Auto-update blog content from Obsidian: 2025-05-19 16:15:27
All checks were successful
Deploy / Deploy (push) Successful in 3s
All checks were successful
Deploy / Deploy (push) Successful in 3s
This commit is contained in:
parent
fad6d22fd6
commit
cf3981ca2d
@ -139,27 +139,24 @@ Layer 2 networking is managed by **UniFi switches**, chosen for their sleek UI a
|
|||||||
|
|
||||||
A 2.5Gbps UniFi switch is dedicated to Ceph storage communications, isolating storage traffic to prevent interference with other networks.
|
A 2.5Gbps UniFi switch is dedicated to Ceph storage communications, isolating storage traffic to prevent interference with other networks.
|
||||||
|
|
||||||
I initially set up **LACP** (Link Aggregation) between the router and the main switch, hoping to double bandwidth. Reality check: it doesn’t. LACP provides redundancy and load balancing, not bandwidth aggregation. It was a good learning experience, but not essential for this setup.
|
I set up **LACP** (Link Aggregation) between the router and the main switch at 1Gbps, hoping to double bandwidth. Reality check: a single session will only use one link, meaning that a single download will still cap at 1Gbps.
|
||||||
|
#### VLANs
|
||||||
---
|
|
||||||
|
|
||||||
#### **VLANs: Segmented Network Design**
|
|
||||||
|
|
||||||
To segment traffic, I divided the network into several VLANs:
|
To segment traffic, I divided the network into several VLANs:
|
||||||
|
|
||||||
| VLAN ID | Name | Purpose |
|
| Name | ID | Purpose |
|
||||||
| ------- | ---------- | -------------------------------------------------------------- |
|
| --------- | ---- | ---------------------------- |
|
||||||
| 10 | Management | Access to infrastructure devices, including OPNsense and UniFi |
|
| User | 13 | Home network |
|
||||||
| 20 | Services | Web servers, containers, VMs |
|
| IoT | 37 | IoT and untrusted equipments |
|
||||||
| 30 | IoT | Smart devices, isolated from the rest of the network |
|
| DMZ | 55 | Internet facing |
|
||||||
| 40 | Storage | Ceph traffic, isolated for data replication |
|
| Lab | 66 | Lab network, trusted |
|
||||||
| 50 | Guests | Internet-only access for visitors |
|
| Heartbeat | 77 | Proxmox cluster heartbeat |
|
||||||
|
| Mgmt | 88 | Management |
|
||||||
|
| Ceph | 99 | Ceph |
|
||||||
|
| VPN | 1337 | Wireguard network |
|
||||||
|
|
||||||
Each VLAN has its own DHCP pool managed by OPNsense, allowing for controlled segmentation and simplified management.
|
Each VLAN has its own DHCP pool managed by OPNsense, excepted the Heartbeat and Ceph ones.
|
||||||
|
#### DNS
|
||||||
---
|
|
||||||
|
|
||||||
#### **DNS: Layered and Encrypted**
|
|
||||||
|
|
||||||
DNS is structured in two layers within OPNsense:
|
DNS is structured in two layers within OPNsense:
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user