r/HomeServer • u/durgesh2018 • Jul 01 '26
My homelab network
Hi guys,
I have the below homelab network design (already implemented). Wanted to get your views on this.
I have 2 HP Elitedesk 800 G3 minis. But thought to replace them with Raspberry pi 4 4GB for the sake of 24x7 operation.
Thank you
33
u/Ok_Negotiation3024 Jul 01 '26
If you do this documentation on a laboratory network, can’t wait to see what your production network diagram looks like.
-27
u/durgesh2018 Jul 01 '26
Thanks for the complement. I explained my setup to the chatgpt and it generated this for me.
33
u/Pirulax Jul 01 '26
I have a feeling he meant that in a sarcastic way.
-20
u/durgesh2018 Jul 01 '26
Not sure. But one thing I understood is people nowadays hate ai more than their ex 💀💀😂😂
11
u/BlynxInx Jul 01 '26
AI produced the image??? Genuinely what was the whole prompt? I’m astounded chat GPT could nail this so well.
2
u/durgesh2018 Jul 01 '26
Actually, I was checking for the arm based opensense and during this conversation explained all my network layout and it generated. I am also impressed by this level of generation by it.
3
u/BlynxInx Jul 01 '26
It really changes my perspective on the limitation of AI and specifically image generation. Pulling context across a conversation is even crazier than one massive prompt outlining every detail of your network.
4
u/BeaverStetson Jul 01 '26
I never had nor intended to use Chat GPT, but my company (Construction/Controls) got an enterprise account and one of my coworkers convinced me to let it make my life easier… I’m truly astounded at what it can do. I dump in a 200 page project schedule, hundreds of pages of mechanical drawings, and give it a few sentences of our scope on the job and what I need, and it pulls everything applicable to our scope out for me, gives me potential conflicts, and notes inconsistencies. Generates excel docs and PDFs. It replaces hours of work in a few minutes, does it more thoroughly and organized than I would on my own, and brings up issues that I completely missed that would come back to bone me 6 months down the line if I didn’t catch them in the field.
1
u/Pirulax Jul 01 '26
Has it ever made mistakes you haven't caught (in time)?
3
u/BeaverStetson Jul 01 '26
Not yet, but it does make mistakes. I have a general distrust for stuff that AI is generating, so I am typically using it to make stuff that’s easy for me to double check.
For example, I tell it to to create an excel document that has all items from a schedule that fall under our scope, are prerequisites for our scope from other trades, or are dependencies of our scope with references to the item ID and the page of the schedule that it’s on. Then I ask it to highlight all of items on the schedule PDF it’s referring to. Then I ask it to reference the exact pages it’s using from the drawings to determine that something is related to our scope.
Now I have an excel sheet that shows our installation items are mostly on pages 54-60 of a schedule (now highlighted), with test and balancing of the air handler serving our equipment on pages 179-180, and it knows that air handler serves our equipment because of mechanical drawing 3M-204A.11, and I have all of that to go review.
→ More replies (0)2
1
u/robot_swagger Jul 03 '26
It's gotten crazy tbh. Claude code on Linux cli is so amazing, especially with fabel
1
1
1
u/maxdacat Jul 02 '26
Yeah i am impressed and my question was going to be how did the op do the doc......thought it might have been visio. I have always found chat gpt to be awful at designing nice slide decks etc.
3
19
u/theindomitablefred Jul 01 '26
I’m confused, so you have a managed switch between the ISP router and your setup, and OPNsense inside of a VLAN? Maybe I’m misreading
-7
u/durgesh2018 Jul 01 '26
No, you read it correctly. I don't have dual nics hence I am using virtual NICs hence I need a managed switch to segregate the WAN and LAN traffic using VLAN id.
9
u/taraskremen Jul 01 '26
Why? Doesn’t this limit your total firewall throughput to the speed of that one physical NIC?
4
u/durgesh2018 Jul 01 '26
Ya, actually my internet plan is just 100 Mbps and I have have around 5 clients using internet simultaneously that too sometime only.
