Review of Suggested Home Network Configuration
Review of Suggested Home Network Configuration
Hello, welcome! I'm excited to help with your custom home network setup. You're taking a solid approach by planning your VLANs carefully. For your setup, using OPNsense as the management layer sounds great, especially since you have gig speed internet. The idea of assigning specific VLANs for private devices, IoT, guest traffic, and public access is logical. Regarding the switch connection, OPNsense can indeed communicate with switches through its management interface, allowing you to configure VLANs remotely. Just ensure your switch supports VLAN tagging and that you're using the correct port settings. If you need guidance on hardware choices or configuration steps, feel free to ask! Good luck, and let me know if you have more details to share.
Label the VLAN in ONSENSE first, then assign ports on switches and APs. Also tag interfaces in your hypervisor for the VMs. Check some YouTube tutorials—it’ll clarify things fast.
Because you're building a full custom router setup, consider adding a Pi-hole VM. Pi-hole runs on Linux, so Opnsense won’t work. You might try pfblocker-ng, which mimics Pi-hole but likely lacks a user-friendly web interface. Use Wireshark across all devices and navigate to view > network addresses to identify the websites you want to block. For Android, especially when away from home, install RethinkDNS to filter out unnecessary or unwanted connections instantly (or at least temporarily). Obtain it from F-droid, configure it as your VPN or firewall, and switch Wi-Fi on/off quickly for a few seconds. Repeat this process to filter out everything you don’t need constantly.