← Back
Christian Lempa July 10, 2026 20m

VLANs for Proxmox + OPNsense: My Homelab Setup

Read full transcript 15 segments
  1. If you are building a home lab, you will If you are building a home lab, you will likely know this problem. Once you start likely know this problem. Once you start likely know this problem. Once you start adding more servers, deploying more adding more servers, deploying more adding more servers, deploying more applications, and experimenting with applications, and experimenting with applications, and experimenting with more gear, it's getting harder and more gear, it's getting harder and more gear, it's getting harder and harder to keep everything organized and harder to keep everything organized and harder to keep everything organized and connected. That's exactly why we're connected. That's exactly why we're connected. That's exactly why we're using VLANs, virtual local area using VLANs, virtual local area using VLANs, virtual local area networks, because they let you create networks, because they let you create networks, because they let you create multiple logical networks on one single multiple logical networks on one single multiple logical networks on one single physical switch without buying a whole physical switch without buying a whole physical switch without buying a whole rack of extra hardware. And together rack of extra hardware. And together rack of extra hardware. And together with a firewall, you can better segment with a firewall, you can better segment with a firewall, you can better segment your network into separate zones like your network into separate zones like your network into separate zones like one for your home lab, one for your one for your home lab, one for your one for your home lab, one for your testing environment, or a DMZ, a testing environment, or a DMZ, a testing environment, or a DMZ, a demilitarized zone where your public-f demilitarized zone where your public-f demilitarized zone where your public-f facing web servers are running all facing web servers are running all facing web servers are running all protected from each other. That's protected from each other. That's protected from each other. That's exactly what I did a few years ago in my exactly what I did a few years ago in my exactly what I did a few years ago in my home lab. But until now, I had one small home lab. But until now, I had one small home lab. But until now, I had one small problem. Although I already had problem. Although I already had problem. Although I already had different network zones like my private different network zones like my private different network zones like my private LAN, my production server network, and a LAN, my production server network, and a LAN, my production server network, and a DMZ for public services, there was one DMZ for public services, there was one DMZ for public services, there was one part that was still not flexible enough, part that was still not flexible enough, part that was still not flexible enough, my Proxmox cluster, because that was my Proxmox cluster, because that was my Proxmox cluster, because that was just part of my production server just part of my production server just part of my production server network. And that meant all of my network. And that meant all of my network. And that meant all of my virtual machines and container workloads virtual machines and container workloads virtual machines and container workloads that I deployed on my Proxmox cluster that I deployed on my Proxmox cluster that I deployed on my Proxmox cluster also naturally ended up in the same also naturally ended up in the same also naturally ended up in the same network as well. And when I then for network as well. And when I then for network as well. And when I then for example want to put a home assistant example want to put a home assistant example want to put a home assistant deployment in a virtual machine on the deployment in a virtual machine on the deployment in a virtual machine on the cluster but connected to my private cluster but connected to my private cluster but connected to my private network that was simply not possible by network that was simply not possible by network that was simply not possible by design. So I changed it. I made my design. So I changed it. I made my design. So I changed it. I made my Proxmox cluster VLAN aware and now my

  2. Proxmox cluster VLAN aware and now my Proxmox cluster VLAN aware and now my open sense firewall the switch and the open sense firewall the switch and the open sense firewall the switch and the virtualization layer carry all the same virtualization layer carry all the same virtualization layer carry all the same network design and I can individually network design and I can individually network design and I can individually put a single virtual machine as part of put a single virtual machine as part of put a single virtual machine as part of any network zone that I want. So, in any network zone that I want. So, in any network zone that I want. So, in this video, I'd like to show you how this video, I'd like to show you how this video, I'd like to show you how exactly you can build this as well. exactly you can build this as well. exactly you can build this as well. We'll cover what VLANs actually are, how We'll cover what VLANs actually are, how We'll cover what VLANs actually are, how the switch and the open sense firewall the switch and the open sense firewall the switch and the open sense firewall work together, and then finally, how to work together, and then finally, how to work together, and then finally, how to bring your Proxmox environment into this bring your Proxmox environment into this bring your Proxmox environment into this game, so you get full control and full game, so you get full control and full game, so you get full control and full flexibility over your HomeLab network flexibility over your HomeLab network flexibility over your HomeLab network setup. By the way, before we jump into setup. By the way, before we jump into setup. By the way, before we jump into this tutorial, I quickly want to thank this tutorial, I quickly want to thank this tutorial, I quickly want to thank WhatsApp Gold for sponsoring this video. WhatsApp Gold for sponsoring this video. WhatsApp Gold for sponsoring this video. And this actually fits pretty well into And this actually fits pretty well into And this actually fits pretty well into this topic because if you're running this topic because if you're running this topic because if you're running infrastructure, whether this is your infrastructure, whether this is your infrastructure, whether this is your home lab or maybe something bigger at home lab or maybe something bigger at home lab or maybe something bigger at work, you know that as soon as you start work, you know that as soon as you start work, you know that as soon as you start segmenting your network with VLANs, segmenting your network with VLANs, segmenting your network with VLANs, things can get complicated pretty fast. things can get complicated pretty fast. things can get complicated pretty fast. That's exactly where WhatsApp Gold comes That's exactly where WhatsApp Gold comes That's exactly where WhatsApp Gold comes in. It gives you a single place to in. It gives you a single place to in. It gives you a single place to monitor your entire network across monitor your entire network across monitor your entire network across devices, traffic, and segments. So devices, traffic, and segments. So devices, traffic, and segments. So instead of checking every switch, every instead of checking every switch, every instead of checking every switch, every firewall, every server and service firewall, every server and service firewall, every server and service separately, you can just see your separately, you can just see your separately, you can just see your infrastructure health, network infrastructure health, network infrastructure health, network performance and traffic patterns performance and traffic patterns performance and traffic patterns together in one view. And that is really together in one view. And that is really together in one view. And that is really important because monitoring is not only important because monitoring is not only important because monitoring is not only about getting an alert when something about getting an alert when something about getting an alert when something goes wrong. The useful part is goes wrong. The useful part is goes wrong. The useful part is understanding where the issue actually understanding where the issue actually understanding where the issue actually sits in. Is it just one device? Is it a sits in. Is it just one device? Is it a sits in. Is it just one device? Is it a group of devices? Maybe just one VLAN or group of devices? Maybe just one VLAN or group of devices? Maybe just one VLAN or is there an unusual behavior sitting is there an unusual behavior sitting is there an unusual behavior sitting inside the entire network? And WhatsApp inside the entire network? And WhatsApp inside the entire network? And WhatsApp Gold also includes a built-in network

  3. Gold also includes a built-in network Gold also includes a built-in network detection and response. So you're not detection and response. So you're not detection and response. So you're not only watching for outages, you can also only watching for outages, you can also only watching for outages, you can also spot unusual behavior earlier. And this spot unusual behavior earlier. And this spot unusual behavior earlier. And this gives you a much better visibility once gives you a much better visibility once gives you a much better visibility once your network becomes more complex. And your network becomes more complex. And your network becomes more complex. And if you want to try it out yourself, then if you want to try it out yourself, then if you want to try it out yourself, then check out the link in the description check out the link in the description check out the link in the description box down below to download the free box down below to download the free box down below to download the free trial and see how WhatsApp Gold fits in trial and see how WhatsApp Gold fits in trial and see how WhatsApp Gold fits in your network design. your network design. your network design. All right, guys. So now let's get All right, guys. So now let's get All right, guys. So now let's get started with VLANs. Before we jump into started with VLANs. Before we jump into started with VLANs. Before we jump into the tutorial part where I explain the tutorial part where I explain the tutorial part where I explain specifically how I changed my Proxmox specifically how I changed my Proxmox specifically how I changed my Proxmox cluster and made it VLAN aware, let's cluster and made it VLAN aware, let's cluster and made it VLAN aware, let's get everybody on the same page and let's get everybody on the same page and let's get everybody on the same page and let's quickly recap what VLANs actually are quickly recap what VLANs actually are quickly recap what VLANs actually are for. Again, as I said in the beginning, for. Again, as I said in the beginning, for. Again, as I said in the beginning, it stands for virtual local area network it stands for virtual local area network it stands for virtual local area network and it basically allows you to split one and it basically allows you to split one and it basically allows you to split one single physical switch into multiple single physical switch into multiple single physical switch into multiple logical networks. For example, what I've logical networks. For example, what I've logical networks. For example, what I've done for my home lab, I've split my big done for my home lab, I've split my big done for my home lab, I've split my big physical switch into three virtual physical switch into three virtual physical switch into three virtual lands. I technically have one or two lands. I technically have one or two lands. I technically have one or two more, but these are the most important more, but these are the most important more, but these are the most important ones. I have one virtual switch for my ones. I have one virtual switch for my ones. I have one virtual switch for my private network. You can see I've mostly private network. You can see I've mostly private network. You can see I've mostly assigned all the ports on the top row of assigned all the ports on the top row of assigned all the ports on the top row of the switch to that VLAN where my the switch to that VLAN where my the switch to that VLAN where my MacBook, my Mac Studio is, my iPhone, MacBook, my Mac Studio is, my iPhone, MacBook, my Mac Studio is, my iPhone, and of course other home devices like and of course other home devices like and of course other home devices like TVs and yeah, things like that. And then TVs and yeah, things like that. And then TVs and yeah, things like that. And then I have a virtual switch for my I have a virtual switch for my I have a virtual switch for my production network. So this is basically production network. So this is basically production network. So this is basically for my container workloads, the virtual for my container workloads, the virtual for my container workloads, the virtual machines, docker environments, basically machines, docker environments, basically machines, docker environments, basically everything that you see in my home lab.

  4. everything that you see in my home lab. everything that you see in my home lab. And the third one is for DMZ. So this And the third one is for DMZ. So this And the third one is for DMZ. So this stands for demilitarized zone. And this stands for demilitarized zone. And this stands for demilitarized zone. And this is a separate network zone where you is a separate network zone where you is a separate network zone where you usually put your public facing services usually put your public facing services usually put your public facing services because you typically want to isolate because you typically want to isolate because you typically want to isolate that part from your protected devices so that part from your protected devices so that part from your protected devices so that there is no natural lateral that there is no natural lateral that there is no natural lateral movement between your public facing movement between your public facing movement between your public facing services and maybe your self-hosted services and maybe your self-hosted services and maybe your self-hosted password manager or something like that. password manager or something like that. password manager or something like that. Now one thing is really important to Now one thing is really important to Now one thing is really important to understand if you want to use VLANs in understand if you want to use VLANs in understand if you want to use VLANs in any network environment you need a VLAN any network environment you need a VLAN any network environment you need a VLAN compatible switch. There are basically compatible switch. There are basically compatible switch. There are basically two types of switches in IT two types of switches in IT two types of switches in IT environments. Managed and unmanaged environments. Managed and unmanaged environments. Managed and unmanaged switches. An unmanaged switch is switches. An unmanaged switch is switches. An unmanaged switch is basically a simple and dump plugandplay basically a simple and dump plugandplay basically a simple and dump plugandplay switch. There's no configurations, no switch. There's no configurations, no switch. There's no configurations, no VLANs, no control, but it's also super VLANs, no control, but it's also super VLANs, no control, but it's also super damn simple and mostly cheaper. However, damn simple and mostly cheaper. However, damn simple and mostly cheaper. However, a managed switch that mostly cost a a managed switch that mostly cost a a managed switch that mostly cost a little more. But this gives you a web little more. But this gives you a web little more. But this gives you a web interface or a CLI where you can interface or a CLI where you can interface or a CLI where you can configure certain settings mostly also configure certain settings mostly also configure certain settings mostly also VLANs and you can assign certain ports VLANs and you can assign certain ports VLANs and you can assign certain ports to VLANs and decide what ports are to VLANs and decide what ports are to VLANs and decide what ports are tagged and untagged. Now this for tagged and untagged. Now this for tagged and untagged. Now this for example is my software switch the CS example is my software switch the CS example is my software switch the CS 11024FP.

  5. 11024FP. 11024FP. So I've already reviewed or shown this So I've already reviewed or shown this So I've already reviewed or shown this in previous videos. Here you can go to in previous videos. Here you can go to in previous videos. Here you can go to the configuration settings and then I the configuration settings and then I the configuration settings and then I can create multiple VLANs. Now it is can create multiple VLANs. Now it is can create multiple VLANs. Now it is important that one switch can assign important that one switch can assign important that one switch can assign each port on one or more of these VLANs. each port on one or more of these VLANs. each port on one or more of these VLANs. So you first basically create these So you first basically create these So you first basically create these VLANs by giving it a specific ID. VLAN VLANs by giving it a specific ID. VLAN VLANs by giving it a specific ID. VLAN ids can go from 1 to 4,94. VLAN one you ids can go from 1 to 4,94. VLAN one you ids can go from 1 to 4,94. VLAN one you can see is grayed out and this is a can see is grayed out and this is a can see is grayed out and this is a special one because this is often the special one because this is often the special one because this is often the default or native VLAN on many switches. default or native VLAN on many switches. default or native VLAN on many switches. So as a best practice, I would always So as a best practice, I would always So as a best practice, I would always avoid using VLAN ID 1 and start avoid using VLAN ID 1 and start avoid using VLAN ID 1 and start somewhere else. You can start at 2, somewhere else. You can start at 2, somewhere else. You can start at 2, three, four, and so on. But it is three, four, and so on. But it is three, four, and so on. But it is completely up to you what number you completely up to you what number you completely up to you what number you use. A switch that understands VLANs can use. A switch that understands VLANs can use. A switch that understands VLANs can send out traffic with a VLAN ID. These send out traffic with a VLAN ID. These send out traffic with a VLAN ID. These are called tacked. And network traffic are called tacked. And network traffic are called tacked. And network traffic without VLAN IDs. These are called without VLAN IDs. These are called without VLAN IDs. These are called untacked ports. And the switch untacked ports. And the switch untacked ports. And the switch automatically adds or removes this VLAN automatically adds or removes this VLAN automatically adds or removes this VLAN tag depending on the network port tag depending on the network port tag depending on the network port configuration. So when a packet leaves configuration. So when a packet leaves configuration. So when a packet leaves the device on that port then that the device on that port then that the device on that port then that belongs to this VLAN the switch can add belongs to this VLAN the switch can add belongs to this VLAN the switch can add this small VLAN ID in front of the this small VLAN ID in front of the this small VLAN ID in front of the Ethernet frame. This is actually a two Ethernet frame. This is actually a two Ethernet frame. This is actually a two bytes ID that sits in the middle of the bytes ID that sits in the middle of the bytes ID that sits in the middle of the source and the data and then the source and the data and then the source and the data and then the receiving device can understand oh this receiving device can understand oh this receiving device can understand oh this packet actually belongs to that specific packet actually belongs to that specific packet actually belongs to that specific VLAN. Now, when should you use what? So, VLAN. Now, when should you use what? So, VLAN. Now, when should you use what? So, that of course depends on the actual that of course depends on the actual that of course depends on the actual device that is connected to that port

  6. device that is connected to that port device that is connected to that port and untacked ports are mostly for normal and untacked ports are mostly for normal and untacked ports are mostly for normal devices like laptops, printers, devices like laptops, printers, devices like laptops, printers, computers, etc. They usually do not computers, etc. They usually do not computers, etc. They usually do not understand that VLAN tag by default. Of understand that VLAN tag by default. Of understand that VLAN tag by default. Of course, you can configure VLAN tags in course, you can configure VLAN tags in course, you can configure VLAN tags in operating systems if you want, but operating systems if you want, but operating systems if you want, but mostly you typically just connect a mostly you typically just connect a mostly you typically just connect a network cable to your computer and you network cable to your computer and you network cable to your computer and you don't configure a VLAN tag at all. So don't configure a VLAN tag at all. So don't configure a VLAN tag at all. So that way when the switch sends out a that way when the switch sends out a that way when the switch sends out a packet that belongs to that network to packet that belongs to that network to packet that belongs to that network to that port it removes the vent tag. So a that port it removes the vent tag. So a that port it removes the vent tag. So a simple device can understand oh I just simple device can understand oh I just simple device can understand oh I just received a packet. Now for other devices received a packet. Now for other devices received a packet. Now for other devices like other switches, firewalls, prox like other switches, firewalls, prox like other switches, firewalls, prox clusters whatever you might want to add clusters whatever you might want to add clusters whatever you might want to add this vlan tag because then they can this vlan tag because then they can this vlan tag because then they can separate the network traffic from each separate the network traffic from each separate the network traffic from each other and they understand oh this packet other and they understand oh this packet other and they understand oh this packet actually belongs to vlan 10. So here for actually belongs to vlan 10. So here for actually belongs to vlan 10. So here for example you can see that on my switch example you can see that on my switch example you can see that on my switch connection I have added the first row as connection I have added the first row as connection I have added the first row as untacked ports of the private network untacked ports of the private network untacked ports of the private network but the port 25 to 28 are considered but the port 25 to 28 are considered but the port 25 to 28 are considered tacked ports in multiple VLANs. So tacked ports in multiple VLANs. So tacked ports in multiple VLANs. So devices that are connected to these devices that are connected to these devices that are connected to these ports like my Proxbox cluster or my open ports like my Proxbox cluster or my open ports like my Proxbox cluster or my open sense firewall here at the port 22 they sense firewall here at the port 22 they sense firewall here at the port 22 they now carry multiple VLANs. I've made them now carry multiple VLANs. I've made them now carry multiple VLANs. I've made them part of the private network with VLAN part of the private network with VLAN part of the private network with VLAN tech 10 VLAN 20 the production network tech 10 VLAN 20 the production network tech 10 VLAN 20 the production network and the DMZ as well. And of course I and the DMZ as well. And of course I and the DMZ as well. And of course I know how to configure these in the know how to configure these in the know how to configure these in the Proxmox cluster as well. It's actually Proxmox cluster as well. It's actually Proxmox cluster as well. It's actually not really difficult but you have to not really difficult but you have to not really difficult but you have to change a few things. I've done this on change a few things. I've done this on change a few things. I've done this on all three Proxmox nodes by the way. I all three Proxmox nodes by the way. I all three Proxmox nodes by the way. I went into the network configuration. You

  7. went into the network configuration. You went into the network configuration. You go into that physical interface or the go into that physical interface or the go into that physical interface or the VM bridge whatever and you enable this VM bridge whatever and you enable this VM bridge whatever and you enable this checkbox here. You make it VLAN aware. checkbox here. You make it VLAN aware. checkbox here. You make it VLAN aware. So this port knows VLANs. When I go to So this port knows VLANs. When I go to So this port knows VLANs. When I go to my server port one, for example, I can my server port one, for example, I can my server port one, for example, I can go into the network device and add a go into the network device and add a go into the network device and add a VLAN tag. So this way I easily put this VLAN tag. So this way I easily put this VLAN tag. So this way I easily put this production server on VLAN 20, which if production server on VLAN 20, which if production server on VLAN 20, which if we return back to the switch means the we return back to the switch means the we return back to the switch means the production network. So this way I easily production network. So this way I easily production network. So this way I easily can put any virtual machine or any alexe can put any virtual machine or any alexe can put any virtual machine or any alexe container into a different VLAN and container into a different VLAN and container into a different VLAN and automatically and logically separate automatically and logically separate automatically and logically separate this out from the other networks. One this out from the other networks. One this out from the other networks. One thing is also important if you want the thing is also important if you want the thing is also important if you want the Proxmox cluster itself to connect or to Proxmox cluster itself to connect or to Proxmox cluster itself to connect or to communicate with that VLAN you also need communicate with that VLAN you also need communicate with that VLAN you also need a VLAN interface that was needed for my a VLAN interface that was needed for my a VLAN interface that was needed for my setup because in my Proxmox cluster it setup because in my Proxmox cluster it setup because in my Proxmox cluster it had an IP address on that production had an IP address on that production had an IP address on that production network. this is the primary IP address network. this is the primary IP address network. this is the primary IP address where I reached this device and when you where I reached this device and when you where I reached this device and when you know would change that network interface know would change that network interface know would change that network interface and make it VLAN aware you also have to and make it VLAN aware you also have to and make it VLAN aware you also have to add a VLAN interface on the Proxmbox add a VLAN interface on the Proxmbox add a VLAN interface on the Proxmbox clusters. So you have to go to network clusters. So you have to go to network clusters. So you have to go to network create another Linux VLAN and then give create another Linux VLAN and then give create another Linux VLAN and then give that the VLAN tag for example VLAN 20 that the VLAN tag for example VLAN 20 that the VLAN tag for example VLAN 20 and then just configure the IP address and then just configure the IP address and then just configure the IP address that you had configured before on the that you had configured before on the that you had configured before on the physical interface here on that VLAN physical interface here on that VLAN physical interface here on that VLAN interface so that you after changing or interface so that you after changing or interface so that you after changing or applying the configuration changes you

  8. applying the configuration changes you applying the configuration changes you can still reach your device otherwise can still reach your device otherwise can still reach your device otherwise you might log out yourself. This is what you might log out yourself. This is what you might log out yourself. This is what actually happened once to me and I actually happened once to me and I actually happened once to me and I needed to connect a mouse and a monitor needed to connect a mouse and a monitor needed to connect a mouse and a monitor and a keyboard and go into the shell and and a keyboard and go into the shell and and a keyboard and go into the shell and repair this. Here by the way you can add repair this. Here by the way you can add repair this. Here by the way you can add the VLAN raw device. So that is the name the VLAN raw device. So that is the name the VLAN raw device. So that is the name of the physical interface where this of the physical interface where this of the physical interface where this VLAN uh interface should be connected VLAN uh interface should be connected VLAN uh interface should be connected to. So in my case this is VMbridge one to. So in my case this is VMbridge one to. So in my case this is VMbridge one and this is the way how I've configured and this is the way how I've configured and this is the way how I've configured all of these different VLANs. So you can all of these different VLANs. So you can all of these different VLANs. So you can see this in VLAN 10. The Proxmox cluster see this in VLAN 10. The Proxmox cluster see this in VLAN 10. The Proxmox cluster has its own IP address in my private has its own IP address in my private has its own IP address in my private network. So it is actually reachable by network. So it is actually reachable by network. So it is actually reachable by any of the private devices at that IP any of the private devices at that IP any of the private devices at that IP address and any of the pro devices at address and any of the pro devices at address and any of the pro devices at this IP address. I by the way also use this IP address. I by the way also use this IP address. I by the way also use that to connect the HA link on the free that to connect the HA link on the free that to connect the HA link on the free Proxmox nodes. I know it is not Proxmox nodes. I know it is not Proxmox nodes. I know it is not recommended by Proxmox. You should not recommended by Proxmox. You should not recommended by Proxmox. You should not do this but honestly guys I don't care. do this but honestly guys I don't care. do this but honestly guys I don't care. I want my home lab to be simple and I want my home lab to be simple and I want my home lab to be simple and efficient. So I did not want to buy a efficient. So I did not want to buy a efficient. So I did not want to buy a separate uh physical switch. So what separate uh physical switch. So what separate uh physical switch. So what I've done is I basically uh created I've done is I basically uh created I've done is I basically uh created another VLAN that is called VLAN HA1 91 another VLAN that is called VLAN HA1 91 another VLAN that is called VLAN HA1 91 and sent out traffic to this VLAN 91 as and sent out traffic to this VLAN 91 as and sent out traffic to this VLAN 91 as tacked network traffic on port 25 to 27.

  9. tacked network traffic on port 25 to 27. tacked network traffic on port 25 to 27. And then what I've also done in the And then what I've also done in the And then what I've also done in the Proxmox cluster so on all three Proxmox Proxmox cluster so on all three Proxmox Proxmox cluster so on all three Proxmox nodes was really important add also a nodes was really important add also a nodes was really important add also a VLAN 91 interface um with that IP VLAN 91 interface um with that IP VLAN 91 interface um with that IP address 10 91 0416 address 10 91 0416 address 10 91 0416 and on the other Proxmox nodes of course and on the other Proxmox nodes of course and on the other Proxmox nodes of course this actually looks the same. So this this actually looks the same. So this this actually looks the same. So this for example has the 10 915 and the for example has the 10 915 and the for example has the 10 915 and the Proxmok notes 3 you might already guess Proxmok notes 3 you might already guess Proxmok notes 3 you might already guess it has the 6 at the end and then in the it has the 6 at the end and then in the it has the 6 at the end and then in the Proximox HA settings when I can remember Proximox HA settings when I can remember Proximox HA settings when I can remember where they are I think it's at data where they are I think it's at data where they are I think it's at data center cluster here you can see these center cluster here you can see these center cluster here you can see these are the IP addresses that I use for the are the IP addresses that I use for the are the IP addresses that I use for the link so the whole communication to the link so the whole communication to the link so the whole communication to the Proxmox cluster and all the different Proxmox cluster and all the different Proxmox cluster and all the different VLANs the HA communication the SE link VLANs the HA communication the SE link VLANs the HA communication the SE link everything goes through these three everything goes through these three everything goes through these three ports let me demonstrate how that works. ports let me demonstrate how that works. ports let me demonstrate how that works. So here's a Windows test machine that So here's a Windows test machine that So here's a Windows test machine that has two network interfaces that is has two network interfaces that is has two network interfaces that is connected to VLAN 10. So this is my connected to VLAN 10. So this is my connected to VLAN 10. So this is my private network even though it's running private network even though it's running private network even though it's running on my uh pro network Proxmox cluster and on my uh pro network Proxmox cluster and on my uh pro network Proxmox cluster and I also have a secondary interface that I also have a secondary interface that I also have a secondary interface that is in the VLAN 30. So that's the DMZ is in the VLAN 30. So that's the DMZ is in the VLAN 30. So that's the DMZ VLAN just for experimenting. And just to VLAN just for experimenting. And just to VLAN just for experimenting. And just to give you an idea of what that looks give you an idea of what that looks give you an idea of what that looks like, if I connect to RDP via this like, if I connect to RDP via this like, if I connect to RDP via this machine here, you can also see those two machine here, you can also see those two machine here, you can also see those two interfaces gets an IP address from the interfaces gets an IP address from the interfaces gets an IP address from the firewall that is 10.10.1.5 firewall that is 10.10.1.5 firewall that is 10.10.1.5 or I have manually configured this. Uh I or I have manually configured this. Uh I or I have manually configured this. Uh I see that usually the DHCP gives IP see that usually the DHCP gives IP see that usually the DHCP gives IP addresses in 1010.0 addresses in 1010.0 addresses in 1010.0 1 to254.

  10. 1 to254. 1 to254. This is the primary DNS. The standard This is the primary DNS. The standard This is the primary DNS. The standard gateway is also the firewall within that gateway is also the firewall within that gateway is also the firewall within that VLAN 10. the LAN network IP subnet. And VLAN 10. the LAN network IP subnet. And VLAN 10. the LAN network IP subnet. And for example, if I want to connect um to for example, if I want to connect um to for example, if I want to connect um to a machine like the 10.20, a machine like the 10.20, a machine like the 10.20, that does not work with a ping request that does not work with a ping request that does not work with a ping request because in my firewall rules, I do not because in my firewall rules, I do not because in my firewall rules, I do not allow anything else than DNS or 4 for allow anything else than DNS or 4 for allow anything else than DNS or 4 for free. But if I do, for example, an NS free. But if I do, for example, an NS free. But if I do, for example, an NS lookup like uh ns.home.cc.de lookup like uh ns.home.cc.de lookup like uh ns.home.cc.de at the 10.22 IP address, you can see at the 10.22 IP address, you can see at the 10.22 IP address, you can see that actually works. But I could not that actually works. But I could not that actually works. But I could not open an SSH connection to the same open an SSH connection to the same open an SSH connection to the same device for example. Yeah, that is simply device for example. Yeah, that is simply device for example. Yeah, that is simply not allowed. However, what I can now not allowed. However, what I can now not allowed. However, what I can now easily do if I return back to my easily do if I return back to my easily do if I return back to my Proxmbox network and I change the Proxmbox network and I change the Proxmbox network and I change the secondary interface that is currently in secondary interface that is currently in secondary interface that is currently in the DMZ zone to the VLAN 20 so that the the DMZ zone to the VLAN 20 so that the the DMZ zone to the VLAN 20 so that the virtual machine actually becomes part of virtual machine actually becomes part of virtual machine actually becomes part of both VLANs, the LAN and the pro network. both VLANs, the LAN and the pro network. both VLANs, the LAN and the pro network. Then I can easily return to the Windows Then I can easily return to the Windows Then I can easily return to the Windows machine. You can see that the network machine. You can see that the network machine. You can see that the network port gets an IP address from my DHCP port gets an IP address from my DHCP port gets an IP address from my DHCP server that is 10.2010.

  11. server that is 10.2010. server that is 10.2010. 35. So that it's logically connected to 35. So that it's logically connected to 35. So that it's logically connected to my pro network. And now because it's my pro network. And now because it's my pro network. And now because it's part of this network, it is able to ping part of this network, it is able to ping part of this network, it is able to ping any of the machines like the server.2, any of the machines like the server.2, any of the machines like the server.2, the server 3, and I could now also open the server 3, and I could now also open the server 3, and I could now also open an SSH connection. Of course, I still an SSH connection. Of course, I still an SSH connection. Of course, I still need to authenticate, but this device is need to authenticate, but this device is need to authenticate, but this device is now part of that network. And I can now part of that network. And I can now part of that network. And I can easily change that back again. You can easily change that back again. You can easily change that back again. You can see that this immediately stops working see that this immediately stops working see that this immediately stops working because the firewall receives that because the firewall receives that because the firewall receives that incoming request from the virtual incoming request from the virtual incoming request from the virtual Windows machine on a different network Windows machine on a different network Windows machine on a different network that is not allowed via the firewall that is not allowed via the firewall that is not allowed via the firewall rule. All right. So let's take a look at rule. All right. So let's take a look at rule. All right. So let's take a look at the open sense firewall. So you might the open sense firewall. So you might the open sense firewall. So you might have seen this before as well, but I have seen this before as well, but I have seen this before as well, but I think it's an important part of this think it's an important part of this think it's an important part of this story because without proper firewall story because without proper firewall story because without proper firewall rules, your visands are basically just rules, your visands are basically just rules, your visands are basically just separated networks. No is actually separated networks. No is actually separated networks. No is actually protecting the devices from VLAN 10 to protecting the devices from VLAN 10 to protecting the devices from VLAN 10 to VLAN 20. Many people think that VLAN VLAN 20. Many people think that VLAN VLAN 20. Many people think that VLAN alone make their setup secure, but they alone make their setup secure, but they alone make their setup secure, but they don't. They're basically just segment don't. They're basically just segment don't. They're basically just segment networks. Only when you add in firewall networks. Only when you add in firewall networks. Only when you add in firewall rules, you do really control what device rules, you do really control what device rules, you do really control what device can talk to another. Because otherwise can talk to another. Because otherwise can talk to another. Because otherwise any machine from VLAN 10 can just send any machine from VLAN 10 can just send any machine from VLAN 10 can just send out a network packet that belongs to a out a network packet that belongs to a out a network packet that belongs to a device in VLAN 20, it will send the device in VLAN 20, it will send the device in VLAN 20, it will send the network packet to its default gateway.

  12. network packet to its default gateway. network packet to its default gateway. If it's just your home router that is If it's just your home router that is If it's just your home router that is connected to all these separate connected to all these separate connected to all these separate networks, the home router will just networks, the home router will just networks, the home router will just forward the packet without any other forward the packet without any other forward the packet without any other controlling instance. So that's why you controlling instance. So that's why you controlling instance. So that's why you should always use a firewall and not a should always use a firewall and not a should always use a firewall and not a router. And you can of course very router. And you can of course very router. And you can of course very granularly define that for a single granularly define that for a single granularly define that for a single device for a whole network and add device for a whole network and add device for a whole network and add incoming and outcoming rules and all of incoming and outcoming rules and all of incoming and outcoming rules and all of that stuff. Now let me show you how I that stuff. Now let me show you how I that stuff. Now let me show you how I have configured that on my open sense have configured that on my open sense have configured that on my open sense firewall. So first of all you have to go firewall. So first of all you have to go firewall. So first of all you have to go devices and then VLAN. So here you can devices and then VLAN. So here you can devices and then VLAN. So here you can add all of your VLANs attached to one add all of your VLANs attached to one add all of your VLANs attached to one physical interface similar like you do physical interface similar like you do physical interface similar like you do it on the switch just in a slightly it on the switch just in a slightly it on the switch just in a slightly different menu of course. So here just different menu of course. So here just different menu of course. So here just pick any of the physical interfaces pick any of the physical interfaces pick any of the physical interfaces maybe the uh real tech interface one. maybe the uh real tech interface one. maybe the uh real tech interface one. Give it a device name like temporary and Give it a device name like temporary and Give it a device name like temporary and then a VLAN tag for example 67. I'm then a VLAN tag for example 67. I'm then a VLAN tag for example 67. I'm sorry guys but my son is currently sorry guys but my son is currently sorry guys but my son is currently getting on my nerves with 67 all the getting on my nerves with 67 all the getting on my nerves with 67 all the time. It's just in my head. It's let's time. It's just in my head. It's let's time. It's just in my head. It's let's not talk about this. No. But what is not talk about this. No. But what is not talk about this. No. But what is also important if you configure a also important if you configure a also important if you configure a firewall that should enforce firewall firewall that should enforce firewall firewall that should enforce firewall rules on these networks, it should have rules on these networks, it should have rules on these networks, it should have an IP address in all of these networks, an IP address in all of these networks, an IP address in all of these networks, of course, and they should be different.

  13. of course, and they should be different. of course, and they should be different. Otherwise, the switch might just route Otherwise, the switch might just route Otherwise, the switch might just route this internally and it never gets to the this internally and it never gets to the this internally and it never gets to the firewall. Only when it's logically firewall. Only when it's logically firewall. Only when it's logically separated with a different subnet mask, separated with a different subnet mask, separated with a different subnet mask, the device will send this out to its the device will send this out to its the device will send this out to its standard gateway, the firewall. You have standard gateway, the firewall. You have standard gateway, the firewall. You have your interfaces once you've created them your interfaces once you've created them your interfaces once you've created them here and then you go into LAN for here and then you go into LAN for here and then you go into LAN for example and give this a static IPv4 example and give this a static IPv4 example and give this a static IPv4 address in my case u the 1010.01 address in my case u the 1010.01 address in my case u the 1010.01 network with a subnet mask of 16. So network with a subnet mask of 16. So network with a subnet mask of 16. So that means that 1010 is actually the that means that 1010 is actually the that means that 1010 is actually the network part and anything after that is network part and anything after that is network part and anything after that is actually the host part and on the pro actually the host part and on the pro actually the host part and on the pro network for example this starts with network for example this starts with network for example this starts with 10.201 2001. That's by the way the 10.201 2001. That's by the way the 10.201 2001. That's by the way the reason why I've chosen VLAN 20 for this reason why I've chosen VLAN 20 for this reason why I've chosen VLAN 20 for this so I can easily remember that IP part. so I can easily remember that IP part. so I can easily remember that IP part. And then you can go into firewall rules. And then you can go into firewall rules. And then you can go into firewall rules. By the way, I've not migrated yet to the By the way, I've not migrated yet to the By the way, I've not migrated yet to the new firewall rule set in OpenSense. new firewall rule set in OpenSense. new firewall rule set in OpenSense. Maybe I'll do a separate video on this Maybe I'll do a separate video on this Maybe I'll do a separate video on this as well. But here in the firewall rules as well. But here in the firewall rules as well. But here in the firewall rules for example, you can see that there are for example, you can see that there are for example, you can see that there are firewall rules that usually prevent any firewall rules that usually prevent any firewall rules that usually prevent any unknown device from the LAN network to unknown device from the LAN network to unknown device from the LAN network to connect to any destination connect to any destination connect to any destination such as the trunk network, the such as the trunk network, the such as the trunk network, the management network. I only allow traffic management network. I only allow traffic management network. I only allow traffic from the LAN devices on specific ports from the LAN devices on specific ports from the LAN devices on specific ports on the server pro one. So this has that on the server pro one. So this has that on the server pro one. So this has that IP address and I only allow DNS lookups IP address and I only allow DNS lookups IP address and I only allow DNS lookups and HTTPS so that no device from the and HTTPS so that no device from the and HTTPS so that no device from the private network is allowed to open or private network is allowed to open or private network is allowed to open or establish an unsecured HTTP connection

  14. establish an unsecured HTTP connection establish an unsecured HTTP connection or an SSH connection or anything else to or an SSH connection or anything else to or an SSH connection or anything else to this production server. This is where my this production server. This is where my this production server. This is where my services are hosted that are actually services are hosted that are actually services are hosted that are actually known to the private network. And then I known to the private network. And then I known to the private network. And then I of course have also created separate uh of course have also created separate uh of course have also created separate uh firewall rules for my devices like firewall rules for my devices like firewall rules for my devices like MacBook Studio, MacBook Air, MacBook MacBook Studio, MacBook Air, MacBook MacBook Studio, MacBook Air, MacBook Pro. You probably know guys, I'm an Pro. You probably know guys, I'm an Pro. You probably know guys, I'm an Apple fanboy. Yeah. So, so I'm not going Apple fanboy. Yeah. So, so I'm not going Apple fanboy. Yeah. So, so I'm not going to lie to you, of course. But yeah, to lie to you, of course. But yeah, to lie to you, of course. But yeah, these devices where I usually work with, these devices where I usually work with, these devices where I usually work with, they of course need to connect to all they of course need to connect to all they of course need to connect to all networks. Yeah. Because otherwise I networks. Yeah. Because otherwise I networks. Yeah. Because otherwise I would lock out myself for my home lab. would lock out myself for my home lab. would lock out myself for my home lab. So this is basically how to use VLANs in So this is basically how to use VLANs in So this is basically how to use VLANs in your home lab. Of course, I know this is your home lab. Of course, I know this is your home lab. Of course, I know this is a topic that is sometimes a bit a topic that is sometimes a bit a topic that is sometimes a bit complicated and you have to think complicated and you have to think complicated and you have to think through it. And I know it's probably not through it. And I know it's probably not through it. And I know it's probably not for everyone, but if you want to for everyone, but if you want to for everyone, but if you want to replicate a setup that is quite common replicate a setup that is quite common replicate a setup that is quite common in professional and enterprise in professional and enterprise in professional and enterprise environments, this is how you usually do environments, this is how you usually do environments, this is how you usually do it just at a larger scale in that it just at a larger scale in that it just at a larger scale in that enterprise companies of course, but you enterprise companies of course, but you enterprise companies of course, but you can still practice with the same can still practice with the same can still practice with the same technology about network segmentation technology about network segmentation technology about network segmentation and protection using firewalls in your and protection using firewalls in your and protection using firewalls in your own home lab. It's absolutely amazing.

  15. own home lab. It's absolutely amazing. own home lab. It's absolutely amazing. You just need a VLAN compatible switch You just need a VLAN compatible switch You just need a VLAN compatible switch and maybe one or two computers where you and maybe one or two computers where you and maybe one or two computers where you can test it, but that's actually all you can test it, but that's actually all you can test it, but that's actually all you need to play around with this. And as I need to play around with this. And as I need to play around with this. And as I said, now that my Proxmox cluster is said, now that my Proxmox cluster is said, now that my Proxmox cluster is VLAN aware, I gained a lot more VLAN aware, I gained a lot more VLAN aware, I gained a lot more flexibility to test and experiment with flexibility to test and experiment with flexibility to test and experiment with new workloads like virtual machines or new workloads like virtual machines or new workloads like virtual machines or containers in one specific network. I containers in one specific network. I containers in one specific network. I absolutely love this. By the way, uh we absolutely love this. By the way, uh we absolutely love this. By the way, uh we have not covered containers yet. So, how have not covered containers yet. So, how have not covered containers yet. So, how do I actually add a container to one do I actually add a container to one do I actually add a container to one specific VLAN? I might do another specific VLAN? I might do another specific VLAN? I might do another session about Docker VLANs at some session about Docker VLANs at some session about Docker VLANs at some point. So, don't forget to give this point. So, don't forget to give this point. So, don't forget to give this video a thumbs up if you'd like to see video a thumbs up if you'd like to see video a thumbs up if you'd like to see that. And don't forget to subscribe to that. And don't forget to subscribe to that. And don't forget to subscribe to the channel if you want to see more the channel if you want to see more the channel if you want to see more tutorials. And as always, a big thanks tutorials. And as always, a big thanks tutorials. And as always, a big thanks goes out to all of my supporters and goes out to all of my supporters and goes out to all of my supporters and members of my channel. You guys are members of my channel. You guys are members of my channel. You guys are really amazing. And to everyone else, really amazing. And to everyone else, really amazing. And to everyone else, thank you so much for watching. Of thank you so much for watching. Of thank you so much for watching. Of course, I'm going to catch you in the course, I'm going to catch you in the course, I'm going to catch you in the next video. Take care. Bye-bye.

Summary

The main theme is organizing a complex home lab network using VLANs and a firewall for better segmentation. Key subjects include Proxmox, OpenSense, virtual machines, containers, and network zones. The practical takeaway is achieving greater control and flexibility over your home lab's network by making your Proxmox cluster VLAN-aware.

View original episode ↗