My network home setup – v4.0
giuliomagnifico.blog
giuliomagnifico.blog
A word of warning, it must be said that you shouldn't have a "normal" data cable in the same conduit as mains.
With CAT 6 cable you won't have transmission/interference problems, but still it is not allowed by code, unless the network cable is of the type insulated up to 400V, marked with "CEI-UNEL 36762 C-4 (U0=400V)", see (italian):
https://fibra.click/cavi/#coesistenza-con-cavi-in-tensione
https://www.cavel.it/it/supporto-tecnico/certificazioni/coes...
Homeowners insurance generally covers negligence by the owner
Does it?
I just know several people who have done their own 'renovations' that have had insurance claims turned down (even after arbitration) because they didn't have a licenses contractor do the work. People who insisted they knew better than anyone else. Typical.
So rewire at your own risk, I guess.
When I moved into my apartment it had just been "certified" by an electrician which took a week. There were outlets without covers on them. Exposed live stripped wires hanging in the hallway. Ground wire to the breaker box but not actually connected to the rest of the house. Exposed terminal blocks hanging everywhere. I doubt this "professional" even bothered to visit the place and just cashed a royal fee to sign the paperwork.
It's a total joke. If this crap gets "certified" then a DC cable beside an AC one In a conduit is really no issue :)
If you see clearly illegal things, report them. The person doing the certification can have their license revoked.
Things aren't always ideal but please don't turn this into a laughing matter.
If I reported such a situation in Canada, it may or may not have satisfactory official resolution before heat death of the universe. One can hope.
If I reported such a situation where I was born, at best nothing would happen ; more likely I would get laughed at. (At worst, electrician and their 3 buddies would teach me a valuable lesson about how things work around these here parts).
And the second is that mains lines are AC and could introduce noise into the wired lines - again, fiber isn't susceptible to this.
The new norm allows this mixing as long as the low voltage cables are certified as having insulation for 400 V.
Still you cannot strip the cable (i.e. you cannot put a terminator/receptacle) in the same box as mains.
The code is mainly about electrical safety, it doesn't consider the possibility of interference, that is "your" problem (but shielded cables give no problems in practice).
> 300.3
> (C) Conductors of Different Systems.
> (1) 600 Volts, Nominal, or Less. Conductors of ac and dc
> circuits, rated 600 volts, nominal, or less, shall be permitted
> to occupy the same equipment wiring enclosure, cable, or
> raceway. All conductors shall have an insulation rating
> equal to at least the maximum circuit voltage applied to any
> conductor within the enclosure, cable, or raceway.
Basically idea is to prevent a low/less voltage cable from potentially being energized by a higher voltage cable. It would suck to strip the ends off your CAT6 and discover it's been energized to 240v.
Although residential in the US rarely (never?) goes above 170 volts (peak), which is more forgiving than the ~325V of most of the world.
Article 100 defines a raceway as “An enclosed channel designed expressly for holding wires, cables, or bus bars, with additional functions as permitted in this Code”
I.e. you can have in same conduit a "protected" (double insulation) mains cable (the type is called FG16 now, it was FG7) and a low voltage/signal cable.
The idea is that the FG cable in itself, having the external insulation besides the single wire insulation and being suitable to "unprotected" installation can coexist with signal cables, the conduit in this case is only an added mechanical protection.
The type of certified 400 V insulated cables I mentioned earlier is instead allowed to coexist with "normal" single wires (this is the normal way electricity is distributed in buildings) inside a conduit.
The issue using FG cables (besides the fact that it is way harder to be inserted in small conduits) might be that it would be suitable to power (say) a mains receptacle (live+neutral+earth) but wouldn't be suitable for (still say) a diverter or a reverse switch due to the colour coding of the wires.
Claiming a conduit is just a convenience doesn't change anything.
Where did you get the 170/325 numbers? In residential applications it's 220-240v for most of the world. North America uses split phase for most outlets but major appliances still run on 220-240v.
While they call mains voltage 120V, that's actually RMS voltage and not peak voltage. The peak is 170V, which I think is a better gauge for thinking about insulation and safety (by the time power is being resistively dissipated, you've already lost). Residential "240V" circuits use opposing legs of a split phase, so nothing is more than 170V from ground, which is what matters for insulation and most failure modes. You're not going to get any more of a shock from a "240V" residential circuit than a "120V" one unless you manage to touch both ungrounded conductors at the same time - it's the arc flash risk that gets worse.
