Files
vps/docs/lan-overview.md
T

11 KiB
Raw Blame History

LAN network overview

A standalone, live-verified map of the internal LAN hosts and the software deployed on them. Written for a future self / another agent to get oriented fast. Focused per-host facts and runbooks live in ../hosts/ and are linked from each section below.

Scope: this document covers the real LAN only. It deliberately excludes the public VPS hosts (mx2, us2, us4, hk2, synapse) and any dormant/stub software. The WireGuard VPN server is external (us4.wsvc.info); there is no WireGuard interface on the LAN side.

Verified live on 2026-08-06 by read-only SSH from the WSL client. No changes were made. gfw.windy.lan root SSH was re-verified the same day after the key was installed; its facts below are from the fresh probe.


Topology

                        Internet
                           │  PPPoE (pppoe0, MTU 1492, IPv6 PD /60)
                           ▼
        ┌───────────────────────────────────────────────┐
        │  gw  — EdgeRouter X  (192.168.66.254)         │
        │  eth0 = LAN66  ·  switch0(eth1-3) = LAN55     │
        │  WAN_IN active on pppoe0 (default-drop)         │
        │  port-forwards: hass/transmission/ssh/openvpn │
  LAN66  └───────────────┬──────────────────────────────┘
  (192.168.66.0/24)      │

        │  gfw.windy.lan  — OpenWrt / OpenClash (192.168.66.1)
        │  dns.windy.lan  — AdGuard Home + Mihomo (192.168.66.36)
        │  ubnt           — UniFi Network Controller (192.168.66.46)

SE5420 purchased (2026-08-09): TP-Link TL-SE5420 acquired; deployment plan is lan-se5420-deployment-guide.md. Design/planning refs: lan-erx-se5420-network.md, lan-core-switch-upgrade-plan.md.


Hosts

Host Role SSH IPv4 Facts
gw EdgeRouter X primary LAN gateway ssh -4 zhiqiang@192.168.66.254 192.168.66.254 hosts/gw.md
PVE Proxmox host (.66.26/vmbr0 · .55.26/vmbr1) — hosts gfw/dns/ubnt/haos VMs ssh -4 root@192.168.66.26 192.168.66.26
gfw.windy.lan OpenWrt LAN gateway / OpenClash — PVE VM 140 ssh -4 root@192.168.66.1 192.168.66.1 hosts/gfw.windy.lan.md
dns.windy.lan AdGuard Home LAN DNS + Mihomo explicit proxy — PVE VM 120 (pihole) ssh -4 windy@192.168.66.36 192.168.66.36 hosts/dns.windy.lan.md
ubnt UniFi Network Controller — PVE VM 160 ssh -4 windy@192.168.66.46 192.168.66.46 hosts/ubnt.md
haos Home Assistant (HAOS) — PVE VM 180 (LAN55) 192.168.55.11
NAS/FreeNAS NAS; transmission jail runs here (.51)
U6 Lite UniFi AP (LAN66) ssh -4 zhiqiangf@192.168.66.6 192.168.66.6 docs/unifi-network.md
UAP-AC-Lite UniFi AP (LAN55) ssh -4 zhiqiangf@192.168.55.5 192.168.55.5 docs/unifi-network.md

Positioning facts (verified 2026-08-09): dns/ubnt/gfw/haos are all VMs on PVE (no separate physical hosts); transmission is a FreeNAS/NAS jail. Only gw, PVE, NAS, U6, UAP-AC-Lite, and wired PCs/NAS are physical SE5420 ports. See lan-se5420-deployment-guide.md §1.


gw — EdgeRouter X (LAN gateway)

Item Value
Platform EdgeOS v3.0.1 (Build 5862409), kernel 4.14.54-UBNT
Interfaces eth0=192.168.66.254/24 (LAN66) · switch0=192.168.55.254/24 (LAN55) · eth4=WAN PPPoE · pppoe0=WAN default route (MTU 1492, IPv6 PD /60)
WAN pppoe0=113.68.54.159 (PPPoE) · IPv6 SLAAC /64 on both LANs
Firewall WAN_IN active on pppoe0 (established/related accept, invalid drop, default drop) · LAN_IN/ LAN_OUT defined but inactive (not attached)
DHCP LAN1 (66) + LAN2 (55), 24h leases, client DNS = 192.168.66.36, pools .38.243, static mappings for infra hosts
DNS service dns forwarding cache 512, listen on eth0 + switch0; DHCP advertises 192.168.66.36 as client DNS
Port-forwards hass→192.168.55.11:8123 · transmission→192.168.66.51:51413 · ssh→192.168.66.36:22 (orig 5822) · openvpn→192.168.66.32:1194 · WAN iface pppoe0
Management SSH TCP 22 · EdgeOS GUI HTTP 80 / HTTPS 443

Static DHCP mappings (LAN66): OnePlus-12=.37, gfw=.1, hp-nas=.32, pihole=.36, pve=.26, transmission=.51, ubnt-6=.6, ubnt-app=.46, windy-pc=.99. LAN55: Aqara-Hub-M3-10CB=.248.

