I spent the last few weeks planning, designing, and rebuilding my home network from the ground up - and while the end result is a segmented Unifi setup with an isolated lab environment for testing, getting there was messier, slower, and honestly more educational than expected going in.
The idea itself wasn't complicated: replace the home modem/router with real infrastructure - a gateway, managed switch, two access points, and a set of VLANs to keep everything isolated. The build uses the home's pre-existing in-wall cabling, with trusted devices in one lane, IoT in another, a dedicated network for security cameras, and a fully air-gapped Lab VLAN where I could actually run scanning tools against a vulnerable target without any risk to the rest of the house.
On paper this should be an afternoon project. In practice, it took the better part of a month - partly due to having to wait a week for missing pieces to arrive and working around my work schedule.
The first surprise: the switch I ordered did not come with a power adapter. Ordered directly from Unifi, apparently the power adapter is a separate line item I failed to catch prior to placing the order. An easy error to make and correct - except when I received the adapter a week later, the second access point wouldn't come online.
Figuring out the issue took some digging. Turns out, the issue was a bad female port connector, and the cable was spliced into another cable. Both problems stacked onto each other with the cable being part of the original cable from when the house was first built. Thankfully, the fix didn't require replacing the cable itself - tearing into the walls to run a new line would have been next to impossible.
On top of all that, the physical layer doesn't care how good your firewall rules are if the cable is bad.
To finish the project, I ran into a small issue which had nothing to do with the networking hardware. Building the isolated Lab VLAN required using a kali Linux machine running VirtualBox with a completely isolated virtual target - no path to the internet, no path to anything else on the network.
Getting VirtualBox's host-only networking working on Kali turned into a real kernel-troubleshooting (and learning) session: a mismatch between my running kernel and the header packages available in the repos, a DKMS module that wouldn't build, and an update to the right package release followed by a reboot into the matching kernel before anything would load. Not what I expected to be debugging when I sat down to build a home network, but a good reminder that Linux systems — especially rolling-release ones — come with their own maintenance overhead.
Once everything was actually online, the validation step was the most satisfying part of the whole project. I Ran an Nmap scan from Kali against an intentionally vulnerable target sitting on the Lab VLAN and watched it come back with over 20 open services, including a couple of well-known intentional backdoors baked into the test image. Then I tried to reach a device on my Trusted network from that same Lab machine — and got nothing. Not a slow response, not a partial connection. The gateway reported the destination as unreachable outright, because there was no route between the two networks at all.
That's the moment the whole project actually proved itself. Not when the VLANs were configured — when the isolation actually held up against something trying to get through it.
While verifying the functionality of the network, I noticed something in the connectivity logs: a device making repeated, rapid-fire authentication attempts against my primary network, all failing with the wrong password. A MAC lookup traced the device to a manufacturer whose chips show up in a huge range of cheap, generic IoT products - which didn't narrow things down much.
At first, I blocked the device, assuming it was an attack on my network. However, after taking a second look at the full log, the pattern didn't appear to be an attack - the connection attempts continued steadily for almost 24 hours with zero escalation or change in behavior, which is more consistent with a forgotten device still trying its old password than an active credential-stuffing attempt. I lifted the block and went on the hunt for the device. A good reminder that not every alarming-looking log entry is a five-alarm fire - sometimes it's just a smart plug you forgot existed.
Overall, I loved working on this build, and learned a lot in the process. Lessons learned here will help improve my ability with future projects of this kind, including: