Designed and implemented a segmented home network security lab behind an apartment-managed ISP environment using OPNsense, VLAN segmentation, Suricata IDS/IPS, Pi-hole DNS filtering, and WireGuard VPN access.
The project focused on zero-trust principles, internal traffic isolation, lateral movement prevention, and real-time network visibility.