Skip to content

Network & Topology

This page is the logical architecture reference for the lab. It shows how remote access, the upstream TELUS network, Proxmox virtual networking, OPNsense, and the internal VLANs relate to each other.

Diagram scope

The diagram records the current logical design with sanitized addresses. Public endpoints, keys, and other credential-adjacent values are omitted.

Current logical topology

flowchart TB
    subgraph CLIENTS["Client access"]
        REMOTE["Laptop on 5G or remote Wi-Fi"]
        HOME["Laptop on home Wi-Fi<br/>192.168.50.0/24"]
        RP["Remote WireGuard profile<br/>DDNS endpoint:51820"]
        HP["Home-internal WireGuard profile<br/>192.168.50.2:51820"]

        REMOTE --> RP
        HOME --> HP
    end

    subgraph UPSTREAM["TELUS upstream network"]
        INTERNET["Internet"]
        DDNS["Dynamic DNS<br/>tracks public IP"]
        NAH["TELUS NAH<br/>router · DHCP · NAT<br/>192.168.50.1"]
        WIFI["TELUS home LAN and Wi-Fi<br/>192.168.50.0/24"]

        INTERNET --> DDNS
        DDNS --> NAH
        NAH --- WIFI
    end

    subgraph DELL["Dell Tiny PC · Proxmox VE"]
        NIC1["NIC1 · 1 Gbps<br/>active upstream port"]
        NIC0["NIC0 · 2.5 Gbps<br/>currently inactive"]
        VMBR0["vmbr0<br/>upstream/WAN bridge"]
        PVE["Proxmox management<br/>192.168.50.10"]
        OPN["OPNsense VM<br/>WAN: 192.168.50.2<br/>WireGuard: 10.42.5.1/24<br/>Firewall · routing · Unbound DNS"]
        VMBR1["vmbr1<br/>VLAN-aware internal bridge<br/>no physical port"]

        NIC1 --> VMBR0
        VMBR0 --> PVE
        VMBR0 -->|"vtnet0 / WAN"| OPN
        OPN -->|"vtnet1 / VLAN trunk"| VMBR1
        NIC0 -. "reserved for later" .-> VMBR1
    end

    subgraph INTERNAL["Internal lab networks"]
        V10["VLAN 10 · Management<br/>10.42.10.0/24"]
        DEBIAN["Debian management VM"]

        V20["VLAN 20 · Infrastructure<br/>10.42.20.0/24"]
        DC["DC-05 · Windows Server 2022<br/>AD DS · DNS · Global Catalog<br/>10.42.20.10"]
        CLIENT["CL-01 · Windows 11<br/>domain client · DHCP"]
        PROXY["Planned: Nginx reverse proxy<br/>and load-balancing lab"]

        V30["VLAN 30 · Applications<br/>10.42.30.0/24"]
        BENTO["BentoPDF LXC<br/>10.42.30.20:8443"]

        V10 --> DEBIAN
        V20 --> DC
        V20 --> CLIENT
        CLIENT -->|"DNS · Kerberos · LDAP"| DC
        V20 -. "future workload" .-> PROXY
        V30 --> BENTO
    end

    RP --> INTERNET
    HP --> WIFI
    NAH -->|"UDP 51820 port forward"| NIC1
    WIFI -->|"direct home-LAN path"| NIC1

    VMBR1 --> V10
    VMBR1 --> V20
    VMBR1 --> V30

    OPN -. "Unbound override<br/>pdf-app.home" .-> BENTO

Access paths

Remote network

Laptop
  -> remote WireGuard profile
  -> dynamic DNS / TELUS public address
  -> TELUS UDP 51820 port forward
  -> OPNsense WireGuard
  -> permitted internal VLAN

Home Wi-Fi

Laptop
  -> home-internal WireGuard profile
  -> OPNsense private WAN address 192.168.50.2:51820
  -> OPNsense WireGuard
  -> permitted internal VLAN

The separate home profile avoids relying on NAT loopback (hairpin) support in the TELUS router.

Proxmox management exception

Proxmox management remains at the sanitized example 192.168.50.10 on the TELUS LAN for convenient recovery while the lab is still being built. It is reachable directly from trusted home Wi-Fi and is not currently part of the VPN-only internal VLAN design.

Topology notes

Proxmox bridges

Bridge Purpose
vmbr0 Upstream bridge connected to NIC1; carries Proxmox management and the OPNsense WAN virtual NIC
vmbr1 VLAN-aware internal bridge; carries the OPNsense LAN trunk and isolated lab guests

OPNsense role

OPNsense sits between the external network and the internal lab. It handles:

  • routing
  • firewall rules
  • NAT
  • DHCP and Unbound DNS where needed
  • WireGuard remote access

Internal segmentation

The internal side is split by function so the lab stays easier to manage and safer to expand:

Segment Purpose
VLAN 10 — Management Debian management VM and future administrative services
VLAN 20 — Infrastructure DC-05 and CL-01 for the temporary Active Directory lab; planned Nginx/reverse-proxy/load-balancing lab
VLAN 30 — Applications BentoPDF and future application workloads

Temporary Active Directory workloads

DC-05 and CL-01 currently share VLAN 20 so the client can discover the domain through DC-05, authenticate with Kerberos, and receive Group Policy. They are planned for deletion after the lab documentation is retained, but the topology continues to show them until that removal occurs.

Design rules I want to keep

  • keep WAN and LAN on different subnets
  • add new services to the internal side, not the WAN side
  • use VLANs only when they help organization or isolation
  • keep remote admin access behind VPN instead of exposing management ports directly
  • keep UDP 51820 as the only intentional public inbound port
  • treat direct home-LAN Proxmox access as a documented temporary exception