

1·
14 days agoThank you for all the questions to help me clarify my use case 🙂
At the very basic, I’d like to:
- achieve better security through segmentation by isolating cloud-connected devices, guest devices from trusted devices.
- Being able to “pin” a Mac address to an IP, and being able to use internal network name resolution to reach those devices.
- a blocklist for known ad-domains / malicious domains.
Once the basics are in place, I’d like to elevate my netsec game and implement:
- a high level monitoring capability to seen what devices are communicating with what domains / IPs
- An IDS capability of some sort to be able to detect anomalies in my LAN.
The NAS part is just for convince, it would be nice to have a samba / NFS with my files available when I need them.
I wanted to use this on my RPI2 buy I think the CPU is too old 🙃 I to however have a openWRT router and I suppose I can achieve similar functionality with a bit of hacking on the OS.