I've decided to document a project I've been working on to completely rebuild and secure my home network.
What started as wanting better control over my network and finally getting VLANs working has turned into something considerably bigger.
The eventual goal is to have a home network with enterprise-style segmentation, monitoring, security controls, remote access, and eventually even a honeypot/deception environment.
And I'm doing it primarily with hardware I already have.
HOW THIS WHOLE THING STARTED
The hardware I'm building this around wasn't something I went out and bought specifically for this project.
A friend of mine several states away runs an e-waste recycling operation. He's constantly running into things around his house that need fixing or remodeling, and since I have a background in construction and remodeling, I'm usually the guy he calls when he needs help figuring something out.
At the same time, I had started taking cybersecurity courses and was getting more interested in networking, infrastructure, and security.
I had mentioned to him that I'd really like to get my hands on some actual networking hardware to practice with. Not just virtual machines or simulations, but real equipment that I could tear into, configure, break, recover, and learn from.
He apparently remembered that.
A while later, he sent me a Sophos XG 210 firewall and a Sophos CS110-24FP managed PoE switch as a thank-you.
At the time, I didn't have some grand plan for them.
The original idea was pretty simple:
Get some real enterprise hardware.
Learn how it works.
Experiment.
Break things.
Fix them.
Learn some more.
Then somewhere along the way, "I want some hardware to practice cybersecurity" turned into:
"Fuck it. Let's go balls deep."
π
That turned into putting OPNsense on the XG 210, learning the Sophos switch, fighting with VLANs, designing a segmented home network, and eventually deciding that I might as well see just how far I can take the whole thing.
And that's basically how this project was born.
THE HARDWARE
The main router/firewall is a Sophos XG 210 running OPNsense.
This is going to remain the brains of the network. OPNsense will handle routing, firewalling, DHCP, DNS, VPN, IDS/IPS, and inter-VLAN routing.
I've also got a Sophos CS110-24FP managed PoE switch handling the switching and VLAN infrastructure.
The XG 210 and the switch have already gone through their own little adventure getting OPNsense, VLANs, DHCP, and the switching configuration working together.
Then there's the newest addition: a Netgear R7900 that I'm converting into an OpenWrt access point.
That one has already given me a story.
I tried the R7900-specific OpenWrt firmware and ended up having to recover the router with NMRPflash. After getting the stock Netgear firmware back, I tried again.
The interesting part?
The R8000 OpenWrt image works on the R7900.
I'm now sitting at the LuCI login screen with OpenWrt running.
So at least for the moment, I haven't bricked anything. π
WHERE I'M GOING WITH THIS
The network will eventually be separated into multiple security zones, including:
– Main/trusted devices
– Kids
– IoT
– Guest
– Network management
– A dedicated security/honeypot environment
The idea is that devices shouldn't automatically be able to communicate with everything else simply because they're connected to my network.
An IoT device shouldn't have unrestricted access to my computers.
A guest shouldn't have access to my infrastructure.
A compromised device shouldn't be able to casually wander around the network.
And management interfaces shouldn't be sitting there accessible from every device in the house.
On top of that, I want to eventually add:
– WPA3
– Multiple VLAN-aware access points
– WireGuard remote access
– IDS/IPS
– Centralized logging
– DNS security
– Device discovery
– Traffic analysis
– Behavioral monitoring
– Honeypots
– Honeytokens
– Canary services
– Security alerts
– Historical network statistics
And eventually I want to build a custom control center for the whole thing.
Something where I can look at my phone and see what's happening on the network, who's connected, what devices are consuming bandwidth, whether anything suspicious has happened, and eventually control portions of the network remotely.
THE BIGGER IDEA
I don't just want this to be a secure network.
I want it to become a security lab.
The honeypot idea is especially interesting to me.
Rather than simply configuring IDS/IPS and hoping it catches something, I'd like to eventually create deliberately isolated systems and services that can act as tripwires.
Things like:
– Honeypots
– Fake credentials
– Honeytokens
– Canary services
– Decoy network shares
– Behavioral baselines
– Suspicious DNS detection
– Device discovery
– Automated security alerts
The goal isn't to blindly have the system block everything that looks suspicious.
I want to eventually build a system that can correlate events and tell me:
"This device normally behaves like this. Something has changed."
Or:
"This device accessed something it should never have touched."
Or:
"This device triggered multiple independent security signals."
That's where I think this could get really interesting.
THE IMPORTANT PART
I'm not documenting this as someone who already has everything figured out.
I'm building it as I go.
So I'm going to document the failures too.
If something doesn't work, I'm going to write about it.
If I accidentally configure something stupid, it'll probably make the blog.
If I spend three hours fighting something that turns out to be a checkbox, that's going in too.
The goal is to eventually have a complete record of taking a relatively ordinary home network and turning it into a seriously segmented and monitored security environment.
I'm also hoping this becomes a learning project as much as a networking project.
I'm interested in cybersecurity, networking, infrastructure, and eventually building software around all of it. So this gives me a place to experiment with all of those things in one project.
And because most of the hardware is older or repurposed equipment, I'm also curious how far I can push hardware that a lot of people would probably consider obsolete.
Old hardware. New purpose. Serious security.
So this is basically Day 0.
OPNsense is running.
The Sophos switch is working.
The VLAN foundation is coming together.
The R7900 is running OpenWrt.
And the next thing on the list is getting the damn Wi-Fi working. π
Let's see how far we can take this.
Source: r/u/Strong_Blacksmith239 · by /u/Strong_Blacksmith239