Topology at a glance
Everything funnels through a Firewalla gateway/router (firewalla.inc.lan, 192.168.10.1) that segments the SF home into three routed subnets/VLANs. Remote access is done with Tailscale (a flat mesh of per-device /32s) rather than port forwards — no device-owner subnet router or exit node is advertised. The tailnet mesh is clean: latency is direct for the spark and nexus nodes.
- 192.168.10.0/24 — main mixed VLAN: WiFi clients, smart home, entertainment, the two NVIDIA DGX Sparks, and the eero/GL.iNet WiFi gear.
- 192.168.30.0/24 — NAS/storage VLAN: davis-vault-i reachable; davis-vault-ii not present on this LAN (remote site, tailnet-only).
- 192.168.40.0/24 — server-rack VLAN: nexus (agent host) reachable; siva & eventide do not respond from the main VLAN (segmentation/firewall).
- Internet — dual-stack AT&T (San Anselmo, CA). Direct egress; no outbound VPN tunnel observed.
Tailnet — otter-hawksbill.ts.net
17 nodes total (16 peers + this Mac). No exit nodes, no subnet routers; every machine joins by its own host /32. MagicDNS resolves <device>.otter-hawksbill.ts.net. Client on this Mac is 1.98.9 (current).
| Hostname | Tailscale IP | OS | Last seen | Notes |
|---|---|---|---|---|
| operator-ii (this Mac) | 100.100.10.11 | macOS | now | SF LAN 192.168.10.203 (DHCP) |
| operator-i | 100.100.10.10 | macOS | Jul 23 | offline ~11d |
| cadmus | 100.100.10.20 | macOS | Jul 21 | offline ~13d |
| scanner | 100.100.10.30 | iOS | now | iPad, online |
| glassway | 100.100.10.40 | iOS | Jul 29 | iPhone, offline ~5d |
| suppressor | 100.100.10.60 | Android | Jul 8 | Pixel Fold, offline ~26d |
| morningstar | 100.100.10.50 | linux | Jul 29 | Windows/WSL 5090 rig, offline ~5d |
| davis-vault-i | 100.100.30.10 | linux | now | Synology DS1825+ (main NAS) |
| davis-vault-ii | 100.100.30.20 | linux | now | Synology DS225+ (backup; remote site) |
| eventide | 100.100.40.10 | macOS | Jul 27 | offline ~6d |
| siva | 100.100.40.20 | linux | now | agent workhorse (rack) |
| siva-portal | 100.100.40.21 | linux | now | verify not in inventory |
| nexus | 100.100.40.30 | linux | now | hermes agent host (rack), direct link |
| nexus-portal | 100.100.40.31 | linux | now | verify not in inventory |
| spark-bottom-level | 100.100.40.100 | linux | now | NVIDIA DGX Spark, direct link |
| spark-top-level | 100.125.54.25 | linux | now | NVIDIA DGX Spark, IP off the usual 100.100.x pattern |
| fee8f1c95c65 | 100.89.126.51 | linux | now | identified = tx9-columbia-agent (TX9 container on nexus) |
SF LAN by subnet
Gathered via ARP/neighbor cache + mDNS (Bonjour) service advertisements from this Mac. Devices marked lease show a DHCP lease/mDNS name but were not reachable at scan time.
Main VLAN — 192.168.10.0/24
| Hostname | IP | Vendor (OUI) | Category | Status |
|---|---|---|---|---|
| firewalla.inc | .1 | Firewalla Inc. | Gateway / router / DNS | live |
| operator-ii | .203 | Apple | This MacBook (M5 Max) | live |
| operator | .10 | Apple | MacBook Pro (M4 Max) | lease |
| operator-caldigit | .142 | CalDigit | Thunderbolt dock NIC | lease |
| cadmus | .20 | Apple | MacBook Neo | lease |
| scanner | .30 | Apple (priv.) | iPad | live |
| glassway | .109 | Apple (priv.) | iPhone — note: private Wi-Fi MAC, IP ≠ recorded .40 | live |
| watch | .159 / .195 | Apple | Apple Watch(es) | lease |
| morningstar | .50 | — | Windows 5090 rig | lease |
| suppressor | .60 | — | Pixel Fold | lease |
| steamdeck | .170 | — | Steam Deck | lease |
| masons.macbook.pro | .173 | — | Guest device | lease |
| mason.iphone | .192 | — | Guest device | lease |
| ipad | .244 | Apple | Spare iPad | lease |
| spark-bottom-level | .193 | NVIDIA | DGX Spark (bottom) | live |
| spark-top-level | .220 | NVIDIA | DGX Spark (top) | live |
| eero | .201 | eero Inc. | Mesh WiFi router (bridge toward Firewalla?) | live |
| GL-RM10-de9 / -da5 | mDNS | GL.iNet | Two travel routers — not in inventory | verify |
| tv.of.apple | .136 | Apple | Apple TV | live |
| control.pod | .219 | Apple | HomePod (port 62078 audio open) | live |
| davis.eight.sleep | .113 | Eight Sleep | Mattress / sleep pod | live |
| lg_smart_laundry2 | .176 | LG Innotek | Washer | lease |
| aqara-hub-m100 | .216 | Aqara | Smart-home hub (Matter/HomeKit) | live |
| smart.switch.studio.lamp | .197 | Tuya | Smart switch | live |
| smart.switch.studio.keylights | .214 | Tuya | Smart switch | live |
