Arnan de Gans

The international goose

PfSense, Vlans and Wifi shenanigans

Recently I bought an old Hewlet Packard Elitedesk 800 G2 SFF to add to the newer G4 SFF I already had. This new G2 model is much older and less capable compared to the G4 model, but for a router and network management device it's way overkill.

Some specs

And I added a 2 port Intel I350AM2 Gbit card to it for some extra networking.
No I didn't add any redundancy to it, it's just a enthusiast home network.

With the onboard NIC set to do Internet things I could then assign the network cards two ports to do Local Networking. 1 is for me, my personal network (LAN) with my media server and stuff. The other (OPT) will host 4 Vlans, one for each apartment. So that those also get a sense of a private network. Each has it's own Wifi hotspot, its own IP range and all that.

PfSense will sit in the middle of it all, doing NAT, DHCP/DNS, A bit of firewalling and handling the Vlan traffic. It's supposed to keep each network separated and private. I've also installed a tracking blocker thingy on it that should block and ignore tracking pixels and cookies among other things. More privacy online is never a bad thing I suppose.

Overkill, for sure, but it was kinda fun to set up a network like this after like 15 years. I used to do this for work from time to time. Back in the early 2010's. Haven't touched anything like it since 2014 or so. Anyway, it's been a frustrating and rewarding ride to make this work. I had hoped to do this with just the ISP modem and a smart switch. But modern devices kinda suck in terms of features these days. Either it doesn't work as advertised or requires such stupid combinations of tools that it just doesn't make sense anymore. But old-reliable PfSense kinda just worked... And for a fraction of what those other 'solutions' cost.

diy, network, Tech, internet

⬅ Previous post
Damage control