 :subnet 192.168.100.0/24
;VLAN-200 :subnet 192.168.200.0/24
;VLAN-300 :subnet 192.168.30.0/24


====Address Space (IPv6)====
HackRVA does not currently utilize IPv6 address space.


==== Wireless SSID List====
----
At Hackrva, we utilize three ssids for specific access to services, which is relevant for different types of users.
<blockquote><span style="color: red;">''Entire page needs to be updated''</span></blockquote>
#hackrva-wireless
#*(vlan-200)
#*General access to internet services only
#hackrva-lan
#*(vlan-300)
#*This is used for member access to all services within Hackrva's internal network.
#*If a peripheral device is connected to the Layer 3 network, and hence connected on vlan-300, then this device will only be accessible via wireless on hackrva-lan ssid.<br>
#hackrva-admin
#*(vlan-1)
#*Used for management purposes, when connecting via the wireless network layer.


== Network Devices ==
----
The HackRVA network is comprised of four primary network infrastructure devices.
===CPE devices===
====SMC Business Gateway====
HackRVA uses comcast business class service with static IPv4 provisioned<br>
The device provided for this service is the SMC Networks SMCD3GCCR business gateway.<br>
The device provides a four port switch, for easy integration into our network architecture.<br>
[[File:SMCD3GCCJR.JPG]]


===Cisco RV180 VPN Router===
==About==
The RV180 VLAN-enabled VPN SOHO router is the brains of the internal network architecture.<br>
-more info coming-
This device provides dhcp to clients on the internal LAN as well as NAT functionlaty for accessing the internet from behind the cable modem.<br>
To understand what vlan capabilities are being used as the space, please reference the VLAN section, below.<br><br>
[[File:RV180VPN Front-REAR.jpg]]<br>


===Ubiquiti Wireless AP===
(This page is somewhat out of date. The server has been upgraded.)
The wireless services are provided by a commerical-grade wireless access point.<br>
----
The access point requires management software installed on a Windows computer, or Linux (with much more work).<br>
[[File:Ubiquiti UniFi-AP.jpg]]<br>
'''CAUTION''' <br>
:* '''Do not plug IEEE standar PoE devices into the output of the supplied Ubiquiti PoE adaptor, or the converse.'''<br>
:* '''The Unifi model that is in use does not comply with IEEE standards based PoE voltages.'''


===NetGear 24-port smart-switch===
==Topology==
This device is referenced by Netgear as the GS724T-300 smart-switch.<br>
This device is capable of vlan tagged ports, as well as port trunking.<br>
[[File:NetGear-GS724Tv2.jpg]]


===Cisco 2651 Series Router===
A crude Network topology by John V.
We have a Cisco 2651xm router which provides all major routing features that are configured on the HackRVA network.<br>
[[File:Cisco-2651.jpg]]
[[file:Net_diagram.png]]


==Network Services==
----
===Domain Name Services (dns)===
==Network Appliances==
HackRVA currently hosts its own domain name services, or "DNS."<br>
Authoritative dns services are supplied to the following domains.


====hackrva.org====
*'''Modem''' - Motorola Surfboard 575186
*lists - hosted offsite, at this time.
*'''Firewall''' - custom PFSense box
*mail
*'''Switch''' - Netgear GS724T
*www
*'''Wifi AP''' - Ubiquity Unifi AP
*imap
*ftp
*listserver
*mobilsync
*smtp
*testweb
*zmail
*zmailserver


====hackrva.net====
----
(Not currently hosted on our dns servers, however this should change soon.)
==Networked Equipment==


====hackrva.us====
*'''[[Proxmox virtualization Node]]'''
*list
-An in house solution to keep the number of physical machines running various services down to a minimum. Rocking dual 12 thread Xeons and 48gb of ram, this thing provides all of our virtualzation needs. Runs Proxmox 4.4
*mail
*'''Networked Attached Storage'''
*www
-The NAS was built out of spare parts donated by several members and has 4 1tb WD greens in a zfs raid 5.
*imap
*'''[[Digital Design Workstation]]'''
*ftp
-Donated by Michael, the Digital Design station is rocking a q6600, 6gb of ddr2, and a Radeon HD 5770, this machine is the work horse for all of our design and manufacturing equipment. This including the CNC router, 3D printers and laser cutter.
*listserver
*'''Wall of monitors machine'''
*mobilsync
-What started off as a separate dev machine, The wall of monitors machine was Aaron's Idea because he wanted to sit in front of a machine that drove 9 screens running off of one tower.
*smtp
*'''TV PC'''
*testweb
A Raspberry Pi model B 1st gen, hooked to the large plasma screen display good for digital signage or just a secondary screen
*zmail
*'''Chromecast'''
*zmailserver
- simple streaming stick that stays plugged in the HDMI switch for broadcasting things wirelessly to the projector, Works best with the Chrome browser.


====hackrva.info====
----
*list
*mail
*www
*imap
*ftp
*listserver
*mobilsync
*smtp
*testweb
*zmail
*zmailserver
 
===Dynamic Host Control Protocol (dhcp)===
The dhcp services are managed by the RV180 VPN router.
 
