I am going to try to setup some VLANS and subnetting for my home network this weekend. I would like input and recommendations for my initial plan, or any corrections to my subnetting math! My current networking equipment is an OpnSense router/firewall, a Cisco Catalyst 2960 24-port switch, and a couple of older entry-level Wi-Fi routers set in AP only mode. While I don't have a whole lot of end point devices, I want to leave some room for additions and expansion.
Here is what I have planned out so far:
Vlan 1 - 192.168.0.0/29 (usable .1-.6) “DMZ” – Gateway, potentially public servers. Not wide-open, but maybe an SSH jump box, media server, and minecraft servers that might be opened for selected access
Vlan2 - 192.168.0.8/29 (usable .9-.14) Internal Servers, things that won't be public facing and may need more restrictions, primarily file serving.
Vlan3 -192.168.0.16/28 (usable .17-.30) Ethernet connected workstations. Will be statically assigned IP addresses. Should have access to Vlan1, 2, 6, 7
Vlan4 - 192.168.0.32/28 (usable .33-46) Main Wi-Fi computers/phones/tablets. DHCP Enabled. Should have access to Vlan1, 2, 6
Vlan5 - 192.168.0.48/27 (usable .43-79) Guest Wi-Fi access. Should only have access to Internet and "public" servers
Vlan6 - 192.168.0.192/28 (usable .193-207) Network connected printers - accessible from Vlan3 and 4. Should not access the Internet
Vlan7 - 192.168.0.240/28 (usable .241-254) Switch/AP Management - may need Internet access to pull firmware updates, should only be accessible by vlan3
Much of this scheme is done in an attempt to preserve existing IP addressing assignments, but if I need to change IP addressing I can. I have plenty of Ip addresses left to use here for future IP security cameras and IoT devices, but I don't have any of those currently.
Recommendations for a beter scheme or any corrections to my setup are welcome!
Here is what I have planned out so far:
Vlan 1 - 192.168.0.0/29 (usable .1-.6) “DMZ” – Gateway, potentially public servers. Not wide-open, but maybe an SSH jump box, media server, and minecraft servers that might be opened for selected access
Vlan2 - 192.168.0.8/29 (usable .9-.14) Internal Servers, things that won't be public facing and may need more restrictions, primarily file serving.
Vlan3 -192.168.0.16/28 (usable .17-.30) Ethernet connected workstations. Will be statically assigned IP addresses. Should have access to Vlan1, 2, 6, 7
Vlan4 - 192.168.0.32/28 (usable .33-46) Main Wi-Fi computers/phones/tablets. DHCP Enabled. Should have access to Vlan1, 2, 6
Vlan5 - 192.168.0.48/27 (usable .43-79) Guest Wi-Fi access. Should only have access to Internet and "public" servers
Vlan6 - 192.168.0.192/28 (usable .193-207) Network connected printers - accessible from Vlan3 and 4. Should not access the Internet
Vlan7 - 192.168.0.240/28 (usable .241-254) Switch/AP Management - may need Internet access to pull firmware updates, should only be accessible by vlan3
Much of this scheme is done in an attempt to preserve existing IP addressing assignments, but if I need to change IP addressing I can. I have plenty of Ip addresses left to use here for future IP security cameras and IoT devices, but I don't have any of those currently.
Recommendations for a beter scheme or any corrections to my setup are welcome!