Although now that I'm really thinking about it, maybe mixing insulation types is not foolproof at the extremes. If there is a wire with 170V inside sitting in free space, the worst case assumption is that it can have 170V on the outside of its insulation as well (due to the parasitic resistance and capacitance across the insulation, and ignoring the parasitics to ground. If this sounds strange to you, think about how those non-contact voltage testers can work). So if you put a grounded conductor with a low insulation rating right next to it, that insulation could have voltage across it higher than its own rating (depending on its parasitic R/C), which may cause it to break down over time. The possibility is likely moot with real world values, but still.
[1] https://www.youtube.com/watch?v=ARSpp4B9-X4
[2] https://sschueller.github.io/posts/wiring-a-home-with-fiber/
But you’re right, I haven’t seen any professional installation, that doesn’t use CAT 7 for a long time.
- complexity is fun to play with during the initial setup, but it sucks long term
- VLANs and inter-VLAN firewalling is needlessly complex, brings endless frustration*, and you shouldn't trust the network to do your auth anyway
- letting a vendor to do something is Actually Good
- dashboards are useless, I can't recall ever using them for anything
So I sold most of my networking gear and replaced it with
- Aruba Instant On fanless PoE switch and a bunch of their APs
- a £100 Topton fanless PC box with VyOS on it, powered with a PoE splitter
- a UPS
No VLANs, simple flat network. Everything internal is either on Tailscale or behind auth. Everything is PoE, things that don't are on PoE splitters, so no power bricks and everything is UPSed. Arubas require zero configuration and are managed through a cloud portal. The router needed to be configured once and required zero intervention for close to two years. It's ridiculously performant, perfectly balances load, and just works.
*: I really have better things to do on a party than debugging firewalling an obscure protocol Airplay uses when my guest can't Airplay from their phone
I tend to agree on the VLAN stuff. I don't feel like I've found a good reason to do that on my home network (yet, at least). Fanless gear is also great.
VyOS is Debian with effectively a single file config, so it’s both simple and rock solid. As a bonus, pings got a couple ms lower on the same hardware.
I did very much like the debian base of VyOS. I've had pretty good experiences with OpenWRT. But it's command line configuration isn't quite as polished as VyOS imo. Interesting note about the pings.
I have a sizeable networking background, but still absolutely hated having to keep up with this many moving parts. I very much didn't enjoy troubleshooting this setup.
Dumb is good.
I'm going to steal the idea of the Raspberry Pi on the phone stand idea, especially when just hacking around with an SBC at my desk.
I would recommend replacing all those USB power adapters with just one or two dedicated USB power adapters. Can recommend the six-port 60W model by Anker that will happily run all those devices you have, and then some.
Yeah me too! What model of stand is it tho? and how would you keep them attached? Looking at the pictures it seems different from one pi to another.
It makes wiring a UPS into the system really easy too - just have backup power on the ethernet switch, the downstream Pis are taken care of. I'd love if the Pi 5 just has PoE out of the box personally, I run all my Pi projects this way now.
I have a 24 port netgear fanless smart switch as the backbone. I did have a POE version but the fans were too loud. I have a PoE injector now which allows me to power the APs and the phones for the house intercom.
I use pfsense for routing and firewall.
Ubuquity for APs. I have four, one for upstairs, one for down, one in the garden and one in the shed. three are second hand.
I have a VLAN for work, (I can ssh in from the normal vlans, but I can't get out from the work VLAN)
A have a VLAN for CCTV, normal use, servers/services, and one for IoT. Seems to work ok for my needs, but most people don't need what I want on a network.
Just out of curiosity, that's the black box in your cabinet balancing on the metal cones?
(And I'm guessing the metal cones are there to lift it off the flat surface for more airflow).
>Very neat - thank you for documenting this, especially the piece about using Avahi to place the HomePods on a different VLAN. This is something I'm planning to do but hadn't looked into yet, so this will save me a lot of effort.
Yes, it's very easy if you use Avahi, but it's important that you're using VLANs and not subnets, because I had lots of troubles using a separate subnets for iot devices and the HomePod in the main subnet. You have to add a route on the router and tweaks the firewall. Using vlans instead is easier and faster.
>Just out of curiosity, that's the black box in your cabinet balancing on the metal cones?
Italian ISP modem "unfortunately". If you see the network scheme you can understand better: https://giuliomagnifico.blog/_images/2023/home-network_v4/Re...
I'm gonna check out grafana, it looks significantly slicker than Cacti.
