| Upstream 500MBit | +-----------------------+ KeaDHCP 192.168.1.0/24, 192.168.10.0/24, LAN |OPNsense 24.1.1-amd64 | 192.168.20.0/24, 192.168.30.0/24 Pass TCP/UDP - LAN -> LAN net -> * -> * |FreeBSD 13.2-RELEASE-p9| AdGuard: 53 -> UnBound: 53530 |OpenSSL 3.0.13 | CrowdSec:8085 USER: VLAN20 |HUSN RJ44 | Unifi: 8443 Pass ICMP - USER -> USER net -> * -> * +-----------------------+ Pass TCP/UDP - SEC -> LAN net -> * -> * | Pass UDP - USER -> USER net -> USER adress -> DNS +-----------|-----------+ |--- Synology 723+/Paperless, Unifi,... Block UDP - USER -> * -> * -> DNS | USW-16 PoE ----+--- Rasbi 4b/Homebridge etc. Pass * - USER -> USER net !> RFC1918 -> * +-----|-----------|-----+ |--- VLAN30: Samsung TV, Apple TV, | | | HP Laser,... +------+ | +------+ IOT: VLAN30 WIP!!!! | AP | | | AP | VLAN20/USER: Macbooks, iPhones,... Pass UDP - IOT -> IOT net -> IOT adress -> DNS | U7-P | | | U6+ | VLAN30/IOT : Echos, Meross, Gosund, Block UDP - IOT -> * -> * -> DNS +------+ | +------+ Nuki, Petkit,... Pass * - IOT -> IOT net !> RFC1918 -> * +-------+ | USW-5 |--------------- VLAN30/IOT : HUE Bridge, SONOS +-------+