Wednesday, August 19, 2026

Transparency Report #014: PHYTWO (Aedon) OS Hypervisor Upgrade Preparation

What are Transparency Reports?
As a community‑operated and governed virtual internet exchange, FurrIX maintains
a commitment to open and honest communication with its members. From time to
time, operational work may occur that affects the exchange or its supporting infrastructure.
When this happens, the FurrIX operations team publishes a transparency report to
ensure all members remain informed. As a hobbyist‑rooted vIX, we aim to keep
communication clear, accessible and practical to the best of our ability.

What Happened
As a small team of volunteers, we pour a lot of free time into maintaining the network’s
engine PHYONE- which leaves our secondary server in need of a little TLC that has gotten
a bit long in the tooth.
Our PHYTWO server (Aedon) is overdue for major updates across its entire stack:
- Debian base OS
- Proxmox VE (PVE)
- Proxmox Backup Server (PBS)

These components are now far enough out of date that routine upgrades carry a
higher‑than‑normal risk of failure. To keep the exchange stable, we’re preparing for
both the best‑case and worst‑case outcomes.

Planned Work
We will be attempting a full upgrade of Aedon’s base OS and PVE environment. If everything
doesn’t explode on us, this will be a straightforward process and PHYTWO will return to service
with current software and no major changes. However, because this host is central to our
control‑plane and monitoring stack, we are staging for the possibility that the upgrade may fail
or leave the system in an unrecoverable state.

Pre‑Upgrade Safeguards
To protect the exchange and ensure continuity of essential services, we are taking the
following steps:
- Temporarily suspending NS2 service
NS2 will be offline during the upgrade window to avoid inconsistent state or partial failure scenarios.

- Backing up critical VMs to PHYONE
Any virtual machines required for day‑to‑day operation will be migrated or backed up to PHYONE.
This ensures we can continue running the vIX even if PHYTWO becomes unavailable.

- Preparing for a full rebuild
If the upgrade fails, we will rebuild PHYTWO from scratch, including its network configuration,
Proxmox environment, and PBS instance. This process may take time, but it will be done methodically
to avoid introducing instability into the fabric.

Expected Impact
- NS2 will be offline temporarily.
- Some internal tooling may experience brief interruptions.
- Limited member‑facing and peering services may be affected.

In the event of a failed upgrade, PHYTWO may remain offline for an extended rebuild period due
to our volunteers having outside pressures and commitments, but core vIX operations will continue
on PHYONE. We work on the exchange as time permits and in a method to avoid burnout of our
volunteers during this rather involved project.

Monday, August 3, 2026

Status Update

The routing stack across the exchange just got a fresh round of updates and a bit of
reconfiguration in response to the IR we posted earlier. Both name servers are now
running the same configuration, traffic shaping is in place where it actually matters
for the exchange, geoblocking has been added for the region where the bulk of the
attack traffic originated and the DNS rate‑limit profiles are now consistent across the
board. Everything within the exchange is back to normal day‑to‑day operation.

Among the changes:
- We’re now enforcing traffic shaping on the opnsense routers that interface
with the name servers, capping DNS networking at 15 Mbps.
- The RRL catch‑net for IPv6 has been widened from /56 to /48.
- The PHYTWO edge router (Groot) has finally been brought up to the latest firmware.
– This included converting older rules to the new UI.
- Not yet reflected in our policies: FurrIX will now retain NS logs for up to 48 hours
for debugging and network configuration work.

Hopefully this cleans up what we were dealing with over the past few days.

Tuesday, June 16, 2026

[Transparency Report #009][OPERATIONS] BGP Is Enabled! (Internally)

What are Transparency Reports?
As a community‑operated and governed virtual internet exchange, FurrIX maintains
a commitment to open and honest communication with its members. From time to
time, operational work may occur that affects the exchange or its supporting infrastructure.
When this happens, the FurrIX operations team publishes a transparency report to
ensure all members remain informed. As a hobbyist‑rooted vIX, we aim to keep
communication clear, accessible and practical to the best of our ability.

What is happening?
This is a good thing for the exchange to have figured out. As of Jun 15th, we have learned
how to configure and enable BGP on OpnSense within the exchange. This means our techs
can now peer the exchange with member delegated /64s over /127 wireguard links! This is
a goal that we have been working towards, which also serves to get us moving towards our
goal of one day having a public ASN. Going forward, members who join the exchange will
have the option of having their /64 on-link or BGP peering with us an announcing their
/64 to our routing fabric.