NAS VLAN — 192.168.30.0/24
| Hostname | IP | Category | Reachable from main? |
|---|---|---|---|
| davis-vault-i (DS1825+) | 192.168.30.10 | Main NAS | yes — SSH/80/443/SMB/DSM |
| davis-vault-ii (DS225+) | n/a on SF LAN | Backup NAS | tailnet-only (remote site) |
Rack VLAN — 192.168.40.0/24
| Hostname | IP | Category | Reachable from main? |
|---|---|---|---|
| nexus | 192.168.40.30 | Agent host (GMKtec) | yes — SSH |
| siva | 192.168.40.20 | Agent workhorse (Framework) | no ICMP/SVC |
| eventide | 192.168.40.10 | Mac Mini (archiving) | no ICMP/SVC |
Connectivity & egress
- Default gateway
- 192.168.10.1 (Firewalla, resolves DNS, advertises SSH:22 + web admin)
- DNS
- Firewalla 192.168.10.1 forwards publicly (AT&T path); MagicDNS active for tailnet names
- WiFi (this Mac)
- SSID “Stripe’s Sanctum” — WPA3-Personal, 6 GHz 802.11be; a WPA2 2.4 GHz AP is also visible
- IPv4 egress
- 104.176.7.113 — AT&T (San Anselmo, CA)
- IPv6 egress
- 2600:1700:2800:8e12:… (AT&T, dual-stack)
- Internet path
- Firewalla → AT&T → Cloudflare → 1.1.1.1 (direct, no outbound VPN)
- Tailscale mesh
- 0 exit nodes, 0 subnet routers — flat per-host /32s; direct paths to nexus & bottom spark
Security review
- Remote access is Tailscale-based — no inbound VPN/management port forwarded from the public Internet could be confirmed from inside the LAN.
- WPA3-Personal on the main WiFi; Firewalla segments NAS and rack onto separate routed VLANs.
- SSH on the fleet is key-based per your inventory; client is current (Tailscale 1.98.9).
- No tailnet exit node is advertised, so no session is being funneled through a shared egress.
| # | Severity | Finding | Evidence / why it matters |
|---|---|---|---|
| 1 | resolved | Unidentified live tailnet node | Identified as tx9-columbia-agent on nexus; benign (agent container, own account, no open service). Opacity retained as an operations note below. |
| 2 | medium | Two Tailscale “Portal” nodes | siva-portal & nexus-portal online, not in inventory — portals/published services are internet-exposed by design; confirm intent |
| 3 | medium | Unknown/unmanaged WiFi routing gear | eero mesh + two GL.iNet RM10 travel routers are live but absent from inventory; travel routers are a classic attack pivot |
| 4 | medium | IoT shares the personal VLAN | Aqara hub, Tuya studio switches, Eight Sleep, LG washer sit on 192.168.10.0/24 alongside laptops/guests — no IoT VLAN observed |
| 5 | medium | NAS admin + SMB exposed on a routed VLAN | davis-vault-i answers SMB(445) and DSM admin(5000/5001) from the main VLAN; confirm DSM 2FA and that Firewalla never port-forwards toward it |
| 6 | medium | Guest devices on the flat LAN | Mason’s MacBook/iPhone and a spare iPad share the segment with the DGX Sparks and smart home |
| 7 | info | Inventory drift | Live DHCP differs from DEVICES.md: operator-ii is .203 (not .11), glassway uses a private Wi-Fi MAC at .109 (not .40) |
| 8 | info | Firewalla listens on SSH:22 + web:80 (Express) on the LAN | Expected for management, but confirm these stay LAN-only with strong auth |
Recommendations
- Give
tx9-columbia-agenta friendly tailnet name (e.g. set--hostname tx9-columbia-agenton the container) so future audits don’t re-flag it as an unknown node. - Audit the portals. Log into the admin console and list what
siva-portal/nexus-portalpublish; revoke anything not intentional. - Document the WiFi/routing gear (eero + 2× GL.iNet RM10): pick one upstream role, check firmware, and confirm travel routers only act as VPN clients / APs, not routers behind NAT.
- Create an IoT VLAN on the Firewalla and move smart-home devices + guest gear there; keep servers/NAS/desktops on your trusted VLAN.
- Harden the NAS: enable DSM 2FA, disable admin login over the segments you don’t need, and confirm no WAN inbound rules point at 5000/5001/445.
- Refresh DEVICES.md with live IPs (operator-ii .203, glassway private-MAC) so the canonical map matches reality.
- Method
- Read-only sweep from operator-ii: tailscale status/JSON, dig/MagicDNS, ARP + mDNS (Bonjour), gentle ICMP, and targeted
ncconnectivity checks on known infrastructure only. No destructive or invasive scanning. - Scope note
- External (WAN-side) exposure could not be tested from inside the LAN; recommend a one-off external port review if you want confirmation of the inbound surface.