01 / THE CHALLENGE
Understanding the problem.
My home lab supports everyday connectivity alongside infrastructure experimentation. Separating those uses gives me a practical environment to work with network boundaries, virtualisation and shared services.
- 01Segmented UniFi network
- 02Proxmox + shared DNS
- 03Hands-on investigation
02 / MY INVESTIGATION
Following the evidence.
I work through DNS resolution, DHCP lease allocation, Linux networking, SSH and NTP behaviour using command-line tools and service logs.
The lab connects the concepts across layers: switch port profiles and VLANs, guest networking, DNS/DHCP services and the behaviour of the operating systems using them.
03 / IMPLEMENTATION
Putting the work into practice.
- 01
Deployed a UniFi Cloud Gateway Fiber, USW Pro XG 8 PoE switch and U7 Pro XGS access point.
- 02
Implemented ten network segments, trunk/access port profiles and zone-based firewall policies to control inter-network traffic.
- 03
Implemented Proxmox VE with dedicated management, storage, egress and AI segments, and deployed two Pi-hole instances for shared DNS with DHCP services configured.
04 / OUTCOME & EVIDENCE
What the work delivered.
Implemented segmented home and lab infrastructure with Proxmox VE, two Pi-hole DNS instances and configured DHCP services.
Network implementation
Ten implemented segments with VLAN, port-profile and firewall configuration.
Working core services
Proxmox VE infrastructure and operational shared DNS using two Pi-hole instances.
Practical investigation
Hands-on Linux and network troubleshooting using command-line tools and service logs.
This is independent lab work. Additional core services and UniFi MCP integration are planned; the two DNS instances are not presented as a tested high-availability design.
05 / ENGINEERING PERSPECTIVE
What I take forward.
Building and troubleshooting a system end to end exposes the dependencies between components. The lab gives me a place to deepen that understanding and test ideas in an environment I operate myself.
Organisation names are generalised. These accounts describe my work without publishing client systems, internal logs or proprietary source code.