The Homelab Show Episode 41: Network Segmentation, VLAN, And Subnets

  Рет қаралды 57,760

Lawrence Systems

Lawrence Systems

Күн бұрын

thehomelab.show/
The sponsor for today's episode www.linode.com/homelabshow
lawrencesystems.com/
www.learnlinux.tv/

Пікірлер: 28
@mikelambert4490
@mikelambert4490 Жыл бұрын
Jay, thanks for sharing your early experience being confused by submitting, vlans, and segmentation. That was true to my experience, but nobody would guessed that you ever had trouble. I think it's important for folks new to it to know it isn't always easy to understand right out of the gate. We all have to start somewhere, so just keep poking at it.
@TanKianW79
@TanKianW79 2 жыл бұрын
Just managed to watch it now due to time zone difference. But will still listen through every morning.
@1over137
@1over137 10 ай бұрын
You answered my "stickler" question. If you subnet everything up, how do you stop forcing everything through the router. Answer: Put devices onto more than one vlan/subnet directly. Then they can access it layer 2 without routing.
@876kc
@876kc 2 жыл бұрын
Thank you for sharing the knowledge.
@popquizzz
@popquizzz Жыл бұрын
Wow Jay, when it come to subnet addressing and the schema of network devices we must have been cut from much of the same cloth.
@kjakobsen
@kjakobsen Жыл бұрын
Speaking of "Not segmentet by default", its important to remember the difference between a router and a firewall. A router is not suppose to segment by default, thats the firewall behavior. On a router we primarily divide networks, to limit the size of our broadcast domains.
@ClearlyCero
@ClearlyCero 2 жыл бұрын
Exceptional helpful!
@johnf2918
@johnf2918 Жыл бұрын
Eventually I'll want to hire you guys, not a doubt in my mind.
@hiddeninthewires2308
@hiddeninthewires2308 2 жыл бұрын
while preventing broadcast storms is cool and all....there is certain traffic that needs broadcasts such as DHCP for discovery. when splitting the network you may need "ip helpers" to advise clients on the different segment the location of the DHCP service
@williamp6800
@williamp6800 5 ай бұрын
I don’t know how it’s done elsewhere, but in pfSense each VLAN or subnet gets its own DHCP server. So at least no broadcasts necessary for that.
@hiddeninthewires2308
@hiddeninthewires2308 5 ай бұрын
@@williamp6800 most networks dont want to deploy dhcp servers in each subnet. they use dhcp relay via ip helpers
@devinwilkes8274
@devinwilkes8274 2 жыл бұрын
Can you please do an in-depth video on UniFi remote adoption and port forwarding ports for cloud key with the fully qualified domain name override and how to preset up the units before deploying them so when they are installed at the customer site that they automatically reach out to the cloud key thanks again
@Visdomr33
@Visdomr33 2 жыл бұрын
“Like getting locked out” - Jay I feel attacked
@jb4608s
@jb4608s 2 жыл бұрын
I learned something, thanks!
@pkmplayer
@pkmplayer 2 жыл бұрын
Haven't checked your channel out yet, but I'm excited to see it! Does someone need to watch the past 40 episodes from the beginning or can we jump around? Thanks!
@willblanton3120
@willblanton3120 2 жыл бұрын
Just jump around. Occasionally they will reference another show and say to go watch that for more details on a particular subject
@michaelrousseau4373
@michaelrousseau4373 2 жыл бұрын
Very informative thank you …. I’ve been playing with my network trying to add a pfsense box to use with my UDM Pro has been a fun endeavor to say the least . I wish UniFi didn’t cripple a mostly great device lol ended up trying to make a vlan only network on the UDM and then tagging all the ports I want on all my switches to that vlan and then plug the pfsense box to one of them to use it’s DHCP server . And then double NAT the UDM Pro . Still testing it to see how it works and leaning in the process
@daleyounk8005
@daleyounk8005 Жыл бұрын
Lol, yup you called it on the 2x.
@pepeshopping
@pepeshopping 2 жыл бұрын
If you “need” to segment your network to control WAN congestion, you obviously lack QoS on the firewall. Even easier: Simply configure a limit, per port, on the Ethernet switch.
@teachit1568
@teachit1568 2 жыл бұрын
What's the name of the standard? RSV-19 or RSB-19? Where do I find more information on the standard itself?
@stevenmishos
@stevenmishos 2 жыл бұрын
RFC1918
@teqik
@teqik 2 жыл бұрын
Thinking of RFC1918? The private IP standard, concerning the 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 network prefixes? For some reason YT removed my answer with the URL to the the whitepaper, but if you google IETF or just look on the ietf dot org site for the RFC1918 page you'll find all the gloriously dry details.
@DanielleEmberley
@DanielleEmberley 2 жыл бұрын
I am hoping you can revisit SyncThing set up AND Unifi USG setup, with phone. If phone is on a separate network, relay enable has to be turned on in SyncThing. If relay enable is turned Unifi detects threats.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
I never use the USG routers but my guess would be you need to turn off threat detection
@DanielleEmberley
@DanielleEmberley 2 жыл бұрын
@@LAWRENCESYSTEMS Even though I get threat notifications indicating blocking, the phone documents will still sync (get copied to the PC). (With phone on separate LAN and relay enable set to on). For now I am switching network briefly just to sync. I debate if syncing with on the same network or syncing using SyncThing relay servers is least secure.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
@@DanielleEmberley The transport layer of Syncthing is secure
@m.m.m.c.a.k.e
@m.m.m.c.a.k.e Жыл бұрын
✨✨ THANK YOU!! Appreciate the content, Tom!! 00:01:25:00 into the video, BAM TWO NON SKIPPABLE advertisements. I sincerely pray 🤲 KZfaq fails for forcing obnoxious, unnecessary, hated, irrelevant ads - furthermore, G AdSense advertisement team all get lined up and golden showered. Hopefully they all step in dog shiat every single day for the rest of their lives.
Home Lab Network Security! - vlans, firewall, micro-segmentation
18:29
VirtualizationHowto
Рет қаралды 46 М.
Useful gadget for styling hair 🤩💖 #gadgets #hairstyle
00:20
FLIP FLOP Hacks
Рет қаралды 5 МЛН
One moment can change your life ✨🔄
00:32
A4
Рет қаралды 35 МЛН
Subnets vs VLANs
5:51
PowerCert Animated Videos
Рет қаралды 547 М.
How To Setup VLANs With pfsense & UniFi 2023
21:57
Lawrence Systems
Рет қаралды 190 М.
pfsense and Rules For IoT Devices with mDNS
17:08
Lawrence Systems
Рет қаралды 114 М.
The BEST Subnets to Use for a VLAN-based Network
9:48
Viatto
Рет қаралды 19 М.
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Dave's Garage
Рет қаралды 2 МЛН
Setting up VLANs in pfSense
13:32
Raid Owl
Рет қаралды 65 М.
And who would you choose?👇
0:20
Kitty Power
Рет қаралды 12 МЛН
Smart Sigma Kid #funny #sigma #comedy
0:26
CRAZY GREAPA
Рет қаралды 19 МЛН