<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network on Deevnet Infrastructure Platform</title><link>https://deevnet.github.io/deevnet-docs/docs/runbook/network/</link><description>Recent content in Network on Deevnet Infrastructure Platform</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://deevnet.github.io/deevnet-docs/docs/runbook/network/index.xml" rel="self" type="application/rss+xml"/><item><title>Important URLs</title><link>https://deevnet.github.io/deevnet-docs/docs/runbook/network/important-urls/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deevnet.github.io/deevnet-docs/docs/runbook/network/important-urls/</guid><description>&lt;h1 id="important-urls">
 Important URLs
 &lt;a class="anchor" href="#important-urls">#&lt;/a>
&lt;/h1>
&lt;p>Every management interface and service endpoint on the mobile site, by DNS name and by IP.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Names&lt;/strong> are in the &lt;code>mobile.deevnet.net&lt;/code> zone and resolve through the core router,
&lt;code>10.20.99.1&lt;/code>.&lt;/li>
&lt;li>&lt;strong>Use the IP&lt;/strong> when DNS is the thing that is broken, or when you are not using the site&amp;rsquo;s
resolver.&lt;/li>
&lt;li>&lt;strong>Where to reach them from:&lt;/strong> the management segment (VLAN 99) — the builder, or a laptop on
the operator port &lt;code>gi1/0/2&lt;/code>, which gets an address from &lt;code>10.20.99.200–230&lt;/code>. From the travel
router&amp;rsquo;s network, tunnel through the builder instead: see

 &lt;a href="https://deevnet.github.io/deevnet-docs/deevnet-docs/docs/runbook/network/operator-access/">Operator Access&lt;/a>.&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Checked 2026-09-11 from the builder:&lt;/strong> every URL below answered, by name and by IP, except
where the Notes say otherwise.&lt;/p></description></item><item><title>Operator Access</title><link>https://deevnet.github.io/deevnet-docs/docs/runbook/network/operator-access/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deevnet.github.io/deevnet-docs/docs/runbook/network/operator-access/</guid><description>&lt;h1 id="operator-access">
 Operator Access
 &lt;a class="anchor" href="#operator-access">#&lt;/a>
&lt;/h1>
&lt;p>Reaching the builder and the management web UIs from an operator laptop, through the travel
router rather than through the site network.&lt;/p>
&lt;p>The management segment (VLAN 99) is not reachable from wireless clients. The builder is on it,
and it also has a second interface, &lt;code>enp1s0&lt;/code>, on the travel router&amp;rsquo;s LAN. A laptop on the travel
router&amp;rsquo;s network (its wireless, or a LAN port) can SSH to the builder there and tunnel every
management UI through that one session.&lt;/p></description></item><item><title>Network Reference</title><link>https://deevnet.github.io/deevnet-docs/docs/runbook/network/network-reference/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deevnet.github.io/deevnet-docs/docs/runbook/network/network-reference/</guid><description>&lt;h1 id="network-reference">
 Network Reference
 &lt;a class="anchor" href="#network-reference">#&lt;/a>
&lt;/h1>
&lt;p>Quick reference for VLAN assignments and network configuration across Deevnet sites.&lt;/p>
&lt;hr>
&lt;h2 id="mobile-vlan-assignments">
 mobile VLAN Assignments
 &lt;a class="anchor" href="#mobile-vlan-assignments">#&lt;/a>
&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Segment&lt;/th>
 &lt;th>VLAN ID&lt;/th>
 &lt;th>Subnet&lt;/th>
 &lt;th>Gateway&lt;/th>
 &lt;th>DHCP&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>Trusted&lt;/td>
 &lt;td>10&lt;/td>
 &lt;td>10.20.10.0/24&lt;/td>
 &lt;td>10.20.10.1&lt;/td>
 &lt;td>.100-.200&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Storage&lt;/td>
 &lt;td>20&lt;/td>
 &lt;td>10.20.20.0/24&lt;/td>
 &lt;td>10.20.20.1&lt;/td>
 &lt;td>Static only&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Platform&lt;/td>
 &lt;td>25&lt;/td>
 &lt;td>10.20.25.0/24&lt;/td>
 &lt;td>10.20.25.1&lt;/td>
 &lt;td>Static only&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>IoT&lt;/td>
 &lt;td>30&lt;/td>
 &lt;td>10.20.30.0/24&lt;/td>
 &lt;td>10.20.30.1&lt;/td>
 &lt;td>.100-.200&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>IoT Vendor&lt;/td>
 &lt;td>31&lt;/td>
 &lt;td>10.20.31.0/24&lt;/td>
 &lt;td>10.20.31.1&lt;/td>
 &lt;td>.100-.200&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>IoT Backend&lt;/td>
 &lt;td>35&lt;/td>
 &lt;td>10.20.35.0/24&lt;/td>
 &lt;td>10.20.35.1&lt;/td>
 &lt;td>Static only&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Guest&lt;/td>
 &lt;td>40&lt;/td>
 &lt;td>10.20.40.0/24&lt;/td>
 &lt;td>10.20.40.1&lt;/td>
 &lt;td>.50-.250&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Tenant Transit&lt;/td>
 &lt;td>50&lt;/td>
 &lt;td>10.20.50.0/24&lt;/td>
 &lt;td>10.20.50.1&lt;/td>
 &lt;td>Static only&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>Tenant Underlay&lt;/td>
 &lt;td>51&lt;/td>
 &lt;td>—&lt;/td>
 &lt;td>—&lt;/td>
 &lt;td>None (unrouted)&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;blockquote>
&lt;p>Tenants are &lt;strong>not&lt;/strong> VLANs. Under 
 &lt;a href="https://deevnet.github.io/deevnet-docs/deevnet-docs/docs/architecture/decisions/0001-tenant-network-fabric/">ADR-0001&lt;/a>
a tenant is an EVPN/VXLAN overlay owned by the tenant hypervisor&amp;rsquo;s fabric, addressed from
&lt;code>10.20.128.0/18&lt;/code> by fabric IPAM. The two VLANs above are the fabric&amp;rsquo;s &lt;em>transport&lt;/em>: transit to
the perimeter, and the VTEP underlay. Creating a tenant changes neither.
| Management | 99 | 10.20.99.0/24 | 10.20.99.1 | .200-.230 (temporary; infrastructure is static or reserved) |
| Blackhole | 999 | — | — | None (unrouted) |&lt;/p></description></item></channel></rss>