nixos/home: Trunk Digiweb VLAN 10 to river instead of translating
With a single ONT the ISP's VLAN 10 is unique on the fabric, so there's no need to swap it to a private fabric VLAN. Carry pon-isp (10) trunked straight through the switches to river and run PPPoE directly on it, dropping the old wan-pon-isp (141) translation. The ONT's untagged management is PVID'd onto wan-pon-ont (140) at its edge switch (brian). wan-pon-isp (141) is kept as a constant, reserved for the future multi-ONT case where per-port VLAN translation disambiguates two VLAN-10 ONTs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+5
-3
@@ -314,9 +314,11 @@ rec {
|
|||||||
wan = 130;
|
wan = 130;
|
||||||
|
|
||||||
# Digiweb delivers the ISP VLAN (pon-isp, 10) single-tagged at the ONT alongside the ONT's
|
# Digiweb delivers the ISP VLAN (pon-isp, 10) single-tagged at the ONT alongside the ONT's
|
||||||
# own untagged management traffic. The switch feeding river tags the untagged ONT port as
|
# own untagged management traffic. With a single ONT we trunk pon-isp (10) straight through
|
||||||
# wan-pon-ont (140) and swaps ingress VLAN 10 to wan-pon-isp (141), so river sees both
|
# the switches to river (PPPoE runs directly on it), and the switch at the ONT edge PVIDs the
|
||||||
# single-tagged and never has to touch VLAN 10 itself (PPPoE runs on wan-pon-isp).
|
# untagged management port onto wan-pon-ont (140). wan-pon-isp (141) is reserved for the
|
||||||
|
# future multi-ONT case, where per-port VLAN translation on a dedicated switch swaps each
|
||||||
|
# ONT's VLAN 10 to a distinct fabric VLAN (see home-switches.md).
|
||||||
pon-isp = 10;
|
pon-isp = 10;
|
||||||
wan-pon-ont = 140;
|
wan-pon-ont = 140;
|
||||||
wan-pon-isp = 141;
|
wan-pon-isp = 141;
|
||||||
|
|||||||
@@ -15,12 +15,12 @@
|
|||||||
inherit (lib.my.c.home) vlans domain prefixes roceBootModules routersPubV4;
|
inherit (lib.my.c.home) vlans domain prefixes roceBootModules routersPubV4;
|
||||||
|
|
||||||
# river reaches the ONT over its 100G `lan` uplink to the dave switch (which downlinks to
|
# river reaches the ONT over its 100G `lan` uplink to the dave switch (which downlinks to
|
||||||
# jim, where the ONT's fibre lands). Digiweb delivers the ISP VLAN (pon-isp, 10) single-tagged
|
# brian, where the ONT lands). Digiweb delivers the ISP VLAN (pon-isp, 10) single-tagged at
|
||||||
# at the ONT alongside the ONT's untagged management traffic. The switch tags the ONT's
|
# the ONT alongside the ONT's untagged management traffic. With a single ONT there's no VLAN
|
||||||
# untagged port as wan-pon-ont (140) and swaps the ISP's VLAN 10 to wan-pon-isp (141) on
|
# collision, so the switches simply trunk the ISP's VLAN 10 straight through to river (PPPoE
|
||||||
# ingress, so both arrive at river single-tagged and PPPoE runs directly on wan-pon-isp.
|
# runs directly on it) and PVID the ONT's untagged management port onto wan-pon-ont (140).
|
||||||
# river takes .100 in the ONT's /24 (matching stream's modem-mgmt .100) to reach its web
|
# river takes .100 in the ONT's /24 (matching stream's modem-mgmt .100) to reach its web
|
||||||
# UI at 192.168.100.1.
|
# UI at 192.168.100.1. (See home-switches.md for the switch side and the multi-ONT plan.)
|
||||||
ontV4 = net.cidr.host 100 prefixes.ont.v4;
|
ontV4 = net.cidr.host 100 prefixes.ont.v4;
|
||||||
|
|
||||||
# river is routing-common index 0; the Digiweb static IP we request via IPCP
|
# river is routing-common index 0; the Digiweb static IP we request via IPCP
|
||||||
@@ -148,7 +148,8 @@
|
|||||||
systemd.network = {
|
systemd.network = {
|
||||||
netdevs = mkMerge [
|
netdevs = mkMerge [
|
||||||
(mkVLAN "wan-pon-ont" vlans.wan-pon-ont)
|
(mkVLAN "wan-pon-ont" vlans.wan-pon-ont)
|
||||||
(mkVLAN "wan-pon-isp" vlans.wan-pon-isp)
|
# The ISP VLAN is trunked through untranslated, so this is the raw pon-isp (10)
|
||||||
|
(mkVLAN "wan-pon-isp" vlans.pon-isp)
|
||||||
];
|
];
|
||||||
|
|
||||||
links = {
|
links = {
|
||||||
@@ -180,13 +181,15 @@
|
|||||||
|
|
||||||
networks = {
|
networks = {
|
||||||
"55-lan" = {
|
"55-lan" = {
|
||||||
# both WAN VLANs arrive single-tagged on the 100G uplink to dave
|
# both WAN VLANs arrive single-tagged on the 100G uplink to dave: wan-pon-ont (140,
|
||||||
|
# the ONT's management, PVID-tagged at the brian edge) and the ISP's VLAN 10, trunked
|
||||||
|
# straight through
|
||||||
vlan = [ "wan-pon-ont" "wan-pon-isp" ];
|
vlan = [ "wan-pon-ont" "wan-pon-isp" ];
|
||||||
};
|
};
|
||||||
# So we don't drop the IP we use to connect to NVMe-oF!
|
# So we don't drop the IP we use to connect to NVMe-oF!
|
||||||
"60-lan-hi".networkConfig.KeepConfiguration = "static";
|
"60-lan-hi".networkConfig.KeepConfiguration = "static";
|
||||||
|
|
||||||
# ONT management: the switch tags the ONT's untagged port as wan-pon-ont, so give
|
# ONT management: the brian edge PVIDs the ONT's untagged port onto wan-pon-ont, so give
|
||||||
# ourselves an address in its /24 to reach the ONT's web UI at 192.168.100.1.
|
# ourselves an address in its /24 to reach the ONT's web UI at 192.168.100.1.
|
||||||
"70-wan-pon-ont" = {
|
"70-wan-pon-ont" = {
|
||||||
matchConfig.Name = "wan-pon-ont";
|
matchConfig.Name = "wan-pon-ont";
|
||||||
@@ -196,8 +199,8 @@
|
|||||||
MTUBytes = "1500";
|
MTUBytes = "1500";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
# pppd attaches PPPoE to this; just needs to be up with no L3. Carries the ISP's
|
# pppd attaches PPPoE to this; just needs to be up with no L3. This is the ISP's
|
||||||
# VLAN 10, swapped to wan-pon-isp by the switch (see "55-lan").
|
# VLAN 10 trunked straight through from the ONT (no switch translation; see "55-lan").
|
||||||
"71-wan-pon-isp" = {
|
"71-wan-pon-isp" = {
|
||||||
matchConfig.Name = "wan-pon-isp";
|
matchConfig.Name = "wan-pon-isp";
|
||||||
linkConfig = {
|
linkConfig = {
|
||||||
|
|||||||
Reference in New Issue
Block a user