← All Engineering Projects

ONYXNET // ENGINEERING CASE STUDY

Network Engineering & Security

Designing a Six-VLAN Homelab Network

How OnyxNet uses VLAN segmentation, pfSense, managed switching, and practical design constraints to operate a production-style home network.

Operational — Security-policy review pending
pfSenseVLANsZyxelUniFiFirewall Policies

OnyxNet is a continuously evolving homelab that I use to develop practical skills in network engineering, infrastructure operations, and system administration.

One of its foundational projects was implementing a segmented network using six operational VLANs.

The network and its existing firewall configuration have been in use for approximately one year.

This case study documents the design goals, deployed architecture, constraints, and lessons learned.

The Engineering Problem

A home network can accumulate devices with very different purposes and security requirements.

OnyxNet includes:

  • Personal computers and gaming systems
  • Servers and virtualization infrastructure
  • IoT and home automation devices
  • Security cameras
  • Guest devices
  • Network management interfaces

Placing all these systems in one unrestricted network would make it difficult to apply different security policies.

The objective was to separate infrastructure according to function and intended trust level.

Requirements

The segmented network needed to:

  1. Support existing devices and services.
  2. Separate management from ordinary client traffic.
  3. Provide distinct networks for IoT and cameras.
  4. Support a guest network.
  5. Allow necessary communication between VLANs.
  6. Operate using existing hardware.
  7. Remain maintainable without unnecessary complexity.

Availability and cost were also important.

The network supports everyday home activities alongside the homelab, making unnecessary disruption undesirable.

Hardware and Technology

The design uses the following infrastructure.

Component Technology
Routing and firewall pfSense
Firewall hardware AWOW AK34 mini PC
Managed switching 3 × Zyxel GS1200-8HPv3
Wireless 2 × UniFi AP AC-Lite
Network speed Primarily 1 GbE
Virtualization Proxmox VE
Storage TrueNAS

The existing hardware is an important design constraint rather than something being immediately replaced.

Implemented Network Segmentation

Six VLANs are currently deployed.

VLAN Name Function
10 Valhalla Management
25 Jotunheim IoT
50 Helheim Security / Cameras
99 Vanaheim Guest
100 Midgard Trusted Devices
1000 Asgard Server / Data

The VLANs provide separate logical network segments for different categories of devices.

pfSense provides routing between the networks and enforces the configured firewall policies.

The switches provide VLAN-capable connectivity to the appropriate network infrastructure and attached devices.

The current design is operational.

However, a formal audit of the firewall rules and their effective security boundaries remains a separate improvement project.

Key Design Decisions

Functional Network Segmentation

VLANs were organized by infrastructure purpose rather than simply dividing devices into arbitrary groups.

This provides a foundation for applying policies based on the role and trust level of a device.

Centralized Routing and Policy

pfSense provides a centralized location for inter-VLAN routing and firewall configuration.

This simplifies identifying the intended policy boundaries between networks.

The precise currently permitted flows will be documented after the ruleset review.

Supporting Required Exceptions

Complete isolation is not always practical.

Examples of services that may require cross-VLAN communication include:

  • Home Assistant integrations
  • DNS
  • Monitoring systems
  • Hosted applications
  • Trusted client access to selected services

The objective is to permit required access without unnecessarily broad permissions.

Working Within Hardware Constraints

OnyxNet currently operates primarily with 1 GbE network infrastructure.

Although higher-speed networking is a long-term goal, the current design must remain viable without additional purchases.

Configuration improvements and operational visibility take priority over hardware upgrades.

What Has Been Achieved

The network currently operates with:

  • Six deployed VLANs
  • pfSense routing and firewall policies
  • VLAN-capable managed switching
  • UniFi wireless connectivity
  • Separate network categories for clients, infrastructure, cameras, IoT, and guests

The segmentation architecture has supported daily homelab operations for approximately one year.

This demonstrates a sustained operational deployment rather than a one-time lab exercise.

What Still Needs Validation

A deployed VLAN configuration is not proof that every intended security restriction is working correctly.

A future policy review will assess:

  1. Firewall rule order and behavior.
  2. Inter-VLAN permissions.
  3. Management network access.
  4. Guest isolation.
  5. Camera and IoT restrictions.
  6. Required application exceptions.
  7. The effectiveness of existing policies.

No formal security validation results are claimed in this case study.

An Architecture Decision: VLAN 700

During future offsite backup planning, I considered introducing VLAN 700, named Ginnungagap.

The original concept involved a dedicated point-to-point transit network and additional remote networking infrastructure.

After evaluating the actual connectivity requirements, cost, and operational complexity, I selected Tailscale instead.

VLAN 700 was never implemented.

The offsite backup project remains deferred due to budget constraints.

This design decision is documented separately in an Architecture Decision Record.

Read ADR-001: Ginnungagap Connectivity

Lessons Learned

Segmentation Is a Starting Point

VLANs establish logical network boundaries.

The security benefits depend on how routing, firewall policies, switching, and endpoint access are configured.

Operational Constraints Matter

An architecture must accommodate the systems that depend on it, available hardware, maintenance requirements, and budget.

Complexity Must Have a Purpose

Adding more networks or dedicated equipment isn’t inherently an improvement.

Architecture decisions should be justified by actual requirements.

Documentation Supports Evolution

Recording the current architecture and the reasoning behind changes makes future improvements easier to evaluate.

Next Steps

OnyxNet’s network redesign remains an independent project that has not yet resumed.

Future improvements will focus on reviewing the existing architecture, validating security policies, and documenting verified behavior.

Results will be incorporated into this case study as changes are implemented.

Technical Documentation