Question 1: For my Segmented Network+VPN project, Having ISP modem in Bridge mode will suffice? Or do I actually need to have static IP? (I am not planning remote access anytime soon though* I have 300mbps plan)
Question 2: Please confirm the hardware aspect, the flow chart picture that I attached, do you think it will work? Or do I need to buy separate switch also?
Also, I noticed pictures are visible only to people who have account here, so step wise flow chart in words: -----> 1) ISP Modem at Home (in bridge mode, wire from its LAN to WAN of MiniPC) ----> 2) “OPNsense on MiniPC with dual NIC, 1st onboard, 2nd in PCIe slot(configure PPPoE, define network segments (subnets), firewall rules for each subnet, define VPN access for different subnets OPT1, aceess for non trusted clients without VPN on OPT2) ----> 3) AP-1 = Tp-Link WiFi 6 dual-band router (in AP mode, wired to OPT1 serving subnet with VPN, for family, trusted clients) ----> 4) AP-2 = D-Link ADSL router 300Mbps (in AP Mode, wired to OPT2 serving subnet without VPN access, for guests/non trusted clients) -Will this hardware be enough?
--- (need to ask dhcp n ssid stuff later*)-I see, most popular YT videos like network chuck, tom from Lawrence etc, they indicate setup: 1) ISP-Modem ---> 2) OPNsenseMini-Pc ----> 3) Switch -----> 4) WirelessAccessPoint -(In this case, I will have to buy switch… and still have 2 separate access points? Or single WAP can serve two different subnets With VPN and Non VPN? Do you prefer this setup?)