I build and run real network infrastructure on enterprise hardware — now going deep on security.
I'm Mihail Pascal — a career-changer moving into network and security operations. Nine years owning web, design and business outcomes taught me to finish things and stay calm under pressure. Now CCNA-certified, I run an enterprise-grade home lab I built, run, and rebuild every day.
A non-traditional path, on purpose.
No CS degree. Instead: a decade of owning real outcomes, and a lab that proves I can build and operate the real thing.
For most of the last decade I ran the business side of technology — I founded and led my own web and branding studios and worked as a UI/UX designer, frontend developer, and account manager. I owned the full lifecycle: finding clients, scoping, negotiating, delivering, and supporting what I shipped.
In 2025 I started over in networking — from zero. I learn by doing, so I bought real enterprise gear and built a physical home lab I run and break every day: firewall configured end to end, the network segmented into purpose-based VLANs, dual-WAN with failover, and a full SOC learning stack to start developing blue-team skills. I'm honest about where I am — I've built real infrastructure, and I'm actively learning to operate it well.
What I can actually do.
Levels are honest on purpose — no inflation. Everything marked Solid I can defend cold.
An enterprise-grade lab I built, run, and learn on — every day.
Real enterprise gear, cabled and configured end to end. The networking is production-style and runs my home; the security/SOC stack is a deliberate learning environment — I'm honest about which is which.
PacketFlow
web-based network simulatorA modern, fully web-based network simulator I built as a cleaner, more usable alternative to Packet Tracer and GNS3 — no installation, accessible from anywhere, with a modern UI.
I built it primarily for my own studying, then made it freely available for others. It doubles as a place to sketch and validate the topologies I run in the lab.
⤢ Click to enlargeSplit a flat home network into five isolated zones with inter-VLAN ACLs, dual-WAN failover and a default-deny policy between every segment.
A working blue-team stack — Wazuh SIEM, Suricata IDS, Velociraptor EDR and TheHive — wired to the lab so I can generate, detect and triage activity.
Zabbix 7.0 LTS watching 14 hosts across the lab — agents on Linux, SNMP on the ASA / MikroTik / Aruba, with email alerting on high-severity events.
Where I am, and where I'm headed.


Write-ups from the lab.
build notes · concepts · later, incident triageA flat network is one compromised device from total compromise. How I split my home lab into five purpose-based VLANs, with default-deny between every zone.
How I configured a Cisco ASA as the Layer 3 gateway for five VLANs — inter-VLAN ACLs, NAT order, locking myself out, and the mistakes I made getting there.
How a home SOC lab fits together — Wazuh SIEM, Suricata IDS, Velociraptor EDR, TheHive — and what running it teaches that installing it doesn't.

