## User - **User:** Howard Enos (howard) - **Machine:** Howard-Home - **Role:** tech # Cascades — CSC ENT device-island consolidation plan + live client inventory ## Session Summary Picked up the Cascades voice-quality thread after Richard Turner (Vertical/Poly) replied that Poly handsets cannot be statically pinned to a band; Poly recommends a dedicated 5 GHz SSID for the phones (or disabling band steering on a shared SSID). Verified the live UniFi config via the `unifi-wifi` skill / UOS Mongo: the voice phones ride a PPSK voice key on the shared `CSCNet` SSID (2.4+5 GHz), band steering (`no2ghz_oui`) is already ON across CSCNet/CSC ENT/Guest, and it is not holding the Poly OUI on 5 GHz. Conclusion: the durable fix is a dedicated 5 GHz network, not toggling steering. Pulled the Helpany context from Howard's mailbox (June 19 forward from John Trozzi + the March install thread). Key findings: the Helpany "Paul" devices are radar fall/motion sensors (Sedimentum backend, no camera/mic — not "IR cameras"), are WPA2-only (no WPA3/hybrid), were deliberately placed on the `CSC ENT` SSID (key `Ftfd85710#`) as Mike's WPA2 island, carry negligible bandwidth (<0.04 Mbps/device, ~1.35 Mbps fleet peak), and Helpany can remotely transition them to a dedicated 5 GHz SSID if given SSID+password. Both vendors converged on the same fix. Designed and documented the consolidation: repurpose CSC ENT as a 5 GHz-only WPA2 PPSK device island carrying both the Poly phones (PPSK key -> VLAN 30) and the Helpany Pauls (PPSK key -> new VLAN 40), separated at the VLAN layer; Pauls keep their SSID+key (not reprogrammed, only band-moved); CSC ENT is NOT deleted (that would orphan the Pauls). Wrote the plan to `docs/network/csc-ent-device-island-plan.md`, folded it into `docs/REMAINING-WORK-PLAN.md` Workstream 6 + the onsite batch, and updated the wiki + `docs/network/wifi.md`. Ran a live client pull (UOS `stat/sta`, site `va6iba3v`) to find who is actually on CSC ENT before any change: 149 associated clients, only 68 Helpany Pauls. The other ~79 must be evacuated first (14 staff PCs, 11 printers, 11 DIRECTV resident TVs, 11 resident IoT/TVs, 15 personal phones/tablets, 17 unknown/randomized). ~51 are on 2.4 GHz and would drop on a 5 GHz-only flip. Built `docs/network/csc-ent-client-inventory-2026-06-24.md`, then re-cut the data into grouped form (Cascades/facility vs resident vs unknown, with room guesses where derivable) and DM'd the grouped list to Howard in Discord. Identified DESKTOP-ROK7VNM as Susan Hicks's machine (`CASCADES\Susan.Hicks`). ## Key Decisions - Repurpose CSC ENT as the permanent 5 GHz-only WPA2 device island rather than build a new SSID: the Pauls are already on CSC ENT, so they are not reprogrammed (Helpany only band-moves them); reuse avoids an extra beaconing SSID on a dense 77-AP site. - One SSID via PPSK with per-key VLANs (phones -> VLAN 30, Helpany -> new VLAN 40) rather than two separate SSIDs — minimizes beacon airtime while keeping voice QoS + HIPAA L2 isolation. - Keep CSC ENT WPA2-only forever (Helpany hard requirement); this is the prerequisite that later lets CSCNet move to WPA3/WiFi7/6 GHz — but that step is gated by the ~230 resident 2.4-only/WPA2 IoT clients on CSCNet, not by the voice/sensor gear (separate project). - Do NOT flip CSC ENT to 5 GHz-only until the ~79 non-Helpany clients are evacuated; 51 clients on 2.4 GHz would drop instantly. - Treat resident devices (DIRECTV/Ring/Echo/TVs/phones) as the visible-impact group requiring an onsite door-to-door reconnection plan (senior population will not self-serve). - Room mapping must come from the AP-name map (Cascades APs are named by room/area), not IP — all CSC ENT clients are in the flat 192.168.2.x/3.x AP pool, not per-room VLANs. ## Problems Encountered - UOS controller login throttle: rapid successive `/api/auth/login` calls (categorizer + retry loop) tripped HTTP 403 lockout that persisted across later attempts. Resolved by stopping the re-auth attempts and working from the first successful `stat/sta` pull. Logged as friction via `log-skill-error.sh --friction`. Lesson: reuse one session / save the JSON, do not re-login per query. The AP-name map + `stat/alluser` pulls are deferred until the lockout clears. - Offline transcription of the captured client list summed to 147 vs the live 149 (2 dropped in hand-transcription); category proportions unaffected. Authoritative count is 149 from