This repository documents Project 2 of my home network infrastructure lab. Phase 1 records the ER605 and Omada cutover. A later equivalent-state refresh put a UniFi UDM Pro and USW-24-PoE at the network core on 2026-09-27. Deco nodes remain in AP mode, and the LAN remains flat. VLAN segmentation and firewall policy are planned.
Project 1 focused on building reliable core infrastructure services such as HA DNS, Unbound recursive DNS, monitoring, alerting, Tailscale remote access, Proxmox-hosted services, and operational validation.
Project 2 builds on that foundation by moving the network to managed routing and switching, creating the baseline required for VLAN segmentation, firewall policy, SSID-to-VLAN mapping, and enterprise-style network administration.
| Area | Link |
|---|---|
| Current Status | CURRENT-STATUS.md |
| Roadmap | ROADMAP.md |
| Changelog | CHANGELOG.md |
| Lessons Learned | LESSONS-LEARNED.md |
| Phase 1 Documentation | docs/phase-1-managed-network-cutover/ |
| Architecture Diagrams | diagrams/ |
| Screenshots | screenshots/ |
| Config Examples | configs/ |
This project documents the cutover from a consumer home network design into a more controlled, managed infrastructure model.
The main goal was to move routing and switching responsibilities away from the mesh system and into dedicated network infrastructure while keeping core services stable.
The original Phase 1 cutover introduced:
- Dedicated routing with TP-Link ER605
- Managed switching with TP-Link TL-SG2210P
- Deco mesh operating in AP mode
- Omada SDN-based device visibility
- Redundant Pi-hole DNS with virtual IP failover
- Proxmox-hosted infrastructure services
- Monitoring validation after the cutover
- A stable baseline for VLAN segmentation
I built this project to practice the kind of work that sits between service desk, network administration, systems administration, and infrastructure engineering.
Instead of only documenting a working home network, this project focuses on the operational side of infrastructure changes:
- Planning a live network cutover
- Validating DNS, DHCP, internet, and service reachability
- Reducing double NAT and consumer-router limitations
- Preserving monitoring and remote access during topology changes
- Creating a VLAN-ready foundation before introducing segmentation
- Documenting the environment in a clear, professional, portfolio-ready format
Internet
↓
ONT
↓
AT&T Gateway / IP Passthrough
↓
UniFi UDM Pro Router / Firewall
↓
UniFi USW-24-PoE Managed Switch
├── Deco Mesh APs
├── Proxmox Host
├── Primary Pi-hole Node
├── Secondary Pi-hole Node
├── Wired Clients
└── Wireless Clients
Client Device
↓
UDM Pro DHCP-Provided DNS
↓
Pi-hole HA VIP
↓
Active Pi-hole Node
↓
Local Unbound Recursive Resolver
↓
Internet DNS Resolution
Infrastructure Targets
↓
Prometheus / Blackbox Exporter
↓
Grafana Dashboards
↓
Alertmanager
↓
Discord Alerts
Admin Endpoint
↓
Trusted LAN / Tailscale
↓
Proxmox / UniFi Network / Pi-hole / Monitoring Services
| Phase | Status | Focus |
|---|---|---|
| Phase 1 - Managed Router/Switch Cutover | ✅ Complete | ER605 cutover, managed switch integration, Deco AP mode, baseline validation |
| UniFi Hardware Refresh (2026-09-27) | ✅ Complete | UDM Pro and USW-24-PoE replaced the ER605 and TL-SG2210P without adding segmentation |
| Phase 2 - VLAN Segmentation | ⏳ Planned | VLAN IDs, subnet plan, network zones, DHCP scopes |
| Phase 3 - Firewall Policy | ⏳ Planned | Inter-VLAN rules, restricted management access, IoT/guest isolation |
| Phase 4 - Wireless SSID Mapping | ⏳ Planned | SSID-to-VLAN mapping for trusted, guest, IoT, and lab wireless |
| Phase 5 - Monitoring and Operations | ⏳ Planned | Monitoring updates, dashboards, runbooks, backups, validation procedures |
Phase 1 documents the ER605 and Omada cutover as it happened. The 2026-09-27 UniFi refresh kept the same flat LAN, gateway, DHCP, and DNS behavior. Phase 2 onward uses the UniFi hardware.