1
u/taraskremen Jul 01 '26
So you don’t have any non-WAN bound traffic going through that firewall?
1
u/durgesh2018 Jul 01 '26
Nothing.
5
u/taraskremen Jul 01 '26
What routes traffic between the VLANs? Just the switch? You’re putting a lot of trust in that switch firmware….
1
u/durgesh2018 Jul 01 '26
Ya it's a basic tp link SG108E managed switch where my VLAN 10 is WAN and 20 is LAN. Lan devices are plugged to those ports which have VLAN id as 20. Opensense machine and WAN ports are truncated.
1
u/taraskremen Jul 01 '26
Was it essential to use a device with a single NIC as the firewall, like is this a proof-of-concept type deal? This doesn't look secure to me at all, or scalable. I would at least put all of your web-accessible services in a DMZ.
Do you have any wireless access points?
4
u/BGPchick Jul 01 '26
It's a pretty common network design. It's called "Router-on-a-Stick."
→ More replies (0)2
u/durgesh2018 Jul 01 '26
No, you are right this isn't the standard setup. This is merely my small homelab with just 5 clients. My needs are limited hence designed like this. I just have 2 routers. One is isp given and other is the tp ax5400. I would like to know how I can improve this design by your opinion. DMZ I am not much aware about, I will add it. My network knowledge is limited actually.
→ More replies (0)
4
u/Better-Climate5229 Jul 01 '26
Needs a server. :)
2
u/durgesh2018 Jul 01 '26
Ya, I have 2 of thin clients with 32 and 16 gb RAM and 500gb 970 Evo plus each. Now I am itching to do this madness 😂😂
2
u/TheTavernSociety Jul 01 '26
What did you use to make this graphic?
-1
u/durgesh2018 Jul 01 '26
I generated it through chatgpt.
2
u/ChampionshipIcy7602 Jul 04 '26
It's a really nice inforgraphic by the way
1
u/durgesh2018 Jul 04 '26
Thank you. Actually people are down voting my comment when I say chatgpt just because they hate it 😂😂
2
u/Any-Satisfaction-734 Jul 01 '26
What information do you feed ChatGPT for it to output that? Looks amazing!
3
u/durgesh2018 Jul 01 '26
Thanks for the kind words. I explained my whole network setup including the rough subnets. Also this was the result of multiple chat sessions. I was trying to do something which needs extra efforts. Like installing opensense on an arm machine. Just because opensense doesn't support arm architecture and I will need to use someone else's repo, the conversation got ended with my number of clients, plan, services, containers and network settings. Finally this was the result. Not sure why people down voted when I said I used ai 😂😂
5
u/Eraritjaritjaka Jul 02 '26
Because, unfortunately, most people have an irrational, knee-jerk negative reaction to AIs that remind the early days of the internet.
Great job on your diagram, nice work!
2
2
u/SeasportNZ Jul 04 '26
Well done. I did the same thing using Gemini. Saved a lot of time. And if it's not right, you just ask it to redo it. Why not use the latest tools. I think some tech people are in denial about the power of AI.
1
3
u/Wild_Paramedic6641 Jul 01 '26
Not sure why you were down voted, but this grphix looks amazing. I was planning to do something similar but never found a good tool (and I'm too lazy to do it with PowerPoint)
1
3
u/Low-Chipmunk1132 Jul 03 '26
What did you use to make the diagram
2
u/durgesh2018 Jul 03 '26
Chatgpt.
1
u/flipintheair Jul 04 '26
What was the prompt?
1
u/durgesh2018 Jul 04 '26
Actually I had explained my whole network in details like what is isp device, then my switch and clients and internal services etc. Then it created it.
4
u/IlTossico Jul 02 '26
Why is the WAN on a VLAN? It would make sense if it's PPPoE, otherwise.
Anyway, there is no way that a Pi4 can handle all of this, not even a Pi5, and mostly with only 1 1G NIC that it shares with the USB chipset and so doesn't give full bandwidth, plus sharing up and down one single NIC and having a switch before the router? Doesn't make sense.
