Jump to content

Network layout showoff

Ssoele

I made a number of changes since my last post...

 

[diagram redacted]

 

For the most part, connections are 1GbE over copper (however many connections use link aggregation/etherchannel). Except for one of the storage servers, which is connected at 10GbE to the Cisco 3650 using fiber, and most of IOT devices (such as the speakers and bridge devices) and surveillance cameras are on 100mbps links. 

 

The network has 3 primary VLANs; one for management, one for most devices and a third one for guest. It also has another isolated VLAN for testing purposes. I do plan on adding a couple more VLANs in the near future for security purposes. Like a VLAN for the cameras that has no internet access and a VLAN for the phones that is prioritized over the network. Also, the Cisco 3750-X may be a layer 3 switch and has an IP Base license, but it is currently only used as a layer 2 access switch (no routing) for devices powered via POE.

 

There are also 3 WiFi SSIDs being broadcasted, a (WPA2 Enterprise) SSID for most devices (such as mobiles devices and laptops), a (WPA2 PSK) SSID for IOT devices and a (Open) SSID for Guests. I used to use Cisco ISE as a RADIUS server, NAC and as a captive portal for the guest WiFi, but now I just use Windows NPS and the built in captive portal in the Cisco WLC cause I corrupted the ISE installation by abruptly disconnecting the ESXi host from the NFS share (where the ISE VM was running from).

 

I only have one relatively small ESXi host at home (E3-1231v3 32GB RAM) because I run the majority of my VMs offsite and use site-to-site VPN tunnels to have those VMs virtually present on my network. The local ESXi host mainly runs a Windows server with active directory replication and a bunch of other random small VMs. The only services that are hosted in my home that are accessible publicly is my Plex server and my OpenVPN server.

 

Network monitoring is currently only done using PRTG, the Meraki Dashboard, and the Palo Alto Networks firewall WebGUI (and also ssh-ing directly into network switches). I plan on adding others in the future, such as InfluxDB or Prometheus with Grafana and ELK stack. Maybe also an IDS, such as Bro or Suricata. Cisco Stealthwatch would be cool to add but it costs way way too much.

 

There are also a few network devices in my diagram (like a number of the surveillance cameras and the surveillance server) that have not been set up yet and are just sitting on a desk right now. I plan on having those up soon.

Edited by Cree340

My Build : AMD Ryzen 9 3950X - Asus Strix X570-E - 64GB G.Skill Trident Z Neo

- Gigabyte RTX 3080 Ti - 2TB Samsung 970 Evo Plus SSD - Corsair AX860i Power Supply

 

Link to comment
Share on other sites

Link to post
Share on other sites

  • 3 weeks later...

My small network:

 

The router is sitting in the basement with the two virtualization hosts. Primary uplink is the cable television. Had once a dead router after a thunderstorm so I went the fiber  route here. Cable is sometime not available so I need LTE as Failover but the reception in the basement is low.

 

Network.thumb.png.62c2c3dbb1cb9187bc5e157402c609af.png

 

The HyperV hosts are running two server 2016 domain controller, a 3cx phone system, hmailserver, Unifi controller and my vpn access.

WIFI is using WPA2 Enterprise with radius assigned vlan. There are with the security cameras, I/O Cards for the home automatisation, TVs and some PCs about 30 wired clients in the network

Link to comment
Share on other sites

Link to post
Share on other sites

  • 4 weeks later...
  • 2 weeks later...

WARNING! It's A LONG POST SO BRACE YOURSELVES!!!! 

 

Father's House (Server location)

  • ISP provided the modem and Router/AP
  • Cisco Switch (Catalyst 2950 series) - provided my dad's colleague who is a legend in my eyes (even though I've never met him). Is only 10/100 as wasn't meant to be permanent but my cheap 8-port gigabit LAN switch from Amazon died after about 4 years.
  • TP-Link Gigabit LAN -  brought to replace a crappy one from 2003.
  • Powerline adapters are 300mbps so my sister, my dad and I can have fast file transfers while my other sister is gaming.
  • OnNetworks APs (both Houses) - slow, unintuitive web UI, and drops out on any devices plugged into it (wireless is stable for once)
  • Server
    • Spare gigabyte board I had lying around with an Intel core i3 2120 @ 3.30GHz, 6 GB of RAM, 3.5TB of storage, onboard Gigabit LAN and a TP-link PCI (not PCI-E otherwise the HP card would be in here) Gigabit LAN card.
    • 3TB WD Red - Pulled from a WD my cloud (didn't have the functionality I needed, and it needed a separate machine for plex)
    • 500GB Seagate - pulled from Cable TV box that was brought by us (Only paid for extra channels as a monthly subscription)
    • Windows Server 2016 
  • The office PC is another gigabyte board with an Intel core i3 3220 @3.30GHz, 8GB RAM, 250GB HDD (boot), 500GB HDD (primary storage), 1TB HDD (secondary storage), onboard gigabit LAN and a Radeon R5 230 from Asus.
  • Some ASRock board (my sister brought it online, second hand, (was 75% brown dust till I came along and cleaned it)

