Lab environment

Enterprise Home Lab

A phased enterprise reference environment for infrastructure, identity, network security, observability, and recovery engineering.

Target-state architecture
Network topologyEditable SVG
Target-state Enterprise Home Lab network topology

Design artifact — not implementation evidence. Addresses and infrastructure health are intentionally omitted.

Technology inventory

platformDocumentation Baseline — Implemented

Typed project record, editable diagrams, status taxonomy, and evidence placeholders are version controlled.

platformVMware Workstation Pro — Implemented

Current virtualization platform hosting the first Windows Server identity workload.

platformProxmox VE — Planned

Target virtualization platform for Windows and Linux workloads; deployment evidence pending.

securitypfSense Firewall — Planned

Target routing, VLAN termination, policy enforcement, DHCP relay/service, VPN, and traffic logging role.

infrastructureManagement VLAN — In Progress

Designated administrative plane for hypervisor, firewall, and management interfaces.

infrastructureServer VLAN — In Progress

Target zone for domain, certificate, logging, monitoring, and application services.

infrastructureClient VLAN — In Progress

Target zone for managed Windows 11 workstations and user policy testing.

securityLab VLAN — In Progress

Isolated target zone for Kali Linux, security tooling, and controlled testing.

securityDMZ — Planned

Restricted target zone for future externally exposed laboratory services.

infrastructureWindows Server 2025 — Implemented

RF-DC01 hosts the implemented Active Directory Domain Services and internal DNS roles.

infrastructureLinux Server — Planned

Target platform for infrastructure utilities, automation, and selected monitoring services.

infrastructureWindows 11 — Planned

Target managed endpoint for domain join, policy, certificate, logging, and security validation.

securityKali Linux — Planned

Target isolated assessment workstation; use limited to authorized lab validation.

securityActive Directory Domain Services — Implemented

First forest and domain controller implemented with initial organizational structure and role-based groups.

infrastructureDNS — Implemented

Internal DNS is operational on RF-DC01; resilience and recovery validation remain pending.

infrastructureDHCP — Planned

Controlled address allocation remains a planned core-network capability.

securityActive Directory Certificate Services — Future

Future internal PKI for certificate enrollment, service identity, and trust testing.

observabilitySplunk Enterprise — Planned

Target SIEM and logging platform for Windows, Linux, firewall, DNS, DHCP, and identity telemetry.

infrastructureBackup Repository — Planned

Target protected backup location with retention and restoration procedures.

cloudHybrid Cloud Connection — Future

Future controlled extension for cloud identity, logging, and network-security scenarios.