traceroute ~/lab

Architecture

The lab is segmented for defense-in-depth: a hardened perimeter, a dedicated detection and threat-intel tier, and isolated self-hosted services behind the load balancer.

Home lab network topology diagram

Edge / Perimeter

pfSense firewall · Suricata IDS/IPS · site-to-site VPN · Kemp load balancer (SSL offload)

Detection & Intel

Wazuh SIEM/EDR · MISP vulnerability feed · OpenCanary honeypots

Services

KASM isolated browser · SearXNG metasearch · Uptime Kuma monitoring