Homelab Network Setup
This skill comes from the open-source community. Credit the original author in any copy or update.
Use this skill to plan a home or small lab network. The plan should be safe, clear, and easy to grow.
When to Use
Use this skill when you need to:
- Plan a new home network.
- Improve a network that only uses an ISP router.
- Pick a gateway, switch, or Wi-Fi access point.
- Plan IP ranges, DHCP, fixed leases, and DNS.
- Add a NAS, Pi-hole, Home Assistant, lab server, or VPN.
- Plan separate networks for guests, smart devices, and servers.
- Fix double NAT, weak Wi-Fi, or server IP addresses that keep changing.
First Steps
Ask for these facts before making a plan:
- Internet speed and ISP device type.
- Home size, floors, and wall types.
- Number of wired and Wi-Fi devices.
- Current router, switches, and access points.
- Devices that must keep the same IP address.
- Need for guest Wi-Fi, smart devices, cameras, or remote VPN access.
- Budget and skill level.
- Need for IPv6, port forwarding, or public services.
If a fact is missing, state the guess you use.
Do not change the live network until there is a backup and rollback plan.
Device Roles
Keep each role clear:
Internet
|
Modem or ONT
|
Gateway or router Firewall, DHCP, DNS, NAT, and network routing
|
Managed switch Wired devices, access points, and VLAN links
|
Access points Wi-Fi only, with wired links when possible
Servers and NAS Fixed leases, clear names, and health checks
Clients and smart gear DHCP pools, with separate networks when neededOne device should run DHCP on each network. Two DHCP servers can give devices bad settings.
A spare router used as an access point should use AP mode. If it has no AP mode, turn off its DHCP and routing features.
Pick a Gateway
Choose a gateway that fits the person who will run it.
| Choice | Best fit | Main concern |
|---|---|---|
| ISP router | Basic internet use | May have weak VLAN and firewall tools |
| UniFi gateway | Simple managed home network | Works best with the UniFi system |
| OPNsense or pfSense | Flexible home lab | Needs more setup and care |
| MikroTik | Skilled network users | Many settings make errors easy |
| Linux router | People who like to build | A bad change can cut off the network |
Check that the gateway can handle the full internet speed with all needed features on. VPN, traffic checks, and smart queue tools may lower speed.
Modem and ISP Checks
Before replacing the ISP router, check:
- Can the ISP device use bridge or pass-through mode?
- Does the ISP use CGNAT?
- Does the ISP need a VLAN tag, login name, or special phone setup?
- Does the ISP use IPv6?
- Will bridge mode stop ISP TV or phone service?
CGNAT may block normal port forwarding. Use a VPN tunnel or another safe relay if remote access is needed.
Do not place two routers in a row unless double NAT is planned and written down.
IP Plan
Avoid common ranges such as 192.168.0.0/24 and 192.168.1.0/24 when VPN use is likely. Hotels, offices, and other homes often use them too.
Make sure every local and remote VPN range is different.
Example home lab plan:
192.168.10.0/24 trusted devices
192.168.20.0/24 smart and media devices
192.168.30.0/24 servers and NAS
192.168.40.0/24 guest Wi-Fi
192.168.99.0/24 network tools
Gateway: .1
Fixed leases: .2 through .49
DHCP pool: .50 through .240
Unused space: .241 through .254A /24 network gives up to 254 usable addresses. Use a smaller or larger network only when there is a clear need.
Do not give the same IP address to two devices. Keep fixed leases outside the DHCP pool, unless the DHCP server safely tracks them.
Use home.arpa for local names:
nas.home.arpa
pihole.home.arpa
gateway.home.arpa
switch-01.home.arpaDo not use made-up endings such as .lan. Do not use .local for normal DNS names because many devices use it for mDNS.
DHCP and DNS
- Use DHCP fixed leases for devices you log in to, save as bookmarks, watch, or run as services.
- Keep the gateway as DNS until a local DNS server is ready.
- Give Pi-hole or another DNS server a fixed lease before clients use it.
- Do not point a DNS server back to itself in a loop.
- Keep a tested way to reach the gateway if local DNS fails.
- A public backup DNS entry may bypass local blocks. State this tradeoff before adding one.
- Set the right time zone and use a trusted time source. Bad time can break logs and secure links.
VLAN Plan
A VLAN is a separate network on shared gear. Each VLAN needs:
- Its own ID.
- Its own IP range.
- A gateway address.
- A DHCP scope.
- Firewall rules.
- A matching switch and Wi-Fi setup.
The gateway, switches, and access points must all support the VLAN plan.
