This document defines the comprehensive network topology, software-defined virtual bridge interfaces, inter-firewall transit architecture, 802.1Q VLAN micro-segmentation, Zero-Trust access control rules, VPN overlays, and DNS resolution infrastructure governing the stefanutc1/infrastructure platform.
The network architecture is built on the principle of Default-DROP: no packet is routed between segments without an explicit, stateful firewall pass rule.
The primary hypervisor (Node 1) implements four software-defined virtual bridges managed by Proxmox VE and FreeBSD VirtIO drivers:
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ PROXMOX VE HYPERVISOR (NODE 1) │
│ │
│ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ │
│ │ vmbr0 │ │ vmbr1 │ │ vmbr2 │ │ vmbr3 │ │
│ │ WAN Edge │ │ LAN Trunk │ │ Transit Link │ │ Isolated DMZ │ │
│ │ 192.168.1.0 │ │ VLAN-Aware │ │ 10.10.20.0/30│ │ No Gateway │ │
│ └──────┬───────┘ └──────┬───────┘ └──────┬───────┘ └──────┬───────┘ │
└─────────┼────────────────────┼────────────────────┼────────────────────┼───────────────┘
│ │ │ │
▼ ▼ ▼ ▼
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ OPNSENSE CORE PERIMETER FIREWALL (VM 200) │
│ │
│ Interface vtnet0 Interface vtnet1 Interface vtnet2 Interface vtnet3 │
│ (WAN / Uplink) (VLAN Trunk Parent) (Transit Interconnect)(DMZ Honeypot Decoys) │
│ IP: 192.168.1.134 Sub-Interfaces 10-50 IP: 10.10.20.1/30 Isolated Bridge │
└────────────────────────────────────────────────────────────────────────────────────────┘
| VLAN ID | Subnet CIDR | Gateway IP | Segment Name | Traffic Classification & Workloads | Default Ingress Policy |
|---|---|---|---|---|---|
| VLAN 10 | 192.168.1.0/24 |
192.168.1.1 / 134 |
Management & Storage | Hypervisor consoles, IPMI, OPNsense WebGUI, NAS NFS/SMB storage, Wazuh SIEM. | DROP (mTLS & Sudoers Only) |
| VLAN 20 | 192.168.20.0/24 |
192.168.20.1 |
Core Production | Home Assistant, Nextcloud, Immich, Scrutiny, Ollama AI, Prometheus monitoring. | DROP (Explicit Whitelist Only) |
| VLAN 30 | 192.168.30.0/24 |
192.168.30.1 |
CyberLab & Sandboxes | Kali Linux pentest workstation, Metasploitable targets, Bachelor Thesis Core-Banking lab. | DROP (Strict Inter-VLAN Block) |
| VLAN 40 | 192.168.40.0/24 |
192.168.40.1 |
DMZ & Honeypots | T-Pot multi-honeypot decoy platform, public-facing reverse proxy honeypots. | DROP (Zero Lateral Movement) |
| VLAN 50 | 192.168.50.0/24 |
192.168.50.1 |
Isolated IoT Sensors | Bare-metal ESP32 microcontrollers (192.168.50.21 to .24), smart plugs, Zigbee bridges. |
DROP (No WAN Access, HA State Track Only) |
All traffic transiting between network segments is evaluated under the Default-DROP Posture.
┌────────────────────────────────────────────────────────┐
│ STATEFUL FIREWALL RULESET │
├────────────────────────────────────────────────────────┤
│ Source Target Protocol Action │
│ ────────────────────────────────────────────────────── │
│ Any WAN ICMP/DNS PASS (via DoT) │
│ VLAN 10 All VLANs Any PASS (Admin) │
│ VLAN 20 VLAN 10 (NAS) NFS/SMB PASS (Backups) │
│ VLAN 20 VLAN 10 (Prom) 9100/TCP PASS (Metrics) │
│ VLAN 30 VLAN 10 / 20 ANY DROP & LOG │
│ VLAN 40 Internal LAN ANY DROP & LOG │
│ VLAN 50 WAN (Internet) ANY DROP & LOG │
│ VLAN 20 (HA) VLAN 50 (IoT) TCP/UDP PASS (Stateful)│
│ Any Any ANY DEFAULT DROP │
└────────────────────────────────────────────────────────┘
- **Protocol**: WireGuard (ChaCha20-Poly1305, Curve25519). - **Listening Port**: `51820/UDP`. - **Tunnel Subnet**: `10.88.0.0/24` (Gateway: `10.88.0.1`). - **Cryptographic Key Rotation**: Automated via `scripts/wireguard_key_rotation.sh` every 90 days. - **Allowed IPs**: Restricted to authorized administrative bastion IPs and hybrid cloud VPC CIDRs (AWS/Azure/GCP). - **Role**: Secure, NAT-traversing administrative access for mobile devices and out-of-band diagnostics. - **Authentication**: Modern OIDC multi-factor authentication. - **Access Control (ACLs)**: Enforces least-privilege tags (`tag:admin` can reach Proxmox console; `tag:media` can only reach Jellyfin on port 8096).
- **Local Namespace**: Authoritative for `*.lan` and `*.stefanut.lan`. - **Upstream Forwarding**: Encrypted DNS-over-TLS (DoT) upstream to Quad9 (`9.9.9.9:853` and `149.112.112.112:853`) with TLS hostname verification (`dns.quad9.net`). - **DNSSEC Validation**: Enforced; unsigned or tampered DNS records are rejected. - Automated synchronization via `scripts/sync_opnsense_blocklist.py` and `scripts/sync_forbidden_domains.py`. - Ingests: 1. Romanian National Cyber Security Directorate (**DNSC**) fraud blocklist (`cyber/mediagalaxy-ecommerce-fraud-forensics/dnsc_blacklist.json`). 2. CERT-EU / URLhaus malicious domain feed. 3. Five Eyes CSIRT coalition indicators (ThreatFox). - Malicious domains are sinkholed to `0.0.0.0` (NXDOMAIN response).
Engineered with precision by Moană Ștefănuț-Cornel (@stefanutc1).
Universitatea din Craiova · Facultatea de Economie și Administrarea Afacerilor (FEAA) · Informatică Economică (2024–2027).