Hello community:
I'm newbie at this fantasic community and networking firmaware/world, I'm learning step by step reading the fantastic wiki that the community has written; first of all, I'm from Spain and because of that, english is not my native language, apologizes if you can't understand me well, hehehe.
Like the title says, if it's possible, can you take a look to my basic config (network, dhcp and firewall config files) to see if everything is ok or I've to make modifications?, because I've basic networking knowledgment and like I've said before, I'm learning and I'm not sure if everything is well configured.
####################################GENERAL INFO####################################
My router is a Linksys WRT 3200 ACM with stable OpenWRT 19.07.5 r11257-5090152ae3.
My home network has the next subnets (wan and local subnets), and their own devices:
####################################WAN Subnets####################################
WAN (ISP IPv4)
ONT (to be able to connect to the ONT directly from my desktop machine).
VPN WAN (right now is disable, but I've made its interface and firewall zone for a future use when I will need it, to work with a travel router like my old TP-link WDR4300 or a raspberry [but I don't have configured it yet]).
####################################LAN Subnets####################################
VoIP: Raspberry Pi 3B+ with Raspbx like telephony central + Grandstream-GXP1620 + 3 old Samsung Galaxy GT-S7580 (Trend Plus) like softphones at home (using the main 2.4 GHz AP).
Servidores [Servers]: Hyper-V Server + AD servers 1&2 + Multimedia server + IoT server + HP OfficeJet 6820 All-in-One printer.
Hosts: 4 Virtual machines at the Hyper-V server, 3 Raspberry Pi model 3B+/4 for remote desktop to the VMs with Remmina (it works very well), my PC Gamer and a Tablet PC (with ASIX USB 3.0 ethernet adapter).
Wireless: 5 GHz for our Wi-Fi devices (using the main 5GHz AP)
Wlessguests: Wi-Fi network for guests, both bands for compatibility (using the second AP).
VPN local (wireguard protocol): I named it local because it's for connect devices away from home, with 6 peers, 3 for the smartphones that we use and the other 3 for to be used with the raspberrys used for remote desktop with remmina, obviously, when we will be away from home (holidays...)
#################################SUBNETS AT LEVEL 2#################################
INFO: I've made a VLAN 802.1q for each subnet at my home network.
INFO2: Like you know, the Linksys WRT 3200 ACM has a double core CPU, and at the switch level, the WAN subnets are linked to the core1 and the LAN subnets are linked to the core0; the internal switch connections are:
Port0=LAN4 | Port1=LAN3 |Port2=LAN2 |Port3=LAN1 |Port4=WAN |Port 5=Core0 LAN| Port 6=Core 1WAN
INFO3: I want to make a link aggregation with the LAN ports 1&2 (Ports 2&3) with a Linksys-LGS308 that I will purchase when I have configured the network correctly.
##########################CONFIGURATION OF EACH SUBNET##########################
Ports 2&3 go to the room where the servers are (raspbx included).
Port 1 is the sitting room.
Port 0 is the living room.
1.20 = 4t 6t
1.21 = 4t 6
1.22 = 4t 6t (disabled right now)
0.25 = 1t 2t 3t 5t
0.30 = 2t 3t 5t
0.35 = 0 1t 2t 3t 5t
0.40 = 5t (bridge interface)
0.45 = 5t (bridge interface)
0.50 = 5t (I got doubts about this, because I don't know if I will have to link it to the wan or the lan core of both, but it's working very well right now).
#################################SUBNETS AT LEVEL 3#################################
INFO: I'm using VLSM for the local subnets, with CIDR /28, making a total of 16 subnets of 16 hosts each one, making possible to use 14 of them for both (networks and hosts).
INFO2: For DNS and DHCP I use "dnsmasq-full" package, with an only one DNS pool and multi DHCP pools for each subnet that I want to assign IP address with static leases (or diynamically for the wlessguests subnet), the only local subnet with static ip addresses is the "Servidores" subnet.
One exception is the VPN local that doesn't use the DHCP protocol / pools, the IP addresses are defined at the wireguard interface (peers section).
INFO3: I'm using DNSCrypt-ProxyV2 and the DNS pool has the use of the WAN peer DNS disabled, using the 127.0.0.53#53 server like the WIKI describe.
VoIP subnet (0.25) = 192.168.100.16/28
Servidores [Servers] (0.30) = 192.168.100.32/28
Hosts (0.35) = 192.168.100.48/28
Wireless (0.40) = 192.168.100.64/28
Wlessguests (0.45) = 192.168.100.80/28
VPN-Local (0.50) = 192.168.100.96/28
Finally, I'm so sorry for this bible, at the next post I will post the network, firewall and dhcp config files.
Kind regards.
P.S.: If you don't understand something about my intentions, configs or something, tell me and I will try to clarify you a.s.a.p.