Start with simple rules:
- Trusted devices may reach needed server services.
- Smart devices should not reach trusted devices.
- Guest devices should reach the internet only.
- Network tool pages should be open only to admin devices.
- Block new traffic between groups unless it is needed.
Allow reply traffic for links that were already opened.
Some tools use mDNS to find printers, speakers, and smart devices. This search may not cross VLANs. Add an mDNS helper only for the groups that need it.
Do not turn on all VLANs at once. Test one group first with a spare device.
IPv6
Do not ignore IPv6 if the ISP gives it to you.
- Add IPv6 firewall rules that match the IPv4 safety plan.
- Do not assume NAT protects IPv6 devices.
- Check how the ISP gives out IPv6 ranges.
- Test DNS, guest access, and VLAN rules over both IPv4 and IPv6.
- Turn off IPv6 only when there is a clear reason and the effect is known.
Cabling and Wi-Fi
- Use wired links for access points when possible.
- Use Cat 6 cable for most new home runs.
- Use a PoE switch for access points and cameras when useful.
- Label both ends of every cable.
- Keep a port map with room, wall jack, switch port, and VLAN.
- Place access points in open, central spots.
- Do not hide an access point in a metal box or behind large gear.
- Use more access points at lower power when one loud access point cannot cover the home well.
- Use mesh only where a cable cannot be run.
- Put the modem, gateway, switch, DNS server, and NAS on battery backup if power cuts are common.
Safe Change Plan
Before a major change:
- Save the current settings.
- Write down all IP ranges, Wi-Fi names, and key device addresses.
- Keep a laptop and Ethernet cable ready.
- Know the default and current gateway address.
- Make one change at a time.
- Test internet, DNS, Wi-Fi, local services, and remote access.
- Roll back if the result is not clear.
Do not change the network tool VLAN from a remote link. A bad rule may lock you out.
Concrete Usage Example
User request:
I have a 1 Gbps cable link, an ISP router, one Wi-Fi access point,
a NAS, Home Assistant, six smart plugs, and two cameras.
I want guest Wi-Fi and remote VPN access.Good answer:
Use the ISP device in bridge mode if the ISP supports it.
Place a VLAN-ready gateway behind it.
Plan:
192.168.10.0/24 laptops and phones
192.168.20.0/24 smart plugs and cameras
192.168.30.0/24 NAS and Home Assistant
192.168.40.0/24 guests
192.168.99.0/24 gateway, switch, and access point
Use .1 as each gateway address.
Use .2 through .49 for fixed leases.
Use .50 through .240 for DHCP.
Give the NAS and Home Assistant fixed leases.
Block smart devices from trusted devices.
Allow trusted devices to reach needed smart device ports.
Give guests internet access only.
Set up VPN access to trusted and server networks.
Do not open the NAS or Home Assistant to the public internet.
Test one VLAN before moving all devices.
Keep the ISP router settings so the old setup can be restored.Common Small Upgrades
Keep the ISP Router
- Add fixed leases for the NAS, Pi, and login hosts.
- Move local names to
home.arpa. - Turn off DHCP on spare routers and access points.
- Wire the main access point if possible.
- Save a copy of the router settings.
Get Ready for VLANs
- Pick separate IP ranges.
- Reserve
.1for each gateway. - Reserve
.2through.49for key devices. - Buy a gateway, switch, and access points that support VLANs.
- Map each Wi-Fi name and switch port to a future network.
- Write the firewall rules before turning VLANs on.
Checks After Setup
Test all of these:
- A client gets the right IP, gateway, and DNS settings.
- Local names such as
nas.home.arpawork. - The internet works from each allowed network.
- Guest devices cannot reach local devices.
- Smart devices cannot reach trusted devices.
- Trusted devices can reach only the needed server ports.
- VPN users can reach only the planned networks.
- IPv4 and IPv6 follow the same safety rules.
- The gateway can still be reached by cable.
- The network still works after a gateway and switch restart.
Avoid These Mistakes
- Double NAT with no clear need.
- IP ranges that overlap with a VPN or remote site.
- Changing server IP addresses.
- More than one DHCP server on the same network.
- Using a spare router as an access point while routing is still on.
- Placing cameras, smart plugs, laptops, and servers in one trust group.
- Making VLANs without matching switch and access point settings.
- Allowing all traffic between VLANs.
- Exposing admin pages or home services to the public internet.
- Changing remote access rules without a local rollback path.
- Backing up settings but never testing that they can be restored.
See Also
- Skill:
network-interface-health - Skill:
network-config-validation