homelab-network-readiness
affaan-m/ecc
Readiness checklist for homelab VLAN, DNS filtering, and VPN changes before touching router or firewall config.
What is homelab-network-readiness?
A planning and review skill for safely staging homelab network changes involving VLAN segmentation, local DNS resolution, and remote VPN access. Use this to inventory your topology, identify risks, and validate each step before modifying gateway, firewall, DHCP, or VPN settings.
- Collect required inventory of internet edge, gateway, switching, Wi-Fi, addressing, DNS/DHCP, management, and recovery paths
- Define trust zones (Trusted, Servers, IoT, Guest, Management, VPN) with default policies before implementing VLANs
- Plan DNS filtering readiness with fallback resolvers and per-VLAN validation steps
- Assess remote VPN access modes (split tunnel, full tunnel, overlay) and confirm endpoint security and key revocation
- Provide a staged change sequence: snapshot → reserve addresses → test one client → add exceptions → document rollback
- Review checklist covering management isolation, DNS resilience, DHCP testing, firewall defaults, and operator recovery paths
How to install homelab-network-readiness
npx skills add null --skill homelab-network-readinessHow to use homelab-network-readiness
- 1.Collect the required inventory: modem/ONT, gateway, switch ports, Wi-Fi SSIDs, current subnets, DNS/DHCP service, management access, and recovery options
- 2.Define your trust zones and their default policies using the provided template (Trusted, Servers, IoT, Guest, Management, VPN)
- 3.Confirm your gateway, switch, and APs support the required features (inter-VLAN routing, firewall rules, VLAN-to-SSID mapping)
- 4.For DNS filtering: reserve a static address for the resolver, test fallback paths, and validate one client before broad rollout
- 5.For VPN: decide the access mode (split tunnel to subnet, split tunnel to services, full tunnel, or overlay) and confirm endpoint maintenance and key revocation
- 6.Follow the change sequence: snapshot current state → reserve infrastructure addresses → create new zone without moving critical devices → test one client → add narrow firewall exceptions → move low-risk groups → add VPN with narrowest policy → document final state and rollback steps
- 7.Review the anti-patterns checklist and confirm no management interface is reachable from guest, IoT, or public internet
Use cases
- Splitting a flat home network into trusted, IoT, guest, server, and management VLANs without locking yourself out
- Migrating DHCP clients to Pi-hole or another local DNS resolver while keeping fallback paths working
- Adding WireGuard, Tailscale, or OpenVPN remote access with appropriate route and firewall policies
- Reviewing whether a planned network change could isolate you from the gateway, switch, AP, DNS server, or VPN endpoint
- Converting an informal homelab idea into a staged migration plan with validation evidence and rollback procedures
- Homelab operators planning network segmentation or DNS filtering upgrades
- System administrators managing small-office or home networks with mixed trust zones
- Network engineers reviewing topology changes for risk before implementation
- Anyone adding remote VPN access to a home or lab network
homelab-network-readiness FAQ
No. This is listed as an anti-pattern. Inventory your switch port assignments, SSID mappings, and current DHCP scopes first, then plan VLAN assignments based on that topology.
No. Reserve a static address for Pi-hole, confirm it resolves both public and local names, keep the gateway or a second resolver as fallback, and test one client or one VLAN before changing every scope.
No. This is explicitly prohibited. VPN endpoints should be patched and maintained, and forwarded ports should go only to the VPN service, not to admin UIs. Keep management interfaces on the local network only.
This is why you need out-of-band or same-room console access before changing management VLANs, trunk ports, firewall defaults, or DHCP/DNS settings. Document your rollback commands or UI steps in advance so you can revert locally if needed.
No. VPN clients should receive only the routes and DNS settings they need for their specific use case. Use split-tunnel modes and narrow firewall rules to limit VPN access, and keep full-tunnel access for untrusted networks only.
Full instructions (SKILL.md)
Source of truth, from affaan-m/ecc.
name: homelab-network-readiness description: Readiness checklist for homelab VLAN segmentation, local DNS filtering, and WireGuard-style remote access before changing router, firewall, DHCP, or VPN configuration. metadata: origin: community
Homelab Network Readiness
Use this skill before changing a home or small-lab network that mixes VLANs, Pi-hole or another local DNS resolver, firewall rules, and remote VPN access.
This is a planning and review skill. Do not turn it into copy-paste router, firewall, or VPN configuration unless the target platform, current topology, rollback path, console access, and maintenance window are all known.
When to Use
- Preparing to split a flat network into trusted, IoT, guest, server, or management VLANs.
- Moving DHCP clients to Pi-hole, AdGuard Home, Unbound, or another local DNS resolver.
- Adding WireGuard, Tailscale, ZeroTier, OpenVPN, or router-native VPN access.
- Reviewing whether a homelab change can lock the operator out of the gateway, switch, access point, DNS server, or VPN server.
- Turning an informal home-network idea into a staged migration plan with validation evidence.
Safety Rules
- Keep the first answer read-only: inventory, risks, staged plan, validation, and rollback.
- Do not expose gateway admin panels, DNS resolvers, SSH, NAS consoles, or VPN management UIs directly to the public internet.
- Do not provide firewall, NAT, VLAN, DHCP, or VPN commands without a confirmed platform and a rollback procedure.
- Require out-of-band or same-room console access before changing management VLANs, trunk ports, firewall default policies, or DHCP/DNS settings.
- Keep a working path back to the internet before pointing the whole network at a new DNS resolver or VPN route.
- Treat IoT, guest, camera, and lab-server networks as different trust zones until the operator explicitly chooses otherwise.
