home/lab
THE FULL BUILDsince Feb 2025 · physical rack

An enterprise-grade lab I built, run, and learn on — every day.

The networking is production-style and runs my home for real. The security/SOC stack is a deliberate learning environment I stood up to study blue-team fundamentals — not professional experience. The achievement is building and operating real infrastructure, and learning on it honestly.

TOPOLOGY — OVERVIEW
ISP 1
ISP 2
EDGE ROUTER
MikroTik RB5009
dual-WAN load balance + failover · NAT · firewall
10.0.0.0/30 transit
L3 FIREWALL
Cisco ASA 5515-X
inter-VLAN ACLs · NAT · sub-interfaces · syslog → SIEM
802.1Q trunk
L2 SWITCH
HPE Aruba 2530 PoE+
VLAN trunking · STP/BPDU guard · port security
UniFi U6+
segmented Wi-Fi 6
Dell / Proxmox
server · SOC stack · EVE-NG
HARDWARE INVENTORY
Edge routerMikroTik RB5009 · dual-WAN
Firewall (L3)Cisco ASA 5515-X
Switch (L2, PoE+)HPE Aruba 2530-24
Lab gearCatalyst 2960 · ISR 4300
HypervisorDell Precision 7920
Wi-Fi APUbiquiti UniFi U6+
Virtual lab · powerEVE-NG · rack UPS
VLAN SEGMENTATION
VLAN 20
Personal / Home
192.168.20.0/24
VLAN 30
Wireless
192.168.30.0/24
VLAN 40
Kids
192.168.40.0/24
VLAN 50
Guest
192.168.50.0/24
VLAN 60
Server / Lab
192.168.60.0/24

Default-deny between segments on the ASA, with explicit, logged exceptions. Wi-Fi segmented by SSID into matching VLANs.

ROUTING & EDGE · MIKROTIK
  • Dual-WAN PCC load balancing + failover (verified by simulating a WAN outage)
  • NAT/masquerade · default-deny WAN input chain
  • DNS forwarding to a filtering resolver over DNS-over-TLS
  • Scheduled daily config backups · dynamic DNS
  • SSH hardened, management restricted to the admin VLAN; Telnet/FTP/HTTP disabled
FIREWALL · CISCO ASA
  • End-to-end perimeter policy; inter-VLAN ACLs with explicit deny + logging
  • No "permit ip any any" — least exposure by default
  • NAT and per-VLAN sub-interfaces · basic threat detection
  • Remote syslog to the SIEM · AAA · login banner · RSA 2048
SWITCHING · HPE ARUBA
  • 802.1Q VLAN trunking · STP with BPDU protection on edge ports
  • Port security · LLDP · SNMP monitoring
  • SSHv2-only management (Telnet/web disabled)
  • Consistent NTP across every device
MONITORING · ZABBIX
  • Zabbix 7.0 LTS watching 14 hosts (~1,700 metrics) across the lab
  • Agentless Proxmox + agents on Linux hosts + SNMP on ASA / MikroTik / Aruba
  • Email alerting on high-severity events: host/link/service down, resource pressure
  • Dashboards for dual-WAN ISP throughput and device health
zabbix · Monitoring › Global viewlive
Zabbix monitoring dashboard — host availability, per-device uptime tiles and live dual-WAN traffic
⤢ Click to enlarge
FIG 1Zabbix 7.0 LTS · 14 monitored hosts · live dual-WAN throughput across the lab
SECURITY / SOC — LEARNING ENVIRONMENT
built to learn blue-team fundamentals

Centralized syslog from the firewall, switch and router feeds the SIEM, with email alerting on high-severity events. This stack is how I practice — not production or professional experience.

Wazuh
SIEM — log collection & analysis
Suricata
Network intrusion detection (IDS)
TheHive + Cortex
Case management & analysis
Velociraptor
Endpoint detection & response
AdGuard Home
Network-wide DNS filtering
WireGuard
Egress/privacy VPN (ProtonVPN) for lab traffic
wazuh · Security › MITRE ATT&CKlearning env
Wazuh MITRE ATT&CK dashboard — tactics and techniques charts across lab agents
⤢ Click to enlarge
FIG 2Wazuh · MITRE ATT&CK coverage across lab agents (learning environment)
THE PHYSICAL BUILD
RACK_CAM_01online
The home-lab rack: patch panel, HPE Aruba switch, Cisco ASA and ISR 4300 with structured cabling
› structured cabling · 5 VLANsGalați, RO

Cabled to be maintained — not just to work.

Rack-mounted with structured cabling: a modular patch panel, labeled and color-coded runs, and PoE to the access points — built to stay readable a year from now, not just to work today.

patch panel
modular · labeled
cabling
color-coded runs
power
rack UPS
online since
Feb 2025
← back to home