Skip to content
stayZ3ROPublic

About

Managed home network lab documenting the completed UniFi UDM Pro and USW-24-PoE cutover, flat LAN validation, and planned VLAN segmentation and firewall policy.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Home Network Managed Infrastructure Lab

Status Project Routing Switching DNS Platform

Managed Network Cutovers, UniFi, AP Mode, and VLAN-Ready Network Foundation


This repository documents Project 2 of my home network infrastructure lab. Phase 1 records the ER605 and Omada cutover. A later equivalent-state refresh put a UniFi UDM Pro and USW-24-PoE at the network core on 2026-09-27. Deco nodes remain in AP mode, and the LAN remains flat. VLAN segmentation and firewall policy are planned.

Project 1 focused on building reliable core infrastructure services such as HA DNS, Unbound recursive DNS, monitoring, alerting, Tailscale remote access, Proxmox-hosted services, and operational validation.

Project 2 builds on that foundation by moving the network to managed routing and switching, creating the baseline required for VLAN segmentation, firewall policy, SSID-to-VLAN mapping, and enterprise-style network administration.


Quick Links

Area Link
Current Status CURRENT-STATUS.md
Roadmap ROADMAP.md
Changelog CHANGELOG.md
Lessons Learned LESSONS-LEARNED.md
Phase 1 Documentation docs/phase-1-managed-network-cutover/
Architecture Diagrams diagrams/
Screenshots screenshots/
Config Examples configs/

About This Project

This project documents the cutover from a consumer home network design into a more controlled, managed infrastructure model.

The main goal was to move routing and switching responsibilities away from the mesh system and into dedicated network infrastructure while keeping core services stable.

The original Phase 1 cutover introduced:

  • Dedicated routing with TP-Link ER605
  • Managed switching with TP-Link TL-SG2210P
  • Deco mesh operating in AP mode
  • Omada SDN-based device visibility
  • Redundant Pi-hole DNS with virtual IP failover
  • Proxmox-hosted infrastructure services
  • Monitoring validation after the cutover
  • A stable baseline for VLAN segmentation

Why I Built This

I built this project to practice the kind of work that sits between service desk, network administration, systems administration, and infrastructure engineering.

Instead of only documenting a working home network, this project focuses on the operational side of infrastructure changes:

  • Planning a live network cutover
  • Validating DNS, DHCP, internet, and service reachability
  • Reducing double NAT and consumer-router limitations
  • Preserving monitoring and remote access during topology changes
  • Creating a VLAN-ready foundation before introducing segmentation
  • Documenting the environment in a clear, professional, portfolio-ready format

Current Architecture Overview

Physical Network Path

Internet
  ↓
ONT
  ↓
AT&T Gateway / IP Passthrough
  ↓
UniFi UDM Pro Router / Firewall
  ↓
UniFi USW-24-PoE Managed Switch
  ├── Deco Mesh APs
  ├── Proxmox Host
  ├── Primary Pi-hole Node
  ├── Secondary Pi-hole Node
  ├── Wired Clients
  └── Wireless Clients

DNS Resolution Path

Client Device
  ↓
UDM Pro DHCP-Provided DNS
  ↓
Pi-hole HA VIP
  ↓
Active Pi-hole Node
  ↓
Local Unbound Recursive Resolver
  ↓
Internet DNS Resolution

Monitoring Path

Infrastructure Targets
  ↓
Prometheus / Blackbox Exporter
  ↓
Grafana Dashboards
  ↓
Alertmanager
  ↓
Discord Alerts

Management and Remote Access Path

Admin Endpoint
  ↓
Trusted LAN / Tailscale
  ↓
Proxmox / UniFi Network / Pi-hole / Monitoring Services

Completed and Planned Phases

Phase Status Focus
Phase 1 - Managed Router/Switch Cutover ✅ Complete ER605 cutover, managed switch integration, Deco AP mode, baseline validation
UniFi Hardware Refresh (2026-09-27) ✅ Complete UDM Pro and USW-24-PoE replaced the ER605 and TL-SG2210P without adding segmentation
Phase 2 - VLAN Segmentation ⏳ Planned VLAN IDs, subnet plan, network zones, DHCP scopes
Phase 3 - Firewall Policy ⏳ Planned Inter-VLAN rules, restricted management access, IoT/guest isolation
Phase 4 - Wireless SSID Mapping ⏳ Planned SSID-to-VLAN mapping for trusted, guest, IoT, and lab wireless
Phase 5 - Monitoring and Operations ⏳ Planned Monitoring updates, dashboards, runbooks, backups, validation procedures

Phase 1 documents the ER605 and Omada cutover as it happened. The 2026-09-27 UniFi refresh kept the same flat LAN, gateway, DHCP, and DNS behavior. Phase 2 onward uses the UniFi hardware.


