feat(mesh): cutover COMPLETE — all three site-pairs on headscale, Site Magic + IPsec dormant
This commit is contained in:
@@ -263,3 +263,15 @@ egress with a native feature. Not yet configured — parked follow-up.
|
||||
**Follow-ups:** operator disables Site Magic; (optional) disable FortiGate phase1 ends for
|
||||
tidiness; advertise exit nodes; self-hosted DERP at ESH on the 2G circuit; remove the
|
||||
FortiGate WAN-SSH trusthosts when the edge is retired; PVE 8.4 upgrade on pfi-pve/nh3-pve.
|
||||
|
||||
## ✅ CUTOVER COMPLETE 2026-09-06 — all three site-pairs on the mesh
|
||||
|
||||
Operator disabled Site Magic in the UniFi UI. NH3↔ESH re-homed to the mesh immediately —
|
||||
traceroute now esh-scale(10.0.50.65)→nh3-scale(100.64.0.1)→dest, no 192.168.1.x SD-WAN
|
||||
transit; esh-scale↔nh3-scale hole-punched a DIRECT public path (70.230.226.88:41641, 8ms),
|
||||
not even DERP. Full matrix verified, all six directions OPEN:
|
||||
NH3↔colo, NH3↔ESH, colo↔ESH. FortiGate mgmt via WAN SSH OPEN; ana-wg WG fallback untouched.
|
||||
|
||||
State: **Site Magic disabled (UI); both IPsec tunnels dormant (UDM ends disabled, config
|
||||
retained); headscale is the sole active site-to-site transport.** Tunnels re-enablable for
|
||||
backup (Site Magic in UI; IPsec by flipping the UDM objects enabled=true). Goal met.
|
||||
|
||||
Reference in New Issue
Block a user