add: OPNsense VM and UniFi network config

- OPNsense VM 130 on pm4 (KavSense, 10.4.2.1)
- VLAN 10 configured (10.4.10.0/24) for future use
- pm4 vmbr0 now VLAN-aware
- UniFi SSIDs: Trusted, IOT, Guest
- VLAN testing paused until GiGaPlus switches arrive

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
2025-12-19 19:31:51 -05:00
parent fe83b760f3
commit 9e050d4677
2 changed files with 20 additions and 3 deletions

View File

@@ -5,11 +5,27 @@
## 2025-12-19 ## 2025-12-19
### Network Upgrade Progress ### Network Upgrade Progress
- **UniFi Controller**: Deployed LXC on pm4 for AP management - **UniFi Controller**: Deployed LXC 111 on pm4 for AP management
- IP: 10.4.2.242 (DHCP, will be assigned static via OPNsense later) - IP: 10.4.2.242 (DHCP, will be assigned static via OPNsense later)
- Port: 8443 (HTTPS web UI) - Port: 8443 (HTTPS web UI)
- Deployed via ProxmoxVE community helper script - Deployed via ProxmoxVE community helper script
- Purpose: Manage U7 AP installed in server closet for testing - Configured 3 SSIDs: KavCorp-Trusted, KavCorp-IOT (2.4GHz only), KavCorp-Guest
- **OPNsense**: Deployed VM 130 on pm4 as future router/firewall
- Hostname: KavSense
- IP: 10.4.2.1 (WAN interface, static)
- Gateway: 10.4.2.254 (Asus router as upstream during transition)
- Memory: 8GB, 2 vCPU, 32GB disk
- VLAN 10 interface configured: 10.4.10.1/24 with DHCP (10.4.10.100-200)
- Web UI: https://10.4.2.1
- Status: Running, ready for migration when GiGaPlus switches arrive
- **pm4 vmbr0**: Enabled VLAN-aware bridge for VLAN support
- **VLAN Testing**: Attempted VLAN 10 through existing Netgear GS308EP
- GS308EP trunk mode configuration unsuccessful
- Decision: Wait for GiGaPlus 10G switches for proper VLAN support
- UniFi VLAN10-Test network created, ready for use
## 2025-12-18 ## 2025-12-18

View File

@@ -44,7 +44,8 @@
| **Immich** | 10.4.2.24:2283 | LXC 126 (pm4) | immich.kavcorp.com | Built-in | | **Immich** | 10.4.2.24:2283 | LXC 126 (pm4) | immich.kavcorp.com | Built-in |
| **Gitea** | 10.4.2.7:3000 | LXC 127 (pm4) | git.kavcorp.com | Built-in | | **Gitea** | 10.4.2.7:3000 | LXC 127 (pm4) | git.kavcorp.com | Built-in |
| **Pi-hole** | 10.4.2.129 | LXC 103 (pm4) | pihole.kavcorp.com | Built-in | | **Pi-hole** | 10.4.2.129 | LXC 103 (pm4) | pihole.kavcorp.com | Built-in |
| **UniFi Controller** | 10.4.2.242:8443 | LXC (pm4) | - | Built-in | | **UniFi Controller** | 10.4.2.242:8443 | LXC 111 (pm4) | - | Built-in |
| **OPNsense (KavSense)** | 10.4.2.1 | VM 130 (pm4) | - | Built-in |
| **KavNas** | 10.4.2.13 | Synology NAS | - | NAS auth | | **KavNas** | 10.4.2.13 | Synology NAS | - | NAS auth |
## Storage Architecture ## Storage Architecture