Balabit - Network sheet L1-L3 (site 1)
Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks
noteThe row of node B's production interface says
DC1-A in the Location column; it is node B's row, a copy-and-paste slip. The redundant-heartbeat host names are spelt dc1-a-ablb001cl02 and dc1-b-ablb001cl2. The lone backtick in the last row of the L3 sheet is a stray character of the spreadsheet.The network spreadsheet of the site 1 cluster as I exported its sheets to text: the port layout of the SCB T-10 (L1), where each port of each appliance is cabled to, the logical interfaces with VLANs, addresses and host names of both nodes (L3), and the cheat sheet of the DNS sub-domains used in the organisation.
| Item | Value |
|---|---|
| Source | The L1-L3 spreadsheet of site 1; the design document's interface summary (picture 1) calls this version v09 |
| Cluster | dc1-s-xblb001, nodes dc1-a-ablb001 (DC1-A) and dc1-b-ablb001 (DC1-B) |
| Sheets | Balabit SCB - LAN L1 (legend), DC1-A - Balabit SCB - LAN L1, DC1-B - Balabit SCB - LAN L1, DC1 - Balabit SCB - LAN L3, DNS cheatsheet |
| Left out | The last sheet, Balabit - SuperMicro: two vendor links, one of them to an unrelated storage product page |
| Format | Cells separated by vertical bars; the L1 sheets are a drawing of the appliance's back panel in cells, so most cells are empty |
The listing
output 80 lines
### sheet Balabit SCB - LAN L1 | Balabit SCB T10 | | | | | | | | | | | | | | | | | | eth2 | eth3 | | IPMI | | | | | | | 3.0 | 4.0 | | | | | | | | | INT | HA | | USB 1 | | | | | eth0 | eth1 | eth4 | eth5 | | USB 2 | SERIAL | VGA | | | 1.0 | 2.0 | 5.0 | 6.0 | | | | | | | EXT | MGMT | A | B | OOB MGMT | 100 Mb Ethernet (IPMI/HW management) | | | | | | | XXX | Cable plugged | ETH-1Gb | 1 Gb Ethernet | | | | | | | XXX | Cable unplugged | ETH-10Gb | 10 Gb Ethernet SFP+ | | | | | | | | | USB | USB port | | | | | | | | | SERIAL | Serial port | | | | | | | | | VGA | VGA port | | | | | | | | ### sheet DC1-A - Balabit SCB - LAN L1 | Balabit SCB T10 | | | | | | | | | | | | | | | | | | eth2 | eth3 | | DC1-A-SOOB003-Gi1/0/16 | | | | | | | DC1-A-SPRO001-Eth1/21 | DC1-A-SPRO002-Eth1/21 | | IPMI | | | | | | | 3/INT | 4/HA | | USB 1 | | | | | eth0 | eth1 | eth4 | eth5 | | USB 2 | DC1-A-ROOB002-port19 | VGA | | | DC1-A-SPRO001-Eth1/5 | DC1-A-SPRO002-Eth1/5 | 5.0 | 6.0 | | | | | | | 1/EXT | 2/MGMT | A | B | OOB MGMT | 100 Mb Ethernet (IPMI/HW management) | | | | | | | | | ETH-1Gb | 1 Gb Ethernet | | | | | | | | | ETH-10Gb | 10 Gb Ethernet SFP+ | | | | | | | | | USB | USB port | | | | | | | | | SERIAL | Serial port | | | | | | | | | VGA | VGA port | | | | | | | | | XXX | Cable plugged | | | | | | | | | XXX | Cable unplugged | | | | | | | | ### sheet DC1-B - Balabit SCB - LAN L1 | Balabit SCB T10 | | | | | | | | | | | | | | | | | | eth2 | eth3 | | DC1-B-SOOB003-Gi1/0/16 | | | | | | | DC1-B-SPRO001-Eth1/21 | DC1-B-SPRO002-Eth1/21 | | IPMI | | | | | | | 3/INT | 4/HA | | USB 1 | | | | | eth0 | eth1 | eth4 | eth5 | | USB 2 | DC1-B-ROOB002-port19 | VGA | | | DC1-B-SPRO001-Eth1/5 | DC1-B-SPRO002-Eth1/5 | 5.0 | 6.0 | | | | | | | 1/EXT | 2/MGMT | A | B | OOB MGMT | 100 Mb Ethernet (IPMI/HW management) | | | | | | | | | ETH-1Gb | 1 Gb Ethernet | | | | | | | | | ETH-10Gb | 10 Gb Ethernet SFP+ | | | | | | | | | USB | USB port | | | | | | | | | SERIAL | Serial port | | | | | | | | | VGA | VGA port | | | | | | | | | XXX | Cable plugged | | | | | | | | | XXX | Cable unplugged | | | | | | | | ### sheet DC1 - Balabit SCB - LAN L3 ID | Location | Physical IF | Logical IF | OS Name | VLAN | OOB MGMT (IPMI) | IBM (OS MGMT) | PRO (Operation ACCESS) | CL2 (HA - Redundant) | BCK (Backup - Archive) | CL1 (HA - Primary) 1.0 | DC1-A | IPMI | - | - | 12.0 | 10.11.15.29 | - | - | - | - | - | DC1-A | 1.0 | 1.0 | eth0.1010 | 1010.0 | - | 10.11.16.81 (VIP) | - | - | - | - | DC1-A | 2.0 | 1.0 | eth1.1009 | 1009.0 | - | - | 10.11.16.65 (VIP) | - | - | - | | | | | | - | - | 2001:db8:a1:c0e::f:1 (VIP) | - | - | - | DC1-A | 3.0 | 1.0 | eth2.1018 | 1018.0 | - | - | - | 10.11.18.209 | - | - | DC1-A | 3.0 | 2.0 | eth2.1020 | 1020.0 | - | - | - | - | 10.11.18.225 (VIP) | - | DC1-A | 4.0 | 1.0 | eth3 | 1016.0 | - | - | - | - | - | 1.2.4.1 | Hostname | | | | | dc1-a-ablb001m.mgmt.example.net | dc1-s-xblb001.adm.example.net | dc1-s-xblb001pro.adm.example.net | dc1-a-ablb001cl02.adm.example.net | dc1-s-xblb001bck.adm.example.net | dc1-a-ablb001cl01.adm.example.net | Hostname 2 | | | | | - | - | scb.example.net | - | - | - ID | Location | Physical IF | Logical IF | OS Name | VLAN | OOB MGMT (IPMI) | IBM (OS MGMT) | PRO (Operation ACCESS) | CL2 (HA - Redundant) | BCK (Backup - Archive) | CL1 (HA - Primary) 2.0 | DC1-B | IPMI | - | - | 12.0 | 10.11.23.29 | - | - | - | - | - | DC1-B | 1.0 | 1.0 | eth0.1010 | 1010.0 | - | 10.11.16.81 (VIP) | - | - | - | - | DC1-A | 2.0 | 1.0 | eth1.1009 | 1009.0 | - | - | 10.11.16.65 (VIP) | - | - | - | | | | | | - | - | 2001:db8:a1:c0e::f:1 (VIP) | - | - | - | DC1-B | 3.0 | 1.0 | eth2.1018 | 1018.0 | - | - | - | 10.11.18.210 | - | - | DC1-B | 3.0 | 2.0 | eth2.1020 | 1020.0 | - | - | - | - | 10.11.18.225 (VIP) | - | DC1-B | 4.0 | 1.0 | eth3 | 1016.0 | - | - | - | - | - | 1.2.4.2 | Hostname | | | | | dc1-b-ablb001m.mgmt.example.net | dc1-s-xblb001.adm.example.net | dc1-s-xblb001pro.adm.example.net | dc1-b-ablb001cl2.adm.example.net | dc1-s-xblb001bck.adm.example.net | dc1-b-ablb001cl01.adm.example.net | Hostname2 | | | | | - | - | scb.example.net | - | - | - | | | | | | DNS record not in the INFOBLOX | | | | | | | | | | | DNS record in the INFOBLOX | | | | | | | | | | | | | ` | | | ### sheet DNS cheatsheet | SubDomains | MainDomain | Purpose | adm | .example.net | Services in management LAN | cimc | .example.net | OOB mgmt UCS servers | mgmt | .example.net | OOB mgmt + Standard mgmt | cmr | .example.net | | pc | .example.net | PARTNER1 infrastructure | ext | .example.net | | int | .example.net | | example | .example.net | Windows domain
How to read the sheets:
| Part | What it means |
|---|---|
| L1 legend | The back panel: IPMI, two USB, serial and VGA on the left; on the right eth2/eth3 above (ports 3 INT and 4 HA) and eth0, eth1, eth4, eth5 below (ports 1 EXT, 2 MGMT, 5 and 6, the last two marked A and B). The legend rows name the port types: 100 Mb Ethernet for IPMI, 1 Gb Ethernet, 10 Gb Ethernet SFP+ |
| L1 per datacenter | The switch port in each cell: IPMI to DC1-x-SOOB003-Gi1/0/16, serial to DC1-x-ROOB002-port19, port 1 to DC1-x-SPRO001-Eth1/5, port 2 to DC1-x-SPRO002-Eth1/5, port 3 to DC1-x-SPRO001-Eth1/21, port 4 to DC1-x-SPRO002-Eth1/21; ports 5 and 6 empty |
| L3 columns | One column per network: OOB MGMT (IPMI), IBM (in-band management of the OS), PRO (operation access for users), CL2 (HA redundant), BCK (backup and archive), CL1 (HA primary). (VIP) marks the cluster addresses that the master holds; 10.11.18.209/.210 and 1.2.4.1/.2 belong to one node each |
VLAN 12.0, 1010.0 | The spreadsheet's number format; read 12, 1010 |
Hostname, Hostname 2 | The DNS names per address; scb.example.net is the second name of the production address |
| Last two L3 rows | The legend of a colour code in the spreadsheet: names in red were "DNS record not in the INFOBLOX", names in black were in it. The colours are lost in the text export; the transcription of the same table as a picture in the design marks the two CL1 names dc1-a-ablb001cl01 and dc1-b-ablb001cl01 as red |
| DNS cheatsheet | adm for services in the management LAN, mgmt for out-of-band and standard management (the IPMI names), pc for partner 1's infrastructure, example for the Windows domain; the others have no purpose filled in |
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| SCB T-10: three traffic ports, HA port, IPMI, two SFP+ ports | The T-Series was last sold on 2019-06-30 and reached End of Support on 2024-07-31; SPS 8.0 is not supported on it. Current appliances are the 3000/3500 and 4000; SPS 9.0 also installs on generic or certified Dell and HPE servers |
| IPMI on a 100 Mb port | "IPMI supports only 100 Mbps Full-Duplex speed" is still in the 9.0 guide |
| Port numbers 1 to 6 on the back panel | On generic hardware a console function maps the detected NICs to the numbers 1 to 6 used in the web interface; interface 4 must stay the one connected to the other node |