Skip to content

Network Topology

IP Address Map

┌─────────────────────────────────────────────────────────┐
│  PUBLIC INTERNET                                         │
│  Strato VPS: 217.154.228.231                             │
└───────────────┬─────────────────────────────────────────┘
                │
┌───────────────┴─────────────────────────────────────────┐
│  STRATO HOST                                             │
│                                                          │
│  WireGuard Interfaces:                                   │
│  ├── strato-host  10.0.0.1/24   (Admin VPN)             │
│  ├── strato-vm    10.0.1.1/24   (VM Access VPN)         │
│  └── openclaw-ai  10.0.3.1/24   (AI Tunnel)             │
│                                                          │
│  Docker Network: openclaw-infra 172.20.10.0/24            │
│  ├── Traefik      172.20.10.10                           │
│  ├── Pi-hole      172.20.10.53                           │
│  ├── Fail2ban     172.20.10.2                            │
│  └── Docs         172.20.10.20                           │
│                                                          │
│  VM Bridge: virbr0 192.168.10.0/24                       │
│  └── Gateway: 192.168.10.1                               │
│                                                          │
│  Control Center: 0.0.0.0:8089 (host network)             │
│                                                          │
│  ┌──────────────────────────────────────────────┐        │
│  │  KVM VM: 192.168.10.10                        │        │
│  │  Gateway: 192.168.10.1                        │        │
│  │  DNS: 192.168.10.1 → Pi-hole                 │        │
│  └──────────────────────────────────────────────┘        │
└─────────────────────────────────────────────────────────┘

VPN Subnets

Subnet Interface Listen Port Purpose Host Access
10.0.0.0/24 strato-host 51820 Admin: SSH, dashboards, DNS ✅ Full
10.0.1.0/24 strato-vm 51821 VM access (forwarded) ❌ INPUT DROP
10.0.3.0/24 openclaw-ai 51822 AI sandbox tunnel ❌ INPUT DROP

INPUT DROP on strato-vm and openclaw-ai

The strato-vm and openclaw-ai interfaces have iptables -I INPUT 1 -i <iface> -j DROP rules. This means traffic arriving on these interfaces can only be forwarded to the VM — it cannot reach the host itself. This is a critical security measure.

Docker Network

The openclaw-infra network (172.20.10.0/24) is a custom bridge network with controlled egress rules:

# Docker network creation
docker network create --driver bridge \
  --subnet 172.20.10.0/24 \
  --gateway 172.20.10.1 \
  openclaw-infra

Port Allocation

Public Ports (UFW)

Port Protocol Service
25 TCP SMTP (DNAT → VM 192.168.10.10)
80 TCP Traefik (HTTP → HTTPS redirect)
143 TCP IMAP (DNAT → VM 192.168.10.10)
443 TCP Traefik (HTTPS)
587 TCP SMTP Submission (DNAT → VM 192.168.10.10)
993 TCP IMAPS (DNAT → VM 192.168.10.10)
2222 TCP SSH forwarding to VM (DNAT)
51820 UDP WireGuard: strato-host
51821 UDP WireGuard: strato-vm
51822 UDP WireGuard: openclaw-ai

SSH (port 22) is VPN-only

Port 22 is not publicly accessible. It's only reachable via VPN subnets (10.0.0.0/24, 10.0.1.0/24, 10.0.3.0/24).

Internal Ports

Port Listener Purpose
8089 Control Center FastAPI management UI
8080 Traefik Internal dashboard
53 Pi-hole DNS (UDP+TCP)

DNS Resolution

Admin Domains (VPN-only)

Pi-hole custom DNS entries resolve admin domains to the VPN gateway:

Domain Resolves To Service
firewall.clsxx.de 10.0.0.1 Control Center
pihole.clsxx.de 10.0.0.1 Pi-hole Dashboard
traefik.clsxx.de 10.0.0.1 Traefik Dashboard
fail2ban.clsxx.de 10.0.0.1 Fail2ban Dashboard
docs.clsxx.de 10.0.0.1 Documentation (this site)

These domains resolve to the VPN IP, making them inaccessible without an active VPN connection.