Starting homelab network - hardware choices

Started by hacktheplanet, January 12, 2026, 10:22:32 PM

Previous topic - Next topic
January 12, 2026, 10:22:32 PM Last Edit: January 12, 2026, 10:56:23 PM by hacktheplanet
Hi all!

I will be building out a homelab and would like to have the router running OPNSense. I am coming from a Fritzbox 7530 AX.

I am considering a number of hardware options and would appreciate some advice to help me narrow it down.

Use Case

My use case, as I implied above, is to set up a homelab but also just have a secure and functional home network, so I can do the following:

  • Segment my network into multiple VLANs
  • Set up semi-managed switches
  • Set up access points
  • Explore the IDS/IPS features - will probably run CrowdSec
  • Support personal devices for a household of 2-4 people
  • Set up PoE security cameras on seperate VLAN
  • Establish homelab to mess about with things like HomeAssistant, etc.
  • Set up a VPN or similar means of accessing self-hosted services when away from home
  • Future proof my network, at least 2.5G capable

My maximum budget would be €800, though ideally I'd like to stay well under that if possible.

Ready and Purpose Built Options

As far as brand new devices, I have been looking at the following:

1. Protectli VP2430

Pros:

  • From my understanding, specs wise it should be able to handle everything I need.
  • I can also configure it to have more than 8GB of RAM or just get it with 8GB and update it myself down the road if I see the need.
  • Can be configured with Coreboot
  • Can be configured with a TPM
  • Has a standard 2-year warranty

Cons

  • American company (with EU offices) - would prefer to support an EU company and not have to worry about current/future international relations
  • Relatively pricey, considering similar devices are available from Ali Express and other similar marketplaces

Overkill alternative:

Protecli VP2440

Similar pros and cons, just not sure if getting 10GbE is worth it.

I am not really convinced of the various Chinese brands that do similar devices, primarily due to concerns regarding ongoing support and security updates, but if somebody has similar suggestions that address these concerns somewhat, I would be interested in finding out more.

2. DEC697

Pros:

  • From my understanding, specs wise it should also be able to handle everything I need.
  • Supports OPNSense development
  • European
  • Comes with 2 year warranty
  • Comes with 1 year OPNSense Business Edition

Cons

  • RAM not upgradable, may not be as future proof?
  • Also pretty pricey

Questions I have about this product:
- Since this is running an AMD chip, does the lack of Coreboot still present a loss in terms of privacy and security?
- How limiting will 8GB be going forward?

Overkill alternative:

DEC750

Again, mainly for 10G future proofing.

Mini PCs

I have also looked into repurposing a SSF/USFF device as a router, like for example a Lenovo ThinkCentre M720q. I also have access to a bunch of Optiplex 5070 Micros, but these don't have the advantage of the PCIe slot (when used with a riser) that the Lenovo has.

Pros

  • Much cheaper
  • Possibly slightly better specs
  • Can be configured with more RAM later
  • Relatively low power still

Cons

  • Sourcing a device that's in good condition, with original power brick may be difficult
  • Need to source reputable/genuine Intel NIC
  • Need to source riser for PCIe slot or alternative for the Optiplex option
  • Very DIY, would feel afraid of misconfiguring the device and exposing myself to security issues
  • No warranty or support
  • Not as quiet
  • Higher power consumption

I also have an old Intel i5-4960k and GTX 970 system lying about in a big case, which maybe I could look at converting into a small form factor build, similar concerns as above though (mainly around security). In general, I am comfortable enough with problem solving with servers and personal devices as a Linux user, but ideally my router would be fairly set and forget (and reliable!), which I'm not sure these options would provide.

Bonus questions:

  • Has anybody had luck putting a device with OPNSense on it downstream of a FritzBox (which doesn't seem to support bridge mode) without too many issues due to double NAT? I've heard mixed reports that you can put the OPNSense router in the DMZ and forward traffic there, in order to avoid some issues with double NAT.
  • Does anybody have any suggestions for PoE capable switches and access points that play nicely with OPNSense - I've been considering MicroTik but I'm not entirely sure what to look for.

Any advice very much appreciated. Happy to elaborate on anything if need be.


I would suggest some cheap N100 box with 2 network ports.

For switches, TP-Link or Mikrotik (but with swos).

Today at 12:30:47 PM #2 Last Edit: Today at 01:08:06 PM by Patrick M. Hausen
Mikrotik CSR326 is a heck of a capable switch for 200 €/$. I run it with Router OS. Good thing is you are free to choose. It does not support PoE, though.

Keep in mind that active PoE in a switch means

- way more expensive than without
- most units are deep 19" devices
- passive cooling is very rare

Depending on how "home" your home lab is going to be (do you have an extra room for a rack?) a switch like the mentioned CSR326, available in either rack or desktop format and passive cooling might be preferable to a loud rack mount only unit intended for data centres.

P.S. The CSR326 does not support 2.5 G Ethernet.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

I would not recommend N1x0 boxes with only two ports:

a. those often tend use Realtek chips, unlike their 4 or more port equivalents, which mostly use Intel I226V. Also, they often are actively cooled.
b. If you want to set up VLANs, you will want to have inter-VLAN traffic at full 2.5 Gbps speed, for which you need multiple physical 2.5 Gbps (V)LAN ports. Thus, two ports will not suffice.
Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, ZTE F6005

1100 down / 800 up, Bufferbloat A+