Skip to main content

Devices and sites

Devices and sites

Source of truth: mikrotik-dashboard/inventory.json. REST is allow-listed to hp02. Addresses below are the management IPs the dashboard uses (vlan89 10.9.8.x first).

L3 routers

Role Device OOB Notes
Core CCR2116-12G-4S+ 10.9.8.252 RSTP root of production (0x1000). OSPF RID 10.255.255.16.
Standby core-sb (CHR on hp02) 10.9.8.251 VRRP backup, OSPF vlan34/36.
Primary WAN CCR2004 Quickline 10.9.8.200 OSPF vlan33 cost 10 + BFD. WAN on CRS317.
Backup WAN CCR2004 Wingo 10.9.8.216 OSPF vlan32 cost 20 + BFD.
Mgmt island CCR2004-16G-2S+ 10.9.8.1 vlan89 gateway, own WAN, WireGuard 10.9.9.1.

Switch fabric

Role Device OOB STP
ISP switch CRS317-1G-16S+ 10.9.8.212 vlan448 island root
Spine CRS326-24S+2Q+_A 10.9.8.205 production 0x2000
Access-core CRS326-24S+2Q+_C 10.9.8.213 production 0x3000; servers, UniFi, garage, core-sb trunk
Copper access CRS326-24G-2S+ 10.9.8.249 vlan50 / vlan62 / vlan59
Desk CRS310-8G+2S+ 10.9.8.203 work / IoT / brother
PoE (vlan448 + OOB) CRS418-8P-8G-2S+ 10.9.8.204 access
Mgmt fabric CRS309-1G-8S+ 10.9.8.210 vlan89 star
Mgmt PoE CRS328-24P-4S+ 10.9.8.232 hp02 mgmt, iLO, NanoKVM, hex-ci
Mgmt leaf CRS305-1G-4S+ 10.9.8.202 vlan89

Servers and DNS

Host Addresses What it is
hp02 172.16.62.253 vlan62, 10.9.8.253 vlan89 Dashboard :8787, Gitea :3030, CHR labs, syslog, backups. Only host allowed to hit RouterOS REST. iLO 10.9.8.218.
hp04 172.16.62.40 vlan62 and 213.221.211.30/28 public Workspace + CI runners. Cannot reach vlan89. Must not forward public ↔ LAN. iLO 10.9.8.224.
mag01 172.16.62.246 CI lab runner (lab label).
apu01 10.9.8.206 / 192.168.53.3 / wg0 172.16.75.1 Unbound + FRR. SSH bodo. DNS APUs.
apu02 10.9.8.207 / 192.168.53.2 Same without wg-home.
NanoKVM 10.9.8.225 / .229 / .230 OOB console.

CPE and lab hardware

Device Address Notes
hEX S garage 172.16.99.69 Trunk vlan58/59/99 to CRS326-C sfp14. ether2 = Luxtronik. REST from hp02's vlan62 address (no vlan89 route).
Luxtronik 172.16.58.10 Isolated on vlan58. Path attested on /pathproof.
hex-ci 10.9.8.240 Physical hEX lab on vlan89. Agents may reconfigure it. Dual uplink into CRS328, RSTP blocks one. Rescue 192.168.88.1.
hex-ci2 10.9.8.241 Same pattern, CRS328 ether7/8.

Lab networks on chrlab/fwlab stay in 198.18.0.0/15 (and the other documentation prefixes). Never put a lab bridge on 10.9.8.0/24, 172.16.0.0/12, 192.168.53.0/24, or 100.64.0.0/10.

Remote sites

Reached from hp02's production NIC, not vlan89.

Site Prefix / CPE Path
hex_51 172.16.52.1 Quickline WG / EoIP; prefixes also via apu01 OSPF
hex_19 172.16.18.1 Same
hex_81 213.221.211.19 On the vlan448 public segment

/sites is the live tunnel view (peers, last handshake). A leftover NEVER peer is a display bug, not a down site.

Operator surfaces

Surface URL Use
Overview http://172.16.62.253:8787/overview Fleet health, issues, WAN, DNS, pathproof
VLAN plan http://172.16.62.253:8787/vlanplan Intent vs live bridges
WAN http://172.16.62.253:8787/wan Which ISP, canary
Sites http://172.16.62.253:8787/sites Remote tunnels
SFP / optics http://172.16.62.253:8787/sfp DDM, path loss
DNS / APU http://172.16.62.253:8787/dns · /apu Anycast probes; metrics over SSH after HOST-APU-01
Gitea http://172.16.62.253:3030/bodo/mikrotik-dashboard Issues, PRs, CI
Grafana APUs http://10.9.8.206:3000/ · http://10.9.8.207:3000/ vlan89 only
  • DNS APUs — Unbound anycast, self-heal, listen map
  • Fiber at home — splice plant, FHD boxes, 2020 rack photos
  • Network — historical iWay / t-online / DrayTek, not this fabric

Rules that do not change because a page exists

Agents never write production routers. Deliverable is a dry-run script plus a one-liner for bodo. hp02 is the jump host. This book is the picture, not a change ticket.