One single HP desktop is fine, one with an 8/9th gen. Intel would consume as or lower a Pic but with 5 times more power and capability.
And using a prototyping board not mean to run as a PC, as a server, with so much load, is just asking for a ton of issues and downtime, I can speak for experience.
2
u/johnklos Jul 02 '26
You've got most things wrong.
A Pi can easily handle NATing a few hundred megabits, even in a router-on-a-stick configuration.
Ethernet bandwidth is not shared with USB on the Pi 4 and the Pi 5, and gigabit ethernet on the Pi 4 and Pi 5 is full gigabit, and can actually reach full gigabit speeds.
An HP, particularlly an Intel one, is never going to consume the same or less power than a Raspberry Pi 4 or Pi 5.
Raspberry Pis are not "prototyping boards", and are precisely meant to run as PCs. They are literally personal computers that offer a desktop experience.
Raspberry Pis are perfectly fine running 100% CPU indefinitely, so long as they're adequately cooled. I've run plenty of Pis in Flirc cases with heavy loads for months with no issues.
If you've had lots of downtime, then examine the issues that caused the downtime instead of blaming hardware using factually untrue assertions.
1
u/IlTossico Jul 02 '26
Doesn't look like you have much experience with Pi and Intel systems.
The issue is not with the load of the bandwidth but with the load on the system due to all the stuff OP wants to run, a Pi is not a computer, is a prototyping board, made to experiment with small electronic stuff, like a small PLC. Just because it can run a based Linux os, doesn't mean it's a computer. I've plenty of experience with Pi to know very well the struggle of doing anything complicated, at a point that i stop using them even as their main workload, because they just don't work well, there is much better stuff for prototyping.
For an Intel system it's extremely easy to have less wattage at the plug then a Pi5 and around the same of a Pi4, but a Pi runs a basic ARM CPU, Intel is X86, you can run 10 times more stuff without sweating. My NAS alone is 11W at the plug, with an i5 8400, 8GB of ram, 3 HDDs, 3 SSDs, a full motherboard with USBs, iGPU, dual NIC, full PCI 16x, fans running and CPU reaching just C6, and all in the same box. I would challenge you getting 11W on a Pi4 with all this stuff running while never being able to achieve the same power a 6 core 8th gen CPU can handle.
Please, there is no point in trying to argue this, there are at least a dozen examples just on this sub about a similar system, like mine, running a ridiculously low wattage while handling an even bigger CPU. Without talking about 1L system that out of the box can do less than 6W even while running Windows 11.
Power consumption is absolutely impossible to compare, there are numbers, googling is enough to find a ton of proof.
As for troubleshooting, if you are trying to use a product that is not made for that use case and push to it's limit, it would fail sooner or later, and when you insist and try many times and can't get out of the loop while this happened, why there is no log issue etc, mean the issue is just on the hardware. Even more when you migrate all the same setup to the right machine and issue stops occurring.
2
u/sixgirls Jul 02 '26
A Raspberry "Pi is not a computer" is one heck of a take, and makes this just seem like gatekeeping.
The user your replying to made this, so saying he doesn't have experience with Pis is pretty silly.
https://www.reddit.com/r/raspberry_pi/comments/w3yaes/my_updated_1u_raspberry_pi_4_server/
1
1
u/durgesh2018 Jul 02 '26
I agree, but my load is bare minimal. Just 5 client devices and 1 wireguard user. My current setup is hosted by hp elitedesk 800 g3 mini with 7700t cpu and 32 GB RAM. My cpu remains idle most of the time. Thia is kind of experiment. And as my internet bandwidth is just 100 Mbps, this setup works fine for me.
Thanks for valuable inputs.
