<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Vlan on trustserv.de</title>
		<link>https://trustserv.de/en/tags/vlan/</link>
		<description>Recent content in Vlan on trustserv.de</description>
		<generator>Hugo</generator>
		<language>en-US</language>
		
		
		
		
			<lastBuildDate>Mon, 17 Aug 2026 08:45:00 +0200</lastBuildDate>
		
			<atom:link href="https://trustserv.de/en/tags/vlan/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Homelab Rebuild Part 7: One SSID, and the Network Decides</title>
				<link>https://trustserv.de/en/post/homelab-teil-7/</link>
				<pubDate>Mon, 17 Aug 2026 08:45:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-7/</guid>
				<description>&lt;h2 id=&#34;what-this-is-about&#34;&gt;&#xA;  What this is about&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#what-this-is-about&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-1/&#34; &gt;Part 1&lt;/a&gt; established that one SSID per VLAN&#xA;doesn&amp;rsquo;t work — every SSID costs airtime, and with five or six of them you&#xA;lose measurable throughput.&lt;/p&gt;&#xA;&lt;p&gt;The alternative is the one companies use: &lt;strong&gt;a single SSID, and the&#xA;network decides per device.&lt;/strong&gt; The device authenticates with its own&#xA;credentials, a RADIUS server checks them and sends the VLAN assignment&#xA;back with the answer.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 5: The First VLAN</title>
				<link>https://trustserv.de/en/post/homelab-teil-5/</link>
				<pubDate>Sat, 15 Aug 2026 20:40:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-5/</guid>
				<description>&lt;h2 id=&#34;why-telephony-of-all-things&#34;&gt;&#xA;  Why telephony of all things&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#why-telephony-of-all-things&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;After &lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-4/&#34; &gt;part 4&lt;/a&gt; everything is in place: a&#xA;firewall that can enforce rules, and a host for services. Now comes the&#xA;first VLAN of my own — and I deliberately started with the case where the&#xA;least can go wrong.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;If the landline dies, it doesn&amp;rsquo;t matter.&lt;/strong&gt; I have a Swiss phone and a&#xA;German phone. A networking experiment whose worst outcome is that one&#xA;handset doesn&amp;rsquo;t ring is the ideal first test. That was the selection&#xA;logic: not the most important service first, the most harmless one.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 4: Somewhere for Services to Live</title>
				<link>https://trustserv.de/en/post/homelab-teil-4/</link>
				<pubDate>Sat, 15 Aug 2026 20:30:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-4/</guid>
				<description>&lt;h2 id=&#34;why-at-all&#34;&gt;&#xA;  Why at all&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#why-at-all&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;After &lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-3/&#34; &gt;part 3&lt;/a&gt; the OPNsense routes and the R4&#xA;is a switch and access point. What&amp;rsquo;s missing is somewhere for services to&#xA;run. FreeRADIUS, an internal CA, a phone system — all of that needs a&#xA;home.&lt;/p&gt;&#xA;&lt;p&gt;The firewall isn&amp;rsquo;t it. A firewall should forward packets and enforce&#xA;rules, nothing else. The more that runs alongside, the bigger the attack&#xA;surface and the more unpleasant every update.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 3: Sliding the Firewall In</title>
				<link>https://trustserv.de/en/post/homelab-teil-3/</link>
				<pubDate>Sat, 15 Aug 2026 20:00:00 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-3/</guid>
				<description>&lt;h2 id=&#34;the-awkward-part&#34;&gt;&#xA;  The awkward part&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-awkward-part&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The hardware from &lt;a href=&#34;https://trustserv.de/en/post/homelab-teil-2/&#34; &gt;part 2&lt;/a&gt; was sitting on the&#xA;desk. The network kept running. And that&amp;rsquo;s exactly the uncomfortable&#xA;spot: the uplink isn&amp;rsquo;t my hobby project, it&amp;rsquo;s the way to the internet. If&#xA;I break it, it&amp;rsquo;s broken.&lt;/p&gt;&#xA;&lt;p&gt;So the task wasn&amp;rsquo;t &amp;ldquo;set up OPNsense&amp;rdquo;, it was &amp;ldquo;set up OPNsense without&#xA;hours of downtime in between&amp;rdquo;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prepare-before-it-counts&#34;&gt;&#xA;  Prepare before it counts&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#prepare-before-it-counts&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The first step had nothing to do with the network: the firewall got&#xA;assembled in my room, hooked up to the workstation, and fully configured.&#xA;LAN on &lt;code&gt;10.0.1.1&lt;/code&gt;, DHCP set up, base rules in place, everything clicked&#xA;through.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Homelab Rebuild Part 1: Where I Started</title>
				<link>https://trustserv.de/en/post/homelab-teil-1/</link>
				<pubDate>Sat, 15 Aug 2026 14:52:30 +0200</pubDate>
				<guid>https://trustserv.de/en/post/homelab-teil-1/</guid>
				<description>&lt;h2 id=&#34;what-this-is-about&#34;&gt;&#xA;  What this is about&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#what-this-is-about&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;My home network grew the way most of them do: add a device, it works,&#xA;stop thinking about it. Eventually everything hung off one box and lived&#xA;in one subnet.&lt;/p&gt;&#xA;&lt;p&gt;That works fine for a surprisingly long time. But at some point I wanted&#xA;to do things the setup had no room for — separate devices from each&#xA;other, push Wi-Fi clients automatically to where they belong, issue my&#xA;own certificates. That needs a different foundation.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