I ended up with a significantly more complex home network than I ever expected -
2 48 Port HPE 1820's 1 24 Port PoE HPE 1820's
All of these are linked with 2 1 GBE links in Port Channel
TP-Link Managed Wifi AP's with controller (I wanted roaming support, and PoE support)
Mikrotik HEx Router also linked in Port Channel to one of the core switches (I'd like to get multiple bonds set up, thats the intent, but I've had trouble making it play nice with rSTP - I think its an issue with my MikroTik Config, but its so poorly documented, its hard to say)
For places where I have lots of port needs where I was unable to pull a ton of cable -
3 24 Port HPE 1810's (2 of these connect back to the Core Switches with port-channels) 1 8 Port HPE 1810 (PoE powered)
The 1810/1820's are great, because they do not have cloud management, are fanless (PoE notwithstanding), and are easy to configure (no weird specific CLI to learn/no poorly implemented copy of Cisco IOS UI) via a web interface. Their lack of 10g support is annoying, but also worth the price savings.
From a VLAN perspective, I have six - one for my external netblock (which is just a pass thru from the cable gateway), and another for my internal LAN, plus two additional VLAN's for my home work lab, and another two for 'utility' which is to say, I built them in, but have not found a use for them yet ;-)
There is also a cacti server in a VM, I need to rebuilt it eventually so I have better instrumentation.
Switching to Ubiquiti, from high-end Asus gear, has been awesome. Everything just works. Networking is now a non-issue, and when my wife tells me the "internet isn't working", I can respond, "it's not my fault!"
That's worth the cost to me.
I heard some horror stories with new ubiquiti gear, but my ERPoE router has been serving me gbit and PoE for AP since 2016 and 0 issues, it even handles WireGuard using some hoops.
I've been meaning to give out different DNS servers via DHCP on the guest network vs the internal but I just can't face trying to configure that thing again.
I'm glad you're happy with yours but replacing mine with Mikrotik kit is super high on my home-network todo list.
Retrospectively I think the ubiquiti AP’s flakiness was caused by a firmware update. This Reddit post is ~2 years old:
https://www.reddit.com/r/Ubiquiti/comments/n46siv/whats_the_...
I’ve been meaning to do a hard reset and/or change the firmware, and put the ubiquiti AP back into service, but the old & slow ddwrt router works fine for everything not an Ethernet cable.
Edit: (note to self) https://help.ui.com/hc/en-us/articles/204910124-UniFi-Networ...
Second because when you send “something” to the TV like 60mpx photos, using a 100mbps port is slower.
Now a TV is also a home hub, not only a Television. And in the next years the 100mbps will be obsolete very fast.
I've seen more devices that have a GB port and can't do anything useful with it than (I suspect) the other way around.
That said, I've never even checked to see what speed my TV connects at.
UHD Blu-Rays already exceed 100mbit/sec. That is current commercially distributed consumer content that requires gigabit to stream properly over a network.
Any 4K capable smart TV or streaming device should have a gigabit ethernet interface, no questions asked. 1080p devices, sure, they can get away with 100mbit just fine, but 4K devices have no excuse.
The fact that LG still to this day ships OLED TVs with potentially five digit price tags and 100mbit ethernet ports is a level of cheapness that I can not fathom.
And they handle gigabit just fine, you can plug a USB gigabit adapter in to the TV and it works entirely as expected.
But that's not a very compelling argument on its own, since the Ethernet link is just one link in the chain. Having a gigabit port doesn't help much if the TV can't handle decoding video at those bitrates in real time. It's definitely possible that TV manufacturers choose 100Mbps ports because they know the TV can't deal with huge streams for other reasons.
It's an interesting situation for the manufacturers. Even if 99.9% of buyers will never see streams above 100Mbps, and even if that other 0.1% can't effectively use them, it might be worth it to bump the port to gigabit since complaints about 100Mbps ports come up so often in reviews and in online discussions. Maybe throwing in a borderline useless gigabit port would generate enough sales to justify the marginal BOM cost increase.
Finally realized my wifi was faster than 100mbps, and hence handled the stream fine, but wired couldn't keep up.
Are people really keeping and 123Mbps or 144Mbps (the two >100Mbps options) 4K Blu-ray rips? The largest 100GB triple layer disc can't even hold 2 hours of video at those rates. Realistically you'll max out at 72Mbps or 92Mbps on 4K discs.
https://en.wikipedia.org/wiki/Ultra_HD_Blu-ray#Specification...
https://electronics.sony.com/bravia-core
To access highest quality Pure Stream available at 80Mbps you must have a minimum internet speed of 115Mbps over Wi-Fi. Ethernet (wired LAN) connections are limited to 100 Mbps due to the TV’s product specifications. Therefore, to enjoy 80 Mbps with Pure Stream functionality, you need to connect to the Internet via Wi-Fi (wireless LAN) that supports minimum IEEE 802.11 n/ac.
