Hi alltogether and first of all a happy new year and a better start to 2021 than 2020 has been all year long
i am new to this forum and stumbled across it via watching the good yt videos!
Thanks for alle the good tips in these videos. greatly appreciated.
as for my question, i am configuring my home network and homelab completly new and need some advice for my layout and how to configure it.
i am working as a backup administrator and have a diploma in business informatics and a degree in software engeneering, so no complete newbee but network, vlan and other things are not my favorite topic.
my hardware:
dell r720 as proxmox host with 128gb ram and 8x 2tb sas drives for zfs datapool, 2x ssd for zfs boot drive.
onboard 2x 1gb and 2x 10gb sfp+ nic
add on 4x 1gb nic
dell r720 with 64gb ram and 2x ssd zfs boot drive for truenas core
onboard 2x 1gb and 2x 10gb sfp+ nic
1sfp+ port on each dell is connected to the other to form a separate network only between proxmox and truenas for max performance. 10.0.0.x
aruba s2500 switch 48 port POE with 4x sfp+ ports
one 10gb sfp+ port is connected to each R720
the other 2x sfp+ 10gb ports are connected to 2 other 10gb sfp+ switches (zyxel xgs)
one of these in the same network, the other comes from a different office.
8x IP cameras for security, cabled, no wifi, poe
avm fritzbox (german brand) isp router for internet connection. not exchangeable.
3x ruckus r610 wifi APs via POE
1 ddwrt router (siemens se505, old one, only 100mbit) for connectivity between my network and the other network from office coming via the other zyxel xgs switch.
i want to get rid of that router as my aruba is capable of routing between networks and subnet itself.
fire tv sticks, smart Tvs, sat receivers (enigma2 devices) for entertainment.
2 kids with tablet and iphone
2 adults with tablets and smartphones
laptops via wifi
computer via cable
gaming consoles (ps3, ps2, xbox, xbox one, psp, psvita, switch) via cable or wifi
proxmox:
pihole
plex mediaserver with data on truenas
syncthing coming on truenas as container (thanks to your youtube guide)
nextcloud, data on truenas
opnsense (and thats the point)
iobroker for smarthome
development for webpages
apache guacamole
gaming windows system with dedficated graphic card
windows system with dedicated graphic card for video and gpraphic editing
several testing enviroments
other things coming soon
truenas:
synthing as container, nothing else planned
datastore for VM backups
datastore for data
syncing to remote truenas in other network (office)
my problem is… where to start and how to set up vlan, routing, networks etc
my goal should be to have everything separated from each other, so firetv stick and TV from kids wifi (vlan).
kids from parents.
cameras from everything else.
but nonetheless i need acces from every corner to the other.
so the kids should use plex to see holiday pictures and tv series i recorded.
fire tv sticks should use plex as well, plex has datrasotre on truenas core and so on.
my plan:
vlan for
kids
entertainment
smarthome
gaming
camera
network coming from the other office
guest
regular , everything else or our laptops and tablets etc… parents so to say.
wifi is separated already but no vlans configured
kids
gaming
entertainment
guests
normal wifi
smarthome (IoT)
motion (linux software for camera)
i need access from the office to my truenas for replication, my truenas to the office and vice versa.
office (my parents) should have access to my plex
plex access to truenas
entertainement access to truenas
kids to syncthing for syncing their fotos as any other mobile device in out house (all android onyl the kids iphone).
my wife and me access to nextcloud, nextcloud access to truenas for datastore.
avm fritzbox (ISP Router)
----------------------------------------> aruba switch
----------------------> proxmox
----------------------> opnsense
i want everything through opnsense and then through pihole, so i need to configure opnsense as gateway and DNS for all devices.
in opnsense i need to configure pihole as gateway and dns, right?
and in pihole i need to configure my avm router as gateway and dns, correct?
how will i handle the different access controls as i dont want any network to be aware of the other.
do i need to configure every vlan for truenas that needs access to it?
is it better to have a second nic in the second network, for example the cameras.
the cam itself is in net a, the motion linux server in net b. is routing from b to a (not the other way) better than having a second nic in net a?
i hope you can understand what i mean as it is quite a bit to explain.
so feel free to ask.
i hope you can help me out.
i have no experiance with opnsense or vlan in promox, but that shouldnt be a big problem.
thanks very much in advance!
Stefan