← All guides

Home lab networking basics: VLANs and segmentation

Networking · 7 min read

Networking is the part of home labbing that intimidates beginners most — and it's also the part that teaches the most. This guide explains why you'd segment your lab network, what the core concepts mean in plain language, and a sensible starter layout you can grow into.

Why segment at all?

In most homes, everything sits on one flat network: laptops, phones, smart TVs, game consoles, and now your lab servers, all able to reach each other freely. That was fine when the network was just for browsing. It becomes a problem when your lab starts running experimental services, test firewalls, and virtual machines you intentionally leave vulnerable for practice.

Segmentation splits the network into separate zones with controlled paths between them. The practical benefits: an experiment gone wrong in the lab can't take down your family's internet; a compromised test VM can't easily reach your personal devices; and traffic stays organized, which makes troubleshooting far easier. It also happens to be exactly how corporate networks are designed, so every hour you spend on it is directly transferable job skill.

Subnets: separate neighborhoods

A subnet is a range of IP addresses treated as one neighborhood. Your home router probably hands out addresses in one range — something like 192.168.1.x — and everything in that range can talk to everything else directly. Creating a second subnet, say 192.168.20.x for the lab, means lab devices get their own address space. But addresses alone don't create real separation: without a router or firewall enforcing rules between the subnets, they're just different labels on one open network. The addressing plan is the foundation; the enforcement is what makes it segmentation.

VLANs: separate networks on the same wires

A VLAN (virtual LAN) is how you create multiple separate networks without running multiple sets of cables. A managed switch can tag each port with a VLAN number: ports in VLAN 10 behave as one network, ports in VLAN 20 as another, even though they share the same physical switch. Devices in different VLANs cannot see each other unless a router or firewall explicitly allows it.

The concept that confuses beginners is the trunk port: a switch port configured to carry multiple VLANs at once, with each frame tagged to say which VLAN it belongs to. You use trunk ports for the connections that need everything — the link to your firewall, and the link to your hypervisor host, which passes VLAN tags through to individual virtual machines. Every other port stays a simple access port in one VLAN.

A sensible starter layout

You don't need a dozen VLANs on day one. Three zones cover most beginner labs:

As you grow, common additions are an IoT zone for smart-home gadgets (which have a poor security reputation and shouldn't sit on your main network) and a guest zone. But start with three; complexity you don't need is just more surface for mistakes.

The minimum hardware

Real VLAN segmentation needs two things: a managed switch (one you can configure, as opposed to a basic unmanaged switch) and a router or firewall that understands VLANs to enforce the rules between them. Many beginners run an open-source firewall as a virtual machine with a couple of virtual network interfaces — it's free, extremely capable, and excellent practice. Your existing ISP router can usually stay as the internet gateway in front of it.

One caution: put the firewall that separates your zones somewhere reliable. If your firewall is a VM and the hypervisor host goes down for maintenance, every zone loses its path to the others. Plan maintenance windows, or keep the firewall on hardware that stays up.

Rules of thumb that prevent most mistakes

Default deny, then allow. Start with zones unable to reach each other, then add explicit rules for what you actually need. It's far easier to open a needed path than to discover an open path you didn't know about.

Document as you go. Write down which VLAN is which number, which subnet each uses, and what your firewall rules allow. Six months from now you will not remember, and "VLAN 30" will be a mystery. A simple table in a text file is enough.

Change one thing at a time. Networking changes can lock you out of your own equipment. Before a change, make sure you have a fallback path — a direct connection, a console cable, or physical access to the switch — so a bad rule is an annoyance, not a disaster.

The bottom line

Segmentation sounds advanced, but the idea is simple: lab experiments live in their own zone, family devices live in theirs, and a firewall decides what crosses between. Start with three zones, default-deny rules, and written documentation, and you'll have a network that's both safer and far more instructive than the flat network you started with.

Next: First 5 services to self-host →