1) I don't trust devices to respect VLANs. I trust the switches to respect VLANs, but not devices. When the VLAN-tagged traffic hits WiFi the VLAN is lost. When it's received at the AP the AP can choose to tag it again before entering the switch. I think I'd still do multiple SSID's + VLAN's so wifi clients intended for different VLANs are not communicating on the same "virtual AP"? I worry my Google IOT devices could be in promiscuous mode looking at everything. Multiple SSID's would separate them from other devices by encryption.
2) I've read a couple articles saying rate-limiting IOT and Guest networks results in more service interruption than one would expect. Simply prioritizing the main network traffic over Guest & IOT is a better setup. How do we do this in OpenWRT?
2) I’m not rate limiting the IoT devices, I’m monitoring them and they make really few traffic, you can limit a device by MAC address in OpenWrt anyway: https://forum.openwrt.org/t/bandwidth-limit-per-ip-mac/35943
This is not Area 51 and a client which doesn't respect VLAN tagging should somehow send packets to a different gateway IP. I don't see a way for a device to know where to send packets if it did break out from VLAN
Appreciate the commitment and dedication to detail.
I run openwrt on some mikrotik switches. I started with a mikrotik rb750 switch, then switched to rb2011 switches (5x 10/100/1000 + 5x 10/100 ports), and now two rb3011uias-rm 10-port gbit switches.
the openwrt rb3011 build comes from https://github.com/adron-s/openwrt-rb3011
I also run openwrt on a turris omnia and a linksys wrt1900acs.
I use raspberry pis for a few things, notably standalone ntp time via a few cheap usb gps dongles. One pi does time exclusively and runs openwrt with a gps hat with pps + a pi ups hat. I like the flirc pi cases - they are cheap, beefy and have great thermals.
I recently upgraded to a CRS326-24S+2Q+RM, and the experience with RouterOS feels much better compared to OpenWrt. Winbox is super polished, everything is well laid out, and it makes even advanced configuration very easy.
I do run OpenWrt on a few APs, and it works fine for that simple use case, but for anything more advanced, I prefer RouterOS. Sure, it's not open source, and not as extensible to allow you to run a bunch of services on it, but those can run on any other server just as well.
The package selection on OpenWrt is an appealing factor, but I can also run any of those on a standalone server or RPi.
I feel like a router is best served by a purpose-built OS, that is heavily focused on that task, and restricts the execution of arbitrary software, for obvious reasons. I suppose one could single-handedly customize a general purpose distro for that task, but I'd rather trust a group of dedicated and more talented hackers to do this for me.
That, and I'd rather not manage nftables rules directly. :) Though it would be a great learning experience, so I'll think about it.
well, in this case, unless something changed recently this is definitely not openwrt
(care to elaborate?)
I like that with openwrt, it doesn't do that, and you can configure all kinds of things just like you want. At first I would use the regular releases and install the packages I wanted. As I got more comfortable with it, I would just build it myself.
It's pretty easy:
git clone https://github.com/openwrt/openwrt
cd openwrt
./scripts/feeds update -a
./scripts/feeds install -a
make menuconfig
make -j$(nproc)
make menuconfig is where you choose how your system is configured (packages, kernel modules, config settings, etc)my initial builds were sort of experimental, but it was kind of fun and eventually I learned to customize exactly what I wanted. For example I would use ipv4 only and strictly control the ip addresses of all my machines. (current openwrt doesn't allow it, you have to turn off ipv6 using sysctl). I configure out wifi/bluetooth from some machines that don't or shouldn't use them. I set up privoxy and some machines do updates through the proxy which whitelists what they can get to. I use vlans, and it keeps traffic segregated well. It's nice to put a weird device on a vlan and know it won't go uploading to the cloud, or update itself without your say so.
make menuconfig
run make -j kernel_menuconfig
To select some additional options for the kernel, then make -j $(($(nproc)+1))
That can be a bit faster nowadays.I had no idea about RouterOS connecting to strange IPs, I'll look into that. Can you link to some research that confirms this, why it's done, and how it can be disabled?
I do like how configurable OpenWrt is, and didn't know it was that easy to make a custom build. I'll probably give that a try the next time I have to set it up. Thanks again.
Some random comments:
I use a Mikrotik router and I have a dedicated network for devices I don’t want to access my main network. They can only access my MQTT server. RouterOS (mikrotik OS) is a bit terse and comes with its own cli interface. I managed to modify the default setup relatively easily via the UI to create the two networks I needed. In the future I may install openWRT but at the moment the current setup works well.
Another think that I did recently that was quite impactful (performance wise) was to add a Omaha controller to make my two access poins work together to expose one single wifi network. Before I had them working on their own. The performance of the network has increased substantially. I’d prefer not having to buy a piece of hardware to do that but I am glad I did.
