Skip to content
Homelab
Esc
↑↓navigate↵open⌘Jpreview
On this page

Edge to core

From the fiber to the VLANs, and what each segment is allowed to see

Fiber reaches the building, and from the unit’s own entry panel a single run of Cat6A carries it to the one box that terminates the line and does everything else. Behind that box, three segments that see each other in one direction only.

The line has been 10G since the day it was installed. What was staged is the LAN, not the connection: the gateway and the access point arrived in steps, and the wired client side is still 2.5G, waiting on a reason rather than on a budget.

Choosing the line

In two steps, not one.

Half the candidates require their own combined ONU and router. That puts a box you do not control at the edge and everything else behind a second layer of NAT, so they were out regardless of price. Among what remained — same fiber, same freedom to bring your own gateway — the decision was monthly cost and contract length, nothing technical.

The one chosen also came out ¥783 a month below the 1G line it replaced, which made ten times the bandwidth the cheaper option and removed the usual reason to start small.

Three segments

One trusted, one for IoT, one for guests. The interesting part is not the split but its asymmetry.

Trusted to IoT is allowed. IoT to trusted is blocked, with replies still flowing because the rule is stateful, so nothing on the IoT side can open a conversation with the machines that matter. Guests reach the internet and nothing else, including each other.

That leaves the smart home controller needing to be reachable from both sides, so it holds an interface on each rather than routing across the boundary.

What a strict split breaks

Discovery. HomeKit, Matter and casting all find each other by multicast, and multicast does not cross a VLAN boundary. The exception is deliberately narrow: multicast DNS is bridged between trusted and IoT, and nowhere else.

Public IPv6 goes to the trusted segment only. Matter and Thread work over link-local and a locally advertised prefix, so the IoT side gives up nothing by having no global address — and an address that does not exist cannot be reached from outside by mistake.

What is reachable from outside

Nothing. No port forwarded, no tunnel published, no service exposed.

Remote access is a VPN and only a VPN, which means a device that is not enrolled has no way in regardless of what it knows. There is deliberately no fallback: a fallback is the thing that would undo the arrangement.

The internal names resolve only from inside the house. They used to resolve from the public zone to private addresses — convenient, and a standing invitation for a page loaded on any device here to aim requests at a named internal service.