You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bought 2026-09-13 (#463): a used MikroTik CRS326-24G-2S+RM, in hand since 2026-09-23 without a power adapter; the MikroTik 24HPOW for it was delivered 2026-09-26. Phase 1 was done at the bench on 2026-10-05, apart from the SNMP proof, which needs the switch racked. What's left is Phase 2, the rack window. Decided by ADR-0041 ahead of the window: RouterOS over SwOS; it inherits the name neo and 10.7.7.2; www-ssl from the estate's CA with plain www off; an SNMPv3 authPriv user; port mirroring left disabled per ADR-0006. Procedure written: docs/runbooks/swap-the-switch.md, two phases — Phase 1 is two hours at a bench, everything but the cabling, and can happen the day the box lands; Phase 2 is the rack window, which shares a visit because neo carries every VLAN and no reboot happens while Mekenna is on the clock.
Moved to Nothing blocks these today: nothing in any other milestone gates it, and it is the thing that closes #84.
"Purchases this needs: the switch, $150–350" — bought; the roadmap took the row off the buy table in the same commit.
"Replace neo" — the name and address stay. What is replaced is the MokerLink.
Done when
swap-the-switch.md Phase 3: snmp-verify.sh clean over GET and GETBULK against the CRS326, the UI reachable over https with the estate's chain, the MokerLink out of the rack. Then close #84, then this.
Body as filed, superseded 2026-09-19
neo is now carrying its third accepted firmware residual, and ADR-0018 says
what to do about it: "A TLS management interface belongs in the selection
criteria whenever this switch is replaced."
This is the issue for that.
The three residuals, and why they are one purchase
#84 — it still accepts its
previous SNMP community, and the stock public and private besides,
measured twice. The firmware will not persist a deletion, and drops its SNMP
agent on each attempt. The other three devices refuse both.
#85 — no SNMPv3. Three of
four devices could move to authPriv; this one is the blocker for doing it
uniformly.
ADR-0018 — no TLS listener and no certificate import, checked against the
live device. So the switch admin password crosses the wire in cleartext,
through neo itself — the device the password protects. A mirrored port or
a foothold on the switch sees the credential to the switch. And unlike the
SNMP communities, that one is read-write.
The roadmap already names a replacement as the thing that would close #84, #85
and ADR-0018's residual together, and records that it was never decided. This
is the decision.
Port mirroring — worth having even though #437 mirrors at the
hypervisor, because it is the thing that would let the estate inspect a
segment morpheus cannot see.
Roughly $150–350: MikroTik CRS326 around $180, TP-Link TL-SG3428 around
$200, Ubiquiti USW-Pro-24 around $380.
What replacing it costs
A cabling window with the house offline — neo carries every VLAN. Worth
pairing with another rack visit rather than scheduling its own.
Per the roadmap's own rule, the PR that acts on this edits Everything still to
buy in the same commit.
Where this stands
Bought 2026-09-13 (#463): a used MikroTik CRS326-24G-2S+RM, in hand since 2026-09-23 without a power adapter; the MikroTik 24HPOW for it was delivered 2026-09-26. Phase 1 was done at the bench on 2026-10-05, apart from the SNMP proof, which needs the switch racked. What's left is Phase 2, the rack window. Decided by ADR-0041 ahead of the window: RouterOS over SwOS; it inherits the name
neoand10.7.7.2;www-sslfrom the estate's CA with plainwwwoff; an SNMPv3 authPriv user; port mirroring left disabled per ADR-0006. Procedure written:docs/runbooks/swap-the-switch.md, two phases — Phase 1 is two hours at a bench, everything but the cabling, and can happen the day the box lands; Phase 2 is the rack window, which shares a visit becauseneocarries every VLAN and no reboot happens while Mekenna is on the clock.Moved to Nothing blocks these today: nothing in any other milestone gates it, and it is the thing that closes #84.
What the body as filed got wrong
neo" — the name and address stay. What is replaced is the MokerLink.Done when
swap-the-switch.mdPhase 3:snmp-verify.shclean over GET and GETBULK against the CRS326, the UI reachable overhttpswith the estate's chain, the MokerLink out of the rack. Then close #84, then this.Body as filed, superseded 2026-09-19
neois now carrying its third accepted firmware residual, andADR-0018 says
what to do about it: "A TLS management interface belongs in the selection
criteria whenever this switch is replaced."
This is the issue for that.
The three residuals, and why they are one purchase
previous SNMP community, and the stock
publicandprivatebesides,measured twice. The firmware will not persist a deletion, and drops its SNMP
agent on each attempt. The other three devices refuse both.
four devices could move to authPriv; this one is the blocker for doing it
uniformly.
live device. So the switch admin password crosses the wire in cleartext,
through
neoitself — the device the password protects. A mirrored port ora foothold on the switch sees the credential to the switch. And unlike the
SNMP communities, that one is read-write.
The roadmap already names a replacement as the thing that would close #84, #85
and ADR-0018's residual together, and records that it was never decided. This
is the decision.
Selection criteria, from ADR-0018 and #85
#437 mirrors at the
hypervisor, because it is the thing that would let the estate inspect a
segment
morpheuscannot see.Roughly $150–350: MikroTik CRS326 around $180, TP-Link TL-SG3428 around
$200, Ubiquiti USW-Pro-24 around $380.
What replacing it costs
A cabling window with the house offline —
neocarries every VLAN. Worthpairing with another rack visit rather than scheduling its own.
Per the roadmap's own rule, the PR that acts on this edits Everything still to
buy in the same commit.
Purchases this needs
The switch. $150–350.