I recently bought a ds720 from Synology. I upgraded the RAM to 6gb. So far I use it to dump my personal backup (restic). Also my Reolink cameras dump video via FTP. Because the ds720 runs linux and docker I am planning on consolidating a few services in the ds720 (home assistant, grafana and Pinole).
Oh, I also got a UPS system for the main components that provide Internet access. I can be without power and have Internet for 2 hours a half. One thing I want to do is to get an alert when the power goes down. The UPS exposes that via USB.
How much of a pain was it to compile? The post doesn't seem to describe any changes made (understandable, most people probably don't care) but there must be some changes if you had to compile it yourself, right?
If you want I can send you my image.
Thanks!
There are some funny (?) things that turn up too, like learning the Roku remote iOS app "discovers" devices by opening a TCP connection to every address in parallel on its local /24 (!!!). It sends out and receives mDNS packets that would tell it exactly where they are, but they are ignored by the app.
VLAN←→subnet
Make sure IGMP is enabled. Devices join IGMP groups to announce they want to receive mDNS- IGMP snooping
- IGMP proxying (if offered)
Depending on your router you might find helpful options like:
- mDNS reflector
- mDNS repeater
- any mDNS + description of multiple networks (Unifi)
tcpdump -i <interface> host 224.0.0.251 or port 5353 -A
Like others mentioned, Avahi is solid but the multicast reflection/repeater/relay must run on the device routing between the VLANS in question.Disclaimer: Deployed and networked thousands of Chromecast at several hotel chains and their wildly variable enterprise networks. Wrote my own mDNS repeater-as-a-packet-rewriter to fine-tune TXT records.
At home I am just using the ISP router but I have my work laptop,desktop, consoles and TV wired with ethernet and it is amazing compared to wifi. No more dropouts, random ping spikes/lag etc.
Just ISP router with 4 gigabit ports + one Netgear GS108 dumb gigabit switch.
I bought a EAP610 which I saw recommended on Reddit, but the range seems worse than the ISP modem's (something Huawei) built in WiFi.
https://giuliomagnifico.blog/_images/2023/home-network_v4/Sc... vs https://giuliomagnifico.blog/_images/2023/home-network_v4/Sc...
1) your photography
2) your HN account is ~3 years old, with 33k karma.
PlayStation dev kits annoyingly require usage on a whitelisted static IP to activate (every 2 days) and access dev PSN environments. It would have been a huge PITA doing it any other way.
Referring to "latency" or (my favorite) "responsiveness" is better.
And I was encouraged to see this recent ZDNet article that mentioned the "ping rates" of 600-1000 msec, and notes that these would cause videoconferencing or gaming to be unusable.
https://www.zdnet.com/home-and-office/networking/i-tried-del...
And as @giuliomagnifico points out, you can fix it yourself if you get the right router.
172.16.0.1 to 172.16.9.255
To be available for non-VLAN DHCP, static leases, and internal devices. Not sure if that's why others do it this way, but it made sense for us.
That everyone does it - even on small home networks - is just convention.
(Can't speak for everyone of course, but that's why I'd use 10.0.10.0/24, then 10.0.20.0/24, etc. Now "same kind of thing next to it" can have 10.0.11.0/24)
Some can argue that using VLAN 1 is also a bit less safe because it’s the default VLAN and attackers usually scan for it like 192.168.1.1 IP for modem/WAN.
Also why 3 raspberrys, instead of one with a few containers on them? Especially the 4s draw quite some power, just from a power saving perspective I would only run one.
You might have PCs, servers, TVs, printers, cameras and more on your network. You might want some of thos to access the internet and some not. Some from the internet and some not. Anyway - policy - what should be able to get from A -> B.
VLANs allow you more flexibility. You can now have lots of different TOs and FROMs. So you can put your security cameras on a VLAN with no access to the internet. You can still access them but they cannot splurge to the wider world.
Three RPis? Perhaps. Depends on the job. I'd probably throw another VM on the fire.
(EDIT - grammar)
But why do you need it in your home? Do you really cut off your printer in a VLAN and do some specific routing/filtering? I know how to do that, but I just don't see the benefit.
If you want to cut off one device from the internet, my solution would be to set a specific DHCP rule to not deliver a gateway/dns. Easy and good enough to cut off a printer from the internet. My home does not need the same network security as a nuclear power plant...
* Broadband 600/60Mb/s with seamless failover to 5G (varying speeds)
* Netgate 6100 router with VPN client, VPN server, site to site VPN configured, traffic shaping to reduce bufferbloat, uplink failover, etc.
