← PROJECT INDEX

ENGINEERING PROJECT / Foundation Design

Enterprise Home Lab

A phased enterprise reference environment for infrastructure, identity, network security, observability, and recovery engineering.

Status
active
Role
Infrastructure and Security Engineer
Duration
Ongoing
Updated
2026-07-23
OverviewArchitectureTimelineChallengesEvidenceRoadmap

01 / Context

Project Overview

IN PROGRESS — A consulting-style reference design for a segmented enterprise laboratory. The documentation baseline and project platform are implemented; infrastructure deployment, validation evidence, and operational metrics remain explicitly tracked as in progress or planned.

EXECUTIVE SUMMARY — Project RedForge is developing an enterprise home lab as a controlled environment for infrastructure administration, security engineering, monitoring, and incident-analysis practice. The current deliverable is the approved logical design and documentation system. It is not a representation of a completed production environment.

BUSINESS GOALS — The lab is intended to provide repeatable engineering scenarios, reduce risk through isolated testing, demonstrate traceable technical decision-making, and create a durable platform for future Active Directory, Splunk, vulnerability-management, automation, and threat-hunting projects.

ENVIRONMENT OVERVIEW — The target state uses a virtualized compute layer behind a policy-enforcing firewall. Dedicated VLANs separate management, servers, clients, security testing, and DMZ workloads. Identity, DNS, DHCP, certificate services, monitoring, and backup are introduced through phased change records.

OPERATING MODEL — Every capability moves through Planned, In Progress, Implemented, and Validated states. Implementation claims require configuration records and sanitized evidence; performance or reliability claims require recorded measurements. No such metrics are asserted in this report.

INFRASTRUCTURE COMPONENTS — PLANNED. A dedicated firewall, a Proxmox virtualization host, Windows Server and Linux guests, Windows 11 and Kali Linux endpoints, and a Splunk-based monitoring tier form the documented target platform. Hardware models and capacity values remain intentionally unspecified until procurement and validation are complete.

SERVER INVENTORY — PLANNED. DC01 is reserved for Active Directory Domain Services and DNS, MGMT01 for DHCP and administration, SIEM01 for Splunk, LNX01 for Linux services, and PKI01 for future certificate services. These names are design identifiers only and are not evidence of deployed systems.

SERVICES INVENTORY — PLANNED. Active Directory Domain Services, DNS, DHCP, centralized logging, SIEM analysis, backup, and administrative access are planned. Certificate services and hybrid-cloud connectivity remain future capabilities.

SECURITY STACK — IN PROGRESS. The design combines firewall policy enforcement, VLAN isolation, least-privilege administration, centralized identity, endpoint logging, Splunk analysis, backup controls, and documented trust boundaries. Product configuration and control validation remain pending.

MONITORING STACK — PLANNED. Windows Event Logs, Sysmon telemetry, Linux system logs, and firewall events will feed a centralized Splunk pipeline. No ingestion rate, retention, detection, or coverage metrics are asserted.

IDENTITY SERVICES — PLANNED. A single-forest Active Directory design will provide centralized authentication and policy management. Administrative tiers, service accounts, Group Policy, and recovery procedures require implementation and testing.

DNS — PLANNED. Active Directory-integrated DNS is the target for internal name resolution. Forwarding, scavenging, logging, and recovery settings remain to be validated.

DHCP — PLANNED. Centralized DHCP scopes will align with approved VLANs and reserve infrastructure addresses. Scope options, exclusions, failover, and lease policy remain undecided.

CERTIFICATE SERVICES — FUTURE. An offline-root and issuing-CA pattern is under consideration. No certificate authority or enterprise PKI is represented as deployed.

LOGGING PIPELINE — PLANNED. Endpoint and infrastructure telemetry will traverse controlled network paths to SIEM01, where parsing, retention, alerting, and access controls will be tested before operational use.

BACKUP AND DISASTER RECOVERY — PLANNED. The target strategy includes versioned configuration exports, scheduled virtual-machine backups, protected copies outside the primary datastore, documented recovery dependencies, and periodic restoration exercises. Recovery time and recovery point objectives remain undefined until workload criticality and measured restore performance are available.