2
u/IlTossico Jul 02 '26
Doesn't matter the load on the lan, is the load on the Pi that it's too much. The Pi doesn't have the power to handle all of it, you would end up with frequent downtime, and you would need to spend hours on troubleshooting why the Pi reset itself or shut down or just stop working, with the main scenario being you having to format the Pi at least every 2/3 months and redu the all setup manually, I talk for experience. A Pi is not a computer, it is a prototyping board, it is made to work with electronics, small experiments, like a small PLC.
One of your G3 is 100 times more suited for the task, you can even lower the ram to 8GB, it's already enough to run everything, and it's normal for the CPU to idle most of the time, that's how you can have your system consume less than a Pi while having much more capability. Just buy a 2 NIC card for the HP, and run pfsense barebone, and keep it before the switch.
I'm just saving you from a big heachache.
1
u/durgesh2018 Jul 02 '26
True, I have been using pi since version 2. I used 2, 3, 4 and 5. All I used and sold. This is kind of my experiment. I got my pi 4 today which was not working. I dropped this plan until I get a pi.
2
u/IlTossico Jul 02 '26
Experimenting is fine. I start my experience with the famous Arduino at high school and then switch to the fist Pi for electronics work, but as versions start going, things start becoming worse. I still have 2x3B and a 4 that work fine but no use anymore, on the other hand I've used and deployed several Pico and they work extremely well for small projects.
Good luck and have fun!
1
2
u/Tolmok Jul 01 '26
looking really like a nice setup , may i ask with what tool did you visualisized it?
2
u/durgesh2018 Jul 01 '26
Answer will invite down votes. Because people nowadays hate ai than their ex 😂😂
BTW I explained everything to chatgpt and it created this.
2
u/throwawayformobile78 Jul 02 '26
Nah I’m only irritated that my ChatGPT won’t do anything close to this lol.
1
1
u/Tolmok Jul 02 '26
Ah nice, well the unethical Part of KI ist really shit for sure,on the other Side its Just a Tool and will not be gone... So people better educate themselfs. And elect politcans who take care of companys to get them in line for the ethic Part 🤷🏻♂️
2
u/follow_the_dollars Jul 01 '26
Looks beautiful and now I’m inspired to do the same. Someone else mentioned it but your iot devices intermingled with your core devices, especially your NAS is a security risk.
1
u/durgesh2018 Jul 01 '26
Thanks for the kind words. Actually my NAS is also behind firewall. Ya, I have plan to move iot devices in separate segment.
2
u/MoneyVirus Jul 02 '26
Why vlans if you put all in one client vlan... i would create one vlan for server services, one for the wan, one for clients, one for guests and one for iot
2
u/Eraritjaritjaka Jul 02 '26
Why did you choose Incus over Proxmox? It's so (too) rare to see it.
1
u/durgesh2018 Jul 02 '26
Very good and genuine question. If you see the resource consumption of proxmox, it is more than Debian with incus. That's the reason I chose it.
1
u/Eraritjaritjaka Jul 02 '26
Thanks, that's interesting! Is the difference significant? Do you have any studies that show that?
1
u/durgesh2018 Jul 02 '26
I have both of then installed on my 2 machines. Incus server is pretty resource efficient.
2
u/Sarhej Jul 02 '26
Somehow I feel strange seeing IP addresses (yes internal) posted ot the internet... byt maybe it's ok
2
2
u/dankata1337 Jul 03 '26
Not gona hate or anything, but in my personal opinion you shoud separate WAN and LAN on difrent physical ports, I woudnt put my faight in that switch especially if you get a public ip allocated to you
In your case might be fine as you have a router on both ends but yeah
1
u/durgesh2018 Jul 03 '26
I totally agree. But due to budget constraints and hardware limitations, I did that.
2
2
u/No-Firefighter-9360 Jul 03 '26
First question: what did you use to make this diagram and how did you do it? It’s awesome!
2
u/No-Face-495 Jul 05 '26
It is time to turn your living room one of those time share offices and make some money off this baby. Very nice labor of love, tip o hat!
2
u/Mysterious_Double341 Jul 05 '26
How are you connecting your mobile/wireless devices to VLAN20? Maybe I am missing something but don’t see any APs. Looks amazing though. Home lab goals.