* 4 Cisco SG 250-8 switches sprinkled throughout the flat. One acting as my core switch.
* QNap with 2 4TB drives in mirror for backups
* A HDD USB station with a stack of 4TB HDDs for backups. Backups are delivered to qnap at various times and then from time to time I make a complete copy to a drive which is put in a rotation. I keep three full copies of the data at any time and at least one of them is off-site with my family. When I visit my family I take the latest backup and replace the drive that is in their custody.
* a small, passively cooled server with 2TB fast SSD, 128GB ECC RAM, Ryzen 5 CPU, Asrock PRO X570D4U-2L2T. Hosts proxmox where I keep about a dozen VMs for various things, Ubiquiti management panel, NVR, dns filter, development tools, minecraft servers, jump box, etc....
* a 10 year old Thinkpad T440s running always on serving as my emergency server and a development environment.
* 4 Ubiquiti WiFi 6 access points -- before you jump in saying this is overkill, I live in a large flat in a dense urban area with about half a thousand 2.4GHz APs and 50 5GHz ones interfering with my WiFi setup. Most people and even network providers are clueless and set up their devices to max power as if it was going to help them -- it only makes things worse. I have 4 APs with reduced power so that anywhere you are at my flat you are always close to one of APs and you roam between them seamlessly as you move.
* Multiple VLANS and WiFi networks
* a VLAN + WLAN for my family for their regular devices to access the Internet and some defined services within network but otherwise disallowed to contact anything else
* a VLAN + WLAN for IOT, legacy devices, devices I don't trust or devices that only support old protocols and would deteriorate WLAN performance (printers, a chinese projector, etc.) This VLAN does not have Internet access (so that devices can't phone home), don't have access to any other device in the network, don't have access to other networks and can only be reached with defined firewall rules.
* a VLAN + WLAN for my work -- this is dedicated for my work laptop, my phone, my electronics lab (oscilloscope, multimeter, programmable PSU/load, etc.)
* a VLAN + WLAN for guests
* a management VLAN -- any network devices, servers, QNAP etc. are only available through this separated VLAN which has very strict access through a jump box. Also does not have direct internet access so the devices can't phone somewhere else (but I have a proxy for software updates, etc.)
* a service VLAN -- where my services are available internally (for example QNAP interface, apps running in VMs, etc.) Some of them have rules to be accessed from other networks
* a DMZ VLAN -- I expose some services to the world, DMZ serves to provide one more hurdle for any attacker
I'm a networking amateur, and one thing I've struggled to figure out is VLANs for wireless devices. It seems like VLANs are managed at switch level, so does that mean that all devices on a particular AP have to share the same VLAN? Or is there a way to segregate devices across multiple VLANs within a single AP?
Eeach of 4 APs serves all 4 WLANs and each WLAN + VLAN are completely separated networks.
The traffic from various WLANS goes directly to their assigned VLANS and never mixes together -- the only way is either through the router or some other service like my proxy.
That's very interesting, but how much power does the whole thing consume?
In my case all this setup is 45-50W, I thinks is a good goal.
On the other hand there are no fans in my setup except, incredibly, the laptop. But this fan is kicking in extremely rarely and only when I am actually using it, so no problem.
The backup NAS makes a bit of noise but this is happening during night when nobody cares.
- Regular VLAN: Access to LAN and Internet (I insist on having root on the device for it to go here)
- Guest VLAN: Access to Internet only
- Quarantine/IoT VLAN: Access to LAN only
I don't feel I need any more granularity than that. Of course the primary LAN backbone is 1Gig ethernet, but I have APs every 50 feet or so for phones.
As to APs, having multiple APs (well configured) and a good router (well configured) has much bigger impact on the quality of user experience than the actual throughput of the broadband itself.
Keep in mind that the power consumption of all the equipment is quite substantial and must be taken into account before starting. Also as your setup becomes more complex backups, redundancy, and security must all be considered - it's easy to run your network dead in the water if you aren't prepared for it, and unlike a single home router you can't just simply reboot and reset if everything relies on the network. For instance assume that all your machines rely on your NFS server to access files - if that server goes down, how quickly can you replace it? If the RADIUS server goes down and your devices can't authenticate across your switches and APs, do you have a fallback method of access?
Finally unless your family knows how to maintain the system as well, you'll be the sole IT contact and will have to do quite a bit of support especially at the start. You'll need a plan of how to remotely manage everything if you're say on vacation since things like to crop up then.
Well. I have over quarter of century of experience in IT, as a sysadmin, developer, electronics engineer and tech lead. It helps. I would never suggest anybody to do this just to have a nice WiFi at home...