| Document | Link |
|---|---|
| Overview | View |
| Implementation | View |
| Validation | View |
| Rollback Plan | View |
| Lessons Learned | View |
| Screenshots Checklist | View |
| Diagrams | View |
| Phase | Link |
|---|---|
| Phase 2 - VLAN Segmentation | View |
| Phase 3 - Firewall Policy | View |
| Phase 4 - Wireless SSID Mapping | View |
| Phase 5 - Monitoring and Operations | View |
| Diagram | Status | Link |
|---|---|---|
| Current Topology (UniFi, flat) | Done | View |
| Phase 2 - VLAN Segmentation Design | Planned | Coming soon |
| Phase 3 - Firewall Policy Flow | Planned | Coming soon |
| Component | Role |
|---|---|
| AT&T Fiber Connection | WAN connectivity |
| ONT / Optical Network Terminal | Fiber handoff |
| AT&T Gateway with IP Passthrough | ISP gateway |
| UniFi UDM Pro | Dedicated router/firewall |
| UniFi USW-24-PoE | Managed PoE switch |
| TP-Link Deco Mesh | Wireless access points in AP mode |
| Raspberry Pi 3B+ | Primary Pi-hole DNS node |
| Raspberry Pi 3B | Secondary Pi-hole DNS node |
| Dell OptiPlex Proxmox Host | Virtualization host |
| UniFi Network | Network management on the UDM Pro |
| Docker Monitoring VM | Monitoring service host |
| Admin Workstation / Laptop | Testing and management endpoint |
| Tool / Service | Purpose |
|---|---|
| UniFi Network | Centralized management for router and switch |
| UniFi UDM Pro | Routing, firewalling, DHCP, and WAN handoff |
| UniFi USW-24-PoE | Managed switching and future VLAN trunk/access ports |
| Pi-hole | DNS filtering and visibility |
| Keepalived | DNS virtual IP failover |
| Gravity Sync | Pi-hole configuration synchronization |
| Unbound | Local recursive DNS resolution |
| Proxmox | Virtualization platform |
| Prometheus | Metrics collection |
| Grafana | Dashboard visualization |
| Blackbox Exporter | Service probing |
| Alertmanager | Alert routing |
| Tailscale | Secure remote administration |
| Docker Compose | Container orchestration |
| Validation Area | Result |
|---|---|
| Internet access | ✅ Passed |
| DHCP assignment | ✅ Passed |
| DNS resolution | ✅ Passed |
| Pi-hole HA VIP | ✅ Passed |
| Primary Pi-hole node | ✅ Passed |
| Secondary Pi-hole node | ✅ Passed |
| Unbound recursion | ✅ Passed |
| Proxmox access | ✅ Passed |
| Omada Controller access | ✅ Passed |
| Managed switch connectivity | ✅ Passed |
| Deco AP mode wireless access | ✅ Passed |
| Grafana / Prometheus monitoring | ✅ Passed |
| Remote management access | ✅ Passed |
- Public WAN IP addresses are not published.
- MAC addresses and serial numbers are redacted from screenshots.
- Raw configuration exports are excluded from Git.
- Secrets, tokens, passwords, and private keys are excluded from this repository.
- Management services are intended to remain LAN-only or privately reachable through trusted remote access.
- Screenshots are sanitized before publishing.
- VLAN and firewall policies will be documented in later phases before being treated as complete.
This project demonstrates practical infrastructure skills across:
- Network cutover planning
- Managed router deployment
- Managed switch integration
- AP-mode wireless design
- DNS and DHCP validation
- High availability DNS awareness
- Infrastructure monitoring validation
- Proxmox-hosted service continuity
- Network documentation
- Screenshot-based proof of work
- Operational rollback planning
- VLAN-ready network design
The next major phase is VLAN segmentation.
Planned work includes:
- Define VLAN IDs
- Build a subnet plan
- Separate trusted, guest, IoT, infrastructure, and lab networks
- Configure VLAN-aware switch ports
- Map SSIDs to VLANs
- Build an inter-VLAN firewall policy matrix
- Validate allowed and denied traffic
- Update monitoring targets after segmentation
- Document final diagrams and screenshots
To build and document a realistic managed home network infrastructure lab that demonstrates routing, switching, DNS, monitoring, virtualization, secure administration, and future VLAN-based segmentation.
This repository is part of a broader infrastructure lab portfolio.
| Repository | Focus | Relationship |
|---|---|---|
| Home Network Infrastructure Lab | HA DNS, Pi-hole, Unbound, monitoring, Tailscale, Proxmox, RustDesk | Provides the core infrastructure foundation used by this project |
| Home Network Managed Infrastructure Lab | Managed router and switching; VLANs, firewall policy, and segmentation planned | Expands the home lab into managed network infrastructure |
| VPS Cloud Infrastructure Lab | Linux VPS hardening, Docker, DNS, HTTPS, monitoring, backups, secure access | Extends infrastructure operations into cloud-hosted services |
See the portfolio for the live project index.