LINUXOR.SK ... open source notes ...

Balabit - Network sheet L1-L3 (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks

noteThe row of node B's production interface says DC1-A in the Location column; it is node B's row, a copy-and-paste slip. The redundant-heartbeat host names are spelt dc1-a-ablb001cl02 and dc1-b-ablb001cl2. The lone backtick in the last row of the L3 sheet is a stray character of the spreadsheet.

The network spreadsheet of the site 1 cluster as I exported its sheets to text: the port layout of the SCB T-10 (L1), where each port of each appliance is cabled to, the logical interfaces with VLANs, addresses and host names of both nodes (L3), and the cheat sheet of the DNS sub-domains used in the organisation.

ItemValue
SourceThe L1-L3 spreadsheet of site 1; the design document's interface summary (picture 1) calls this version v09
Clusterdc1-s-xblb001, nodes dc1-a-ablb001 (DC1-A) and dc1-b-ablb001 (DC1-B)
SheetsBalabit SCB - LAN L1 (legend), DC1-A - Balabit SCB - LAN L1, DC1-B - Balabit SCB - LAN L1, DC1 - Balabit SCB - LAN L3, DNS cheatsheet
Left outThe last sheet, Balabit - SuperMicro: two vendor links, one of them to an unrelated storage product page
FormatCells separated by vertical bars; the L1 sheets are a drawing of the appliance's back panel in cells, so most cells are empty