the live pull. - Mailbox/web lookup mismatch: helpany.com markets "PAUL" radar (no cameras), while Howard described "IR cameras." Reconciled via the March install email — they are radar sensors; the "IR camera" label is colloquial. Flagged in docs. ## Configuration Changes Created: - `clients/cascades-tucson/docs/network/csc-ent-device-island-plan.md` — full consolidation design, vendor constraints, VLAN 40 spec, execution sequence (incl. evacuation prerequisite), WPA3 future. - `clients/cascades-tucson/docs/network/csc-ent-client-inventory-2026-06-24.md` — per-device CSC ENT inventory (149), resident "help-reconnect" list, staff/printer/Helpany breakdown. Modified: - `clients/cascades-tucson/docs/REMAINING-WORK-PLAN.md` — Workstream 6 rewritten to lead with the CSC ENT consolidation + evacuation prerequisite; onsite batch now includes per-room 5 GHz coverage verification. - `wiki/clients/cascades-tucson.md` — voice "actual fix" bullet updated (Richard reply), added the `[PLAN 2026-06-24]` consolidation bullet + a Helpany vendor/hardware entry. - `clients/cascades-tucson/docs/network/wifi.md` — CSC ENT SSID row (repurpose + do-not-delete); Issue #5 (band steering) corrected. - `errorlog.md` — friction entry for the login-throttle. ## Credentials & Secrets - `CSC ENT` / `CSCNet` WPA2 key: `Ftfd85710#` — surfaced in the March Helpany install thread. Already vaulted as the CSCNet password (`clients/cascades-tucson/wifi-cscnet.sops.yaml`, `credentials` block). CSC ENT shares the same key. A dedicated `clients/cascades-tucson/wifi-csc-ent` entry was offered but not yet created (the secret value is already captured). - Read-only UOS controller admin used for live pulls: vault `infrastructure/uos-server-network-api`. ## Infrastructure & Servers - UOS UniFi controller: `172.16.3.29:11443` (HTTPS), site short `va6iba3v` / site_id `685f39068e65331c46ef6dd2`. Mongo read via `.claude/scripts/uos-mongo.sh` (vault `infrastructure/uos-server-ssh-key`). - Cascades WLANs (wlanconf): CSCNet `685f39078e65331c46ef7ee5` (PPSK, 2g+5g, WPA2, no2ghz_oui ON, bss_transition ON); CSC ENT `685f39078e65331c46ef7ee4` (single PSK, 2g+5g, WPA2, no2ghz_oui ON); Guest `685f39078e65331c46ef7ee6` (2g/5g/6g); `element-5b32...` `685f39078e65331c46ef7ee3` (unnamed, investigate). - Helpany/Sedimentum egress (for VLAN 40): `*.sedimentum.com` on 5671 AMQPS, 8883 MQTT, 8030 HTTP, 443 HTTPS; plus snapcraft.io / api.snapcraft.io / public.apps.ubuntu.com / fastly.cdn.snapcraft.io on 443. - Live SSID client counts (2026-06-24): CSCNet 434, CSC ENT 149, Guest 21. - CSC ENT breakdown: Helpany Paul 68 (42 on 5 GHz, 26 on 2.4), Staff PC 14, Printer 11, DIRECTV 11, Resident IoT/TV 11, Personal phone/tab 15, Unknown/randomized 17. ~51 on 2.4 GHz total. ## Commands & Outputs - Live WLAN config: `echo 'db.wlanconf.find({site_id:"685f39068e65331c46ef6dd2"},{...}).forEach(...)' | bash .claude/scripts/uos-mongo.sh` - Live clients per SSID + CSC ENT detail: custom curl login to `https://172.16.3.29:11443/api/auth/login` then `GET /proxy/network/api/s/va6iba3v/stat/sta`, grouped by `essid` in Python. JSON saved to scratchpad `sta.json`. - Mailbox search: `/mailbox` skill (ComputerGuru Mailbox app `1873b1b0`) — search `"helpany"`, read the June 19 forward (`...AAG6nFrbAAA=`) + March install thread (`...AAGDNhycAAA=`). - Discord: grouped list DM'd to howard via `bash .claude/scripts/discord-dm.sh howard` (2 messages). - Friction log: `bash .claude/scripts/log-skill-error.sh "unifi-wifi/live-stats" "rapid successive controller logins -> HTTP 403 lockout..." --friction`. ## Pending / Incomplete Tasks - Controller login-throttled; once clear, pull: (1) `stat/device` AP-name map -> attach real room/area to all 149 CSC ENT clients; (2) `stat/alluser` -> add offline resident TVs/boxes (true count > 149). - Identify the 17 unknown/randomized devices + the generic iPhone/iPad/Samsung BYOD (DHCP lease names + onsite pass / John Trozzi for the named phones Espe, Sepopo). - Reconcile the 68 Helpany serials against Helpany's install QA/placement forms (their room map). - Build the resident-device reconnection sub-plan (target network + who reconnects what; door-to-door worksheet). - Decide PPSK-on-one-SSID (recommended) vs two SSIDs; confirm VLAN 40 free (and whether VLAN 10 "CSC Internal Network" is an orphan to reclaim). - Coordinate the change window with Vertical (Richard) + Helpany (Sandro/Eugenie); verify per-room 5 