Davis Network — Topology & Device Map

A read-only survey of the otter-hawksbill tailnet, the SF LAN (Firewalla), WiFi, egress, and a security review. All data gathered live from this Mac (operator-ii) on .

Tailnet nodes
17
otter-hawksbill.ts.net
SF LAN subnets
3
10 / 30 / 40 (Firewalla)
Named LAN devices
25+
incl. IoT to guests
Security alerts
5
0 high after lead resolved
Unidentified-node alert: resolved — it’s your own agent box

fee8f1c95c65 (100.89.126.51) was flagged as an unknown live node. Follow-up confirmed it is tx9-columbia-agent, a TX9 (hermes-box-lite) agent container running on nexus (192.168.40.30, image tx9-box:0.8.0). Its hostname is the Docker container-ID prefix, so the tailnet node inherited the opaque name. Benign — your own account, no open services, no inbound traffic.

Topology at a glance

Everything funnels through a Firewalla gateway/router (firewalla.inc.lan, 192.168.10.1) that segments the SF home into three routed subnets/VLANs. Remote access is done with Tailscale (a flat mesh of per-device /32s) rather than port forwards — no device-owner subnet router or exit node is advertised. The tailnet mesh is clean: latency is direct for the spark and nexus nodes.

  • 192.168.10.0/24 — main mixed VLAN: WiFi clients, smart home, entertainment, the two NVIDIA DGX Sparks, and the eero/GL.iNet WiFi gear.
  • 192.168.30.0/24 — NAS/storage VLAN: davis-vault-i reachable; davis-vault-ii not present on this LAN (remote site, tailnet-only).
  • 192.168.40.0/24 — server-rack VLAN: nexus (agent host) reachable; siva & eventide do not respond from the main VLAN (segmentation/firewall).
  • Internet — dual-stack AT&T (San Anselmo, CA). Direct egress; no outbound VPN tunnel observed.

Tailnet — otter-hawksbill.ts.net

17 nodes total (16 peers + this Mac). No exit nodes, no subnet routers; every machine joins by its own host /32. MagicDNS resolves <device>.otter-hawksbill.ts.net. Client on this Mac is 1.98.9 (current).

Tailnet nodes (status as observed)
HostnameTailscale IPOSLast seenNotes
operator-ii (this Mac)100.100.10.11macOSnowSF LAN 192.168.10.203 (DHCP)
operator-i100.100.10.10macOSJul 23offline ~11d
cadmus100.100.10.20macOSJul 21offline ~13d
scanner100.100.10.30iOSnowiPad, online
glassway100.100.10.40iOSJul 29iPhone, offline ~5d
suppressor100.100.10.60AndroidJul 8Pixel Fold, offline ~26d
morningstar100.100.10.50linuxJul 29Windows/WSL 5090 rig, offline ~5d
davis-vault-i100.100.30.10linuxnowSynology DS1825+ (main NAS)
davis-vault-ii100.100.30.20linuxnowSynology DS225+ (backup; remote site)
eventide100.100.40.10macOSJul 27offline ~6d
siva100.100.40.20linuxnowagent workhorse (rack)
siva-portal100.100.40.21linuxnowverify not in inventory
nexus100.100.40.30linuxnowhermes agent host (rack), direct link
nexus-portal100.100.40.31linuxnowverify not in inventory
spark-bottom-level100.100.40.100linuxnowNVIDIA DGX Spark, direct link
spark-top-level100.125.54.25linuxnowNVIDIA DGX Spark, IP off the usual 100.100.x pattern
fee8f1c95c65100.89.126.51linuxnowidentified = tx9-columbia-agent (TX9 container on nexus)

SF LAN by subnet

Gathered via ARP/neighbor cache + mDNS (Bonjour) service advertisements from this Mac. Devices marked lease show a DHCP lease/mDNS name but were not reachable at scan time.

Main VLAN — 192.168.10.0/24

Main VLAN (Firewalla gateway .1)
HostnameIPVendor (OUI)CategoryStatus
firewalla.inc.1Firewalla Inc.Gateway / router / DNSlive
operator-ii.203AppleThis MacBook (M5 Max)live
operator.10AppleMacBook Pro (M4 Max)lease
operator-caldigit.142CalDigitThunderbolt dock NIClease
cadmus.20AppleMacBook Neolease
scanner.30Apple (priv.)iPadlive
glassway.109Apple (priv.)iPhone — note: private Wi-Fi MAC, IP ≠ recorded .40live
watch.159 / .195AppleApple Watch(es)lease
morningstar.50Windows 5090 riglease
suppressor.60Pixel Foldlease
steamdeck.170Steam Decklease
masons.macbook.pro.173Guest devicelease
mason.iphone.192Guest devicelease
ipad.244AppleSpare iPadlease
spark-bottom-level.193NVIDIADGX Spark (bottom)live
spark-top-level.220NVIDIADGX Spark (top)live
eero.201eero Inc.Mesh WiFi router (bridge toward Firewalla?)live
GL-RM10-de9 / -da5mDNSGL.iNetTwo travel routers — not in inventoryverify
tv.of.apple.136AppleApple TVlive
control.pod.219AppleHomePod (port 62078 audio open)live
davis.eight.sleep.113Eight SleepMattress / sleep podlive
lg_smart_laundry2.176LG InnotekWasherlease
aqara-hub-m100.216AqaraSmart-home hub (Matter/HomeKit)live
smart.switch.studio.lamp.197TuyaSmart switchlive
smart.switch.studio.keylights.214TuyaSmart switchlive