The listing

output 80 lines
### sheet Balabit SCB - LAN L1
 | Balabit SCB T10 |  |  |  |  |  |  |  |  | 
 |  |  |  |  |  |  |  |  | eth2 | eth3
 |  | IPMI |  |  |  |  |  |  | 3.0 | 4.0
 |  |  |  |  |  |  |  |  | INT | HA
 |  | USB 1 |  |  |  |  | eth0 | eth1 | eth4 | eth5
 |  | USB 2 | SERIAL | VGA |  |  | 1.0 | 2.0 | 5.0 | 6.0
 |  |  |  |  |  |  | EXT | MGMT | A | B
 | OOB MGMT | 100 Mb Ethernet (IPMI/HW management) |  |  |  |  |  |  | XXX | Cable plugged
 | ETH-1Gb | 1 Gb Ethernet |  |  |  |  |  |  | XXX | Cable unplugged
 | ETH-10Gb | 10 Gb Ethernet SFP+ |  |  |  |  |  |  |  | 
 | USB | USB port |  |  |  |  |  |  |  | 
 | SERIAL | Serial port |  |  |  |  |  |  |  | 
 | VGA | VGA port |  |  |  |  |  |  |  | 
### sheet DC1-A - Balabit SCB - LAN L1
 | Balabit SCB T10 |  |  |  |  |  |  |  |  | 
 |  |  |  |  |  |  |  |  | eth2 | eth3
 |  | DC1-A-SOOB003-Gi1/0/16 |  |  |  |  |  |  | DC1-A-SPRO001-Eth1/21 | DC1-A-SPRO002-Eth1/21
 |  | IPMI |  |  |  |  |  |  | 3/INT | 4/HA
 |  | USB 1 |  |  |  |  | eth0 | eth1 | eth4 | eth5
 |  | USB 2 | DC1-A-ROOB002-port19 | VGA |  |  | DC1-A-SPRO001-Eth1/5 | DC1-A-SPRO002-Eth1/5 | 5.0 | 6.0
 |  |  |  |  |  |  | 1/EXT | 2/MGMT | A | B
 | OOB MGMT | 100 Mb Ethernet (IPMI/HW management) |  |  |  |  |  |  |  | 
 | ETH-1Gb | 1 Gb Ethernet |  |  |  |  |  |  |  | 
 | ETH-10Gb | 10 Gb Ethernet SFP+ |  |  |  |  |  |  |  | 
 | USB | USB port |  |  |  |  |  |  |  | 
 | SERIAL | Serial port |  |  |  |  |  |  |  | 
 | VGA | VGA port |  |  |  |  |  |  |  | 
 | XXX | Cable plugged |  |  |  |  |  |  |  | 
 | XXX | Cable unplugged |  |  |  |  |  |  |  | 
### sheet DC1-B - Balabit SCB - LAN L1
 | Balabit SCB T10 |  |  |  |  |  |  |  |  | 
 |  |  |  |  |  |  |  |  | eth2 | eth3
 |  | DC1-B-SOOB003-Gi1/0/16 |  |  |  |  |  |  | DC1-B-SPRO001-Eth1/21 | DC1-B-SPRO002-Eth1/21
 |  | IPMI |  |  |  |  |  |  | 3/INT | 4/HA
 |  | USB 1 |  |  |  |  | eth0 | eth1 | eth4 | eth5
 |  | USB 2 | DC1-B-ROOB002-port19 | VGA |  |  | DC1-B-SPRO001-Eth1/5 | DC1-B-SPRO002-Eth1/5 | 5.0 | 6.0
 |  |  |  |  |  |  | 1/EXT | 2/MGMT | A | B
 | OOB MGMT | 100 Mb Ethernet (IPMI/HW management) |  |  |  |  |  |  |  | 
 | ETH-1Gb | 1 Gb Ethernet |  |  |  |  |  |  |  | 
 | ETH-10Gb | 10 Gb Ethernet SFP+ |  |  |  |  |  |  |  | 
 | USB | USB port |  |  |  |  |  |  |  | 
 | SERIAL | Serial port |  |  |  |  |  |  |  | 
 | VGA | VGA port |  |  |  |  |  |  |  | 
 | XXX | Cable plugged |  |  |  |  |  |  |  | 
 | XXX | Cable unplugged |  |  |  |  |  |  |  | 
### sheet DC1 - Balabit SCB - LAN L3
ID | Location | Physical IF | Logical IF | OS Name | VLAN | OOB MGMT (IPMI) | IBM (OS MGMT) | PRO (Operation ACCESS) | CL2 (HA - Redundant) | BCK (Backup - Archive) | CL1 (HA - Primary)
1.0 | DC1-A | IPMI | - | - | 12.0 | 10.11.15.29 | - | - | - | - | -
 | DC1-A | 1.0 | 1.0 | eth0.1010 | 1010.0 | - | 10.11.16.81 (VIP) | - | - | - | -
 | DC1-A | 2.0 | 1.0 | eth1.1009 | 1009.0 | - | - | 10.11.16.65 (VIP) | - | - | -
 |  |  |  |  |  | - | - | 2001:db8:a1:c0e::f:1 (VIP) | - | - | -
 | DC1-A | 3.0 | 1.0 | eth2.1018 | 1018.0 | - | - | - | 10.11.18.209 | - | -
 | DC1-A | 3.0 | 2.0 | eth2.1020 | 1020.0 | - | - | - | - | 10.11.18.225 (VIP) | -
 | DC1-A | 4.0 | 1.0 | eth3 | 1016.0 | - | - | - | - | - | 1.2.4.1
 | Hostname |  |  |  |  | dc1-a-ablb001m.mgmt.example.net | dc1-s-xblb001.adm.example.net | dc1-s-xblb001pro.adm.example.net | dc1-a-ablb001cl02.adm.example.net | dc1-s-xblb001bck.adm.example.net | dc1-a-ablb001cl01.adm.example.net
 | Hostname 2 |  |  |  |  | - | - | scb.example.net | - | - | -
ID | Location | Physical IF | Logical IF | OS Name | VLAN | OOB MGMT (IPMI) | IBM (OS MGMT) | PRO (Operation ACCESS) | CL2 (HA - Redundant) | BCK (Backup - Archive) | CL1 (HA - Primary)
2.0 | DC1-B | IPMI | - | - | 12.0 | 10.11.23.29 | - | - | - | - | -
 | DC1-B | 1.0 | 1.0 | eth0.1010 | 1010.0 | - | 10.11.16.81 (VIP) | - | - | - | -
 | DC1-A | 2.0 | 1.0 | eth1.1009 | 1009.0 | - | - | 10.11.16.65 (VIP) | - | - | -
 |  |  |  |  |  | - | - | 2001:db8:a1:c0e::f:1 (VIP) | - | - | -
 | DC1-B | 3.0 | 1.0 | eth2.1018 | 1018.0 | - | - | - | 10.11.18.210 | - | -
 | DC1-B | 3.0 | 2.0 | eth2.1020 | 1020.0 | - | - | - | - | 10.11.18.225 (VIP) | -
 | DC1-B | 4.0 | 1.0 | eth3 | 1016.0 | - | - | - | - | - | 1.2.4.2
 | Hostname |  |  |  |  | dc1-b-ablb001m.mgmt.example.net | dc1-s-xblb001.adm.example.net | dc1-s-xblb001pro.adm.example.net | dc1-b-ablb001cl2.adm.example.net | dc1-s-xblb001bck.adm.example.net | dc1-b-ablb001cl01.adm.example.net
 | Hostname2 |  |  |  |  | - | - | scb.example.net | - | - | -
 |  |  |  |  |  | DNS record not in the INFOBLOX |  |  |  |  | 
 |  |  |  |  |  | DNS record in the INFOBLOX |  |  |  |  | 
 |  |  |  |  |  |  |  | ` |  |  | 
### sheet DNS cheatsheet
 | SubDomains | MainDomain | Purpose
 | adm | .example.net | Services in management LAN
 | cimc | .example.net | OOB mgmt UCS servers
 | mgmt | .example.net | OOB mgmt + Standard mgmt
 | cmr | .example.net | 
 | pc | .example.net | PARTNER1 infrastructure
 | ext | .example.net | 
 | int | .example.net | 
 | example | .example.net | Windows domain