Note: LAN_IN/LAN_OUT are defined but not applied to an interface, so LAN55 and LAN66 are bidirectionally reachable by default. Do not rely on those rules as an access boundary. See hosts/gw.md.


gfw.windy.lan — OpenWrt / OpenClash gateway

Item Value
IPv4 192.168.66.1
OS ImmortalWrt 25.12.0 (r37854), Linux 6.12.87, x86/64
SSH ssh -4 root@192.168.66.1 (key-only, verified 2026-08-06)
OpenClash /etc/openclash/clash (clash_meta core) + config /etc/openclash/pass-cat.yaml
Mode fake-ip + TPROXY transparent proxy (operation_mode=fake-ip, en_mode=fake-ip, proxy_mode=rule)
DNS dnsmasq → clash DNS 127.0.0.1#7874; mosdns also listens on 127.0.0.1:6052 (not the active path)
nft table inet fw4 with OpenClash TPROXY/redirect + DNS-hijack rules; residual table inet passwall (0 packets, unused)

OpenClash listeners: HTTP 7890 · SOCKS 7891 · Redirect 7892 · Mixed 7893 · TPROXY 7895 · DNS 7874 · dashboard 9090. 8443 is not an OpenClash listener (only in its TLS-sniffing port list).

Operational note: a LAN client request logged as <client> --> localhost:8443 + refusal is normally an explicit-proxy client sending its own loopback to the gateway. Fix the originating host's NO_PROXY/no_proxy config; do not create a listener on this router to mask it. See docs/unifi-openclash-localhost.md.


dns.windy.lan — AdGuard Home + Mihomo (DNS & proxy host)

Item Value
IPv4 192.168.66.36
OS Debian 12 (kernel 6.1.0-43)
SSH ssh -4 windy@192.168.66.36
AdGuard Home Docker container adguardhome (host network, pinned digest), /opt/adguardhome
DNS TCP/UDP 53 (no source ACL — serves both LAN55 and LAN66)
UI 192.168.66.36:80 (LAN66 only via nft agh_ui_access)
Upstreams https://dns.alidns.com/dns-query + https://doh.pub/dns-query (load-balanced) · bootstrap 223.5.5.5/223.6.6.6 · fallback https://adg.chans.xyz/dns-query
DNSSEC disabled (upstream path failed known-bad-signature check)
Rewrites hass.local + hass.windy.lan → same Home Assistant address
Query log 14 days, anonymized client IPs
Mihomo systemd service (NOT Docker) — /usr/local/bin/mihomo -d /etc/mihomo, config /etc/mihomo/config.yaml
Mihomo listeners HTTP 7890 · SOCKS 7891 · Mixed 7892 · DNS 1053 · external-controller 9090 · allow-lan: true · mode rule
nft table inet agh_ui_access permits only 192.168.66.0/24 to TCP/80, drops other TCP/80 input

Routing boundary: read-only checks found no host TUN policy routing or nftables/iptables transparent-redirection on this host. A Mihomo listener alone does not mean it intercepts AdGuard traffic; the default gateway (gfw.windy.lan) can still affect outbound, so inspect its OpenClash rules separately before changing upstream routing.


ubnt — UniFi controller host

Item Value
IPv4 192.168.66.46
Compose /home/windy/unifi-9/compose.yml · service unifi · container unifi-controller
Image jacobalberty/unifi:v9.5.21 (host network)
HTTPS UI https://192.168.66.46:8443
Inform http://192.168.66.46:9080/inform (not 8080)
Health docker inspect --format '{{.State.Health.Status}}' unifi-controllerhealthy (2026-08-06)
Also running dockge (louislam/dockge:1, healthy) — compose UI, /opt/stacks
Dormant semaphoreui (semaphore + postgres, exited 9 months) · homarr dir (no container)

Proxy contract: the container keeps NO_PROXY/no_proxy enabled with localhost,127.0.0.1,::1,192.168.0.0/16,10.0.0.0/8,172.16.0.0/12 so a controller request to localhost:8443 stays local instead of going to the OpenClash gateway. See docs/unifi-openclash-localhost.md.


Managed access points

Name Model Mgmt IP Firmware Network Inform
U6 Lite U6 Lite (UAL6) 192.168.66.6 6.7.54.15663 LAN66 :9080
UAP-AC-Lite U7LT 192.168.55.5 6.8.2.15592 LAN55 :9080

Both reported Connected to http://192.168.66.46:9080/inform on 2026-08-06. AP SSH account is zhiqiangf (key-only, verified). See docs/unifi-network.md.


Quick orientation (who runs what)

Service Host How to reach
LAN gateway / routing / DHCP gw ssh -4 zhiqiang@192.168.66.254
Transparent/explicit proxy (OpenClash) gfw.windy.lan ssh -4 root@192.168.66.1
LAN DNS (AdGuard Home) + Mihomo proxy dns.windy.lan ssh -4 windy@192.168.66.36
UniFi controller + dockge ubnt ssh -4 windy@192.168.66.46
Wi-Fi APs U6 Lite / UAP-AC-Lite via controller