Skip to main content

Port Mappings

Source: Marc Mercer (SRE Lead) — sre-iac repository, Rev 1.0, 2026-02-24

This document covers physical port → connection mappings only. For VLAN/IP assignments see VLAN & IP Allocation.

Naming Convention

TypePatternExample
Server data port<hostname>-p<N>m35g9-stk01-p1 (eno1)
Server iLO port<hostname>-ilom35g9-ilo01
UPS management port<model>-<unit>smt15c-apc01
NAS port<hostname>-p<N>qnap-01-p1
Workstation port<hostname>-p<N>ser5-fed4201-p1
DMZ appliance port<hostname>-p<N>ser7-opn01-p1
Controller port<hostname>-p<N>oc200-01-p1
Switch/routernative interface namingge-0/0/1, SFP+ 1, etc.

Server port numbering: p1=eno1, p2=eno2, p3=eno3, p4=eno4, piLO=dedicated iLO NIC.

OOB Management IP Assignments (VLAN 100 — 192.168.169.0/24)

IP AddressDeviceDescription
192.168.169.1srx320-01 (irb.100)Router OOB management gateway
192.168.169.33ex2200t-01 (vlan.100)Network switch management
192.168.169.34ex2200p-01 (vlan.100)OOB switch management
192.168.169.35ex2200t-02 (vlan.100)Storage switch management
192.168.168.xiLO/IPMIServer management interfaces

Part 1 — Interim (Juniper Hardware, 1G)

srx320-01 — Edge Router/Firewall

PortConnectionSecurity ZoneTrunk VLANsPurpose
ge-0/0/0ISP / FTTHUNTRUSTWAN uplink
ge-0/0/1ex2200t-01 (LACP ae0)TRUST + DMZ + MGMT2, 100, 200, 500, 600, 610, 1000–1099Network switch uplink
ge-0/0/2ex2200t-01 (LACP ae0)TRUST + DMZ + MGMT(same)LACP pair with ge-0/0/1
ge-0/0/3Available
ge-0/0/4Available
ge-0/0/5Homestead switchHOMESTEADuntaggedLee home network (192.168.125.0/24)

IRB Interfaces:

InterfaceIPZonePurpose
irb.210.10.96.1/20TRUSTLegacy Production
irb.100192.168.169.1/24MGMTOOB Management
irb.20010.20.0.1/24TRUSTControl Plane
irb.50010.50.0.1/24TRUSTProvider
irb.60010.60.0.1/24DMZDMZ

ex2200t-01 — Network Switch (24× 1G + 4× SFP)

VLANs: 2 (Legacy), 100 (Management), 200 (Control), 500 (Provider), 600 (DMZ), 610 (HA Sync), 1000–1099 (Tenant) Management: 192.168.169.33 (VLAN 100)

PortConnectionLACP GroupPurpose
ge-0/0/0srx320-01 ge-0/0/1ae0 (router uplink)SRX LACP member 1
ge-0/0/1srx320-01 ge-0/0/2ae0 (router uplink)SRX LACP member 2
ge-0/0/2m35g9-stk01-p1ae1 (stk01-net)Server 1 eno1 — bond-net
ge-0/0/3m35g9-stk01-p2ae1 (stk01-net)Server 1 eno2 — bond-net
ge-0/0/4m35g9-stk02-p1ae2 (stk02-net)Server 2 eno1 — bond-net
ge-0/0/5m35g9-stk02-p2ae2 (stk02-net)Server 2 eno2 — bond-net
ge-0/0/6m35g9-stk03-p1ae3 (stk03-net)Server 3 eno1 — bond-net
ge-0/0/7m35g9-stk03-p2ae3 (stk03-net)Server 3 eno2 — bond-net
ge-0/0/8m35g9-pmx01-p1ae4 (pmx01-net)Server 4 eno1 — bond-net
ge-0/0/9m35g9-pmx01-p2ae4 (pmx01-net)Server 4 eno2 — bond-net
ge-0/0/10ser5-fed4201-p1ae5 (ws-net)Workstation eno1 — bond-net
ge-0/0/11ser5-fed4201-p2ae5 (ws-net)Workstation eno2 — bond-net
ge-0/0/12qnap-01-p1NAS — single link
ge-0/0/13–22Available
ge-0/0/23ex2200p-01 ge-0/0/23Inter-switch trunk (VLAN 100 only) — OOB path

ex2200t-02 — Storage Switch (24× 1G + 4× SFP)

VLANs: 100 (OOB only), 300 (Ceph Public), 400 (Ceph Cluster) Management: 192.168.169.35 (VLAN 100 via OOB trunk)

Storage Isolation

NO uplink to router for storage traffic. VLANs 300/400 are a completely isolated storage fabric.

