diff options
| author | arf20 <aruizfernandez05@gmail.com> | 2026-07-28 00:46:42 +0200 |
|---|---|---|
| committer | arf20 <aruizfernandez05@gmail.com> | 2026-07-28 00:46:42 +0200 |
| commit | 41be4027340004955d34cead91de3733802aa8e3 (patch) | |
| tree | 0d7712c9bde2d70819f6a11fbc3f6bcb3c2f5df2 | |
| parent | 4ac5ad64bf7883c63ba02ecd1f1091cab08126f0 (diff) | |
| download | arfnet2-41be4027340004955d34cead91de3733802aa8e3.tar.gz arfnet2-41be4027340004955d34cead91de3733802aa8e3.zip | |
phase 8 init
| -rw-r--r-- | arfnet2.html | 59 | ||||
| -rw-r--r-- | arfnet2.md | 35 | ||||
| -rw-r--r-- | arfnet2.pdf | bin | 164402 -> 165187 bytes |
3 files changed, 76 insertions, 18 deletions
diff --git a/arfnet2.html b/arfnet2.html index 4abb8fd..86366bb 100644 --- a/arfnet2.html +++ b/arfnet2.html @@ -26,7 +26,7 @@ <p>After the disastrous ISP <a href="http://arf20.com/explanation.txt">schism</a></p> <h2 id="masterplan">Masterplan</h2> -<h3 id="stage-1-very-safe">Stage 1: very safe</h3> +<h3 id="phase-1-very-safe">Phase 1: very safe</h3> <ul> <li>Close all ports</li> <li>Nuke (or stop) all old VMs (exclude OPNSense)</li> @@ -34,14 +34,14 @@ href="http://arf20.com/explanation.txt">schism</a></p> <li>Make new basic VMs (cloning deb12 template)</li> <li>Open basic ports</li> </ul> -<h3 id="stage-2-new-services">Stage 2: new services</h3> +<h3 id="phase-2-new-services">Phase 2: new services</h3> <ul> <li>IONOS VPS for mail</li> <li>Some new very safe services</li> <li>HE IPv6 tunnel</li> <li>Own authoritative nameservers for domain zone</li> </ul> -<h3 id="stage-3-finally">*Stage 3: finally</h3> +<h3 id="phase-3-finally">*Phase 3: finally</h3> <ul> <li>Another VPS in unknown provider for <ul> @@ -52,26 +52,26 @@ href="http://arf20.com/explanation.txt">schism</a></p> secure</li> <li>More new services</li> </ul> -<h3 id="stage-4-dn42">Stage 4: DN42</h3> +<h3 id="phase-4-dn42">Phase 4: DN42</h3> <ul> <li>Make DN42 router VM with bird and wg</li> <li>Peer with people</li> <li>Bring up BGP sessions</li> <li>Services</li> </ul> -<h3 id="stage-5-telephony">Stage 5: Telephony</h3> +<h3 id="phase-5-telephony">Phase 5: Telephony</h3> <ul> <li>Asterisk</li> <li>IP phones and ATAs</li> <li>Trunks; SDF, Tandmx, uwutel, PSTN</li> </ul> -<h3 id="stage-6-site-b-piso">*Stage 6: Site B (piso)</h3> +<h3 id="phase-6-site-b-piso">*Phase 6: Site B (piso)</h3> <ul> <li>Firewall and switch</li> <li>Site to Site wireguard</li> <li>Establish telephony</li> </ul> -<h3 id="stage-7-ca-pki-ldap-iam-and-sso">*Stage 7: CA, PKI, LDAP, IAM +<h3 id="phase-7-ca-pki-ldap-iam-and-sso">*Phase 7: CA, PKI, LDAP, IAM and SSO</h3> <p>Objectives</p> <ul> @@ -112,9 +112,31 @@ endpoints TLS certificates</label></li> possible</label></li> <li><label><input type="checkbox" />Kerberos and Keycloak</label></li> </ul> +<h3 id="phase-8-10-gigabit">*Phase 8: 10 gigabit</h3> +<p>Acquire</p> +<ul class="task-list"> +<li><label><input type="checkbox" checked="" />10G Firewall (Sophos XG +330)</label></li> +<li><label><input type="checkbox" />10G Switch (HP ProCurve 2910al-48G + +2x J4009A SFP+ modules)</label></li> +<li><label><input type="checkbox" />10G NICs (Intel +X520-DA2)</label></li> +<li><label><input type="checkbox" />10GBASE-SR transceivers (Cisco +SFP-10G-SR)</label></li> +<li><label><input type="checkbox" />OM3 fiber</label></li> +</ul> +<p>Steps</p> +<ul class="task-list"> +<li><label><input type="checkbox" />Replace OPNsense with VyOS in +firewall</label></li> +<li><label><input type="checkbox" />Replace DELL switch with 10G +switch</label></li> +<li><label><input type="checkbox" />Connect firewall to switch and +server to switch with 10G</label></li> +</ul> <h2 id="domain">Domain</h2> <p>arf20.com</p> -<p>Registrar: namecheap</p> +<p>Registrar: porkbun</p> <h3 id="name-sever-glue-records-at-registrar">Name sever glue records at registrar</h3> <table> @@ -1060,16 +1082,21 @@ http://ca.lan:80</td> <td></td> </tr> <tr class="even"> +<td>office.arf20.com</td> +<td>onlyoffice</td> +<td></td> +</tr> +<tr class="odd"> <td></td> <td></td> <td></td> </tr> -<tr class="odd"> +<tr class="even"> <td>status.yero.dev</td> <td>http://yerovps.lan:3001</td> <td></td> </tr> -<tr class="even"> +<tr class="odd"> <td>panaland.arf20.com</td> <td>/var/www/panaland.arf20.com/html/</td> <td></td> @@ -1988,6 +2015,18 @@ Number Assignation Table</h2> <td></td> </tr> <tr class="even"> +<td>testcert.arf20.com</td> +<td>CNAME</td> +<td>web.arf20.com</td> +<td></td> +</tr> +<tr class="odd"> +<td>office.arf20.com</td> +<td>CNAME</td> +<td>web.arf20.com</td> +<td></td> +</tr> +<tr class="even"> <td></td> <td></td> <td></td> @@ -4,7 +4,7 @@ After the disastrous ISP [schism](http://arf20.com/explanation.txt) ## Masterplan -### Stage 1: very safe +### Phase 1: very safe - Close all ports - Nuke (or stop) all old VMs (exclude OPNSense) @@ -12,14 +12,14 @@ After the disastrous ISP [schism](http://arf20.com/explanation.txt) - Make new basic VMs (cloning deb12 template) - Open basic ports -### Stage 2: new services +### Phase 2: new services - IONOS VPS for mail - Some new very safe services - HE IPv6 tunnel - Own authoritative nameservers for domain zone -### \*Stage 3: finally +### \*Phase 3: finally - Another VPS in unknown provider for - Tor @@ -27,25 +27,25 @@ After the disastrous ISP [schism](http://arf20.com/explanation.txt) - PHP on main site with more web services from scratch, hopefully secure - More new services -### Stage 4: DN42 +### Phase 4: DN42 - Make DN42 router VM with bird and wg - Peer with people - Bring up BGP sessions - Services -### Stage 5: Telephony +### Phase 5: Telephony - Asterisk - IP phones and ATAs - Trunks; SDF, Tandmx, uwutel, PSTN -### \*Stage 6: Site B (piso) +### \*Phase 6: Site B (piso) - Firewall and switch - Site to Site wireguard - Establish telephony -### \*Stage 7: CA, PKI, LDAP, IAM and SSO +### \*Phase 7: CA, PKI, LDAP, IAM and SSO Objectives @@ -74,11 +74,27 @@ Steps - [ ] Put SSO login on services where possible - [ ] Kerberos and Keycloak +### \*Phase 8: 10 gigabit + +Acquire + + - [X] 10G Firewall (Sophos XG 330) + - [ ] 10G Switch (HP ProCurve 2910al-48G + 2x J4009A SFP+ modules) + - [ ] 10G NICs (Intel X520-DA2) + - [ ] 10GBASE-SR transceivers (Cisco SFP-10G-SR) + - [ ] OM3 fiber + +Steps + + - [ ] Replace OPNsense with VyOS in firewall + - [ ] Replace DELL switch with 10G switch + - [ ] Connect firewall to switch and server to switch with 10G + ## Domain arf20.com -Registrar: namecheap +Registrar: porkbun ### Name sever glue records at registrar @@ -404,6 +420,7 @@ RAID attached here (with the grey stuff) (local only) | raip.arf20.com | / = /var/www/raip.arf20.com/html<br>/status = http://comm.lan:8080 | | | pki.arf20.com | / = /var/www/pki.arf20.com/html<br>/download/ = http://ca.lan:80 | | | testcert.arf20.com | / = /var/www/testcert.arf20.com/html/ | | +| office.arf20.com | onlyoffice | | | | | | | status.yero.dev | http://yerovps.lan:3001 | | | panaland.arf20.com | /var/www/panaland.arf20.com/html/ | | @@ -707,6 +724,8 @@ Site-B:PiSoNet | raip.arf20.com | CNAME | web.arf20.com | | dmr.arf20.com | CNAME | comm.arf20.com | | pki.arf20.com | CNAME | web.arf20.com | +| testcert.arf20.com | CNAME | web.arf20.com | +| office.arf20.com | CNAME | web.arf20.com | | | status.arf20.com | CNAME | mail.arf20.com | | lists.arf20.com | CNAME | mail.arf20.com | diff --git a/arfnet2.pdf b/arfnet2.pdf Binary files differindex f47a514..5cbf014 100644 --- a/arfnet2.pdf +++ b/arfnet2.pdf |
