docs(device-edge): add B2 public pilot runbook
This commit is contained in:
@@ -0,0 +1,106 @@
|
|||||||
|
# Device Edge B2 public pilot runbook
|
||||||
|
|
||||||
|
Status: router/NAT is **not configured** by this document. It is a one-pilot,
|
||||||
|
human-operated exposure gate for the already accepted Mini relay. It never
|
||||||
|
changes Synology, Gelios, VPN, Device Plane command transport or device
|
||||||
|
ownership.
|
||||||
|
|
||||||
|
## Exact traffic path
|
||||||
|
|
||||||
|
```text
|
||||||
|
ARUSNAVI B2 pilot
|
||||||
|
-> public IPv4 : TCP/9921
|
||||||
|
-> provider router : TCP/9921 -> 192.168.1.151:9921
|
||||||
|
-> Deco X55 : TCP/9921 -> 192.168.71.253:9921
|
||||||
|
-> Mini IPvlan relay
|
||||||
|
-> restricted private backhaul
|
||||||
|
-> Synology Gateway 127.0.0.1:9921
|
||||||
|
```
|
||||||
|
|
||||||
|
The observed Deco WAN is `192.168.1.151` with gateway `192.168.0.1`; it is an
|
||||||
|
RFC1918 address. Therefore this is a double-NAT topology. A Deco rule alone
|
||||||
|
cannot make the tracker reachable from the internet.
|
||||||
|
|
||||||
|
## Immutable safety boundary
|
||||||
|
|
||||||
|
- Forward **TCP only**, external and internal port `9921`.
|
||||||
|
- Deco target is exactly `192.168.71.253`, never the Mini host
|
||||||
|
`192.168.68.54` and never Synology.
|
||||||
|
- Do not enable DMZ, UPnP, port ranges, UDP, 443 forwarding or any catch-all
|
||||||
|
rule.
|
||||||
|
- Do not remove, replace or edit the Gelios monitoring route.
|
||||||
|
- The relay accepts connections only from a public IPv4 source, keeps
|
||||||
|
quarantine-only discovery and has no command transport. A LAN client will
|
||||||
|
intentionally be rejected; that is not a test failure.
|
||||||
|
- The rule must be deleted again if the single pilot is abandoned or the
|
||||||
|
expected quarantine evidence is not obtained.
|
||||||
|
|
||||||
|
## Gate 1 — DNS and public address
|
||||||
|
|
||||||
|
1. Determine the actual public IPv4 on the provider-facing edge. Do not use
|
||||||
|
`192.168.0.1`, `192.168.1.151`, `192.168.68.1` or `192.168.71.253` as a
|
||||||
|
DNS answer: all are private addresses.
|
||||||
|
2. Point `device.nodedc.ru` to that public IPv4 only if the tracker UI accepts
|
||||||
|
a hostname. Otherwise configure the public IPv4 directly.
|
||||||
|
3. If the provider router has no public WAN IPv4, or an internet check still
|
||||||
|
cannot reach it after both rules below, stop. This is provider CGNAT/bridge
|
||||||
|
territory: request a public IPv4 or a bridge/forwarding option from the
|
||||||
|
provider. Do not introduce a VPS as an unreviewed workaround.
|
||||||
|
|
||||||
|
## Gate 2 — provider router
|
||||||
|
|
||||||
|
On the upstream/provider router, create one port-forward rule:
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
| --- | --- |
|
||||||
|
| Name | `NDC B2 pilot to Deco` |
|
||||||
|
| Protocol | `TCP` |
|
||||||
|
| External port | `9921` |
|
||||||
|
| Target address | `192.168.1.151` |
|
||||||
|
| Target port | `9921` |
|
||||||
|
|
||||||
|
Save only that rule. It targets the Deco WAN address, not a service host.
|
||||||
|
|
||||||
|
## Gate 3 — Deco X55
|
||||||
|
|
||||||
|
In the Deco mobile app: **More → Advanced → NAT Forwarding → Port Forwarding →
|
||||||
|
Add**. Create exactly:
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
| --- | --- |
|
||||||
|
| Name | `NDC B2 pilot` |
|
||||||
|
| Protocol | `TCP` |
|
||||||
|
| External port | `9921` |
|
||||||
|
| Internal IP | `192.168.71.253` |
|
||||||
|
| Internal port | `9921` |
|
||||||
|
|
||||||
|
If the app forces a client selection, select the IPvlan relay only if its
|
||||||
|
address is shown as `192.168.71.253`. Do not select the Mini host or any NAS.
|
||||||
|
If the UI will not accept the fixed IPvlan address, stop and record that fact;
|
||||||
|
do not substitute a DHCP address.
|
||||||
|
|
||||||
|
## Gate 4 — ARUSNAVI B2 route
|
||||||
|
|
||||||
|
Use one known pilot B2 and one unused monitoring-server slot. Configure an
|
||||||
|
additional route with the documented **INTERNAL** protocol and the public
|
||||||
|
hostname/IP from Gate 1, TCP port `9921`. Preserve the existing Gelios route in
|
||||||
|
its current slot. The ARUSNAVI account password stays in the operator surface;
|
||||||
|
it is not entered into Foundry, Device Plane or the relay.
|
||||||
|
|
||||||
|
The device IMEI observed in `HEADER2` is a claimed identifier only. It becomes
|
||||||
|
a quarantine discovery, not an owned device and never a command target.
|
||||||
|
|
||||||
|
## Acceptance and failure handling
|
||||||
|
|
||||||
|
The first valid HEADER/PACKAGE through the pilot route must produce a masked,
|
||||||
|
quarantine-only discovery in Device Control Core and the existing Gelios map
|
||||||
|
path must continue independently. Do not issue a device command.
|
||||||
|
|
||||||
|
On any unexpected behavior, remove the two NAT rules in reverse order:
|
||||||
|
|
||||||
|
1. remove the Deco `NDC B2 pilot` rule;
|
||||||
|
2. remove the provider-router `NDC B2 pilot to Deco` rule.
|
||||||
|
|
||||||
|
This ends external reachability while leaving the Mini, VPN, backhaul,
|
||||||
|
Synology and Gelios unchanged. Do not use a LAN port probe as acceptance: the
|
||||||
|
relay correctly rejects private source addresses.
|
||||||
Reference in New Issue
Block a user