Prevailance of home ip addresses in DDoS attacks and in proxy pools does suggest so ¯\_(ツ)_/¯
Vetting devices you introduce to network is of course solid advice, but a little bit of paranoia never hurts in tech.
My whole point above that it does actively hurt, with devices randomly misbehaving at exactly wrong times. It's not enough to set up everything once because devices get updated and change ports, domains, and protocols. It also makes everything more brittle, requiring multiple inter-VLAN proxies to be running at all times for seemingly unrelated devices to work. That SD card in your raspi died? You decided to update Docker on it and run into problems? No Sonos for anyone in the house until it's fixed.
There's a real cost to that paranoia, it's just another case of security/convenience tradeoff.
If you're worried about your network being saturated for DDoS by a random IoT device, I suspect you'll notice it even without explicit monitoring.
Besides, risks need to be weighed by their probabilities. It's a small chance of name-brand IoT devices "going rogue" vs the certainty of random things not working when they should, and I don't think this tradeoff leans towards VLANs for most people.
(edit: admittedly the five or six times I've setup a home network more complicated than just connecting to a router I've ended up regretting it after a few months)
Building my home network though is teaching me IPv6.
Every time I try setting my home network up like that (smart firewall, traffic graphs, etc), I just end up going back to a $30 router/AP.
Today it's ISP router + separate AP (better coverage). Chinese hackers aren't attacking my network, and if they did, cool, have at it. Basic firewall + NAT + AV covers 99% of use cases, even in a business, with the right configuration. Turns out I don't miss pfSense either.
Makes sense for keeping skills up to date, though, and as a hobby, I can see how one can get into it. Reddit's r/homelab has some crazy builds to check out.
1. An OPNSense firewall between my cable modem and the rest of the network running on a low-power PC Engines APU2. The web-based UI is funky but workable, full SSH access to the box for digging into the internals when needed, online upgrades are a cinch.
2. An 8-port gigabit unmanaged switch that everything hangs off of.
3. A Netgear WAX218 business-grade access point for wifi, running the stock firmware. Web UI is decent and doesn't require any cloud-based management bullshit. For around $100, it works much better than it has any right to, given the prices of mid-range APs and wifi routers these days.
4. A small fleet of Raspberry Pis for miscellaneous tasks.
If I get more into IoT, it shouldn't be much of a hassle to add VLANs and maybe another switch.
In retrospect, I lied a bit about not missing pfSense (or OPNSense in your case) because truthfully I miss the monitoring, packages, configuration and expandability options. At the same time, I also don't miss them, because 0 headaches and actually better latency is still a plus. Just need to login to that god awful ATT interface to open up a port, but these are 1st world problems... there's always VPNs and cloud VPS to fix that.
ATT fiber 300 up/down provides 4 ms consistent ping to google's closest's datacenter, sometimes at 3 ms, which is of course nuts. Might as well be in my apartment block. Perfectly happy with provided unit, although it's an older one.
Tangential, but have used vyOS some years ago to create a makeshift 10G switch using commodity hardware and an old PC. Routed and switched amazingly fast - the demise was related to what I could guess were broadcast storms.
I'm with you in spirit however. Want and will probably need to switch back to a more customizable router.
Good enough for me.
I would set up something simple like port-forwarding to a static IP and test that it worked
then I'd come back a few days later to use it and found the router had helpfully changed the IP to another one
and this happened with several different features (IPv6, DHCP, etc)
I replaced it with a much cheaper Mikrotik box and that's worked flawlessly ever since
I would not recommend the Fritzbox to my worst enemy
Anyway, I have logged on to my headless GPU machines remotely through port forwarding for years and never had an issue.
But that sucks ass.
Wouldn't you rather have real monitors/screens, a solid wired connection to a network and a real keyboard and mouse? Yea it takes space and time but its way better.
I do for most things, but better is personal.
Saying that OP's setup is overly convoluted or better is entirely missing the point -- it's what they want to do for enjoyment. Personal taste doesn't need to be justified.