Executive Summary
Transitioned an unmanaged flat consumer network into an enterprise-grade private IP addressing fabric. The deployment enforces strict inter-VLAN default-deny boundaries, layer-7 deep packet inspection (DPI), isolated out-of-band hypervisor management, and an air-gapped security staging sandbox.
1. Network Topology & Addressing Schema
Routing and packet inspection are handled by an Intel i3-N300 hardware node running a virtualized OPNsense Core Router (VMID 100) over 4x Intel i226-V 2.5GbE interfaces, connected to a TP-Link Omada SG2210XMP-M2 managed 2.5G PoE+ switch.
| VLAN ID | Subnet CIDR | Zone Purpose | Isolation & Ingress/Egress Rules |
|---|---|---|---|
| VLAN 1 | 192.168.1.0/24 |
TRUSTED_LAN | Primary workstation access; tightly restricted dynamic scope (.200-.220) with static DHCP reservations for authorized physical nodes. |
| VLAN 2 | 192.168.2.0/24 |
OOB_MGMT | Air-gapped management network for Proxmox VE hypervisor web consoles, Unraid administration dashboards, and switch UI. Inaccessible from WAN or standard subnets. |
| VLAN 10 | 10.10.10.0/24 |
APP_CORE | Core identity control plane hosting Authentik OIDC forward-auth engine, Vaultwarden password vault, and AdGuard Home DNS. |
| VLAN 20 | 10.20.20.0/24 |
DMZ_MEDIA | High-throughput containerized media stack and transcode workloads on the Ryzen compute core. |
| VLAN 30 | 10.30.30.0/24 |
IOT_SMART | Home automation appliances, smart TVs, and IoT microcontrollers. Default-deny rule back into internal RFC1918 subnets; untrusted devices restricted via explicit MAC drop loops. |
| VLAN 40 | 10.40.40.0/24 |
GUEST_NET | Direct-to-WAN guest internet only. DHCP lease times compressed to 2 hours with client isolation enabled. |
| VLAN 99 | 10.99.99.0/24 |
STAGING | Sandboxed forensic/test laboratory for packet capturing untrusted containers and new images. Dropped from 100% of lateral internal network routes. |
2. Firewall Policy & Packet Filtering Design
Inter-VLAN Isolation Matrix
The firewall applies a Zero-Trust Default-Deny model across all subnets:
[VLAN 30: IoT] ──(BLOCKED)──> [VLAN 1, 2, 10, 20]
[VLAN 40: Guest] ──(BLOCKED)──> [ALL INTERNAL RFC1918]
[VLAN 99: Stage] ──(BLOCKED)──> [ALL INTERNAL RFC1918 (WAN Outbound Only)]
[VLAN 1: Admin] ──(ALLOW)────> [VLAN 2, 10, 20, 30] (Stateful inspection)
Step 3: Build the Second Project (Proxmox Compute & Storage Cluster)
Create the virtualization case study at content/projects/proxmox-virtualized-storage.md:
---
title: "Multi-Node Hypervisor Fabric & Hardware-Accelerated Storage Cluster"
date: 2026-09-30
draft: false
tags: ["Proxmox", "Unraid", "ZFS", "PCIe-Passthrough", "Virtualization"]
summary: "Implementation of a 3-node fault-tolerant virtualization architecture featuring IOMMU hardware passthrough, local ZFS mirror pools, and decoupled power resiliency."
weight: 2
---
## Architecture Overview
A purpose-built hybrid hypervisor architecture running Proxmox VE, combining high-efficiency gateway compute, dedicated high-throughput array storage, and out-of-band power orchestration.
---
## 1. Node Topology & Workload Segmentation
### Node 1: Intel i3-N300 Gateway Core [VMID 100 - 299]
- **Compute:** 8C/8T low-power Gracemont architecture, 16GB Crucial DDR5 4800MHz, Samsung PM9A1 NVMe.
- **VMID 100 (OPNsense Router):** 8GB RAM pinned; manages Zenarmor Layer 7 DPI in-memory databases and multi-VLAN policy routing.
- **VMID 200 (Identity Core LXC):** Unprivileged Linux container hosting Authentik OIDC control plane, Vaultwarden, and Primary AdGuard Home.
### Node 2: AMD Ryzen 5 Compute & Storage Core [VMID 300 - 499]
- **Compute:** AMD Ryzen 5 3600 (6C/12T), ASRock B550M Pro4, 32GB DDR4 3000MHz RAM.
- **Interconnect:** Mellanox ConnectX-3 10G SFP+ linked via DAC Twinax cable directly to core storage distribution.
- **Local Hypervisor Tier:** Proxmox VE operating system installed across 2x Intel DC S3500 Enterprise SSDs in a mirrored ZFS pool.
- **VMID 300 (Unraid VM):** Direct PCIe IOMMU passthrough of an **LSI Broadcom SAS 9211-8i HBA Card (IT-Mode)** managing mechanical hard drives alongside a dedicated Western Digital NVMe SSD cache tier.
- **LXC 310 (DMZ Media):** Unprivileged container with direct NVIDIA GeForce GTX 1660 `/dev/dri` passthrough for hardware-accelerated NVENC transcode pipelines.
### Node 3: Raspberry Pi 5 Resiliency Anchor [VMID 500 - 599]
- **Infrastructure Independence:** Powered via 2.5G PoE+ HAT inside an aluminum chassis (completely isolated from the Proxmox cluster domain).
- **VMID 500 (NUT Master):** USB-tethered to a CyberPower CP1500PFCLCD Pure Sine Wave UPS; coordinates automated orderly hypervisor shutdown sequences during power loss events.
- **VMID 520 (Fallback DNS Engine):** Secondary AdGuard Home synchronizing filters every 15 minutes, with local `ctrld` proxy routing DoQ and automated failover to Quad9 Oblivious DoH.
---
## 2. Storage Strategy & I/O Optimization
- **Atomic Hardlinks:** Storage topology leverages a unified parent share (`/mnt/user/data/`), allowing Docker containers to execute instant 0ms hardlink pointer moves between download scratch disks and media libraries without invoking storage-bus write cycles.