Documentation

Phase 1 - Managed Router/Switch Cutover

Document Link
Overview View
Implementation View
Validation View
Rollback Plan View
Lessons Learned View
Screenshots Checklist View
Diagrams View

Future Phases

Phase Link
Phase 2 - VLAN Segmentation View
Phase 3 - Firewall Policy View
Phase 4 - Wireless SSID Mapping View
Phase 5 - Monitoring and Operations View

Architecture Diagrams

Diagram Status Link
Current Topology (UniFi, flat) Done View
Phase 2 - VLAN Segmentation Design Planned Coming soon
Phase 3 - Firewall Policy Flow Planned Coming soon

Hardware and Lab Systems

Component Role
AT&T Fiber Connection WAN connectivity
ONT / Optical Network Terminal Fiber handoff
AT&T Gateway with IP Passthrough ISP gateway
UniFi UDM Pro Dedicated router/firewall
UniFi USW-24-PoE Managed PoE switch
TP-Link Deco Mesh Wireless access points in AP mode
Raspberry Pi 3B+ Primary Pi-hole DNS node
Raspberry Pi 3B Secondary Pi-hole DNS node
Dell OptiPlex Proxmox Host Virtualization host
UniFi Network Network management on the UDM Pro
Docker Monitoring VM Monitoring service host
Admin Workstation / Laptop Testing and management endpoint

Core Tools and Services

Tool / Service Purpose
UniFi Network Centralized management for router and switch
UniFi UDM Pro Routing, firewalling, DHCP, and WAN handoff
UniFi USW-24-PoE Managed switching and future VLAN trunk/access ports
Pi-hole DNS filtering and visibility
Keepalived DNS virtual IP failover
Gravity Sync Pi-hole configuration synchronization
Unbound Local recursive DNS resolution
Proxmox Virtualization platform
Prometheus Metrics collection
Grafana Dashboard visualization
Blackbox Exporter Service probing
Alertmanager Alert routing
Tailscale Secure remote administration
Docker Compose Container orchestration

Historical Phase 1 Validation Summary (ER605 and Omada)

Validation Area Result
Internet access ✅ Passed
DHCP assignment ✅ Passed
DNS resolution ✅ Passed
Pi-hole HA VIP ✅ Passed
Primary Pi-hole node ✅ Passed
Secondary Pi-hole node ✅ Passed
Unbound recursion ✅ Passed
Proxmox access ✅ Passed
Omada Controller access ✅ Passed
Managed switch connectivity ✅ Passed
Deco AP mode wireless access ✅ Passed
Grafana / Prometheus monitoring ✅ Passed
Remote management access ✅ Passed

Security Notes

  • Public WAN IP addresses are not published.
  • MAC addresses and serial numbers are redacted from screenshots.
  • Raw configuration exports are excluded from Git.
  • Secrets, tokens, passwords, and private keys are excluded from this repository.
  • Management services are intended to remain LAN-only or privately reachable through trusted remote access.
  • Screenshots are sanitized before publishing.
  • VLAN and firewall policies will be documented in later phases before being treated as complete.

What This Project Demonstrates

This project demonstrates practical infrastructure skills across:

  • Network cutover planning
  • Managed router deployment
  • Managed switch integration
  • AP-mode wireless design
  • DNS and DHCP validation
  • High availability DNS awareness
  • Infrastructure monitoring validation
  • Proxmox-hosted service continuity
  • Network documentation
  • Screenshot-based proof of work
  • Operational rollback planning
  • VLAN-ready network design

Future Work

The next major phase is VLAN segmentation.

Planned work includes:

  • Define VLAN IDs
  • Build a subnet plan
  • Separate trusted, guest, IoT, infrastructure, and lab networks
  • Configure VLAN-aware switch ports
  • Map SSIDs to VLANs
  • Build an inter-VLAN firewall policy matrix
  • Validate allowed and denied traffic
  • Update monitoring targets after segmentation
  • Document final diagrams and screenshots

Goal

To build and document a realistic managed home network infrastructure lab that demonstrates routing, switching, DNS, monitoring, virtualization, secure administration, and future VLAN-based segmentation.


Related Infrastructure Labs

This repository is part of a broader infrastructure lab portfolio.

Repository Focus Relationship
Home Network Infrastructure Lab HA DNS, Pi-hole, Unbound, monitoring, Tailscale, Proxmox, RustDesk Provides the core infrastructure foundation used by this project
Home Network Managed Infrastructure Lab Managed router and switching; VLANs, firewall policy, and segmentation planned Expands the home lab into managed network infrastructure
VPS Cloud Infrastructure Lab Linux VPS hardening, Docker, DNS, HTTPS, monitoring, backups, secure access Extends infrastructure operations into cloud-hosted services

See the portfolio for the live project index.

About

Managed home network lab documenting the completed UniFi UDM Pro and USW-24-PoE cutover, flat LAN validation, and planned VLAN segmentation and firewall policy.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages