Homelab Vlan Segmentation

作者 affaan-mef648e01899b无许可证275K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3天前更新

ホームラボVLANセグメンテーション、ネットワーク分離、アクセス制御、およびトラフィック管理。

AI 生成的概览

指导将家庭网络划分为隔离的 VLAN,用于 IoT、访客、服务器和可信设备。

功能
提供设计模板和分步配置指导,把家庭网络拆分为可信、IoT、服务器、访客和管理等多个 VLAN。内容涵盖 VLAN 与子网规划、SSID 到 VLAN 的映射、干道端口与接入端口、DHCP 设置,以及阻断 VLAN 间流量同时放行 DNS 和互联网访问的防火墙规则。文中给出 UniFi、pfSense/OPNsense 和 MikroTik 的配置示例,并附反模式与最佳实践。
适用场景
适用于首次在家庭网络中搭建 VLAN、将 IoT 设备或访客与可信设备隔离,或在 UniFi、pfSense/OPNsense、MikroTik 设备上排查 VLAN 间路由与防火墙规则问题。也适合向不熟悉 VLAN 的人解释其工作原理。
运行要求
无需脚本或凭据,仅为说明性指导。实际应用需要可管理网络硬件,例如支持 VLAN 的交换机、接入点,以及路由器或防火墙平台(UniFi、pfSense/OPNsense 或 MikroTik)。

Homelab VLAN Segmentation

How to split a home network into isolated VLANs so IoT devices, guests, and your main PCs cannot talk to each other. The most impactful security upgrade for a home network.

All firewall rules shown here add isolation between segments — they do not remove existing protections. Apply changes in a maintenance window and verify connectivity between segments after each step before moving on.

When to Use

  • Setting up VLANs on a home network for the first time
  • Isolating IoT devices (smart bulbs, cameras, TVs) from trusted devices
  • Creating a guest Wi-Fi network that cannot reach home devices
  • Explaining how VLANs work to someone unfamiliar with the concept
  • Configuring trunk ports, access ports, and SSID-to-VLAN mapping
  • Troubleshooting inter-VLAN routing or firewall rule issues on pfSense/OPNsense/UniFi

How It Works

Without VLANs — flat network:  All devices on 192.168.1.0/24  Smart TV (potential malware) → can reach your NAS, PCs, everything
With VLANs:  VLAN 10 — Trusted    192.168.10.0/24  (PCs, phones, laptops)  VLAN 20 — IoT        192.168.20.0/24  (smart TV, bulbs, cameras)  VLAN 30 — Servers    192.168.30.0/24  (NAS, Pi, VMs)  VLAN 40 — Guest      192.168.40.0/24  (visitor Wi-Fi)  VLAN 99 — Management 192.168.99.0/24  (switch/AP web UIs)
  Smart TV → blocked from reaching 192.168.10.0/24 and 192.168.30.0/24  Guests → internet only, cannot see any home devices

VLAN Design Template

VLAN  Name        Subnet              Gateway         Purpose10    trusted     192.168.10.0/24     192.168.10.1    PCs, phones, laptops20    iot         192.168.20.0/24     192.168.20.1    Smart home devices30    servers     192.168.30.0/24     192.168.30.1    NAS, Pi, self-hosted40    guest       192.168.40.0/24     192.168.40.1    Visitor Wi-Fi99    management  192.168.99.0/24     192.168.99.1    Network gear web UIs

Examples

Typical homelab with UniFi AP and managed switch:

Scenario: 3-bedroom house, UniFi Dream Machine + UniFi 8-port switch + 2 APs
VLAN 10 — Trusted    192.168.10.0/24   MacBook, iPhones, iPadVLAN 20 — IoT        192.168.20.0/24   Nest thermostat, Philips Hue, Ring doorbell, smart TVsVLAN 30 — Servers    192.168.30.0/24   Synology NAS (192.168.30.10), Pi-hole (192.168.30.2)VLAN 40 — Guest      192.168.40.0/24   Visitor Wi-Fi — internet only
SSID → VLAN mapping:  "Home"      → VLAN 10 (WPA2, strong password, trusted devices only)  "IoT"       → VLAN 20 (WPA2, separate password, printed on router for setup)  "Guest"     → VLAN 40 (WPA2, simple password you can share freely)
Switch port behavior:  Port 1  → trunk to router (tagged VLANs 10,20,30,40,99)  Port 2  → trunk to APs (tagged VLANs 10,20,40; AP handles per-SSID tagging)  Port 3  → access VLAN 30 (NAS — untagged, no VLAN awareness needed)  Port 4  → access VLAN 30 (Pi-hole — untagged)  Port 5–8 → access VLAN 10 (wired workstations)
Firewall rules applied (all rules add isolation, none remove existing protections):  IoT → Trusted: BLOCK  IoT → Servers: BLOCK except 192.168.30.2:53 (Pi-hole DNS allowed)  IoT → Internet: ALLOW  Guest → Local networks: BLOCK  Guest → Internet: ALLOW  Trusted → everywhere: ALLOW

UniFi Configuration

Create Networks in UniFi Controller

Settings → Networks → Create New Network
For each VLAN:  Name: IoT  Purpose: Corporate  (gives DHCP + routing)  VLAN ID: 20  Network: 192.168.20.0/24  Gateway IP: 192.168.20.1  DHCP: Enable  DHCP Range: 192.168.20.100 – 192.168.20.254

Map SSIDs to VLANs (UniFi)

Settings → WiFi → Create New WiFi
  Name: IoT-Network  Password: <separate password>  Network: IoT  ← select your VLAN here  # All devices connecting to this SSID land in VLAN 20
  Name: Guest  Password: <guest password>  Network: Guest  Guest Policy: Enable  ← isolates guests from each other too

UniFi Firewall Rules (Traffic Rules)

Settings → Traffic & Security → Traffic Rules
# Block IoT from reaching Trusted VLAN  Action: Block  Category: Local Network  Source: IoT (192.168.20.0/24)  Destination: Trusted (192.168.10.0/24)
# Allow IoT to reach internet only  Action: Allow  Source: IoT  Destination: Internet
# Block Guest from all local networks  Action: Block  Source: Guest  Destination: Local Networks

pfSense / OPNsense Configuration

Create VLANs

Interfaces → Assignments → VLANs → Add
  Parent Interface: em1  (your LAN NIC)  VLAN Tag: 20  Description: IoT
# Repeat for each VLAN, then assign each VLAN to an interface:Interfaces → Assignments → Add  Select the VLAN you created → click Add  Enable the interface, set IP to gateway address (192.168.20.1/24)

DHCP for Each VLAN

Services → DHCP Server → Select your VLAN interface
  Enable DHCP  Range: 192.168.20.100 to 192.168.20.254  DNS Servers: 192.168.30.2  ← Pi-hole IP if you have one

Firewall Rules (pfSense/OPNsense)

# Rules are processed top-to-bottom, first match wins.
# On the IoT interface (VLAN 20):  Rule 1: Allow IoT → Pi-hole DNS  ← MUST come before the RFC1918 block rule    Protocol: UDP/TCP    Source: IoT net    Destination: 192.168.30.2 port 53    Action: Allow
  Rule 2: Block IoT → RFC1918 (all private IP ranges)    Protocol: any    Source: IoT net    Destination: RFC1918  (192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12)    Action: Block
  Rule 3: Allow IoT → internet    Protocol: any    Source: IoT net    Destination: any    Action: Allow
# On the Trusted interface (VLAN 10):  Allow all (trusted devices can reach everything)    Source: Trusted net    Destination: any    Action: Allow
# Additional exceptions for IoT devices that need specific local services:  Insert before Rule 2 (the RFC1918 block):    Protocol: TCP    Source: IoT net    Destination: 192.168.30.x port 8123  ← Home Assistant    Action: Allow

MikroTik Configuration

# Step 1: Create a bridge with VLAN filtering enabled/interface bridgeadd name=bridge vlan-filtering=yes
# Step 2: Add physical ports to the bridge# Trunk port to router/uplink (tagged for all VLANs)/interface bridge portadd bridge=bridge interface=ether1 frame-types=admit-only-vlan-tagged
# Access port for trusted devices (untagged VLAN 10)/interface bridge portadd bridge=bridge interface=ether2 pvid=10 frame-types=admit-only-untagged-and-priority-tagged
# Access port for IoT devices (untagged VLAN 20)/interface bridge portadd bridge=bridge interface=ether3 pvid=20 frame-types=admit-only-untagged-and-priority-tagged
# Step 3: Define which VLANs are allowed on which ports/interface bridge vlanadd bridge=bridge tagged=ether1 untagged=ether2 vlan-ids=10add bridge=bridge tagged=ether1 untagged=ether3 vlan-ids=20
# Step 4: Create VLAN interfaces on the bridge (gateway IPs)/interface vlanadd interface=bridge name=vlan10 vlan-id=10add interface=bridge name=vlan20 vlan-id=20
# Step 5: Assign gateway IPs/ip addressadd interface=vlan10 address=192.168.10.1/24add interface=vlan20 address=192.168.20.1/24
# Step 6: DHCP pools and servers/ip pooladd name=pool-trusted ranges=192.168.10.100-192.168.10.254add name=pool-iot ranges=192.168.20.100-192.168.20.254
/ip dhcp-serveradd interface=vlan10 address-pool=pool-trusted name=dhcp-trustedadd interface=vlan20 address-pool=pool-iot name=dhcp-iot
/ip dhcp-server networkadd address=192.168.10.0/24 gateway=192.168.10.1add address=192.168.20.0/24 gateway=192.168.20.1
# Step 7: Firewall — block IoT from reaching trusted VLAN/ip firewall filteradd chain=forward src-address=192.168.20.0/24 dst-address=192.168.10.0/24 \    action=drop comment="Block IoT to Trusted"

Switch Trunk vs Access Ports

# Trunk port: carries multiple VLANs (tagged) — connects switch-to-switch, switch-to-router, switch-to-AP# Access port: carries one VLAN (untagged) — connects to end devices (PC, camera, NAS)
# A managed switch port connected to your router should be a trunk:  Allowed VLANs: 10, 20, 30, 40, 99
# A port connecting to a PC should be an access port:  VLAN: 10 (trusted)  No tagging — the PC does not know or care about VLANs
# A port connecting to an AP must be a trunk:  The AP tags traffic from each SSID with the right VLAN ID  Allowed VLANs: 10, 20, 40  (whichever SSIDs the AP serves)

Anti-Patterns

# BAD: Creating VLANs without adding firewall rules# VLANs without firewall rules do not provide security — inter-VLAN routing is open by default# GOOD: Add explicit block rules immediately after creating VLANs
# BAD: Putting the Pi-hole in the IoT VLAN# IoT devices can reach it but trusted devices cannot (without extra rules)# GOOD: Pi-hole in the Servers VLAN with a rule allowing all VLANs to reach port 53
# BAD: Native VLAN equals management VLAN# Untagged traffic landing in your management VLAN enables VLAN hopping attacks# GOOD: Use a dedicated unused VLAN as native (e.g. VLAN 999), keep management traffic tagged
# BAD: Same Wi-Fi password for IoT SSID and trusted SSID# Anyone who learns the password can connect IoT devices to the wrong segment

Best Practices

  • Start with 4 VLANs: Trusted, IoT, Servers, Guest — add more as needed
  • Put Pi-hole in the Servers VLAN (192.168.30.x)
  • Add a firewall rule allowing DNS (port 53) from all VLANs to the Pi-hole IP — before any RFC1918 block rule
  • Test isolation after every rule change: from the IoT VLAN, try to ping a trusted device — it should fail
  • Use a management VLAN for switch and AP web UIs and restrict access to the Trusted VLAN only
  • Document your VLAN design in a table (VLAN ID, name, subnet, purpose)

Related Skills

  • homelab-network-setup
  • homelab-pihole-dns
  • homelab-wireguard-vpn

来源与署名

来源:affaan-m/ecc位于docs/ja-JP/skills/homelab-vlan-segmentation提交ef648e0

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架