π‘ Homelab Network Architecture and Traffic Flows
This page documents the complete network architecture of the homelab, including:
- Physical topology (switching, APs, wiring)
- VLAN segmentation
- DMZ placement
- Ingress and egress paths
- Firewall rule flows
- Forward proxy and VPN chaining
- Serviceβtoβservice communication
- Proxmox node placement
It serves as the authoritative reference for contributors, troubleshooting, and future expansion.
π‘ 1. Physical Network Topology
This ASCII diagram recreates the physical topology in the homelab network as defined in the TP-Link Omada Ecosystem. It shows how the modem, router, switches, APs, cameras, and client/server devices are interconnected.
ββββββββββββββββ
β INTERNET β
ββββββββ¬ββββββββ
β
βββββββΌβββββ
β xDSL β
β Modem β
βββββββ¬βββββ
β
ββββββββββββββββΌββββββββββββββ
β Router / Switch β
ββββββ¬ββββββββββ¬ββββββββββ¬ββββ
β β β
β β β
βΌ βΌ βΌ
ββββββββββ ββββββββββ ββββββββββ
β Access β β Access β β Access β
β Switch β β Switch β β Switch β
ββββ¬ββββ¬ββ ββββ¬ββββ¬ββ ββββ¬ββββ¬ββ
β β β β β β
βΌ βΌ βΌ βΌ βΌ βΌ
[3] [24] [4] [21] [11][10]
C/S C/S C/S C/S AP C/S
β β β β β β
βΌ βΌ βΌ βΌ βΌ βΌ
C/S C/S C/S C/S C/S C/S
π Legend
- C/S = Client/Server device
- AP = Access Point
- Numbers in brackets represent the number of devices connected at that node
This diagram represents the physical wiring and switching hierarchy. The logical architecture below overlays VLANs, DMZ boundaries, and traffic flows on top of this structure.
π§ 2. VLAN & Security Zone Architecture
Your homelab uses three primary VLANs:
| VLAN | Purpose | Notes |
|---|---|---|
| 10 | DNS / Unbound | Piβhole primary/secondary, recursive resolver,workstations, laptops, phones, tablets, home devices actively used |
| 20 | Internal Services | App containers, databases, automation, hypervisors, core services, internal-only apps, management interfaces |
| 30 | DMZ | Reverse proxy, publicβfacing services, egress proxy, anything exposed to or tightly coupled with the Internet |
These VLANs are trunked across the access switches shown in the physical topology.
π 3. DMZ Placement
The DMZ (VLAN 30) sits between:
- External Firewall (Internet β DMZ)
- Internal Firewall (DMZ β Internal Services)
This isolates publicβfacing or boundaryβfacing services from the trusted LAN.
DMZ hosts include:
- Reverse Proxy (Nginx)
- Forward Proxy (Tinyproxy)
- VPN egress gateway (optional)
π 4. Ingress Architecture (Reverse Proxy)
Inbound traffic flow:
Internet
β External Firewall
β VLAN 30 (DMZ Reverse Proxy)
β Internal Firewall
β VLAN 20 (Internal Services)
The reverse proxy enforces:
- HTTPS termination
- OAuth2 / SSO
- Pathβbased routing
- Rate limiting
- Zeroβtrust boundaries
π€ 5. Egress Architecture (Forward Proxy + VPN)
Outbound traffic flow:
VLAN 20 (Internal Services)
β Internal Firewall
β VLAN 30 (Forward Proxy)
β VPN Gateway (optional)
β External Firewall
β Internet
This provides:
- Centralized outbound filtering
- Logging and auditing
- Optional countryβspecific VPN exit nodes
- Prevention of direct LAN β Internet access
π§ 6. Firewall Rule Flows
External Firewall (WAN β DMZ)
- Allow:
443 β Reverse Proxy - Allow:
DMZ β Internet(forward proxy only) - Deny: all other inbound
Internal Firewall (DMZ β LAN)
- Allow:
Reverse Proxy β App Ports - Allow:
LAN β Forward Proxy:3128 - Allow:
DNS VLAN 10 β LAN/DMZ - Deny: all other DMZ β LAN traffic
π 7. ServiceβtoβService Flows
User β App
Internet β Reverse Proxy β Internal Service
App β Internet
Internal Service β Forward Proxy β Internet
App β Database
Internal Service β Database (same VLAN 20)
App β DNS
Internal Service β VLAN 10 (Piβhole/Unbound)
π₯οΈ 8. Proxmox Node Placement
Proxmox Node 1
- DMZ-Proxy-01 (VLAN 30)
- DNS-01 (VLAN 10)
Proxmox Node 2
- Apps-01 (VLAN 20)
- DNS-02 (VLAN 10)
Both nodes trunk VLANs 10/20/30 from the physical topology.
π― Purpose of This Page
This page serves as the authoritative reference for:
- Understanding the homelabβs network architecture
- Onboarding new contributors
- Troubleshooting connectivity
- Planning future expansions
- Maintaining consistent security boundaries