Networking
We’re moving into Netbox – @imcatwhocode, Sep. 2024
Everything on this page describes the Lanskoe site unless stated otherwise.
Emphasis on Zero Trust Network in Hackerspace.
External
WAN
Etelecom ISP.
IP:
83.243.68.157Netmask:
255.255.255.240Gateway:
83.243.68.145MAC:
4c:60:de:df:0f:e0
Internal
IPv6
fd91:652e:271a::/48 – ULA from “registry” (https://ula.ungleich.ch/)
fd2d:f:e7bf:f::/64 – BKSP-DN42-B network prefix for Lanskoe LAN
Internal
Internal network.
IPv4:
10.0.2.0/23IPv6 ULA:
fd91:652e:271a:0::/64Internet: yes
Medium: LAN & WLAN
B4CKat Lanskoe.
Guest
Guest network.
IPv4:
10.0.0.0/23Internet: yes
Medium: LAN & WLAN
SP4CEat Lanskoe.
SIPRNET
Overlay network for external client connections to our PBX.
IPv6:
fd91:652e:271a:e164::/64Internet: no
Medium: WireGuard tunnel
Hackfed0
Nebula mesh for intra-hackerspace telephony. Only on Phonebooth node.
Check https://hackfed.org for more info.
Hackfed ULA prefix –
fd79:7636:1f08::/48Hackfed Nebula subnet –
fd79:7636:1f08:883d::/64
Meowcast
Use BKSP ingress as a home-grown Cloudflare LB.
By @Dmitry Nourell x @Den Afanasyev
IPv6:
fd6d:5b4f:be76::/48Internet: no
Tailnet
Primary Tailscale network.
IPv4:
100.64.86.0/20IPv6:
fd7a:115c:a1e0:8:1337::/64
VRUN: b4ck2sp4ce
VPN from MikroTik hAP lite b4ck2sp4ce back to B4ckSp4ce Runet (via Lanskoe, uxie).
IPv4 LAN @ hAP:
10.62.78.128/25WireGuard tunnel subnet:
10.16.235.8/30Internet: yes
VRUN: Virtual RUssian Network
TBD.
172.30.64.x100.64.3.0/24
end2sp4ce
VPN from remote endpoints (e.g. laptops) back to B4ckSp4ce (via 2sp4ce interface at uxie)
Subnet:
10.91.66.0/24IPv4 endpoints:
10.91.66.128/25IPv4 @
uxie:10.91.66.129IPv6 endpoints:
fd91:652e:271a:ae16::/64IPv6 @
uxie:fd91:652e:271a:ae16::1Internet: no
rt2sp4ce
VPN from remote routers back to B4ckSp4ce (via 2sp4ce interface at uxie)
Remote subnets allocated from:
10.91.66.0/2510.91.66.0/27— Chaos Constructions 2025 booth, MikroTik RB951G-2HnD withBKSPIOTandB4CK
10.91.66.56/29— @Leonid Evdokimov, MikroTik hAP ax³: SIP (Nokia E61), Meshtastic (LILYGO T-Beam)
Wireless
ESSID | Network | Description |
|---|---|---|
B4CK | Internal | Main network |
SP4CE | Guest | Isolated guest network |
B4CK2BLACK | Internal | Limited access for legacy devices |
BKSPIOT | Internal | IoT devices |
VLANs SW01
VLAN ID | Network |
|---|---|
10 | Internal |
20 | Guest |
30 | CCTV |
Core network structure
[somewhat] Outdated, as of Dec 2025.
uxie– OPNSense Router & FW, Uxiesw01– Brocade ICX7250 Core Switchsw03-open-space…– Noname 2.5GbE/10GbE SFP+ Open Space, unmanaged switchSW03 – TP-Link TL-SG105E, Open Space Table Switchsw02-openspace-table– Cisco SG 200-08, Open Space Table, smart-switchsw05-openspace-ac– Cisco SG 200-08, Open Space next-to-AC, smart-switchsw0104– MikroTik RB260GSP, Open Space Table smart-switch + Passive PoEsw-04-hwroom…– D-Link DGS-1016C, Workshop, unmanaged switchsw-07-3d…– TP-Link LS1005G, Workshop, next-to-3d-printerunmanaged switchsw-06-portal…– MOXA EDS-205, Seni, unmanaged 100Mbit switchUAP Kitchen – UniFi AC Pro in Kitchen
UAP Open Space – UniFi 7 Pro in Open Space
UAP … – UniFi … in Residential
Tunnels
Lanskoe, uxie — flareon
WireGuard tunnel subnet:
fd91:652e:271a:38a9:e506:24a8:29de::/112,10.16.235.4/30Lanskoe,
uxie:fd91:652e:271a:38a9:e506:24a8:29de:1flareon:fd91:652e:271a:38a9:e506:24a8:29de:2💰❓ — ask @Egor Koleda
Lanskoe, uxie — netcup
WireGuard tunnel subnet:
10.16.235.72/30💰❓ — ask @Danil ShaTie
10.16.235.x/30 для туннелей
10.16.235.4:uxie<→flareon10.16.235.8:uxie<→b4ck2sp4ceMikroTik10.16.235.12:451f<→xris10.16.235.16:451f<→anfe10.16.235.20:451f<→tapk10.16.235.24:sail-gw<→sail10.16.235.28:isla-gw<→isla10.16.235.32:posh-gw<→posh10.16.235.36:daxh-gw<→daxh10.16.235.40:effe-gw<→effe10.16.235.44:451f<→t46010.16.235.48:clefable<→t46010.16.235.52:oob<→clefable(@Dmitry Nourell,ru-mur1, МТС)10.16.235.56:oob<→ac2(@Dmitry@SailCast, SkyNet)10.16.235.60:oob<→status-page(@Egor Koleda, RuVDS)10.16.235.64:oob<→ax3(@Leonid Evdokimov, П.А.К.Т.)10.16.235.68:oob<→ekrt(@Egor Koleda, SkyNet)10.16.235.72:uxie<→netcup(@Danil ShaTie)