<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Home&#x2F;homelab network design - Am I overthinking this?]]></title><description><![CDATA[[[topic:post-is-deleted]]]]></description><link>https://forum.netgate.com/topic/183139/home-homelab-network-design-am-i-overthinking-this</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 04:41:24 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/183139.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 30 Sep 2023 23:55:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Home&#x2F;homelab network design - Am I overthinking this? on Mon, 02 Oct 2023 00:06:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/michmoor">@<bdi>michmoor</bdi></a> said in <a href="/post/1127992">Home/homelab network design - Am I overthinking this?</a>:</p>
<blockquote>
<p dir="auto">The amount of VLANs here are , imo, a bit of an overkill</p>
</blockquote>
<p dir="auto">OK. Would you mind telling me what you'd do differently? And why?</p>
<blockquote>
<ol>
<li>Do not host an email server. There will be plenty of people here that will list the multiple reasons but chief among them is that it will be extremely easy to get your IP on a bad reputation list.</li>
</ol>
</blockquote>
<p dir="auto">I know that's the conventional wisdom. I also know there are plenty of people out there who are doing it successfully and have been for years. I plan to use an SMTP relay so I don't have to worry about my IP being on a bad rep list.</p>
<blockquote>
<ol start="2">
<li>If you are a novice as you state then the recommendation would be to not expose any services to the internet. If you need to make your NextCloud or any other app accessible to others than a remote access VPN would be best. If you dont want to do that then look at CloudFlare tunneling but i honestly just wouldnt do it if you are not prepared in all the things that could go wrong.</li>
</ol>
</blockquote>
<p dir="auto">I'm already using CF tunneling. I plan to be prepared for worst case scenarios with a very good backup plan/system. If everything crashes and burns, OK. Great learning opportunity.</p>
<blockquote>
<p dir="auto">If you are going down this rabbit hole of simulating an enterprise then look also into setting up a remote logging server (Graylog), perhaps a SIEM (Wazuh) which i would highly recommend considering you are exposing web servers to the world.</p>
</blockquote>
<p dir="auto">Yep. Planning to use both of those. Maybe Zabbix and Suricata, too. All stuff I want to learn.</p>
]]></description><link>https://forum.netgate.com/post/1128086</link><guid isPermaLink="true">https://forum.netgate.com/post/1128086</guid><dc:creator><![CDATA[ErniePantuso]]></dc:creator><pubDate>Mon, 02 Oct 2023 00:06:35 GMT</pubDate></item><item><title><![CDATA[Reply to Home&#x2F;homelab network design - Am I overthinking this? on Sun, 01 Oct 2023 06:55:54 GMT]]></title><description><![CDATA[<p dir="auto">And avoid using ranges from all available private ranges.<br />
Peak one, segment at /24 and make sure you can aggregate effectively in rules. i.e. use / 23 aggregates ir even /22 or /21</p>
<p dir="auto">And start small. Too many things can go wrong with all these</p>
<p dir="auto">Learning is one thing. Overwhelming is another</p>
]]></description><link>https://forum.netgate.com/post/1128007</link><guid isPermaLink="true">https://forum.netgate.com/post/1128007</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Sun, 01 Oct 2023 06:55:54 GMT</pubDate></item><item><title><![CDATA[Reply to Home&#x2F;homelab network design - Am I overthinking this? on Sun, 01 Oct 2023 02:08:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/erniepantuso">@<bdi>ErniePantuso</bdi></a><br />
The amount of VLANs here are , imo, a bit of an overkill but you do you. If that works that works.<br />
The only two points i would bring up are the following</p>
<ol>
<li>Do not host an email server. There will be plenty of people here that will list the multiple reasons but chief among them is that it will be extremely easy to get your IP on a bad reputation list. Honestly, dont do it.</li>
<li>If you are a novice as you state then the recommendation would be to not expose any services to the internet. If you need to make your NextCloud or any other app accessible to others than a remote access VPN would be best. If you dont want to do that then look at CloudFlare tunneling but i honestly just wouldnt do it if you are not prepared in all the things that could go wrong.</li>
</ol>
<p dir="auto">If you are going down this rabbit hole of simulating an enterprise then look also into setting up a remote logging server (Graylog), perhaps a SIEM (Wazuh) which i would highly recommend considering you are exposing web servers to the world.</p>
<p dir="auto">The biggest advice i would give is this. If you could avoid exposing anything to the internet then do that.</p>
<p dir="auto">Also, its your home. Give yourself/24s for your VLANs. I tried to be clever like you and give reasonable sizes to my DMZ. I gave a /29, After a few weeks i realized i had a lot of virtual machines that i have spun up and i had to go around re-iping everything.</p>
]]></description><link>https://forum.netgate.com/post/1127992</link><guid isPermaLink="true">https://forum.netgate.com/post/1127992</guid><dc:creator><![CDATA[michmoor]]></dc:creator><pubDate>Sun, 01 Oct 2023 02:08:26 GMT</pubDate></item></channel></rss>