Network Topology¶
IP Address Map¶
┌─────────────────────────────────────────────────────────┐
│ PUBLIC INTERNET │
│ Strato VPS: 217.154.228.231 │
└───────────────┬─────────────────────────────────────────┘
│
┌───────────────┴─────────────────────────────────────────┐
│ STRATO HOST │
│ │
│ WireGuard Interfaces: │
│ ├── strato-host 10.0.0.1/24 (Admin VPN) │
│ ├── strato-vm 10.0.1.1/24 (VM Access VPN) │
│ └── openclaw-ai 10.0.3.1/24 (AI Tunnel) │
│ │
│ Docker Network: openclaw-infra 172.20.10.0/24 │
│ ├── Traefik 172.20.10.10 │
│ ├── Pi-hole 172.20.10.53 │
│ ├── Fail2ban 172.20.10.2 │
│ └── Docs 172.20.10.20 │
│ │
│ VM Bridge: virbr0 192.168.10.0/24 │
│ └── Gateway: 192.168.10.1 │
│ │
│ Control Center: 0.0.0.0:8089 (host network) │
│ │
│ ┌──────────────────────────────────────────────┐ │
│ │ KVM VM: 192.168.10.10 │ │
│ │ Gateway: 192.168.10.1 │ │
│ │ DNS: 192.168.10.1 → Pi-hole │ │
│ └──────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────────┘
VPN Subnets¶
| Subnet | Interface | Listen Port | Purpose | Host Access |
|---|---|---|---|---|
| 10.0.0.0/24 | strato-host | 51820 | Admin: SSH, dashboards, DNS | ✅ Full |
| 10.0.1.0/24 | strato-vm | 51821 | VM access (forwarded) | ❌ INPUT DROP |
| 10.0.3.0/24 | openclaw-ai | 51822 | AI sandbox tunnel | ❌ INPUT DROP |
INPUT DROP on strato-vm and openclaw-ai
The strato-vm and openclaw-ai interfaces have iptables -I INPUT 1 -i <iface> -j DROP rules. This means traffic arriving on these interfaces can only be forwarded to the VM — it cannot reach the host itself. This is a critical security measure.
Docker Network¶
The openclaw-infra network (172.20.10.0/24) is a custom bridge network with controlled egress rules:
# Docker network creation
docker network create --driver bridge \
--subnet 172.20.10.0/24 \
--gateway 172.20.10.1 \
openclaw-infra
Port Allocation¶
Public Ports (UFW)¶
| Port | Protocol | Service |
|---|---|---|
| 25 | TCP | SMTP (DNAT → VM 192.168.10.10) |
| 80 | TCP | Traefik (HTTP → HTTPS redirect) |
| 143 | TCP | IMAP (DNAT → VM 192.168.10.10) |
| 443 | TCP | Traefik (HTTPS) |
| 587 | TCP | SMTP Submission (DNAT → VM 192.168.10.10) |
| 993 | TCP | IMAPS (DNAT → VM 192.168.10.10) |
| 2222 | TCP | SSH forwarding to VM (DNAT) |
| 51820 | UDP | WireGuard: strato-host |
| 51821 | UDP | WireGuard: strato-vm |
| 51822 | UDP | WireGuard: openclaw-ai |
SSH (port 22) is VPN-only
Port 22 is not publicly accessible. It's only reachable via VPN subnets (10.0.0.0/24, 10.0.1.0/24, 10.0.3.0/24).
Internal Ports¶
| Port | Listener | Purpose |
|---|---|---|
| 8089 | Control Center | FastAPI management UI |
| 8080 | Traefik | Internal dashboard |
| 53 | Pi-hole | DNS (UDP+TCP) |
DNS Resolution¶
Admin Domains (VPN-only)¶
Pi-hole custom DNS entries resolve admin domains to the VPN gateway:
| Domain | Resolves To | Service |
|---|---|---|
firewall.clsxx.de |
10.0.0.1 | Control Center |
pihole.clsxx.de |
10.0.0.1 | Pi-hole Dashboard |
traefik.clsxx.de |
10.0.0.1 | Traefik Dashboard |
fail2ban.clsxx.de |
10.0.0.1 | Fail2ban Dashboard |
docs.clsxx.de |
10.0.0.1 | Documentation (this site) |
These domains resolve to the VPN IP, making them inaccessible without an active VPN connection.