Network

Executive Summary

The HHT network is a UniFi-managed ecosystem designed for high-availability theater operations. It utilizes a Double NAT architecture to maintain an “easy-recovery” path: the ISP router remains in ‘Router Mode’ to allow basic internet access via local ports if the UniFi stack fails.

1. Physical Infrastructure

Internet Service Provider (ISP)

  • Provider: BT Business Broadband
  • Modem/Gateway: TP-Link VR400
  • Mode: Router Mode (Handing off 192.168.1.x to the UniFi WAN)
  • DMZ: Configured to point to UniFi Gateway WAN IP to mitigate Double NAT issues.

Core Hardware

DeviceModelPhysical LocationNotes
GatewayUCG-UltraComms RackReplaced USG-3P (Jan 2026)
Core SwitchUSW-Pro-48-PoEComms Rack600W PoE Budget
ControllerIntel NUC (Docker)Comms Rack172.16.0.94

Wireless Access Points (WAPs)

LocationModelRole
Foyer (Bar)UAP-AC-ProHigh-density public/staff access
Foyer (Box Office)UAP-AC-ProHigh-density public/staff access
BackstageUAP-AC-LRLong-range coverage for tech crew
BalconyUAP-AC-LRCoverage for auditorium/balcony
GarrickUAP-AC-LRRoom-specific coverage
YardleyUAP-AC-LRRoom-specific coverage

2. Logical Network (VLANs & SSIDs)

VLANNameSubnetSSIDUsage
1Management172.16.0.0/24HiddenUniFi Hardware & NUC
10Public172.16.10.0/24teddingtontheatreclubGuest/Audience WiFi
20Admin172.16.20.0/24ttcadminStaff PCs, Office Printer
30General172.16.30.0/24TBDGeneral purpose / Staff BYOD
40Security172.16.40.xN/A (Wired)DualCom Alarm System
50Pixalite172.16.50.xN/A (Wired)Lighting & AV Control

3. Remote Access Strategy

Remote management is handled primarily through the UniFi Cloud Portal.

  • Primary VPN: UniFi Teleport (via WiFiman App).
  • Direct Access: Teleport bypasses the TP-Link firewall via the DMZ.
  • Backup Access: NUC is accessible via ZeroTier (Management VLAN).

4. Maintenance Notes

  • Switch Ports: 1-40 (PoE+), 41-48 (PoE++). PoE is disabled on ports 1-40 unless an AP is connected to reduce heat.
  • Backups: “Settings Only” .unf files are generated before any configuration changes and stored on the NUC and off-site.
  • Recovery: In the event of a UniFi failure, plug a laptop directly into the TP-Link VR400 (192.168.1.1) to regain basic internet access.

5. Port Map Reference

See separate Port Map Document for individual 48-port switch assignments.