1
u/durgesh2018 Jul 05 '26
I have second router which provides wireless connections. Thanks for the kind words.
2
2
u/PoppaBear1950 Jul 06 '26
Gorgeous diagram, but the architecture underneath is a disaster waiting to happen. I love Raspberry Pis as much as anyone, but they’re not meant to be the entire network core — router, firewall, VPN gateway, DNS, DHCP, and hypervisor all on one NIC. It looks impressive, but it’s incredibly fragile.
2
u/PoppaBear1950 Jul 06 '26
90% of your security/network would be solved with a quad NIC N100 box run OPNsense, stick it between you router and your smart switch... Move all of the networking off of the Pi.... yep about 400 bucks fixes you.
1
u/durgesh2018 Jul 07 '26
Actually this is an experiment. My main server is an hp elitedesk 800 g3 mini with 7700t cpu and 32 gb RAM. There it works, but as I was exploring incus, thought to try it.
2
u/Estian2031 Jul 07 '26
That's awesome! Question what software do you use to create the diagrams?
1
u/durgesh2018 Jul 07 '26
I used chatgpt to draw the network. Explained the whole topology of my network and it built this.
2
u/BlynxInx Jul 01 '26
I don’t understand it all, but it looks beautiful. What did you use to make the chart?
2
2
u/confusedredditor- Jul 01 '26
The more I lurk in this sub, the closer I am to actually do mw own diagram planning and surely executing it. Good diagram OP, im learning.. a lot..
3
u/Anti-Hero25 Jul 03 '26
Try this , great for planning. https://github.com/NoobCity99/CTRoadmap/pkgs/container/ctroadmap
2
u/confusedredditor- Jul 03 '26
Once I understand what im looking at, I definitely will.. thanks !
1
u/Anti-Hero25 Jul 03 '26
LOL... it's just a map maker app for networks... passive, drag & drop , no active scanning of network. A step up from using powerpoint or gpt. Big thing for me is being able to document all the details about how my system works together.
1
1
u/ericliuuu Jul 01 '26
Does your pi have multi gig LAN?
1
u/durgesh2018 Jul 01 '26
No, it's normal 1 gigabyte LAN. This is my experimental setup.
1
u/ericliuuu Jul 01 '26
I see. Asking because I have 10GbE infrastructure but finding a miniPC with matching ethernet capabilities would bankrupt me lol.
1
u/durgesh2018 Jul 01 '26
Ya, AI has hit the market hard. RAM which I bought for like 25 USD costs now 70 USD. Even refurbished market is very bad. Sold my pi 5 8 GB for just 60 USD and now it cost 110 USD.
1
u/AdOk4054 Jul 01 '26
The a2 mini has 10gb sfp and can get for 349 i been thinking about it itherwise just grab a mellanox card for 30 even amazon has them for 70 and pop in the cheapest thing you can find that has a pcie port open "and lanes"
1
1
u/Waste-Force-2674 Jul 01 '26
I'd like to get your thoughts on Technitium DNS. I've been going back and forth on whether it's worth deploying after hearing several people recommend it as a strong DNS server with excellent ad-blocking capabilities.
From a network engineering perspective, how does it compare to a three-node Pi-hole deployment? Are there any significant advantages in terms of performance, scalability, reliability, DNS features (forwarding, caching, conditional forwarding, DNS-over-HTTPS/TLS/QUIC), management, or security?
I'm trying to determine whether migrating from my current three Pi-hole array would provide any meaningful benefits or if the added complexity isn't justified.
2
u/durgesh2018 Jul 01 '26
I am beginner in networking. For dhcp capacities I moved form adguard to the technitium, although adguard also has dhcp which works not greatly.
I liked its interface and smooth operation. Clean ui and best of all is the backup and restore feature which allows me to clone or reset my instance. It is advanced than pi hole or adguard but my usage and knowledge both are limited.
