Skip to content

Rede SP (Presidente Prudente)

Rede SP (Presidente Prudente)

Topologia

Internet (UNESP/ANSP)
│ 186.217.182.224/27 (gateway .254)
┌────┴────────────────────────────────────┐
│ VyOS SP (VM 6001 — pve-ippri-11) │
│ eth0: 186.217.182.242/27 (WAN) │
│ eth1.192: 192.168.10.5/23 (LAN mgmt) │
│ eth1.197: 192.168.12.5/24 (LAB) │
└────┬────────────┬──────────────────────┘
│ │
VLAN 192 VLAN 197
192.168.10.0/23 192.168.12.0/24
(management) (lab machines)

VyOS SP

ItemValor
VMID6001
Nodepve-ippri-11
VersaoVyOS rolling (2026.04.13)
Storagelinstor-ssd-01 (DRBD replicado 3 nodes)
SSHporta 65401
IP WAN186.217.182.242/27
Gateway WAN186.217.182.254

VLANs

VLANSubnetGatewayUso
192192.168.10.0/23192.168.10.5Proxmox nodes, VMs, infra
197192.168.12.0/24192.168.12.5Maquinas lab (workstations)

NAT Destination (port forwarding)

Porta externaDestinoServico
22192.168.11.200:22SSH VM 1030
80192.168.10.6:80HTTP Traefik SP
443192.168.10.6:443HTTPS Traefik SP
65402192.168.10.6:22SSH traefik-sp
65403192.168.10.51:22SSH k3s-sp

NAT Source (masquerade)

RegraSubnetDescricao
100192.168.10.0/23LAN para internet
110192.168.12.0/24LAB para internet

DHCP

RedeRange DHCP dinâmicoLease
LAN (192.168.10.0/23)192.168.11.200 - 192.168.11.20924h
LAB (192.168.12.0/24)192.168.12.200 - 192.168.12.25024h

LAB — divisão do /24

RangeUso
192.168.12.1-4Reservado
192.168.12.5VyOS LAB (gateway, eth1.197)
192.168.12.6-9Reservado
192.168.12.10-199STATIC — workstations + servidores conhecidos (cfg local)
192.168.12.200-250DHCP dinâmico — visitantes / dispositivos não-cadastrados
192.168.12.251-254Reservado

Workstations cadastradas (ippri02-06) ficam em .100-104 (dentro do range static — configuradas estaticamente nos hosts ou via Ansible).

Firewall

  • Forward: drop por default; permite LAN/LAB → WAN, established/related, DNAT
  • Input: drop por default; permite SSH 65401, established/related, loopback, LAN, LAB

Nodes na VLAN 192 (management)

IPHostDescricao
192.168.10.5vyos-spVyOS gateway (LAN mgmt eth1.192)
192.168.10.6traefik-spReverse proxy + K3s
192.168.10.11pve-ippri-11Proxmox node
192.168.10.12pve-ippri-12Proxmox node
192.168.10.31pve-ippri-31Proxmox node (GPU A5000)
192.168.10.32pve-ippri-32Proxmox node
192.168.10.33pve-ippri-33Proxmox node (GPU A5000)
192.168.10.34pve-ippri-34Proxmox node (GPU A5000)
192.168.10.51k3s-spK3s cluster node
192.168.10.61gpu-sp-01LXC GPU (A5000)
192.168.11.200VM 1030SSH acessivel externamente

Rede 10G (LINSTOR)

Rede dedicada para replicacao DRBD entre nodes com SSD:

IPNodeAndar
10.10.20.11pve-ippri-11A
10.10.20.12pve-ippri-12A
10.10.20.31pve-ippri-31B

VIP LINSTOR controller: 10.10.20.1

Politica de replicacao: 1 replica por andar (via Aux/floor label + replicas-on-different). Detalhes em linstor-operacoes.md.