> Finally unless your family knows how to maintain the system as well, you'll be the sole IT contact and will have to do quite a bit of support especially at the start. You'll need a plan of how to remotely manage everything if you're say on vacation since things like to crop up then.
Yep. I have VPN I can use to manage the network. All devices can be rebooted remotely.
I also have some backups -- the 5G router can be disconnected from the setup and used standalone and I have instructed my wife how to do this. Most of the files are synchronised to a cloud service where she can connect in need.
The passwords to everything are stored in tamper evident envelopes (and a paper books with a log in my own handwriting).
As to power consumption this probably is the weakest point of all of this. Yes, a lot of devices equals a lot of power, but my devices are extra power hungry. Although I tried to avoid unnecessary electricity waste (if only to keep it fanless) I never compromised quality for it. For example, I went out of my way to not buy an actual server even though there is a plenty of used servers that I would be perfectly happy with. Instead I built my own based on one of a kind motherboard that supports a consumer CPU and ECC RAM and uses relatively little power.
I really like your idea of having a separate router that can be used standalone if the main system fails, and might actually consider adopting that for my family as it would be very useful if I'm not available. Currently I'm looking into a virtual HA Opnsense setup on two servers to maintain routing if one fails and cannot restart for whatever reason.
One large bank I worked for was very surprised and practically enraged when they figured out I work on a VM and they don't actually control the device I am sitting on. It all started because they decided I am obliged to "provide for basic security" and install an antivirus. I told them there is absolutely no need for me to install an antivirus on this machine. This machine has only ever been used to connect to their network and I have neither installed anything or even visited any website from it. Moreover, it is snapshotted and restored from a snapshot every single day. It is fun to sometimes battle those mindless corporate drones.
I know it happens but I hate that these devices probe my networks and report on what they find. Is there anyway to stop this discovery?
The correct way is to create VLANs. Then use the router's firewall to prevent devices in the IOT network from reaching into your other networks. Not all consumer network hardware supports VLANs though.
So, you probably need an access point that can do "client isolation" or "layer 2 isolation". This would prevent clients on the same wireless SSID from talking to each other.
For example, looks like the Ubiquiti access points can do it. https://evanmccann.net/blog/2021/11/unifi-advanced-wi-fi-set...
I’ve seen similar patch panels for structured wiring, but not for server racks.
It’s on your main net, but guests sometimes would like to connect for for example some streaming.
Also, Plex should be on the tv network, but accessible (Uni directional) from the main net
I'm pretty familiar with managing compute & storage, but the networking is largely a mystery to me. I've read a bunch of CompTIA study materials but it was all very abstract
- get computers. laptops, desktops, raspberry pis, custom-built ("whitebox") servers, old dell poweredges you got off ebay, etc etc. Install linux on them.
- plug servers into switches, switches into switches, and eventually into your router. Don't create cycles in your tree (unless you know your router/switches support it (STP), and unless you paid $1k for your switch, it doesn't support it)
- Figure out your router config to assign them static/reserved DHCP IP addresses so they always get the same IP.
- put those IPs in your hosts file. (optionally, set up a DNS server.)
- ssh-copy-id your ssh key to all servers
Now you have a bunch of machines you can ssh to. Which imo is the most basic definition of a homelab.
Lots of people get super creative and use fancy routers and switches and enterprise gear and do complicated networking and etc etc etc but all that stuff is just good fun and not necessary.
It will teach you what a switch and a router do, the difference between LANs and WANs, what DHCP and DNS do. The different ISO/OSI layers involve, TCP vs UDP.
Then you'll be able to setup a home network without issues, because you'll know the different moving pieces and how they fit together.
This is a textbook that's used in such classes
https://intronetworks.cs.luc.edu/current2/html/
From the syllabus, this Coursera class looks OK:
* https://www.netacad.com/courses/packet-tracer
It is network simulation software that simulates down to the hardware level and will let you setup networks and see how they work as individual packets move through.
I spent weeks searching for a 10G switch that can support the IEEE 1588v2 PTP Transparent Clock (TC) mode but couldn't find anyone that can fit into my budget ($1-2k USD new or <$1k for used). Anyone has such switch to recommend?
As for actual advantage, I can think of reduced configuration burden since you don't have to maintain two sets of firewall configs for dual-stack hosts. It's a small advantage only.
On the other hand, I'll be honest with you, there are disadvantages. As recently as 2021, people are still discovering problems on IPv6-only networks that necessitate writing new RFCs to mandate new behavior. Yes I'm talking about https://www.rfc-editor.org/rfc/rfc9131.html It's because of the low prevalence of IPv6-only networks that changes as fundamental as Neighbor Discovery have to be proposed in this decade.
