Hello Everyone, I hope you are having a Good whatevertimeoftheday !
I went through a few of the other topics before signing up and asking questions and the quality of questions and responses were fantastic !
With such an opening, I hope that my absolutely basic and somewhat long question would generate some responses and nudge me to make better decisions.
The fact is, I want to upgrade my home networking system and I have done my research, but what I lack is feedback on what I want to do.
My question therefore is to please review the plan and recommend if anything better can be done.
Existing setup -
ISP’s line goes to WAN of TPLink Archer A9 ac1900 which gives wireless access to all devices (personal and office laptops, Desktop, wireless cameras, smartwatch, smartphones, printer, FireTV, Echo and a raspberry-pi based home NAS ). There is a TPlink AC1200 that sometimes runs in bridge mode to extend same network to another floor.I also need to plan for scalability.
Terrible practice, I know !
Planned setup -
I intend to use one of the mini-router PCs with multiple NICs (example from Aliexpress) and install IPFire. I should even be able to re-use the old ac1900 as a wireless access point. That AC1200 can be used to expand same or another network wirelessly if needed. I also understand that I should also get a L3 switch for future expansion. Also, my ISP connection is 300 mbps.
Then with firewalls I would implement rulesets like -
- All Personal laptops and desktops get static IP from the Router (Mac-binding)
- All Work computers can only talk to internet, but not any other device (DMZ)
- All mobiles can talk to internet, but also to a select few IOT device (such as printer)
- [ and more ]
The Must Haves :
- logging
- DNS-over-TLS support (or local implementation of DNSMASQ)
- port-forwarding
- openvpn
- dDOS protection
- IPS
- Support CIFS (not a deal breaker)
I use openSUSE quite extensively, so documnetation hunting or CLI doesn’t scare me.
But keeping the internet off fore more than a day on a weekend, does.
Questions -
Do you have any feedback on the plan ?
Do you have any recommendation for a better piece of equipment than this router-pc?
Do you have any recommendation for a L3 switch thats suitable for home (something like 8-12 port) ?