● LIVE SNAPSHOT · 2026-09-23
OptiNation network atlas
Current read-only inventory of systems, routing, services and Cloudflare edge state. Replaces stale legacy documentation.
Routing topology
How the network works
Virtualization + backup
pve and pve2 run Proxmox VE 9.1 across production and HQ. Guests cover store, mail, DNS, SOC, PacketFence, TDAI, Zabbix, opsi and internal apps. pbs provides backup.
Identity + storage
Univention/Samba supplies AD, LDAP and DNS. TrueNAS supplies ZFS/SMB plus Docker and libvirt; its four IPs are aliases.
Routing
UDM-Pro is HQ gateway/VLAN router. pfSense is firewall/transit. WireGuard joins production, HQ, firewall and remote networks.
Control + apps
ns8 runs node/cluster agents, APIs, Redis, Rclone and observability. Other nodes provide mail, web, database, DNS and NAC roles.
Live host inventory
Verified uses host-reported SSH data. Observed uses discovery and service fingerprinting only.
| Address | Role | Services | Evidence |
|---|---|---|---|
| 192.168.1.1 | gateway | Unbound, HAProxy | observed |
| 192.168.1.5 | pve / Proxmox | PVE 9.1.9, primary VM/LXC estate | verified |
| 192.168.1.10 | Linux | SSH, HTTPS | observed |
| 192.168.1.11 | mail/web | Dovecot, nginx | observed |
| 192.168.1.13 | Ubuntu web | nginx | observed |
| 192.168.1.15 | Proxmox/mail | Postfix, PVE 8006 | observed |
| 192.168.1.22 | TDAI | Werkzeug 5000; key denied | observed |
| 192.168.1.24 | Apache host | HTTP/S | observed |
| 192.168.1.25 | DNS | Unbound | observed |
| 192.168.1.26 | tfdatabase-wiki | Docker, Uvicorn, Apache | verified |
| 192.168.1.28 | management | Cockpit, proxy | observed |
| 192.168.1.30 | app host | Express 9000 | observed |
| 192.168.1.32 | web host | nginx TLS | observed |
| 192.168.1.44 | Axigen mail | SMTP, IMAP, webmail | observed |
| 192.168.1.50 | Go service | HTTP | observed |
| 192.168.1.111 | prod hosting | Apache, mail, MariaDB, Redis | verified |
| 192.168.1.211 | Ubuntu web | nginx | observed |
| 192.168.5.1 | UDM-Pro | UniFi OS 5.1.19, routing | verified |
| 192.168.5.6 | pbs | Proxmox Backup Server | verified |
| 192.168.5.9 | Debian | SSH | observed |
| 192.168.5.29 | data/app | PostgreSQL, Redis | observed |
| 192.168.5.40 | Debian | SSH | observed |
| 192.168.5.53 | APC power | FTP, Telnet, HTTP | observed |
| 192.168.5.110 | ns8 alias | DNS, HTTP/S, SMB | verified |
| 192.168.5.111 | nas | TrueNAS, SMB, Docker, ZFS | verified |
| 192.168.5.112 | nas alias | same TrueNAS host | verified |
| 192.168.5.113 | AD / Univention | Samba AD, LDAP, DNS | verified |
| 192.168.5.114 | pve2 / Proxmox | PVE 9.1.19, VM/LXC estate | verified |
| 192.168.5.115 | nas alias | same TrueNAS host | verified |
| 192.168.5.118 | unknown live | no targeted ports | observed |
| 192.168.5.120 | SMB/SSH | SSH banner timeout | observed |
| 192.168.5.128 | app host | SSH, TLS 8443 | observed |
| 192.168.5.130 | ns8 | control plane, Redis, observability | verified |
| 192.168.5.145 | Debian | SSH | observed |
| 192.168.5.153 | web host | SSH, nginx | observed |
| 192.168.5.161 | embedded | Dropbear, HTTP | observed |
| 192.168.5.177 | nas alias | same TrueNAS host | verified |
| 192.168.5.207 | NAC | SSH denied, nginx | observed |
| 192.168.5.237 | EdgeSwitch | lighttpd; no key support | observed |
| 192.168.5.243 | quorum | Gluster, RPC | verified |
| 192.168.11.1 | pfSense | FreeBSD 15, BIND, WireGuard | verified |
Cloudflare edge
Pages + Access
docs.optination.net → optination-docs.pages.dev. The OptiNation Docs Access app uses a 24h session and Authress.
Tunnels
PT HQ Edge Connector: healthy (4)
opencode: down (0)
Authress
prod-sso-auth-identity-gateway.optination.net with validation, mail, DMARC and DKIM records.
DNS
Docs, Authress, corporate tunnel, mail/MX, status, firewall, SPF, DKIM, DMARC, MTA-STS, TLS reporting and TLSA.
Findings
- The opencode Cloudflare tunnel is down.
- 192.168.5.53 exposes Telnet management.
- 192.168.1.111 exposes a broad legacy hosting stack and network-visible MariaDB.
- Deduplicate TrueNAS aliases in monitoring.
- Additional UDM VLANs were observed but not scanned.
Method
Read-only discovery and targeted TCP fingerprinting covered 192.168.1.0/24, 192.168.5.0/24 and 192.168.11.0/24. SSH collected OS, routes and service names where the existing key worked. Cloudflare Pages, DNS, Access and Tunnels came from current API reads.
Known exclusions: .1.1, .1.22, .5.237 and .127.55 key access. .5.120 timed out at SSH banner. Other refusals remain observed only.