ONYXNET // ENGINEERING CASE STUDY
Network Engineering & Security
Designing a Six-VLAN Homelab Network
How OnyxNet uses VLAN segmentation, pfSense, managed switching, and practical design constraints to operate a production-style home network.
OnyxNet is a continuously evolving homelab that I use to develop practical skills in network engineering, infrastructure operations, and system administration.
One of its foundational projects was implementing a segmented network using six operational VLANs.
The network and its existing firewall configuration have been in use for approximately one year.
This case study documents the design goals, deployed architecture, constraints, and lessons learned.
The Engineering Problem
A home network can accumulate devices with very different purposes and security requirements.
OnyxNet includes:
- Personal computers and gaming systems
- Servers and virtualization infrastructure
- IoT and home automation devices
- Security cameras
- Guest devices
- Network management interfaces
Placing all these systems in one unrestricted network would make it difficult to apply different security policies.
The objective was to separate infrastructure according to function and intended trust level.
Requirements
The segmented network needed to:
- Support existing devices and services.
- Separate management from ordinary client traffic.
- Provide distinct networks for IoT and cameras.
- Support a guest network.
- Allow necessary communication between VLANs.
- Operate using existing hardware.
- Remain maintainable without unnecessary complexity.
Availability and cost were also important.
The network supports everyday home activities alongside the homelab, making unnecessary disruption undesirable.
Hardware and Technology
The design uses the following infrastructure.
| Component | Technology |
|---|---|
| Routing and firewall | pfSense |
| Firewall hardware | AWOW AK34 mini PC |
| Managed switching | 3 × Zyxel GS1200-8HPv3 |
| Wireless | 2 × UniFi AP AC-Lite |
| Network speed | Primarily 1 GbE |
| Virtualization | Proxmox VE |
| Storage | TrueNAS |
The existing hardware is an important design constraint rather than something being immediately replaced.
Implemented Network Segmentation
Six VLANs are currently deployed.
| VLAN | Name | Function |
|---|---|---|
| 10 | Valhalla | Management |
| 25 | Jotunheim | IoT |
| 50 | Helheim | Security / Cameras |
| 99 | Vanaheim | Guest |
| 100 | Midgard | Trusted Devices |
| 1000 | Asgard | Server / Data |
The VLANs provide separate logical network segments for different categories of devices.
pfSense provides routing between the networks and enforces the configured firewall policies.
The switches provide VLAN-capable connectivity to the appropriate network infrastructure and attached devices.
The current design is operational.
However, a formal audit of the firewall rules and their effective security boundaries remains a separate improvement project.
Key Design Decisions
Functional Network Segmentation
VLANs were organized by infrastructure purpose rather than simply dividing devices into arbitrary groups.
This provides a foundation for applying policies based on the role and trust level of a device.
Centralized Routing and Policy
pfSense provides a centralized location for inter-VLAN routing and firewall configuration.
This simplifies identifying the intended policy boundaries between networks.
The precise currently permitted flows will be documented after the ruleset review.
Supporting Required Exceptions
Complete isolation is not always practical.
Examples of services that may require cross-VLAN communication include:
- Home Assistant integrations
- DNS
- Monitoring systems
- Hosted applications
- Trusted client access to selected services
The objective is to permit required access without unnecessarily broad permissions.
Working Within Hardware Constraints
OnyxNet currently operates primarily with 1 GbE network infrastructure.
Although higher-speed networking is a long-term goal, the current design must remain viable without additional purchases.
Configuration improvements and operational visibility take priority over hardware upgrades.
What Has Been Achieved
The network currently operates with:
- Six deployed VLANs
- pfSense routing and firewall policies
- VLAN-capable managed switching
- UniFi wireless connectivity
- Separate network categories for clients, infrastructure, cameras, IoT, and guests
The segmentation architecture has supported daily homelab operations for approximately one year.
This demonstrates a sustained operational deployment rather than a one-time lab exercise.
What Still Needs Validation
A deployed VLAN configuration is not proof that every intended security restriction is working correctly.
A future policy review will assess:
- Firewall rule order and behavior.
- Inter-VLAN permissions.
- Management network access.
- Guest isolation.
- Camera and IoT restrictions.
- Required application exceptions.
- The effectiveness of existing policies.
No formal security validation results are claimed in this case study.
An Architecture Decision: VLAN 700
During future offsite backup planning, I considered introducing VLAN 700, named Ginnungagap.
The original concept involved a dedicated point-to-point transit network and additional remote networking infrastructure.
After evaluating the actual connectivity requirements, cost, and operational complexity, I selected Tailscale instead.
VLAN 700 was never implemented.
The offsite backup project remains deferred due to budget constraints.
This design decision is documented separately in an Architecture Decision Record.
Read ADR-001: Ginnungagap Connectivity
Lessons Learned
Segmentation Is a Starting Point
VLANs establish logical network boundaries.
The security benefits depend on how routing, firewall policies, switching, and endpoint access are configured.
Operational Constraints Matter
An architecture must accommodate the systems that depend on it, available hardware, maintenance requirements, and budget.
Complexity Must Have a Purpose
Adding more networks or dedicated equipment isn’t inherently an improvement.
Architecture decisions should be justified by actual requirements.
Documentation Supports Evolution
Recording the current architecture and the reasoning behind changes makes future improvements easier to evaluate.
Next Steps
OnyxNet’s network redesign remains an independent project that has not yet resumed.
Future improvements will focus on reviewing the existing architecture, validating security policies, and documenting verified behavior.
Results will be incorporated into this case study as changes are implemented.