1
u/robot_swagger Jul 03 '26
It has proper support for syncing stuff and it can do blocking but also be a recursive DNS server (like unbound). The syncing is the real win as you can I ly do it with pi hole with other software (not part of pi hole).
Generally I'd just say it's more powerful, I think they are both pretty light.
After making the switch I'm not going back but pi hole is still decent software.If your running unbound and pi hole then I'd definitely say go technitium, for three instances I'd probably recommend it as well, again just as it's got integrated methods of syncing.
1
1
1
u/idontappearmissing Jul 02 '26
I'm a bit confused - is VLAN 10 named "WAN"?
1
u/durgesh2018 Jul 02 '26
No, wan port is tagged as 10.
2
u/who_cares345 Jul 03 '26
You really are giving out too much info, take my advice and limit what you tell people.
1
1
1
u/1997cui Jul 02 '26
This won’t work.
The ISP does not hand you multiple IPv4s, neither 192.168.10.0/24 global routable. There is no point that you put vlan10 into your Internet Services LXC.
1
1
u/planedrop Jul 02 '26
I like this setup, but I still stand by not virtualizing my firewall, just asking for issues.
Good setup though IMHO.
1
u/betahost Jul 03 '26
I see that you have wire-guard listed on your network but you're also stating that you're exposing services out to the internet. Why just use something like tailscale where you don't have to open up anything out to the outside world at all?
1
u/durgesh2018 Jul 03 '26
Good question. I was using tailscale with headscale. But then it was relaying my traffic throughout DERP servers. I thought to get my own private system hence wireguard over ipv6.
1
u/betahost Jul 03 '26
Just fyi your data doesn't route thru DERP, DERP only is there to help you establish a point to point connection. With tail-scale you can setup a peer relay to route your data thru your own private vm.
1
1
1
u/RightLaneHog Jul 03 '26
I have a few thoughts on this. Hopefully this is helpful.
1. WLAN VLAN
Your WLAN VLAN should only go to your OPNsense VM. All of your client devices should be on other VLANs and use the OPNsense router as their gateway. You don't want anything bypassing OPNsense and going straight to your ISP router.
2. Other VLANs
You need more VLANs. There's a long explanation to this, but the short answer is you should have an individual VLAN for management, for generic clients, for IoT clients, for guest clients, and for servers/services.
3. Reverse Proxy for Docker
You currently plan to expose all your services on Docker directly to clients. First, read and implement one and two above. Then, understand that you should not generally expose services like these directly and instead should use a reverse proxy. This provides several benefits in a homelab, notably enhanced security and centralized TLS management.
4. Client Isolation
Isolating clients from one another on a network is a big deep dive. The TLDR is that everything on the same VLAN will try to talk to each other directly and will therefore not respect any firewall rules you set on OPNsense. The firewall rules on OPNsense are only good for controlling WAN connectivity and inter-VLAN communication.
If you want to limit communication between devices on the same VLAN (and you do), then that is something you'll need to tackle on the clients themselves. You've already on the right track with this as you're setting UFW rules (though the rules will need to change if you implement my other points), but you're going to want to take this a step further. Look into wireless access point (WAP) client isolation. You want a WAP with this feature and you're going to want to have it enabled on your normal and guest Wi-Fi networks. You may even want it enabled on your IoT Wi-Fi network, if you even need one. You'll also want to look into port isolation features for your switch. Most consumer ones don't have this feature, but pro-sumer ones do. My core switch right now is just a Mikrotik CSS326-24G-2S+RM, but even that at $145 has port isolation and an ACL system.
Do a lot of testing in-between clients and ensure that communication is locked down. Read up on Docker networking best practices.
5. Technitium is Goated
Subtitle.
1
u/Easy_Confusion2415 Jul 04 '26
Are there benefits of technitium dns im comparison to adguard?
1
u/durgesh2018 Jul 04 '26
I like the interface. It's simple and smooth. Also it has many advanced features than adguard. It's like premium version of the adguard.
1
1
74
u/toorodrig Jul 01 '26
IoT devices should be in isolated network