Seriously, the global addressability of ipv6 is something that people used to using ipv4/NAT tend to forget. I know a bunch of people (well, two) that make a living scanning for IPv6 addresses inside networks that the admins didn't realize were open to the world.
My current theory is that the WDS link devices' wifi firmware or drivers are doing some sort of packet content based QoS. They see the IPv4 ICMP ping request go by and optimize for return latency. The IPv6 ICMP ping request, on the other hand, doesn't. It's like diesel emissions cheating by having the car detect it's on a dyno...
Every time I try setting my home network up like that (smart firewall, traffic graphs, etc), I just end up going back to a $30 router/AP.
Today it's ISP router + separate AP (better coverage). Chinese hackers aren't attacking my network, and if they did, cool, have at it. Basic firewall + NAT + AV covers 99% of use cases, even in a business, with the right configuration. Turns out I don't miss pfSense either.
Makes sense for keeping skills up to date, though, and as a hobby, I can see how one can get into it. Reddit's r/homelab has some crazy builds to check out.
1. An OPNSense firewall between my cable modem and the rest of the network running on a low-power PC Engines APU2. The web-based UI is funky but workable, full SSH access to the box for digging into the internals when needed, online upgrades are a cinch.
2. An 8-port gigabit unmanaged switch that everything hangs off of.
3. A Netgear WAX218 business-grade access point for wifi, running the stock firmware. Web UI is decent and doesn't require any cloud-based management bullshit. For around $100, it works much better than it has any right to, given the prices of mid-range APs and wifi routers these days.
4. A small fleet of Raspberry Pis for miscellaneous tasks.
If I get more into IoT, it shouldn't be much of a hassle to add VLANs and maybe another switch.
In retrospect, I lied a bit about not missing pfSense (or OPNSense in your case) because truthfully I miss the monitoring, packages, configuration and expandability options. At the same time, I also don't miss them, because 0 headaches and actually better latency is still a plus. Just need to login to that god awful ATT interface to open up a port, but these are 1st world problems... there's always VPNs and cloud VPS to fix that.
ATT fiber 300 up/down provides 4 ms consistent ping to google's closest's datacenter, sometimes at 3 ms, which is of course nuts. Might as well be in my apartment block. Perfectly happy with provided unit, although it's an older one.
Tangential, but have used vyOS some years ago to create a makeshift 10G switch using commodity hardware and an old PC. Routed and switched amazingly fast - the demise was related to what I could guess were broadcast storms.
I'm with you in spirit however. Want and will probably need to switch back to a more customizable router.
Good enough for me.
I would set up something simple like port-forwarding to a static IP and test that it worked
then I'd come back a few days later to use it and found the router had helpfully changed the IP to another one
and this happened with several different features (IPv6, DHCP, etc)
I replaced it with a much cheaper Mikrotik box and that's worked flawlessly ever since
I would not recommend the Fritzbox to my worst enemy
Anyway, I have logged on to my headless GPU machines remotely through port forwarding for years and never had an issue.
Prevailance of home ip addresses in DDoS attacks and in proxy pools does suggest so ¯\_(ツ)_/¯
Vetting devices you introduce to network is of course solid advice, but a little bit of paranoia never hurts in tech.
My whole point above that it does actively hurt, with devices randomly misbehaving at exactly wrong times. It's not enough to set up everything once because devices get updated and change ports, domains, and protocols. It also makes everything more brittle, requiring multiple inter-VLAN proxies to be running at all times for seemingly unrelated devices to work. That SD card in your raspi died? You decided to update Docker on it and run into problems? No Sonos for anyone in the house until it's fixed.
There's a real cost to that paranoia, it's just another case of security/convenience tradeoff.
If you're worried about your network being saturated for DDoS by a random IoT device, I suspect you'll notice it even without explicit monitoring.
Besides, risks need to be weighed by their probabilities. It's a small chance of name-brand IoT devices "going rogue" vs the certainty of random things not working when they should, and I don't think this tradeoff leans towards VLANs for most people.
(edit: admittedly the five or six times I've setup a home network more complicated than just connecting to a router I've ended up regretting it after a few months)
Building my home network though is teaching me IPv6.
But that sucks ass.
Wouldn't you rather have real monitors/screens, a solid wired connection to a network and a real keyboard and mouse? Yea it takes space and time but its way better.
I do for most things, but better is personal.
Saying that OP's setup is overly convoluted or better is entirely missing the point -- it's what they want to do for enjoyment. Personal taste doesn't need to be justified.