06-22-2026, 12:25 PM
Lab update: finally got around to setting up proper VLANs. Should have done this years ago.
Setup: OPNsense on a small Protectli box, managed switch (TP-Link T1700G-28TQ), access points on their own VLAN.
VLANs I'm running:
The IoT isolation was the main driver. Smart home devices from various manufacturers phoning home to who-knows-where, with no ability to audit the traffic, were sharing a network with everything else. Not anymore.
Setup: OPNsense on a small Protectli box, managed switch (TP-Link T1700G-28TQ), access points on their own VLAN.
VLANs I'm running:
- Management - switches, APs, OPNsense itself. Isolated, no internet access for devices on this VLAN.
- Trusted - main computers and phones
- IoT - smart plugs, cameras, anything that shouldn't be trusted. Internet access but isolated from Trusted
- Servers - home lab VMs and containers. Can reach internet but Trusted devices have to explicitly access it
- Guest - isolated WiFi for visitors, internet only
The IoT isolation was the main driver. Smart home devices from various manufacturers phoning home to who-knows-where, with no ability to audit the traffic, were sharing a network with everything else. Not anymore.