NAS VLAN — 192.168.30.0/24

NAS/storage VLAN
HostnameIPCategoryReachable from main?
davis-vault-i (DS1825+)192.168.30.10Main NASyes — SSH/80/443/SMB/DSM
davis-vault-ii (DS225+)n/a on SF LANBackup NAStailnet-only (remote site)

Rack VLAN — 192.168.40.0/24

Server-rack VLAN
HostnameIPCategoryReachable from main?
nexus192.168.40.30Agent host (GMKtec)yes — SSH
siva192.168.40.20Agent workhorse (Framework)no ICMP/SVC
eventide192.168.40.10Mac Mini (archiving)no ICMP/SVC

Connectivity & egress

Default gateway
192.168.10.1 (Firewalla, resolves DNS, advertises SSH:22 + web admin)
DNS
Firewalla 192.168.10.1 forwards publicly (AT&T path); MagicDNS active for tailnet names
WiFi (this Mac)
SSID “Stripe’s Sanctum” — WPA3-Personal, 6 GHz 802.11be; a WPA2 2.4 GHz AP is also visible
IPv4 egress
104.176.7.113 — AT&T (San Anselmo, CA)
IPv6 egress
2600:1700:2800:8e12:… (AT&T, dual-stack)
Internet path
Firewalla → AT&T → Cloudflare → 1.1.1.1 (direct, no outbound VPN)
Tailscale mesh
0 exit nodes, 0 subnet routers — flat per-host /32s; direct paths to nexus & bottom spark

Security review

What is in good shape
  • Remote access is Tailscale-based — no inbound VPN/management port forwarded from the public Internet could be confirmed from inside the LAN.
  • WPA3-Personal on the main WiFi; Firewalla segments NAS and rack onto separate routed VLANs.
  • SSH on the fleet is key-based per your inventory; client is current (Tailscale 1.98.9).
  • No tailnet exit node is advertised, so no session is being funneled through a shared egress.
Findings, ordered by severity
#SeverityFindingEvidence / why it matters
1resolvedUnidentified live tailnet nodeIdentified as tx9-columbia-agent on nexus; benign (agent container, own account, no open service). Opacity retained as an operations note below.
2mediumTwo Tailscale “Portal” nodessiva-portal & nexus-portal online, not in inventory — portals/published services are internet-exposed by design; confirm intent
3mediumUnknown/unmanaged WiFi routing geareero mesh + two GL.iNet RM10 travel routers are live but absent from inventory; travel routers are a classic attack pivot
4mediumIoT shares the personal VLANAqara hub, Tuya studio switches, Eight Sleep, LG washer sit on 192.168.10.0/24 alongside laptops/guests — no IoT VLAN observed
5mediumNAS admin + SMB exposed on a routed VLANdavis-vault-i answers SMB(445) and DSM admin(5000/5001) from the main VLAN; confirm DSM 2FA and that Firewalla never port-forwards toward it
6mediumGuest devices on the flat LANMason’s MacBook/iPhone and a spare iPad share the segment with the DGX Sparks and smart home
7infoInventory driftLive DHCP differs from DEVICES.md: operator-ii is .203 (not .11), glassway uses a private Wi-Fi MAC at .109 (not .40)
8infoFirewalla listens on SSH:22 + web:80 (Express) on the LANExpected for management, but confirm these stay LAN-only with strong auth

Recommendations

  1. Give tx9-columbia-agent a friendly tailnet name (e.g. set --hostname tx9-columbia-agent on the container) so future audits don’t re-flag it as an unknown node.
  2. Audit the portals. Log into the admin console and list what siva-portal / nexus-portal publish; revoke anything not intentional.
  3. Document the WiFi/routing gear (eero + 2× GL.iNet RM10): pick one upstream role, check firmware, and confirm travel routers only act as VPN clients / APs, not routers behind NAT.
  4. Create an IoT VLAN on the Firewalla and move smart-home devices + guest gear there; keep servers/NAS/desktops on your trusted VLAN.
  5. Harden the NAS: enable DSM 2FA, disable admin login over the segments you don’t need, and confirm no WAN inbound rules point at 5000/5001/445.
  6. Refresh DEVICES.md with live IPs (operator-ii .203, glassway private-MAC) so the canonical map matches reality.
Method
Read-only sweep from operator-ii: tailscale status/JSON, dig/MagicDNS, ARP + mDNS (Bonjour), gentle ICMP, and targeted nc connectivity checks on known infrastructure only. No destructive or invasive scanning.
Scope note
External (WAN-side) exposure could not be tested from inside the LAN; recommend a one-off external port review if you want confirmation of the inbound surface.