REFERENCES — VERIFIED SOURCES. The report links to Microsoft, Netgate, Proxmox, and Splunk documentation used to frame the design. References inform the architecture; they do not constitute implementation evidence.

02 / Requirements

Engineering Objectives

  1. 01IMPLEMENTED — Establish a version-controlled engineering report, architecture baseline, and evidence standards.
  2. 02IN PROGRESS — Define segmented management, server, client, lab, and DMZ security zones with explicit trust boundaries.
  3. 03PLANNED — Deploy centralized identity, DNS, DHCP, certificate, logging, monitoring, backup, and recovery services.
  4. 04PLANNED — Validate firewall policy, authentication, name resolution, address allocation, telemetry delivery, backup restoration, and recovery procedures.

03 / System Design

Project Architecture

IN PROGRESS — The target logical design places an Internet edge and firewall before DMZ, management, server, client, and lab VLANs. Identity and infrastructure services remain in the server zone; monitoring receives controlled telemetry across trust boundaries.
Architecture topology Expand / collapse
network

Internet

EXTERNAL — Untrusted upstream network.

security

Firewall

PLANNED — Routing, segmentation, policy, DHCP, VPN, and network logging.

network

DMZ

PLANNED — Restricted zone for future published services.

network

Management Network

IN PROGRESS — Administrative interfaces and controlled operator access.

network

Server VLAN

IN PROGRESS — Identity, network, monitoring, and platform services.

network

Client VLAN

IN PROGRESS — Managed Windows 11 workstations.

network

Lab VLAN

IN PROGRESS — Isolated Kali Linux and authorized test systems.

server

Domain Controller

PLANNED — Windows Server providing AD DS and integrated DNS.

service

DHCP Service

PLANNED — Scoped address allocation and option management.

service

Certificate Authority

FUTURE — Internal certificate enrollment and trust services.

security

Splunk / SIEM

PLANNED — Centralized ingestion, search, dashboards, and detections.

server

Linux Server

PLANNED — Utility, automation, and telemetry workload.

client

Windows 11 Workstation

PLANNED — Managed domain endpoint.

client

Kali Linux

PLANNED — Isolated authorized assessment endpoint.

cloud

Future Cloud Connection

FUTURE — Controlled hybrid identity, logging, and network integration.

  • internet→ Untrusted edge →firewall
  • firewall→ Restricted inbound policy →dmz
  • firewall→ Administrative policy →management
  • firewall→ Service policy →server-vlan
  • firewall→ User egress and service access →client-vlan
  • firewall→ Isolated test policy →lab-vlan
  • server-vlan→ AD DS and DNS →domain-controller
  • server-vlan→ Address services →dhcp
  • server-vlan→ Future PKI →certificate-authority
  • client-vlan→ Authentication and policy →domain-controller
  • lab-vlan→ Authorized testing →kali
  • firewall→ Network telemetry →splunk
  • domain-controller→ Identity and DNS logs →splunk
  • server-vlan→ Future hybrid connection →cloud

04 / Stack

Technology Stack

platform

Documentation Baseline — Implemented

Typed project record, editable diagrams, status taxonomy, and evidence placeholders are version controlled.

platform

Proxmox VE — Planned

Target virtualization platform for Windows and Linux workloads; deployment evidence pending.

security

pfSense Firewall — Planned

Target routing, VLAN termination, policy enforcement, DHCP relay/service, VPN, and traffic logging role.

infrastructure

Management VLAN — In Progress

Designated administrative plane for hypervisor, firewall, and management interfaces.

infrastructure

Server VLAN — In Progress

Target zone for domain, certificate, logging, monitoring, and application services.

infrastructure

Client VLAN — In Progress

Target zone for managed Windows 11 workstations and user policy testing.

security

Lab VLAN — In Progress

Isolated target zone for Kali Linux, security tooling, and controlled testing.

