summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorarf20 <aruizfernandez05@gmail.com>2026-07-28 00:46:42 +0200
committerarf20 <aruizfernandez05@gmail.com>2026-07-28 00:46:42 +0200
commit41be4027340004955d34cead91de3733802aa8e3 (patch)
tree0d7712c9bde2d70819f6a11fbc3f6bcb3c2f5df2
parent4ac5ad64bf7883c63ba02ecd1f1091cab08126f0 (diff)
downloadarfnet2-41be4027340004955d34cead91de3733802aa8e3.tar.gz
arfnet2-41be4027340004955d34cead91de3733802aa8e3.zip
phase 8 init
-rw-r--r--arfnet2.html59
-rw-r--r--arfnet2.md35
-rw-r--r--arfnet2.pdfbin164402 -> 165187 bytes
3 files changed, 76 insertions, 18 deletions
diff --git a/arfnet2.html b/arfnet2.html
index 4abb8fd..86366bb 100644
--- a/arfnet2.html
+++ b/arfnet2.html
@@ -26,7 +26,7 @@
<p>After the disastrous ISP <a
href="http://arf20.com/explanation.txt">schism</a></p>
<h2 id="masterplan">Masterplan</h2>
-<h3 id="stage-1-very-safe">Stage 1: very safe</h3>
+<h3 id="phase-1-very-safe">Phase 1: very safe</h3>
<ul>
<li>Close all ports</li>
<li>Nuke (or stop) all old VMs (exclude OPNSense)</li>
@@ -34,14 +34,14 @@ href="http://arf20.com/explanation.txt">schism</a></p>
<li>Make new basic VMs (cloning deb12 template)</li>
<li>Open basic ports</li>
</ul>
-<h3 id="stage-2-new-services">Stage 2: new services</h3>
+<h3 id="phase-2-new-services">Phase 2: new services</h3>
<ul>
<li>IONOS VPS for mail</li>
<li>Some new very safe services</li>
<li>HE IPv6 tunnel</li>
<li>Own authoritative nameservers for domain zone</li>
</ul>
-<h3 id="stage-3-finally">*Stage 3: finally</h3>
+<h3 id="phase-3-finally">*Phase 3: finally</h3>
<ul>
<li>Another VPS in unknown provider for
<ul>
@@ -52,26 +52,26 @@ href="http://arf20.com/explanation.txt">schism</a></p>
secure</li>
<li>More new services</li>
</ul>
-<h3 id="stage-4-dn42">Stage 4: DN42</h3>
+<h3 id="phase-4-dn42">Phase 4: DN42</h3>
<ul>
<li>Make DN42 router VM with bird and wg</li>
<li>Peer with people</li>
<li>Bring up BGP sessions</li>
<li>Services</li>
</ul>
-<h3 id="stage-5-telephony">Stage 5: Telephony</h3>
+<h3 id="phase-5-telephony">Phase 5: Telephony</h3>
<ul>
<li>Asterisk</li>
<li>IP phones and ATAs</li>
<li>Trunks; SDF, Tandmx, uwutel, PSTN</li>
</ul>
-<h3 id="stage-6-site-b-piso">*Stage 6: Site B (piso)</h3>
+<h3 id="phase-6-site-b-piso">*Phase 6: Site B (piso)</h3>
<ul>
<li>Firewall and switch</li>
<li>Site to Site wireguard</li>
<li>Establish telephony</li>
</ul>
-<h3 id="stage-7-ca-pki-ldap-iam-and-sso">*Stage 7: CA, PKI, LDAP, IAM
+<h3 id="phase-7-ca-pki-ldap-iam-and-sso">*Phase 7: CA, PKI, LDAP, IAM
and SSO</h3>
<p>Objectives</p>
<ul>
@@ -112,9 +112,31 @@ endpoints TLS certificates</label></li>
possible</label></li>
<li><label><input type="checkbox" />Kerberos and Keycloak</label></li>
</ul>
+<h3 id="phase-8-10-gigabit">*Phase 8: 10 gigabit</h3>
+<p>Acquire</p>
+<ul class="task-list">
+<li><label><input type="checkbox" checked="" />10G Firewall (Sophos XG
+330)</label></li>
+<li><label><input type="checkbox" />10G Switch (HP ProCurve 2910al-48G +
+2x J4009A SFP+ modules)</label></li>
+<li><label><input type="checkbox" />10G NICs (Intel
+X520-DA2)</label></li>
+<li><label><input type="checkbox" />10GBASE-SR transceivers (Cisco
+SFP-10G-SR)</label></li>
+<li><label><input type="checkbox" />OM3 fiber</label></li>
+</ul>
+<p>Steps</p>
+<ul class="task-list">
+<li><label><input type="checkbox" />Replace OPNsense with VyOS in
+firewall</label></li>
+<li><label><input type="checkbox" />Replace DELL switch with 10G
+switch</label></li>
+<li><label><input type="checkbox" />Connect firewall to switch and
+server to switch with 10G</label></li>
+</ul>
<h2 id="domain">Domain</h2>
<p>arf20.com</p>
-<p>Registrar: namecheap</p>
+<p>Registrar: porkbun</p>
<h3 id="name-sever-glue-records-at-registrar">Name sever glue records at