GHz coverage onsite before any band flip. - Optional: create dedicated `clients/cascades-tucson/wifi-csc-ent` vault entry; draft the two vendor coordination emails. - Update REMAINING-WORK-PLAN Workstream 2 to mark Susan Hicks's machine (DESKTOP-ROK7VNM) pinned. ## Reference Information - Plan: `clients/cascades-tucson/docs/network/csc-ent-device-island-plan.md` - Inventory: `clients/cascades-tucson/docs/network/csc-ent-client-inventory-2026-06-24.md` - Prior voice work: `docs/network/2026-06-19-vertical-5ghz-lock-request.md`, `docs/network/voice-vlan-cutover.md`, `reports/2026-06-18-voice-quality-diagnostic.md`. - Vendors: Richard Turner (Poly/Vertical); Sandro Cilurzo , Eugenie Nicoud (Helpany); John Trozzi (facility liaison). - DESKTOP-ROK7VNM = `CASCADES\Susan.Hicks`. --- ## Update: 17:40 PT — scope correction, IP segmentation, printer model lookup (blocked), LAN outage ### Summary After the grouped device list was DM'd to Howard, the plan scope was corrected and narrowed, and a printer model lookup was attempted but blocked by a network outage. - **Scope correction (Howard):** do NOT build VLANs for internal/resident devices — only the phones (VLAN 30) and Helpany (VLAN 40) get VLANs on CSC ENT. All other CSC ENT devices are *removed* to existing networks (staff -> CSCNet/INTERNAL, residents -> CSCNet), not re-segmented. Dropped the earlier over-engineered print-VLAN / resident-VLAN proposal. - **CSC ENT goes 5 GHz-only by DISABLING 2.4.** Both Poly/Vertical AND Helpany confirmed they cannot pin a device to a band from their side, so a 5 GHz-only SSID is the ONLY mechanism. Key consequence captured in the plan: on a 5 GHz-only SSID there is NO 2.4 fallback, so a Paul/phone in a weak-5 GHz spot will fail to connect entirely — 5 GHz coverage is now a HARD GATE, not a precaution. The 26 Pauls currently on 2.4 are the survey/risk set. - **2.4-only devices** (esp. ~10 of 11 wireless printers) must move to CSCNet (which keeps 2.4) before the 2.4 disable. Identified DESKTOP-ROK7VNM = Susan Hicks during this pass. - **Printer model lookup attempted, blocked:** tried CS-SERVER via GuruRMM to enumerate printer driver names + IPs. RMM login returned empty; probing found ALL THREE internal endpoints unreachable (RMM 172.16.3.30:3001, UOS 172.16.3.29:11443, coord 172.16.3.30:8001 — all HTTP 000), i.e. the Howard-Home -> 172.16.3.x path is down (VPN/site link). Recorded best-effort assessment (1 confirmed dual-band on 5 GHz, 10 likely 2.4-only by brand) in the inventory doc. - **Background auto-retry armed:** `printer-probe-watch.sh` waits ~45 min for RMM to return, then probes CS-SERVER and saves results. First launch failed (exit 127 — detached shell does not inherit $TMPDIR -> empty path); relaunched with absolute paths (task bxi7itkby). Logged the $TMPDIR friction. ### Configuration Changes (this update) - `docs/network/csc-ent-device-island-plan.md` — corrected scope (only phones/Helpany VLANed; others removed not segmented); reworded the flip to "disable 2.4" with the no-fallback ordering caution; added the both-vendors-cannot-pin-band constraint + 5 GHz-coverage-as-hard-gate. - `docs/network/csc-ent-client-inventory-2026-06-24.md` — DESKTOP-ROK7VNM -> Susan Hicks; printer section rebuilt as a per-device table with band-capability assessment + pending-probe note. - `errorlog.md` — two friction entries: UOS login throttle (earlier) + background-shell $TMPDIR. - Scratch (not committed): `printer-probe-watch.sh` + result file in the session scratchpad. ### Live data captured (this update) - Live SSID client counts: CSCNet 434, CSC ENT 149, Guest 21. - CSC ENT 149 grouped: Helpany Paul 68 (42 on 5 GHz / 26 on 2.4), Staff PC 14, Printer 11 (1 dual-band, 10 on 2.4), DIRECTV 11, Resident IoT/TV 11, Personal phone/tab 15, Unknown 17. - The 11 wireless printer IPs probed for: 192.168.2.67, .3.232, .3.227, .3.52, .3.10, .3.44, .2.53, .2.75, .2.145, .3.88, .2.147. ### Pending / blockers (this update) - **Howard-Home -> 172.16.3.x path is DOWN** — blocks RMM, UniFi controller, and coord. Restoring it unblocks: printer model probe (auto-armed), AP->room map, `stat/alluser` offline-device pull. - Background task `bxi7itkby` will finish the printer probe automatically when the LAN returns (or time out at ~45 min). On result: fill printer models + lock 2.4-only flags in the inventory doc. - Onsite fallback: eyeball printer models during the visit if the LAN stays down.