this post was submitted on 17 May 2026
994 points (99.4% liked)
Technology
86600 readers
3672 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Just adding if you have any resources about how to go about this i would more than appreciate any nuggets you can share. I have a some networking background from college but its been about a decade since I used any of it so any help to point me in the right direction of hardening my network like this would be extremely appreciated. Thanks!
Good morning. First, please let me apologize for basically dropping this all of a sudden. Life happened and I had to be away for quite a while.
I am very sorry, because by the time I came back to be able to sit down in my computer to go over find my notes, I completely forgot about this.
Now, this will be very long, as I have it all documented with as much detail as possible to make sure I can reproduce it if anything goes catastrophically wrong.
Having said that, here goes:
As I mentioned, devices and choice of software is very personal. For example, I choose OPNSense vs PFSense for very personal reasons. Additionally, my infrastructure is so 'hardware-bloated' because the walls are all concrete, so I needed to make sure WiFi is covering as much as possible, which led to a shitload of APs. This caused me to spends quite some time tweaking the power and channels of each AP to make it easier for devices to move from one to the other without losing connectivity.
Lots of trial and error, but absolutely worth it once deployed.
The 2.5GB and 10GB ports were chosen just to future-proof the setup. My internet is not even 1Gb, but who knows where wee'll be in 5 years, right?
All cabling is Cat 6A shielded, and everything with a LAN port is wired, with WiFi disabled, this helps with keeping the RF a bit cleaner while ensuring a much more reliable connection for those devices (TVs, PCs, Consoles, Cameras, etc)
The choice of mini-PC for OPNSense is entirely based on the fact that I want to do IPS all the time, and an n95 CPU would choke with the ridiculous amount of devices and hosts in my network.
I would like to see what you guys have as well. This could be fun.
By all means man. Full disclosure, what I suggest is because it worked for me, so it's always wise to research based on anyone's suggestions and then choose the path that would work best for your intentions. In my case, I have a VLAN for my kids because their access goes away every night at 8pm on weekdays, for example. My wife has her own VLAN because there some stuff I have blocked that she wants access to. Then I have a media VLAN for gaming consoles and streaming devices, IOT is separate, CCTV in it's own VLAN, etc. I you scroll up a bit, you'll find another reply I just added. If you can tell us what you're looking to achieve, and what infrastructure you currently run, I know some of us will love to suggest options to point you in the right direction.
On a separate note, I still want someone to tell me if there's anything else I can do on my ONT modem to harden it even more.