● LIVE SNAPSHOT · 2026-09-23

OptiNation network atlas

Current read-only inventory of systems, routing, services and Cloudflare edge state. Replaces stale legacy documentation.

41
live addresses
3
scanned subnets
9
verified roles
1 / 2
healthy tunnels

Routing topology

Cloudflare → docs.optination.net (Pages + Access/Authress) └─ PT HQ Edge Connector: healthy / 4 connections 192.168.5.0/24 HQ/core → .5.1 UDM-Pro ├─ pve2 .114 · pbs .6 · AD .113 · quorum .243 ├─ TrueNAS .111/.112/.115/.177 (one host) └─ ns8 .110/.130 (one host) 192.168.1.0/24 production → .1.1 gateway └─ pve .5 · mail/web/app workloads 192.168.11.0/24 firewall transit → .11.1 pfSense Observed UDM VLANs: 20, 30, 40, 98, 99, 127. WireGuard also routes 42 and 100.

How the network works

Virtualization + backup

pve and pve2 run Proxmox VE 9.1 across production and HQ. Guests cover store, mail, DNS, SOC, PacketFence, TDAI, Zabbix, opsi and internal apps. pbs provides backup.

Identity + storage

Univention/Samba supplies AD, LDAP and DNS. TrueNAS supplies ZFS/SMB plus Docker and libvirt; its four IPs are aliases.

Routing

UDM-Pro is HQ gateway/VLAN router. pfSense is firewall/transit. WireGuard joins production, HQ, firewall and remote networks.

Control + apps

ns8 runs node/cluster agents, APIs, Redis, Rclone and observability. Other nodes provide mail, web, database, DNS and NAC roles.

Live host inventory

Verified uses host-reported SSH data. Observed uses discovery and service fingerprinting only.

AddressRoleServicesEvidence
192.168.1.1gatewayUnbound, HAProxyobserved
192.168.1.5pve / ProxmoxPVE 9.1.9, primary VM/LXC estateverified
192.168.1.10LinuxSSH, HTTPSobserved
192.168.1.11mail/webDovecot, nginxobserved
192.168.1.13Ubuntu webnginxobserved
192.168.1.15Proxmox/mailPostfix, PVE 8006observed
192.168.1.22TDAIWerkzeug 5000; key deniedobserved
192.168.1.24Apache hostHTTP/Sobserved
192.168.1.25DNSUnboundobserved
192.168.1.26tfdatabase-wikiDocker, Uvicorn, Apacheverified
192.168.1.28managementCockpit, proxyobserved
192.168.1.30app hostExpress 9000observed
192.168.1.32web hostnginx TLSobserved
192.168.1.44Axigen mailSMTP, IMAP, webmailobserved
192.168.1.50Go serviceHTTPobserved
192.168.1.111prod hostingApache, mail, MariaDB, Redisverified
192.168.1.211Ubuntu webnginxobserved
192.168.5.1UDM-ProUniFi OS 5.1.19, routingverified
192.168.5.6pbsProxmox Backup Serververified
192.168.5.9DebianSSHobserved
192.168.5.29data/appPostgreSQL, Redisobserved
192.168.5.40DebianSSHobserved
192.168.5.53APC powerFTP, Telnet, HTTPobserved
192.168.5.110ns8 aliasDNS, HTTP/S, SMBverified
192.168.5.111nasTrueNAS, SMB, Docker, ZFSverified
192.168.5.112nas aliassame TrueNAS hostverified
192.168.5.113AD / UniventionSamba AD, LDAP, DNSverified
192.168.5.114pve2 / ProxmoxPVE 9.1.19, VM/LXC estateverified
192.168.5.115nas aliassame TrueNAS hostverified
192.168.5.118unknown liveno targeted portsobserved
192.168.5.120SMB/SSHSSH banner timeoutobserved
192.168.5.128app hostSSH, TLS 8443observed
192.168.5.130ns8control plane, Redis, observabilityverified
192.168.5.145DebianSSHobserved
192.168.5.153web hostSSH, nginxobserved
192.168.5.161embeddedDropbear, HTTPobserved
192.168.5.177nas aliassame TrueNAS hostverified
192.168.5.207NACSSH denied, nginxobserved
192.168.5.237EdgeSwitchlighttpd; no key supportobserved
192.168.5.243quorumGluster, RPCverified
192.168.11.1pfSenseFreeBSD 15, BIND, WireGuardverified

Cloudflare edge

Pages + Access

docs.optination.net → optination-docs.pages.dev. The OptiNation Docs Access app uses a 24h session and Authress.

Tunnels

PT HQ Edge Connector: healthy (4)

opencode: down (0)

Authress

prod-sso-auth-identity-gateway.optination.net with validation, mail, DMARC and DKIM records.

DNS

Docs, Authress, corporate tunnel, mail/MX, status, firewall, SPF, DKIM, DMARC, MTA-STS, TLS reporting and TLSA.

Findings

No remote files, packages, users, services, rules or settings were changed.

Method

Read-only discovery and targeted TCP fingerprinting covered 192.168.1.0/24, 192.168.5.0/24 and 192.168.11.0/24. SSH collected OS, routes and service names where the existing key worked. Cloudflare Pages, DNS, Access and Tunnels came from current API reads.

Known exclusions: .1.1, .1.22, .5.237 and .127.55 key access. .5.120 timed out at SSH banner. Other refusals remain observed only.