Executive Summary

Deploying a single monolithic VPN introduces lateral movement risks and breaks non-technical user workflows. This deployment implements Intent-Based Access Control (IBAC), partitioning remote access into three isolated planes: application-level ZTNA for administration, automated hardware-level mesh routing for mobile travel, and dynamic IP-whitelisted edge proxying for consumer client hardware.


1. Architectural Allocation Matrix

Access Vector Technology Tier Target Scope Security Policy & Ingress Mechanics
Consumer Application Ingress Pangolin + Authentik Media & Streaming Workloads (VLAN 30) Ingests native smart TV/client app requests without VPN clients. Authentik fires webhooks upon WebAuthn validation to dynamically whitelist consumer WAN IPs on Pangolin.
Administrative Control Plane Twingate (ZTNA) Core Management (VLAN 10 & VLAN 1) Enforces micro-segmented, least-privilege resource mapping. Grants point-to-point socket access (e.g., 10.1.1.2:8006) without exposing Layer 3 subnets.
Infrastructure Mesh Backhaul Tailscale Physical Node Interconnect Encrypted WireGuard overlay bridging remote hardware (GL.iNet Slate 7 Pro) to OPNsense via Subnet Routing and Split-Horizon DNS.

2. Ingress & Routing Topology

                                 [ THE PUBLIC WAN INTERNET ]
                                                │
                ┌───────────────────────────────┼──────────────────────────────┐
                ▼ (Public Web / Media Ingress)  ▼ (ZTNA Admin Traffic)         ▼ (Mesh Satellite Bridge)
     ┌──────────────────────┐        ┌──────────────────────┐       ┌──────────────────────┐
     │   Cloudflare Edge    │        │   Twingate Relays    │       │ Tailscale DERP Fleet │
     │   • DDoS/WAF Gating  │        │   • Identity Brokered│       │ • Encrypted P2P Mesh │
     └──────────┬───────────┘        └──────────┬───────────┘       └──────────┬───────────┘
                │ (Port 443)                    │                              │
                ▼                               │ (Direct Outbound Egress)     │ (Direct Outbound Egress)
     ┌──────────────────────┐                   │                              │
     │  OVHcloud VPS Edge   │                   │                              │
     │  • Caddy L4/L7 SNI   │                   │                              │
     │  • GeoIP / CrowdSec  │                   │                              │
     └──────────┬───────────┘                   │                              │
                │                               │                              │
                │ (Outbound WireGuard /30)      │                              │
                ▼                               ▼                              ▼
 ┌─────────────────────────────── HOME FIREWALL BOUNDARY ────────────────────────────────────────┐
 │                                                                                               │
 │   ┌───────────────────────────────────────────────────────────────────────────────────────┐   │
 │   │ VMID 100: OPNsense Core Gateway (Intel i3-N300 Node)                                  │   │
 │   │  • Static Inbound WAN Ports: 0 OPEN (All Ingress Outbound-Initiated)                  │   │
 │   │  • Tailscale Subnet Router (Mesh Bridge to Travel Slate 7 Pro)                        │   │
 │   │  • Zenarmor Layer 7 DPI (Deep Packet Inspection on Inter-VLAN Traffic)                │   │
 │   └──────────────────────────────────────────┬────────────────────────────────────────────┘   │
 └──────────────────────────────────────────────┼────────────────────────────────────────────────┘
                                                │ (802.1Q Trunk / 10G MikroTik CRS305 Spine)
                                                ▼
 ┌───────────────────────────────── COMPUTATION & CLUSTER FABRIC ────────────────────────────────┐
 │                                                                                               │
 │   [ NODE 1: Intel i3-N300 Core ]                                                              │
 │   ┌─────────────────────────────── VMID 200: App Core Container (VLAN 10) ────────────────┐   │
 │   │                                                                                       │   │
 │   │  ┌────────────────────────┐                   ┌────────────────────────┐              │   │
 │   │  │ Authentik IdP Core     │                   │ Twingate Connector     │              │   │
 │   │  │ • 10.10.10.10          │                   │ • 10.10.10.20          │              │   │
 │   │  │ • WebAuthn / OIDC      │                   │ • Scoped Resource Broker              │   │
 │   │  └───────────┬────────────┘                   └────────────────────────┘              │   │
 │   └──────────────│────────────────────────────────────────────────────────────────────────┘   │
 │                  │                                                                            │
 │                  │ (Cross-VLAN Webhook Auth / Dynamic IP Allow)                               │
 │                  ▼                                                                            │
 │   [ NODE 2: AMD Ryzen 5 Core ]                                                                │
 │   ┌──────────────┴──────────────── LXC 310: DMZ Media Cluster (VLAN 30) ──────────────────┐   │
 │   │                                                                                       │   │
 │   │  ┌────────────────────────┐                   ┌────────────────────────┐              │   │
 │   │  │ Pangolin Ingress Proxy │                   │ Jellyfin Media Server  │              │   │
 │   │  │ • 10.30.30.30          │──────────────────►│ • 10.30.30.40          │              │   │
 │   │  │ • Dynamic IP Whitelist │  (Local Stream)   │ • Hardware NVENC Trans │              │   │
 │   │  └────────────────────────┘                   └────────────────────────┘              │   │
 │   └───────────────────────────────────────────────────────────────────────────────────────┘   │
 └───────────────────────────────────────────────────────────────────────────────────────────────┘