Required Inventory
Collect this before giving implementation steps:
| Area | Questions |
|---|---|
| Internet edge | What is the modem or ONT? Is the ISP router bridged or still routing? |
| Gateway | What routes, firewalls, handles DHCP, and terminates VPNs? |
| Switching | Which switch ports are uplinks, access ports, trunks, or unmanaged? |
| Wi-Fi | Which SSIDs map to which networks, and are APs wired or mesh? |
| Addressing | What subnets exist today, and which ranges conflict with VPN sites? |
| DNS/DHCP | Which service currently hands out leases and resolver addresses? |
| Management | How will the operator reach the gateway, switch, and AP after changes? |
| Recovery | What can be reverted locally if DNS, DHCP, VLANs, or VPN routes break? |
VLAN And Trust-Zone Plan
Start with intent rather than vendor syntax.
| Zone | Typical contents | Default policy |
|---|---|---|
| Trusted | Laptops, phones, admin workstations | Can reach shared services and management only when needed |
| Servers | NAS, Home Assistant, lab hosts, DNS resolver | Accepts narrow inbound flows from trusted clients |
| IoT | TVs, smart plugs, cameras, speakers | Internet access plus explicit exceptions only |
| Guest | Visitor devices | Internet-only, no LAN reachability |
| Management | Gateway, switches, APs, controllers | Reachable only from trusted admin devices |
| VPN | Remote clients | Same or narrower access than trusted clients |
Before recommending VLAN IDs or subnets, confirm:
- The gateway supports inter-VLAN routing and firewall rules.
- The switch supports the required tagged and untagged port behavior.
- The APs can map SSIDs to VLANs.
- The operator knows which port they are connected through during the change.
- The management network remains reachable after trunk and SSID changes.
DNS Filtering Readiness
Pi-hole or another local resolver should be introduced as a dependency, not as a single point of failure.
- Give the resolver a reserved address before using it in DHCP options.
- Confirm it can resolve public DNS and local
home.arpanames. - Keep the gateway or a second resolver available as a temporary fallback.
- Test one client or one VLAN before changing every DHCP scope.
- Document which networks may bypass filtering and why.
- Check that blocking rules do not break captive portals, work VPNs, firmware updates, or medical/security devices.
Useful validation evidence:
Client gets expected DHCP lease
Client receives expected DNS resolver
Public DNS lookup succeeds
Local home.arpa lookup succeeds
Blocked test domain is blocked only where intended
Gateway and DNS admin interfaces are not reachable from guest or IoT networks
Remote Access Readiness
For WireGuard-style access, decide what the VPN is allowed to reach before generating keys or opening ports.
| Mode | Use when | Risk notes |
|---|---|---|
| Split tunnel to one subnet | Remote admin for NAS or lab hosts | Keep route list narrow |
| Split tunnel to trusted services | Access selected apps by IP or DNS | Requires precise firewall rules |
| Full tunnel | Untrusted networks or travel | More bandwidth and DNS responsibility |
| Overlay VPN | Simpler remote access with identity controls | Still needs ACL review |
Do not recommend port forwarding until the operator confirms:
- The VPN endpoint is patched and actively maintained.
- The forwarded port goes only to the VPN service, not an admin UI.
- Dynamic DNS, public IP behavior, and ISP CGNAT status are understood.
- Peer keys can be revoked without rebuilding the whole network.
- Logs or connection status can verify who connected and when.
Change Sequence
Prefer small, reversible changes:
- Snapshot the current topology, IP plan, DHCP settings, DNS settings, and firewall rules.
- Reserve infrastructure addresses for gateway, DNS, controller, APs, NAS, and VPN endpoint.
- Create the new zone or VLAN without moving critical devices.
- Move one test client and validate DHCP, DNS, routing, internet, and block behavior.
- Add narrow firewall exceptions for required flows.
- Move one low-risk device group.
- Add VPN access with the narrowest route and firewall policy that satisfies the use case.
- Document final state, known exceptions, and rollback commands or UI steps.
Review Checklist
- Each network has a reason to exist and a clear trust boundary.
- No management interface is reachable from guest, IoT, or the public internet.
- DNS failure does not take down the operator's ability to recover locally.
- DHCP scope changes were tested on one client before broad rollout.
- VPN clients receive only the routes and DNS settings they need.
- Firewall rules are default-deny between zones, with named exceptions.
- The operator can still reach gateway, switch, AP, DNS, and VPN admin surfaces.
- Rollback is documented in the same vocabulary as the chosen platform UI or CLI.
Anti-Patterns
- Segmenting networks before knowing which switch ports and SSIDs carry which VLANs.
- Moving the admin workstation off the only reachable management network.
- Pointing all DHCP scopes at a Pi-hole before testing fallback DNS.
- Publishing NAS, DNS, router, or hypervisor management directly to the internet.
- Treating VPN access as equivalent to full trusted-LAN access.
- Adding allow-all firewall rules temporarily and forgetting to remove them.
- Copying commands from another vendor or firmware version without checking the exact platform syntax.
See Also
- Skill:
homelab-network-setup - Skill:
network-config-validation - Skill:
network-interface-health
Related skills
More from affaan-m/ecc and the wider catalog.
homelab-network-setup
Plan scalable home and homelab networks with proper IP ranges, DHCP, DNS, and device roles.
homelab-pihole-dns
Network-wide DNS ad blocker and local DNS management for home networks.
homelab-vlan-segmentation
Segment home networks into isolated VLANs for IoT, guest, and trusted traffic using UniFi, pfSense, OPNsense, or MikroTik.
homelab-wireguard-vpn
Fast, modern WireGuard VPN server setup for secure remote access to your home network.
hookify-rules
Create and manage Hookify rules to enforce patterns and guard against risky operations in Claude Code.
inherit-legacy-style
Agent skill from affaan-m/ecc.