The networking is production-style and runs my home for real. The security/SOC stack is a deliberate learning environment I stood up to study blue-team fundamentals — not professional experience. The achievement is building and operating real infrastructure, and learning on it honestly.
Default-deny between segments on the ASA, with explicit, logged exceptions. Wi-Fi segmented by SSID into matching VLANs.
Centralized syslog from the firewall, switch and router feeds the SIEM, with email alerting on high-severity events. This stack is how I practice — not production or professional experience.
Rack-mounted with structured cabling: a modular patch panel, labeled and color-coded runs, and PoE to the access points — built to stay readable a year from now, not just to work today.