How to read the sheets:

PartWhat it means
L1 legendThe back panel: IPMI, two USB, serial and VGA on the left; on the right eth2/eth3 above (ports 3 INT and 4 HA) and eth0, eth1, eth4, eth5 below (ports 1 EXT, 2 MGMT, 5 and 6, the last two marked A and B). The legend rows name the port types: 100 Mb Ethernet for IPMI, 1 Gb Ethernet, 10 Gb Ethernet SFP+
L1 per datacenterThe switch port in each cell: IPMI to DC1-x-SOOB003-Gi1/0/16, serial to DC1-x-ROOB002-port19, port 1 to DC1-x-SPRO001-Eth1/5, port 2 to DC1-x-SPRO002-Eth1/5, port 3 to DC1-x-SPRO001-Eth1/21, port 4 to DC1-x-SPRO002-Eth1/21; ports 5 and 6 empty
L3 columnsOne column per network: OOB MGMT (IPMI), IBM (in-band management of the OS), PRO (operation access for users), CL2 (HA redundant), BCK (backup and archive), CL1 (HA primary). (VIP) marks the cluster addresses that the master holds; 10.11.18.209/.210 and 1.2.4.1/.2 belong to one node each
VLAN 12.0, 1010.0The spreadsheet's number format; read 12, 1010
Hostname, Hostname 2The DNS names per address; scb.example.net is the second name of the production address
Last two L3 rowsThe legend of a colour code in the spreadsheet: names in red were "DNS record not in the INFOBLOX", names in black were in it. The colours are lost in the text export; the transcription of the same table as a picture in the design marks the two CL1 names dc1-a-ablb001cl01 and dc1-b-ablb001cl01 as red
DNS cheatsheetadm for services in the management LAN, mgmt for out-of-band and standard management (the IPMI names), pc for partner 1's infrastructure, example for the Windows domain; the others have no purpose filled in

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
SCB T-10: three traffic ports, HA port, IPMI, two SFP+ portsThe T-Series was last sold on 2019-06-30 and reached End of Support on 2024-07-31; SPS 8.0 is not supported on it. Current appliances are the 3000/3500 and 4000; SPS 9.0 also installs on generic or certified Dell and HPE servers
IPMI on a 100 Mb port"IPMI supports only 100 Mbps Full-Duplex speed" is still in the 9.0 guide
Port numbers 1 to 6 on the back panelOn generic hardware a console function maps the detected NICs to the numbers 1 to 6 used in the web interface; interface 4 must stay the one connected to the other node
← solutionz