A project to construct a reliable, low-cost, secure, IPv6 gigabit intranet. At home.

Servers

By Name

  • Azathoth - Phase I general purpose gateway
  • Byatis
  • Niggurath - general purpose app server
  • Hastur - media processor and storage
  • Cyclops - new media server
  • Yuggoth - publicly accessible services
  • Pixie - home automation controller

By Service

Network Hardware

Switches

  • Extreme Networks Summit X450e-24p Gigabit PoE switch
  • Dell PowerConnect 2716 - 16-port gigabit rackmount switch
  • Zyxel GS108 - 8-port gigabit "media" switch
  • Netgear FS105 - 5-port 100Mbit desktop switch
  • On-Networks DSG005 - 5-port gigabit desktop switch

Access Points

  • Ubiquiti Unifi AP x3
  • Ubiquiti Unifi AC Lite x2

Other Network Hardware

  • Linksys WRT54GL - 802.11g wireless router
  • D-Link DGS-1008D - 8-port gigabit desktop switch
  • Netgear DG834GT - Sky router

Services

Features

Clients

Troubleshooting

Upgrades


Planned Features

Implementation

Network is implemented in three phases:

Phase I - Single subnet

In this phase a single privately addressed (NATted) subnet is created.

  • Single general purpose gateway (Azathoth)
  • Public systems are accessible via DNAT on the gateway.
  • One DNS server provides local cacheing and authoritative for public systems.
  • Private DNS info is kept in /etc/hosts on each system.
  • Single Mail server for secure submission and retrieval
  • Azathoth is replaced with embedded/SBC system
  • Public domain name registered
    • Update /etc files, mail config, LDAP database, certificates

Phase II - Perimeter and Private subnets

In this phase the subnet is split in to perimeter (non-NAT) and private (NAT) and IPv6 migration begins.

  • Second switch is added and Azathoth assumes the role of private router.
  • Attempt Gigabit routing throughput on Azathoth.
  • Private net migrates to pure IPv6, router provides IPv6-to-IPv4
  • Second DNS is added and provides cacheing and DNS for all systems
  • Perimeter router provides Bandwith Management
  • VPN gateway provides two-factor authenticated access to private network.

Phase III - Perimeter, Private, Wireless

A wireless IPv6 network is created on the internet side of the perimeter firewall

  • Wireless adapter is added to perimeter router
  • Pure IPv6 wireless network is created with router running radvd on wireless interface
  • Aside from radvd, no systems exist on the wireless network

Notes