
Homelab Network Setup
- 1.4k installs
- 238k repo stars
- Updated August 5, 2026
- affaan-m/ecc
This is a copy of homelab-network-setup by affaan-m - installs and ranking accrue to the original listing.
homelab-network-setup is an agent skill that designs scalable home lab and small-office network architecture with gateway, switch, and access point roles for developers who need stable IP plans, DNS, and growth paths for
About
homelab-network-setup is a community ECC skill for developers planning or redesigning home and small-lab networks that must scale without tearing everything down later. It separates device roles—from modem through gateway, switch, and access points—and designs IP ranges, DHCP scopes, static reservations, and DNS with headroom for future VLANs, Pi-hole, NAS, lab servers, and VPN access. Use homelab-network-setup when escaping ISP-router-only setups, fixing double NAT, stabilizing Wi-Fi, or stopping servers from getting new addresses on every reboot. The skill produces a growth-ready foundation that pairs naturally with homelab-vlan-segmentation and homelab-pihole-dns follow-on work.
- Separates clear device roles from modem through gateway, managed switch, access points, servers, and clients
- Guides selection of gateway (ISP, UniFi, OPNsense/pfSense) based on actual operator needs rather than feature lists
- Designs IP ranges, DHCP scopes, static reservations, and DNS layout with growth in mind
- Prepares for future VLANs, Pi-hole, NAS, lab servers, and VPN access
- Helps diagnose and fix common issues such as double NAT, unstable Wi-Fi, and changing server addresses
Homelab Network Setup by the numbers
- 1,362 all-time installs (skills.sh)
- +84 installs in the week ending Aug 5, 2026 (Skillselion tracking)
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/affaan-m/ecc --skill homelab-network-setupAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 1.4k |
|---|---|
| repo stars | ★ 238k |
| Last updated | August 5, 2026 |
| Repository | affaan-m/ecc ↗ |
How do you design a scalable homelab network?
Generate a scalable, future-proof network architecture for a home lab or small office that supports servers, NAS, VPN, and VLANs.
Who is it for?
Developers building home labs or small offices who need a future-proof network foundation before adding VLANs, NAS, Pi-hole, or VPN services.
Skip if: Enterprise WAN architects designing multi-site MPLS backbones or teams with fully managed corporate networking teams handling all LAN design.
When should I use this skill?
A developer plans a new home network, redesigns an ISP-router setup, fixes double NAT or unstable Wi-Fi, or prepares IP/DNS for upcoming VLANs and lab servers.
What you get
Network topology diagram, IP and DHCP plan, static reservation table, DNS layout, and migration steps away from ISP-router-only setups.
- Network topology diagram
- IP and DHCP plan
- DNS and reservation table
Files
Homelab Network Setup
Use this skill to design a home or small-lab network that can grow without needing a full rebuild.
When to Use
- Planning a new home network or redesigning an ISP-router-only setup.
- Choosing gateway, switch, and access point roles.
- Designing IP ranges, DHCP scopes, static reservations, and DNS.
- Preparing for future VLANs, Pi-hole, NAS, lab servers, or VPN access.
- Troubleshooting a new network that has double NAT, unstable Wi-Fi, or changing
server addresses.
How It Works
Start by separating device roles:
Internet
|
Modem or ONT
|
Gateway or router NAT, firewall, DHCP, DNS, inter-VLAN routing
|
Managed switch wired clients, AP uplinks, optional VLAN trunks
|
Access points Wi-Fi only; ideally wired backhaul
Servers and NAS stable addresses, DNS names, monitoring
Clients and IoT DHCP pools, isolated later if VLANs are availablePick a gateway that matches the operator, not just the feature checklist:
| Option | Best fit | Notes |
|---|---|---|
| ISP router | Basic internet only | Limited control and often poor VLAN support |
| UniFi gateway | Managed home network | Good UI, ecosystem lock-in |
| OPNsense or pfSense | Flexible homelab | Strong VLAN, firewall, VPN, and DNS control |
| MikroTik | Advanced network users | Powerful, but easy to misconfigure |
| Linux router | Tinkerers | Document rollback before using as primary gateway |
IP Plan
Avoid the most common default, 192.168.1.0/24, when you expect to use VPNs. It often conflicts with hotels, offices, and ISP routers.
Example small homelab plan:
192.168.10.0/24 trusted clients
192.168.20.0/24 IoT and media devices
192.168.30.0/24 servers and NAS
192.168.40.0/24 guest Wi-Fi
192.168.99.0/24 network management
Gateway convention: .1
Infrastructure reservations: .2 through .49
Dynamic DHCP pool: .50 through .240
Spare room: .241 through .254Use home.arpa for local names. It is reserved for home networks and avoids the leakage/conflict problems of ad hoc names like home.lan.
nas.home.arpa
pihole.home.arpa
gateway.home.arpa
switch-01.home.arpaDHCP And DNS
- Use DHCP reservations for anything you SSH into, bookmark, monitor, or expose
as a service.
- Hand out the gateway as DNS until a local resolver is intentionally deployed.
- If using Pi-hole or another DNS filter, give it a reservation first, then point
DHCP DNS options at that address.
- Keep a small static/reserved range per subnet so replacements do not collide
with dynamic leases.
Cabling And Wi-Fi
- Prefer wired AP backhaul over mesh when you can run Ethernet.
- Use a PoE switch for APs and cameras if the budget allows it.
- Label both ends of each cable and keep a simple port map.
- Put the gateway, switch, DNS server, and NAS on UPS power if outages are common.
Examples
Beginner Upgrade
Goal: Keep the ISP router but stabilize a small lab.
1. Set DHCP reservations for NAS, Pi, and any SSH hosts. 2. Move local names to home.arpa. 3. Disable duplicate DHCP servers on secondary routers or APs. 4. Wire the main AP instead of relying on wireless backhaul.
VLAN-Ready Plan
Goal: Prepare for future segmentation without enabling it immediately.
1. Choose non-overlapping /24 ranges for trusted, IoT, servers, guest, and management. 2. Reserve .1 for the gateway and .2-.49 for infrastructure on every subnet. 3. Buy a gateway and switch that support VLANs and inter-VLAN firewall rules. 4. Document which SSIDs and switch ports will eventually map to each network.
Anti-Patterns
- Double NAT without a reason or documentation.
- Using
192.168.1.0/24when VPN access is planned. - Dynamic addresses for NAS, Pi-hole, Home Assistant, or other service hosts.
- Consumer routers repurposed as APs while their DHCP servers are still enabled.
- Flat networks with cameras, smart plugs, laptops, and servers all sharing the
same trust boundary.
See Also
- Skill:
network-interface-health - Skill:
network-config-validation
Related skills
FAQ
What does homelab-network-setup design first?
homelab-network-setup starts by separating modem, gateway, switch, and access point roles, then defines IP ranges, DHCP scopes, static reservations, and DNS so future VLANs, Pi-hole, NAS, lab servers, and VPN can be added without a full rebuild.
Can homelab-network-setup fix double NAT issues?
homelab-network-setup includes troubleshooting for new networks suffering double NAT, unstable Wi-Fi, or servers receiving changing addresses, guiding developers toward a single controlled gateway architecture.