PortConnectionLACP GroupPurpose
ge-0/0/0m35g9-stk01-p3ae1 (stk01-stor)Server 1 eno3 — bond-stor
ge-0/0/1m35g9-stk01-p4ae1 (stk01-stor)Server 1 eno4 — bond-stor
ge-0/0/2m35g9-stk02-p3ae2 (stk02-stor)Server 2 eno3 — bond-stor
ge-0/0/3m35g9-stk02-p4ae2 (stk02-stor)Server 2 eno4 — bond-stor
ge-0/0/4m35g9-stk03-p3ae3 (stk03-stor)Server 3 eno3 — bond-stor
ge-0/0/5m35g9-stk03-p4ae3 (stk03-stor)Server 3 eno4 — bond-stor
ge-0/0/6m35g9-pmx01-p3ae4 (pmx01-stor)Server 4 eno3 — bond-stor (Ceph client)
ge-0/0/7m35g9-pmx01-p4ae4 (pmx01-stor)Server 4 eno4 — bond-stor (Ceph client)
ge-0/0/8–22Available
ge-0/0/23ex2200p-01 ge-0/0/8Inter-switch trunk (VLAN 100 only) — OOB path

ex2200p-01 — OOB Management Switch (24× 1G PoE + 4× SFP)

VLAN: 100 only Management: 192.168.169.34

PortConnectionPurpose
ge-0/0/0m35g9-ilo01Server 1 iLO
ge-0/0/1m35g9-ilo02Server 2 iLO
ge-0/0/2m35g9-ilo03Server 3 iLO
ge-0/0/3m35g9-ilo04Server 4 iLO
ge-0/0/4smt15c-apc01UPS 1 management
ge-0/0/5smt15c-apc02UPS 2 management
ge-0/0/6smt15c-apc03UPS 3 management
ge-0/0/7smt15c-apc04UPS 4 management
ge-0/0/8ex2200t-02 ge-0/0/23Inter-switch trunk (VLAN 100) — storage switch OOB
ge-0/0/9–22Available
ge-0/0/23ex2200t-01 ge-0/0/23Inter-switch trunk (VLAN 100) — primary OOB path

OOB Management Topology (VLAN 100)

┌─────────────────┐
│ ser5-fed4201 │
│ (Workstation) │
└────────┬────────┘
│ ae5 (VLAN 100 tagged)

┌─────────────────┐ ae0 ┌─────────────────┐
│ srx320-01 │◄───────►│ ex2200t-01 │
│ irb.100 = .1 │ VLAN100 │ vlan.100 = .33 │
└─────────────────┘ trunk └────────┬────────┘
│ ge-0/0/23 (VLAN 100 trunk)

┌─────────────────┐ ge-0/0/8 ┌─────────────────┐
│ ex2200t-02 │◄─────────│ ex2200p-01 │◄─── iLO × 4
│ vlan.100 = .35 │ VLAN100 │ vlan.100 = .34 │◄─── UPS × 4
└─────────────────┘ trunk └─────────────────┘

OOB Access Paths from Workstation (ae5, VLAN 100 tagged):

  • → ex2200t-01 → srx320-01 (192.168.169.1)
  • → ex2200t-01 (192.168.169.33)
  • → ex2200t-01 → ge-0/0/23 → ex2200p-01 (192.168.169.34)
  • → ex2200t-01 → ge-0/0/23 → ex2200p-01 → iLO × 4, UPS × 4
  • → ex2200t-01 → ge-0/0/23 → ex2200p-01 → ge-0/0/8 → ex2200t-02 (192.168.169.35)

Part 2 — Target (Omada + Juniper OOB)

The target architecture adds 10G SFP+ uplinks per server while maintaining identical VLAN IDs and IP allocations. Each server gains dual paths per plane (10G primary + 1G LACP fallback).

PortConnectionZonePurpose
WAN (10G SFP+)ISP / FTTHUNTRUSTWAN uplink
2.5G Port 1ser7-opn01-p1DMZOPNsense HA primary
2.5G Port 2ser7-opn02-p1DMZOPNsense HA secondary
1G Port (LACP)sx3008-01TRUST + DMZ + MGMTNetwork switch primary uplink
1G Port (LACP)sg3428-01TRUST + DMZ + MGMTNetwork switch secondary uplink
1G Port (LACP)sg3452-01HOMESTEADLee home network

sx3008-01 — 10G Network Switch

Carries: 200 (Control), 500 (Provider), 600 (DMZ), 610 (HA Sync), 1000–1099 (Tenant)

Each server connects via 10G SFP+ (bond-net primary path). Router uplink via 10G SFP+.

sx3008-02 — 10G Storage Switch (Isolated)

Carries: 300 (Ceph Public), 400 (Ceph Cluster) only. No router uplink.

Each server connects via 10G SFP+ (bond-stor primary path).

sg3428-01 — 1G Network Switch (Fallback)

Carries: 200, 500, 600, 610, 1000–1099. 1G LACP bonds from each server (bond-net fallback path). QNAP NAS, workstation.

sg3428-02 — 1G Storage Switch (Fallback, Isolated)

Carries: 300, 400 only. No router uplink. 1G LACP bonds from each server (bond-stor fallback path).

ex2200-01 — OOB Switch (Repurposed from Interim)

Carries: VLAN 100 only. Same port assignments as ex2200p-01 in interim (iLO × 4, UPS × 4). Adds Omada controller (oc200-01, PoE powered).

DMZ Appliances (Bare-Metal in Target)

DevicePort 1Port 2
ser7-opn012.5G → er74m-01 port 1 (DMZ inbound)Cross-connect → ser7-opn02 port 2 (HA sync)
ser7-opn022.5G → er74m-01 port 2 (DMZ inbound)Cross-connect → ser7-opn01 port 2 (HA sync)

Direct physical connections — no switch in the DMZ path.


Document Control

RevDateAuthorDescription
1.02026-02-24Marc MercerInitial release