registrar</h3>
<table>
@@ -1060,16 +1082,21 @@ http://ca.lan:80</td>
<td></td>
</tr>
<tr class="even">
+<td>office.arf20.com</td>
+<td>onlyoffice</td>
+<td></td>
+</tr>
+<tr class="odd">
<td></td>
<td></td>
<td></td>
</tr>
-<tr class="odd">
+<tr class="even">
<td>status.yero.dev</td>
<td>http://yerovps.lan:3001</td>
<td></td>
</tr>
-<tr class="even">
+<tr class="odd">
<td>panaland.arf20.com</td>
<td>/var/www/panaland.arf20.com/html/</td>
<td></td>
@@ -1988,6 +2015,18 @@ Number Assignation Table</h2>
<td></td>
</tr>
<tr class="even">
+<td>testcert.arf20.com</td>
+<td>CNAME</td>
+<td>web.arf20.com</td>
+<td></td>
+</tr>
+<tr class="odd">
+<td>office.arf20.com</td>
+<td>CNAME</td>
+<td>web.arf20.com</td>
+<td></td>
+</tr>
+<tr class="even">
<td></td>
<td></td>
<td></td>
diff --git a/arfnet2.md b/arfnet2.md
index 5e93887..dab9d82 100644
--- a/arfnet2.md
+++ b/arfnet2.md
@@ -4,7 +4,7 @@ After the disastrous ISP [schism](http://arf20.com/explanation.txt)
## Masterplan
-### Stage 1: very safe
+### Phase 1: very safe
- Close all ports
- Nuke (or stop) all old VMs (exclude OPNSense)
@@ -12,14 +12,14 @@ After the disastrous ISP [schism](http://arf20.com/explanation.txt)
- Make new basic VMs (cloning deb12 template)
- Open basic ports
-### Stage 2: new services
+### Phase 2: new services
- IONOS VPS for mail
- Some new very safe services
- HE IPv6 tunnel
- Own authoritative nameservers for domain zone
-### \*Stage 3: finally
+### \*Phase 3: finally
- Another VPS in unknown provider for
- Tor
@@ -27,25 +27,25 @@ After the disastrous ISP [schism](http://arf20.com/explanation.txt)
- PHP on main site with more web services from scratch, hopefully secure
- More new services
-### Stage 4: DN42
+### Phase 4: DN42
- Make DN42 router VM with bird and wg
- Peer with people
- Bring up BGP sessions
- Services
-### Stage 5: Telephony
+### Phase 5: Telephony
- Asterisk
- IP phones and ATAs
- Trunks; SDF, Tandmx, uwutel, PSTN
-### \*Stage 6: Site B (piso)
+### \*Phase 6: Site B (piso)
- Firewall and switch
- Site to Site wireguard
- Establish telephony
-### \*Stage 7: CA, PKI, LDAP, IAM and SSO
+### \*Phase 7: CA, PKI, LDAP, IAM and SSO
Objectives
@@ -74,11 +74,27 @@ Steps
- [ ] Put SSO login on services where possible
- [ ] Kerberos and Keycloak
+### \*Phase 8: 10 gigabit
+
+Acquire
+
+ - [X] 10G Firewall (Sophos XG 330)
+ - [ ] 10G Switch (HP ProCurve 2910al-48G + 2x J4009A SFP+ modules)
+ - [ ] 10G NICs (Intel X520-DA2)
+ - [ ] 10GBASE-SR transceivers (Cisco SFP-10G-SR)
+ - [ ] OM3 fiber
+
+Steps
+
+ - [ ] Replace OPNsense with VyOS in firewall
+ - [ ] Replace DELL switch with 10G switch
+ - [ ] Connect firewall to switch and server to switch with 10G
+
## Domain
arf20.com
-Registrar: namecheap
+Registrar: porkbun
### Name sever glue records at registrar
@@ -404,6 +420,7 @@ RAID attached here (with the grey stuff) (local only)
| raip.arf20.com | / = /var/www/raip.arf20.com/html<br>/status = http://comm.lan:8080 | |
| pki.arf20.com | / = /var/www/pki.arf20.com/html<br>/download/ = http://ca.lan:80 | |
| testcert.arf20.com | / = /var/www/testcert.arf20.com/html/ | |
+| office.arf20.com | onlyoffice | |
| | | |
| status.yero.dev | http://yerovps.lan:3001 | |
| panaland.arf20.com | /var/www/panaland.arf20.com/html/ | |
@@ -707,6 +724,8 @@ Site-B:PiSoNet
| raip.arf20.com | CNAME | web.arf20.com |
| dmr.arf20.com | CNAME | comm.arf20.com |
| pki.arf20.com | CNAME | web.arf20.com |
+| testcert.arf20.com | CNAME | web.arf20.com |
+| office.arf20.com | CNAME | web.arf20.com |
|
| status.arf20.com | CNAME | mail.arf20.com |
| lists.arf20.com | CNAME | mail.arf20.com |
diff --git a/arfnet2.pdf b/arfnet2.pdf
index f47a514..5cbf014 100644
--- a/arfnet2.pdf
+++ b/arfnet2.pdf
Binary files differ