security

DMZ — Planned

Restricted target zone for future externally exposed laboratory services.

infrastructure

Windows Server — Planned

Target platform for AD DS, DNS, DHCP, and AD CS roles.

infrastructure

Linux Server — Planned

Target platform for infrastructure utilities, automation, and selected monitoring services.

infrastructure

Windows 11 — Planned

Target managed endpoint for domain join, policy, certificate, logging, and security validation.

security

Kali Linux — Planned

Target isolated assessment workstation; use limited to authorized lab validation.

security

Active Directory Domain Services — Planned

Target identity authority for accounts, computers, groups, Kerberos, LDAP, and Group Policy.

infrastructure

DNS and DHCP — Planned

Target internal name resolution and controlled address allocation with documented dependencies.

security

Active Directory Certificate Services — Future

Future internal PKI for certificate enrollment, service identity, and trust testing.

observability

Splunk Enterprise — Planned

Target SIEM and logging platform for Windows, Linux, firewall, DNS, DHCP, and identity telemetry.

infrastructure

Backup Repository — Planned

Target protected backup location with retention and restoration procedures.

cloud

Hybrid Cloud Connection — Future

Future controlled extension for cloud identity, logging, and network-security scenarios.

05 / Delivery

Engineering Timeline

  1. Jul 2026

    Documentation and report platform

    IMPLEMENTED — Established the reusable project experience, typed content model, authoring standards, and editable SVG architecture package.

  2. Current

    Logical architecture and segmentation

    IN PROGRESS — Defining VLANs, trust boundaries, service dependencies, server inventory, and traffic-flow requirements.

  3. Next

    Firewall and virtualization foundation

    PLANNED — Install the hypervisor and firewall, create initial networks, record configurations, and validate administrative access.

  4. Planned

    Identity and core network services

    PLANNED — Deploy Windows Server, AD DS, DNS, DHCP, managed clients, and administrative policy.

  5. Planned

    Logging and security monitoring

    PLANNED — Deploy Splunk, define source onboarding, validate transport, and document retention decisions.

  6. Future

    PKI, resilience, and hybrid cloud

    FUTURE — Evaluate AD CS, backup restoration exercises, recovery runbooks, and a controlled cloud connection.

06 / Decisions

Engineering Challenges

Enterprise realism within finite resources

IN PROGRESS — The target design must represent enterprise boundaries without claiming production scale or resilience.

Resolution

Use phased capacity planning, explicit workload priorities, resource reservations where justified, and evidence-based scaling decisions.

Service dependency sequencing

IN PROGRESS — Identity, DNS, DHCP, PKI, logging, backup, and monitoring have ordering and recovery dependencies.

Resolution

Maintain a dependency map, deploy core network services before dependent workloads, and validate each phase before adding the next service.

Trust-boundary clarity

IN PROGRESS — Permissive laboratory rules would reduce the value of segmentation exercises.

Resolution

Adopt default-deny inter-zone policy, document required flows, and approve exceptions against named services and validation cases.

Evidence without sensitive disclosure

IMPLEMENTED — Engineering records must demonstrate work without exposing credentials, private addressing, secrets, or unsafe configurations.

Resolution

Use sanitized diagrams, redaction review, scoped screenshots, and placeholders until publishable evidence is available.

07 / Retrospective

Lessons Learned

Documentation is a control

IMPLEMENTED — Status-qualified records prevent planned capabilities from being represented as deployed or validated.

Boundaries precede workloads

IN PROGRESS — VLANs, administrative paths, and permitted flows should be defined before services are placed into zones.

Identity depends on foundational services

PLANNED VALIDATION — AD DS design must account for DNS, time synchronization, certificate, backup, and recovery dependencies.

Recovery claims require exercises

PLANNED VALIDATION — Backups alone do not demonstrate recoverability; restoration procedures and measured tests are required.

08 / Artifacts

Implementation Evidence

Screenshot Gallery

Planned Enterprise Home Lab network topology showing Internet, firewall, DMZ, management, server, client, and lab security zones
IN PROGRESS — Target network topology and VLAN separation. This is a design artifact, not implementation evidence.
Planned logical architecture showing identity, DNS, DHCP, certificate, logging, and monitoring services
IN PROGRESS — Logical service architecture with planned identity and observability dependencies.
Planned security zones and trust boundaries for the Enterprise Home Lab
IN PROGRESS — Security-zone classification and intended trust boundaries.
Planned traffic flows between client, identity, firewall, SIEM, and external services
PLANNED — Required traffic-flow categories; ports and rule identifiers await implementation.
Planned VLAN layout for management, server, client, lab, and DMZ networks
IN PROGRESS — VLAN purpose model. VLAN identifiers and subnets remain placeholders.
Planned trust boundaries separating external, administrative, enterprise, and security-testing systems
IN PROGRESS — Trust-boundary model used to guide default-deny policy.
Planned rack elevation showing firewall, virtualization host, switching, backup, and reserved capacity
PLANNED — Conceptual rack elevation; hardware units and placement are not implementation evidence.
Future hybrid cloud layout connecting the laboratory firewall and server network to a cloud environment
FUTURE — Conceptual cloud connection reserved for a later approved phase.
EVIDENCE 09
PLACEHOLDER — Real firewall configuration evidence will be added after implementation and redaction review.
EVIDENCE 10
PLACEHOLDER — Real virtualization and server inventory evidence has not been captured.
EVIDENCE 11
PLACEHOLDER — Logging pipeline and SIEM evidence will be added only after validated ingestion.

Video Documentation

VIDEO

Architecture review

PLANNED — A guided design review will be recorded after architecture approval.

Pending
VIDEO

Implementation walkthrough

PLACEHOLDER — No deployment walkthrough exists because the infrastructure milestone is not complete.

Pending

Code Examples

Planned validation manifest

DESIGN EXAMPLE — A proposed machine-readable inventory for future connectivity validation; not executed evidence.

yaml
environment: enterprise-home-lab
status: planned
zones:
  - management
  - server
  - client
  - lab
  - dmz
checks:
  - dns-resolution
  - dhcp-allocation
  - identity-authentication
  - telemetry-delivery
  - backup-restoration

Downloads and references

SVG

Network topology SVG

Editable RedForge target-state network topology.

Download
SVG

Logical architecture SVG

Editable identity, infrastructure, and monitoring service design.

Download
Reference

Microsoft AD DS overview

Official reference for Active Directory Domain Services concepts.

Open reference
Reference

Microsoft AD CS overview

Official reference for future certificate-services design.

Open reference
Reference

Netgate VLAN documentation

Official reference for planned pfSense VLAN configuration.

Open reference
Reference

Proxmox VE administration guide

Official platform administration reference.

Open reference
Reference

Splunk Enterprise documentation

Official reference for planned logging and SIEM services.

Open reference

09 / Next

Future Roadmap

  1. 01IN PROGRESS — Approve VLAN purposes, trust boundaries, dependency map, and traffic-flow matrix.
  2. 02PLANNED — Install and baseline the firewall and virtualization platform with sanitized configuration records.
  3. 03PLANNED — Deploy the domain controller, AD DS, integrated DNS, DHCP, and the first managed Windows 11 workstation.
  4. 04PLANNED — Deploy Linux services and Splunk, then validate the logging pipeline from firewall, Windows, DNS, and identity sources.
  5. 05PLANNED — Implement protected backups, document restoration order, and execute recovery exercises before stating recovery capability.
  6. 06FUTURE — Evaluate AD CS, DMZ workloads, additional domain-controller resilience, vulnerability management, and hybrid cloud connectivity.

CONTINUE EXPLORING

Related Projects

planned

Active Directory Lab

Identity, policy, authentication, and administrative controls.

planned

Splunk Detection Lab

Telemetry ingestion, investigation, dashboards, and detection workflows.

planned

Network Engineering

Routing, segmentation, services, and resilient network operations.

PROJECT REDFORGE / ENGINEERING RECORD

Return to project index →