Network Topology

Managed Switches and VLAN Isolation

Explore the robust network architecture powering Stiaan's Lab, featuring advanced managed switches, strict VLAN isolation, and meticulously crafted firewall rulesets for optimal security and performance.

Architecture Overview

Core Network Components

Managed Switches

24-port PoE switches form the backbone, enabling granular control over traffic flow and power delivery to critical devices across the lab environment.

Firewall Appliance

An OPNsense-powered firewall enforces strict rulesets, ensuring secure inter-VLAN routing and protecting internal segments from unauthorized access or external threats.

Edge Routing

Dedicated edge routing layers handle external connectivity and internal subnet management, optimizing data paths and maintaining low-latency communication.

Security Best Practices

VLAN Isolation and Firewall Rulesets

01
02
03
04

VLAN Segmentation

Subnet Assignment

Firewall Policy

Priority & Logging

Eight distinct isolated VLANs segment the network, separating IoT devices, servers, workstations, and guest access to minimize attack surface and contain breaches.

Each VLAN is assigned a dedicated subnet, ensuring logical separation and efficient IP address management, preventing broadcast storm propagation.

Default-deny firewall policies drop all inter-VLAN traffic, with explicit rules whitelisting only essential services and protocols for controlled communication.

Rules are prioritized to enforce critical security policies first, with comprehensive logging enabled to monitor traffic, detect anomalies, and aid in incident response.

Performance Metrics

High-Speed Interconnects

10 Gbps

SFP+ Trunk Links

0%

Packet Loss

<1 ms

Internal Latency