this post was submitted on 12 Jul 2026
8 points (100.0% liked)

homelab

10538 readers
3 users here now

founded 6 years ago
MODERATORS
 

Hey y'all, I have a small network with opnsense firewall, a unify ap, some client in different subnets, vpn, DNS and some servers.

As I am completely self thought, I got everything to run reading the docs and forums, but I have no idea how to test if what I build is safe and stable.

Are there good up to date tools, or checklists one could follow to audit the different parts of the network (most important the opnsense config)?

What do you check if looking for security issues?

The network mostly relies on client separation through different subnets on different vlans, but I fear I dont understand how for example the vpn and the nas work together in detail to be sure there is no security implication I oversee.

Also: how do you handle client authentication for devices on the same subnet? I know IP/mac-adress ARP entries are easily spoofed and therefore not secure, but I haven't seen how to do it correctly

you are viewing a single comment's thread
view the rest of the comments
[–] IsoKiero@sopuli.xyz 0 points 3 weeks ago (1 children)

Perhaps the easiest, and still at least decent, approach is to just run nmap (or any other port scanner) against your own subnets/IP addresses. That way you'll at least find out if the firewall allows something trough which it shouldn't, Also you can run tcpdump/wireshark on destination host to see if it receives packets it shouldn't.

For client authentication, if ARP filtering is not enough, you could set up 802.1x, but that's likely a massive overkill (and overhead) for home network. I personally don't authenticate clients separately. Just WPA2 on wifi and firewall rules to allow/deny traffic between subnets. Sure, it's pretty easy to bypass, but in practise you'd need to be inside the house to access some parts of the network. But my threat model is mostly about a handful of IOT things which I don't trust with full network access, not about someone unauthorized getting access to my home network.

[–] Jean_le_Flambeur@discuss.tchncs.de 2 points 2 weeks ago (1 children)

I tried that a little, but my problem was that there was to much stuff going on in the network for me to understand and review all. I am currently not reachable at all from the big internet, only local server access and I only get working connections if I rset an IP corresponding to the vlan I am in, but unify broadcasting, Nat, VPN, etc. Make a lot of connections and connection attempts internally I dont understand.

Problem with no client authentication is that the network is used by multiple separate households not necessary trusting each other, and some now want to host servers to the public, which would mean lots of untrusted traffic. I am concerned if they dont handle their security right and have access to for example our shared media server, they could scrape ip-mac address pairs to get deeper in the network. Any thoughts on benefits and lows of 802.1 vs. Radius?

[–] IsoKiero@sopuli.xyz 2 points 2 weeks ago

Radius is a part of 802.1x standard and for your threat model that does absolutely nothing. If a bad actor can access a device already in your network, then network level authentication doesn't do anything. For example it prevents from someone randomly plugging their device in your switch and getting access that way, or it only allows verified clients to your WLAN. But once the network connectivity is already established you need a totally different tools.

Mainly that means firewall on your network and/or servers. There's multiple ways to build that. You could get a separate firewall device to block access from the rest of the network to your devices or you can set up firewall for each of your things separately. All solutions have their own pros and cons and 'correct' solution depends on multiple variables.