# Network Physical and logical network topology for the homelab. ## Why The homelab runs on a dedicated internal subnet (`192.168.8.0/24`) isolated from the main household LAN (`192.168.178.0/24`). Isolation is enforced at Proxmox: LXC/VM traffic is bridged only on the internal `vmbr0` bridge; Proxmox routes packets out to Fritz!Box via `vmbr1`. The main LAN cannot reach homelab services directly without a Fritz!Box static route (which is configured to allow inbound). Fritz!OS 8.x does not support second IP networks on LAN ports, so Proxmox (`hubris`) acts as the subnet router rather than the Fritz!Box. ## Hardware | Device | Role | |---|---| | Fritz!Box 7590 | Main router / ISP gateway (`192.168.178.1`) | | SODOLA 5-Port 2.5Gbit Managed | Homelab switch — flat L2, all ports native | | hubris (Proxmox) | Subnet router — routes between `192.168.8.0/24` and `192.168.178.0/24` | ## Topology ``` ISP └── Fritz!Box 7590 (192.168.178.1) │ static route: 192.168.8.0/24 → 192.168.178.10 │ └── SODOLA 5-Port 2.5Gbit ├── Port 1 uplink → Fritz!Box LAN ├── Port 2 hubris eno1 → vmbr1 (192.168.178.10) ├── Port 3 [device] ├── Port 4 [device] └── Port 5 spare hubris internal bridges: vmbr1 192.168.178.10/24 eno1 (uplink, DHCP-reserved) gateway 192.168.178.1 vmbr0 192.168.8.77/24 no physical port (internal) 192.168.8.1/24 alias — LXC default gateway ├── all 16 LXCs └── HAOS VM ``` ## Subnets | Subnet | Gateway | Purpose | |---|---|---| | `192.168.178.0/24` | `192.168.178.1` | Household LAN — laptops, phones, Fritz!Box DHCP | | `192.168.8.0/24` | `192.168.8.1` (Proxmox `vmbr0` alias) | Homelab — all LXCs and VMs | ## DHCP - **Household (`192.168.178.x`)**: Fritz!Box built-in DHCP. Proxmox `vmbr1` has a reservation: MAC `84:47:09:6b:e7:58` → `192.168.178.10`. - **Homelab (`192.168.8.x`)**: Technitium on [CT 107](../containers/107-dns.md) at `192.168.8.2`. Range `192.168.8.100–192.168.8.240`, gateway `192.168.8.1`, DNS `192.168.8.2`. Most homelab LXCs use static IPs below `.100`. DHCP only covers new/transient containers. ## DNS Split-horizon DNS for `*.hubris.network` served by Technitium on [CT 107](../containers/107-dns.md) at `192.168.8.2:53`. See [dns.md](dns.md) for full detail. ## Routing Proxmox has `net.ipv4.ip_forward=1` (already enabled by PVE). Packets from LXCs on `vmbr0` destined for the internet exit via `vmbr1` → Fritz!Box. Fritz!Box masquerades all outbound WAN traffic. Fritz!Box has a static route (`192.168.8.0/24 → 192.168.178.10`) so return traffic reaches the LXCs. No NAT on Proxmox — traffic flows without double-NAT. ## Remote access - **NetBird mesh** — primary path for remote administration. Authenticated via [Authentik on the VPS](../vps/). - **Tailscale** — legacy, being phased out. See [mesh.md](mesh.md). ## Related - [DNS](dns.md) — split-horizon config and entry list - [Ingress](ingress.md) — public entry points via VPS traefik - [Mesh](mesh.md) — NetBird / Tailscale VPN overlay - [hosts/hubris.md](../hosts/hubris.md) — Proxmox host (vmbr0/vmbr1 config) - [CT 107 — dns](../containers/107-dns.md) — Technitium DNS + DHCP server ## Changelog ### 2026-06-02 — Executed migration; Proxmox as subnet router Fritz!OS 8.x does not support second IP networks on LAN ports, so the final design uses Proxmox as the router: `vmbr1` (eno1 → SODOLA → Fritz!Box) is the uplink at `192.168.178.10`; `vmbr0` is a portless internal bridge with `192.168.8.1` alias as the LXC gateway. Technitium DHCP enabled for `192.168.8.100–240`. Caddy service unit was missing and recreated. See [migration plan](../plans/2026-06-01-slate-ax-to-sodola-migration.md). ### 2026-06-01 — Initial network doc; Slate AX retired; SODOLA switch added Replaced the GL.iNet Slate AX sub-router with the SODOLA 5-Port 2.5Gbit managed switch. Eliminated double-NAT. See [migration plan](../plans/2026-06-01-slate-ax-to-sodola-migration.md).