Mother's House (where I live on weekdays)

  • both switches are TP-link 5port 10/100mbps 
  • My Room
    • FYI I can still access my file server from here I just have to use a VPN
    • Domain laptop - Dell Latitude D630 4GB RAM, 500GB HDD (was from my main one as it was dying (kept on BSODing) but I wasn't worried about space on my main so I swapped the drives and reinstalled windows on them.
    • Main Laptop - Dell Latitude E6410 8GB RAM, 80GB HDD (both Dell's have Gigabit LAN)
    • Linux Test Bench - My sister's old Toshiba laptop 4GB RAM, 320GB HDD (CBA to put it in my main)
    • My PC - Biostar (with a soldered on Celeron CPU), 5GB RAM, 160GB HDD (boot), 250GB HDD (storage), HP enterprise dual gigabit LAN PCI-E card. 
  • I still have to rebuild my step-dad's PC because it was a HP prebuilt but the PSU failed and nuked the board (RAM, GPU and HDD are confirmed fine but have no way to test the AMD CPU as I'm more of an intel guy TBH)

 

If you read all that, you deserve a snack

WAN Map.PNG

Link to comment
Share on other sites

Link to post
Share on other sites

Here is my updated network. I've added another 2 Servers which are running as VMs

 

 

Network.png

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 9/2/2018 at 3:54 PM, Lurick said:

Made some updates and whatnot

 

 

 

Spoiler

683WvtR.jpg

 

 

 

 

 

Spoiler

fyZM0iU.jpg

raspberry Pi 1

 

 

How old are those RPI's?  I had a RPI3 Model B running 24/7 (it was running apt-mirror once a day)  and the darn thing died on me....

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, jagdtigger said:

How old are those RPI's?  I had a RPI3 Model B running 24/7 (it was running apt-mirror once a day)  and the darn thing died on me....

I think they are about 4 years old at this point. They are the RPI2 Model B iirc

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Lurick said:

I think they are about 4 years old at this point. They are the RPI2 Model B iirc

Nice, my rpi3b lasted for about 2 years. A HP office PC took its place(260-a101ng, im currently trying to get ESXi recognize the internal HDD, currently im using it with a NFS mount until i fix the issue.

Link to comment
Share on other sites

Link to post
Share on other sites

It's slow as ass but the other alternative would to be not having internet at all on my desktop and I'd rather have some experience resembling what I'm used to.

5b9201d8a8457_networksummer2018.png.c068b51c78aa258b3671d44c516f6d27.png

also you're welcome for this top notch diagram of my network, created with the best program known to man. Microsoft Paint.

a Moo Floof connoisseur and curator.

:x@handymanshandle x @pinksnowbirdie || Jake x Brendan :x
Youtube Audio Normalization
 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Thats the logical side of it, physically we have Cat.6 sockets in every room, Cat.7 cable and everything nice and tidy in a little rack. I have to use my ISPs ONT, not pictured in there (imagine as the cloud). For the AP-AC-LR we have another Cat.7 running in the floor below, as well as a LWL for future use. Also another LWL in the basement, where my future office/studio will be located. The IP camera is just the first one, recording to the QNAP Surveillance Station running on the NAS with more to follow.

Heimnetzwerk giffy.png

Link to comment
Share on other sites

Link to post
Share on other sites

On 8/17/2014 at 6:53 AM, Ssoele said:

 

They are 2 separate networks, with different DHCP servers and different IP-ranges, connecting them would cause clients from 1.x to get IP's in the range of 2.x and vice-versa.

Sorry, 4 years late to the party. Using VLANs can keep them separate when connecting them together for network redundancy.

Link to comment
Share on other sites

Link to post
Share on other sites

  • 4 weeks later...

Pretty small in comparison:

5120A854-4881-4A6A-ACA9-D1662A570C4A.jpeg

A long time LTT viewer that signed up “7 minutes ago”.

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 weeks later...
  • 1 month later...
On 8/17/2014 at 12:24 PM, Ssoele said:

 

Nice :o 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

PNG, JPG, and PDF Versions Attached...

Network Layout_Direct.pdf

Network Layout.png

 

 

 

 

Edit: Wanted to put a gap in between the PNG and JPG versions! The one above is the PNG with transparency...the JPG below is the smaller one...

 

 

 

 

 

 

Network Layout.jpg

Edited by DanielNS84

PCPartPicker URL: https://pcpartpicker.com/list/8GYLQD

System Specifications:

CPU: AMD Ryzen 9 5950x
Motherboard: MSI MEG X570 Unify
RAM: 32GB G.Skill Trident RGB PC4000 16-16-16-36
GPU: eVGA RTX 3090 K|ngp|n Hybrid W/ 120mm Noctua iPPC 2000 RPM Industrial Fans  (Undervolted, No OC Yet)
Case: Corsair 4000D W/ a 120mm Noctua iPPC 2000 RPM Industrial Fan in the Only Spot Without a Radiator
Storage: Samsung 980 Pro 2TB (Boot) + Samsung 970 Evo 1TB x 2 (RAID-0) + 8TB RAID-1 NAS Drive x 2 (RAID-1) + PERC H730 W/ Toshiba PX04SMB160 1.6TB Enterprise SSD x 2 (RAID-0)
PSU: EVGA - 1000 T2 Modular PSU
Display(s): Acer - Predator Z1 31.5" 2560x1440 165 Hz Monitor +TCL 55S405 55" 4K HDR Display (Gaming Mode) + Samsung 27" Display (1080p60 Trash lol)
Cooling: Liquid Freezer II 280mm W/ 140mm Noctua iPPC 3000 RPM PWM Industrial Fans
Keyboard: Corsair K68 RGB (Cherry MX Red)
Mouse: Cooler Master MM720
Sound: Logitech G Series G935

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

  • 3 weeks later...
On 12/16/2018 at 8:54 AM, DanielNS84 said:

PNG, JPG, and PDF Versions Attached...

Network Layout_Direct.pdf

 

 

 

 

 

Edit: Wanted to put a gap in between the PNG and JPG versions! The one above is the PNG with transparency...the JPG below is the smaller one...

 

 

 

 

 

 

 

I've been thinking of adding a second connection for redundancy. Do you use your ATT DSL as a backup?

Main Rig CPU: AMD Ryzen 7 5700x GPU: Asus TUF Gaming RX5700XT MBASUS AM4 TUF Gaming X570-Plus RAM: 64GB Corsair Dominator Platinum 3200 CPU Cooler: Cooler Master Master Liquid LC240E SSD: Crucial 250gb M.2 + Crucial 500gb SSD HDD: PSU: Thermaltake Toughpower Gran RGB 850W 80+ Gold Case: Corsair Carbide 275R KB: Glorious GMMK 85% MOUSE: Razer Naga Trinity HEADSET: Go XLR with Shure SM7B mic and beyerdynamic DT 990

 

unRAID Plex Server CPU: Intel i7 6700 GPU: Nvidia Quadro P2000 MB: Asus B150M-C RAM: Crucial Ballistix 32gb DDR4 3000MT/s CPU Cooler: Stock Intel SSD: Western Digital 500GB Red HDD: 4TB Seagate Baracude 3x 4TB Seagate Ironwolf PSU: EVGA BT 80+ Bronze 450W Case: Cooler Master HAF XB EVO KB: Cheap Logitech KB + Mouse combo

Link to comment
Share on other sites

Link to post
Share on other sites

A simple drawing of my network, only fancy bit is probably the vpn tunnel to my offsite server

Screen Shot 2019-01-06 at 2.53.15 PM.png

Link to comment
Share on other sites

Link to post
Share on other sites

  • 1 month later...

Well, Here is my home setup. Didn't bother with drawing the wireless devices. But i use a surface pro 4 mostly in the outdoor area close to the AC AP Lite, 2 iPhones (me and my wife), 2 iPads (Kids), Galaxy Tab (work), Galaxy phone (work) and two Chromecast audios. When we moved in i also put an ethernet connection in the bedroom for a smart tv, but we never used it, so i put that tv in the outdoor area. I also put in an extra ethernet cable to the living room for the tv settop box, because it needed a straight connection to the modem, but we got rid of the cable tv because we never watched it.

 

network.png

Link to comment
Share on other sites

Link to post
Share on other sites

Rather boring so far, standard consumer-grade gear, I will be turning an old computer into an ESXi host and offload the VMs off my desktop onto that.

As you can tell from the little IP range list, I'm leaving myself lots of headroom with my IP designations, I'd rather not change that in the future once this expands.

 

The reason I have the second router running as a full router and not running them in bridged is because the first one is a router/modem combo and it doesn't have good configuration options, which the second one allows. I'm still trying to figure out how to properly forward ports through two NATs, but, eh, I'll figure it out.

network.png

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×