===Network Time Protocol (ntp)===


===File Transfer Protocol (ftp)===
==Services==
*'''LAN games'''
-We host our own Minecraft Server @ minecraft.hackrva.org:25565


===VoIP===
-Saturday nights tends to turn into Age Of Emipres 3 lan gaming
===www===
===EMail===
===VPN===


= Servers and Workstations=
-Occasionally an Artemis game gets played though, not too often any more
*[[Primary Servers]]
*'''Community storage'''
*[[Primary Workstations]]
-We have a 4tb NAS for community use, It holds  a fair amount of various Operating system ISOs and other wise is a hub for hackrva related files
*'''Virtualization'''
We have a in house hypervisor machine for public use after training.
*'''Cad software'''
The digital design station is full to the brim with different CAD software, the main suite being Auto desk products


=Power Management=
==History==
==Battery Backup Devices==
We have been supporting our network infrastructure, and servers with an entry-level server UPS from CyberPower since August 2013.
===CyberPower OR700LCDRM1U===
The CyberPower Smart App LCD 700VA Line-Interactive UPS with AVR, provides line conditioning, and other features which allow HackRVA to maintain a good uptime, in leu of power outages.<br>
[[File:Cyberpower 700VA-400W UPS Accessories View.jpg]]<br>




====Key Information====
<blockquote><span style="color: red;">''This section needs to be updated''</span></blockquote>
[[File:CyberPower-OR700LCDRM1U UPS INFO View.jpg]]<br>
[[File:CyberPower-OR700LCDRM1U-UPS-Rear-View.jpg]]


==Power Distributors==


=Racks and Cabinets=
The network at hackrva started out as a just a WRT54GL named "robot king" and a fall back AP named "robot queen". They had to be rebooted almost weekly due to the constant traffic and numerous DHCP problems. These devices ran out of address space very quickly.


At HackRVA Labs, Inc. we have two racks, or "cabinets" in use.<br>
One is a 36U full depth data server cabinet.<br>
==Enclosures==


===NORCO Rack===
Thus a beefier network needed to be created. A more reliable network was created with enterprise grade gear and, in a lot of ways, this network became the model of what is currently in place.
:And the other is a Norco 9U netMwork cabinet.<br>
:[[File:Norco-9u-enclosure.jpg]]<br>
[[File:HackRVALabs-Wallmount-Rack.jpg]] <br>


=Computer Lab Systems=
*[[Computer Lab]]


=Historical Reference=
Many hands are involved in maintaining the network, running network cabling throughout the space and ensuring minimal downtime.
*[[Primary Network 1.0]]
The equipment at the space is there to be used. If you would like access to a VM or would like to contribute to the maintenance of the infrastructure, please email HackRATnetworkRats@googlegroups.com
*[[Primary Network 2.0]]
*[[Primary Network 2.1]]
*[[Primary Network 2.2]]
*[[Primary Network 2.3]]
*[[Primary Network 2.4]]
*[[Primary Network 2.5]]

Latest revision as of 21:34, 4 August 2019

Hack.rva provides community wifi and lan drops in all rooms, as well as a few in house hosted services. All traffic is monitored by a snorby server that checks for illegal torrents, bots and other malware.




Serverrack.jpg



Entire page needs to be updated


About

-more info coming-

(This page is somewhat out of date. The server has been upgraded.)


Topology

A crude Network topology by John V.

Net diagram.png


Network Appliances

  • Modem - Motorola Surfboard 575186
  • Firewall - custom PFSense box
  • Switch - Netgear GS724T
  • Wifi AP - Ubiquity Unifi AP

Networked Equipment

-An in house solution to keep the number of physical machines running various services down to a minimum. Rocking dual 12 thread Xeons and 48gb of ram, this thing provides all of our virtualzation needs. Runs Proxmox 4.4

  • Networked Attached Storage

-The NAS was built out of spare parts donated by several members and has 4 1tb WD greens in a zfs raid 5.

-Donated by Michael, the Digital Design station is rocking a q6600, 6gb of ddr2, and a Radeon HD 5770, this machine is the work horse for all of our design and manufacturing equipment. This including the CNC router, 3D printers and laser cutter.

  • Wall of monitors machine

-What started off as a separate dev machine, The wall of monitors machine was Aaron's Idea because he wanted to sit in front of a machine that drove 9 screens running off of one tower.

  • TV PC

A Raspberry Pi model B 1st gen, hooked to the large plasma screen display good for digital signage or just a secondary screen

  • Chromecast

- simple streaming stick that stays plugged in the HDMI switch for broadcasting things wirelessly to the projector, Works best with the Chrome browser.


Services

  • LAN games

-We host our own Minecraft Server @ minecraft.hackrva.org:25565

-Saturday nights tends to turn into Age Of Emipres 3 lan gaming

-Occasionally an Artemis game gets played though, not too often any more

  • Community storage

-We have a 4tb NAS for community use, It holds a fair amount of various Operating system ISOs and other wise is a hub for hackrva related files

  • Virtualization

We have a in house hypervisor machine for public use after training.

  • Cad software

The digital design station is full to the brim with different CAD software, the main suite being Auto desk products

History

This section needs to be updated


The network at hackrva started out as a just a WRT54GL named "robot king" and a fall back AP named "robot queen". They had to be rebooted almost weekly due to the constant traffic and numerous DHCP problems. These devices ran out of address space very quickly.


Thus a beefier network needed to be created. A more reliable network was created with enterprise grade gear and, in a lot of ways, this network became the model of what is currently in place.


Many hands are involved in maintaining the network, running network cabling throughout the space and ensuring minimal downtime. The equipment at the space is there to be used. If you would like access to a VM or would like to contribute to the maintenance of the infrastructure, please email [email protected]