UniFi & VLANs
Splitting IoT, guest and trusted devices, firewall rules that actually hold, and the gotchas nobody mentions.
Notes from a real home setup
I'm John. I run a segmented UniFi network, network-wide DNS filtering, Home Assistant and a handful of self-hosted services. This is where I write down how I built it, what went wrong, and what I'd do differently.
Read the write-ups About this site# ~/home-lab/stack.txt network UniFi, segmented VLANs dns Pi-hole ← every VLAN automate Home Assistant services self-hosted, local-first desktop Fedora Linux # status: works (mostly)
Four areas, all running in my own house. No sponsored kit, no theory I haven't tried myself.
Splitting IoT, guest and trusted devices, firewall rules that actually hold, and the gotchas nobody mentions.
Pointing every VLAN at one resolver, blocklists that don't break things, and keeping DNS up when a box goes down.
Automations the household actually tolerates, device choices, and keeping it all working without the cloud.
What I run at home, how it's reached safely, and how I back it up so a dead disk isn't a disaster.
The first articles are being written now.
The layout I landed on, the firewall rules between segments, and the mistakes I made first time round.
Handing out Pi-hole via DHCP on each network, stopping devices that ignore it, and what to do about hard-coded DNS.
Letting Home Assistant reach IoT devices without letting IoT devices reach everything else.
I'm John Allan. I'm not a network engineer by trade — I just wanted a home setup that was private, reliable and under my control, and I learned the hard way how to get there.
This site is the notebook I wish I'd had when I started.