Changes to the exchange:
- FurrIX Transit Fabric: Edge, Catos and Nardoragon are all peered using AS65300. Edge
announces a default route downstream, while the other two routers announce their assigned
/58s to the Edge.
- Exchange Member Peering: FurrIX has reserved AS65320 for peering with members of
our exchange, we also have started to rework our peering policies along with reserving
AS65400-65500 for member BGP sessions and AS65501-AS6550 for peering with other
hobbyist networks.

Changes Proposed:
Eventually FurrIX would like to add a BGP looking glass to our network that is peered
with the Edge that will should all ASNs and routes on the exchange, but this is a ways
off for the moment.

Are exchange operations affected?

Everything is operating normally, this was just quiet work in the background in order to
mature the exchange a little further and get to a point that we are reaching some of our
goals that were set for this year.

Thursday, June 11, 2026

[Transparency Report #008][OPERATIONS] OS Upgrades and House Keeping!

What are Transparency Reports?
As a community‑operated and governed virtual internet exchange, FurrIX maintains
a commitment to open and honest communication with its members. From time to
time, operational work may occur that affects the exchange or its supporting infrastructure.
When this happens, the FurrIX operations team publishes a transparency report to
ensure all members remain informed. As a hobbyist‑rooted vIX, we aim to keep
communication clear, accessible and practical to the best of our ability.

What is happening?
FurrIX relies on a variety of open‑source operating systems and software projects that
work together to form the vIX. Periodically, our volunteers must perform housekeeping
tasks such as OS upgrades, NS zone updates and adjustments to routing and firewall
policies. Today marks the beginning of one such maintenance period focused on system
upgrades and lifecycle management.

What has been worked on so far:
- Core Router: Updated firewall rules to consolidate LIR‑range egress handling into a single
alias, reducing configuration duplication and improving maintainability
- Catos Access Router: Upgraded the OS due to end‑of‑life concerns and resolved an IPv6
routing issue affecting WireGuard interfaces
- Nardoragon Router: Upgraded the OS due to end‑of‑life concerns

Parts of the exchange still being worked on:
- Core Router: Pending OS upgrade to address EOL status
- Ikus vIX Access Router: Still offline and awaiting re‑deployment
- NMS: Monitoring is currently unavailable and requires full reconfiguration
- Status Page: Requires reconfiguration and an upgrade before it can be brought back online

Are exchange operations affected?

Yes — temporarily.
During house keeping, routing and service availability will be patchy as systems are updated
and rebooted. Once the work is complete, normal operations will resume as normal.

Monday, May 25, 2026

[Transparency Report #007][OPERATIONS] Full Environment Rebuild Scheduled WIP

What are Transparency Reports?
As a community‑operated and governed virtual internet exchange, FurrIX maintains
a commitment to open and honest communication with its members. From time to
time, operational work may occur that affects the exchange or its supporting infrastructure.
When this happens, the FurrIX operations team publishes a transparency report to
ensure all members remain informed. As a hobbyist‑rooted vIX, we aim to keep
communication clear, accessible and practical to the best of our ability.

What is happening?
The FurrIX vIX is currently going through its rebuild of our exchange and it is taking a little
longer than we expected. Due to a miscommunication, reinstalling the physical server’s OS
took a bit of time.

What has been reworked so far:
- Phy One: The ProxMox host has been rebuilt
- Core Router: We condensed our IPv6 edge and core router into one VM
- Nardoragon Router: Our services router is back online with new config
- Catos vIX Access Router: Has been pulled from backup and reconfigured
- NS1/Games-3P: These member facing services are back online
- Web Server: Our websites are back online

Parts of the exchange still being worked on:
- Mail-NG: the mail server has to be brought back online
- Ikus vIX Access Router: Secondary member facing router still being reconfig’d
- NMS: We currently have no monitoring, needs to be reconfigured

Are exchange operations affected?

Yes — temporarily.
During the rebuild window, routing and service availability will be null as systems are rebuilt
and renumbered. Once the work is complete, normal operations will resume with improved
stability, ease of expansion, better rooted upkeep and clarity.