How to Build A Powerful Networking Learning Lab

preview_player
Показать описание
Lawrence.Video/StorageDesign

Connect With Us
---------------------------------------------------

Lawrence Systems Shirts and Swag
---------------------------------------------------

AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store

UniFi Affiliate Link

All Of Our Affiliates help us out and can get you discounts!

Gear we use on Kit

Use OfferCode LTSERVICES to get 10% off your order at

Digital Ocean Offer Code

HostiFi UniFi Cloud Hosting Service

Protect your privacy with a VPN from Private Internet Access

Patreon

Chapters
00:00 Lab Setup
01:41 Lab VLAN Setup
07:30 Diagram of The Lab Setup
09:03 pfsense, UniFi, XCP-ng VLAN setup
10:17 Virtualized pfsense
12:10 Emulating Client Networks
14:36 Assigning Network Interfaces to Virtual Machines
16:32 Using pfsense to route public IP's
17:39 Using External Firewalls With the Lab
Рекомендации по теме
Комментарии
Автор

That is the best title, My eyes went wide. Finally the secrets will be unlocked!

Aick
Автор

Had to rewatch a few times but I get it now. Great video.

alexramossr
Автор

Thanks for this great video Tom. Will implement something similar when I upgrade my lab in the coming year.

project_mini_hero
Автор

In the case of learning, VLAN1 is fine. When your lab starts mimicking production, then it should match your production environment.

When you get to that point, this video is beyond that scope.

arandomthoughttoday
Автор

I think I'd enjoy working for you, Tom.

DarthKielbasa
Автор

This is a really great video and while watching I think I understood most of what was going on but feel like if I went to implement a similar setup I might get a bit lost on some of the smaller details. I would really like to see some reference doc or something similar linked to be able to refer back to with more details on the config and setup. If there is one and I missed where to find it my apologies in advance. I only recall mention of the diagrams on github. Keep up the great work as always! will continue to watch the channel love the videos.

ThePC_Geek
Автор

I'd advise home folks and particularly businesses never assign CGNAT addresses to anything... It's not extra private IP space for your private network to use. It's specifically made for carriers to utilize. (I suppose you might argue for it in lab settings like Tom is showing but it's not needed)

xephael
Автор

Since you say you should not route storage, how do you handle it when a VM needs access to e.g. an NFS share for docker? Do I also create that VLAN then on the virtualization host and give the VM an extra interface with a static IP just for accessing that share? Would be interesting to know since I plan on redoing my setup soon and the issue has come up

colinschaffer
Автор

Great stuff Tom! Love your work. Any chance of making a video of a sample customer setup using CGNAT? (If you haven't already) Thanks!!

theinfogrp
Автор

Hey Tom, great video! In this video is the head end pfsense connected to your home pfsense? I didn’t see any home type vlans. Thanks!

McBomber
Автор

Hey Tom, I have a question hopefully you still read old videos comments haha
So in my lab I have a pfsense and some vlans, I also have a unifi switch that connects to my servers but I saw that you only create two vlans in pfsense which is your gateway, In my environment all the rules are setup in my pfsense and I just pass down to my unifi switch with trunk, in your case you create the vlans on the unifi switch and make a trunk to your virtual pfsense and from there build the labs, do they get addresses from your pfsense gateway or from the virtual one? I couldnt quite understand that part.

gfmnetwork
Автор

Thanks! Another great video. Question: do you use VLANs at customer sites? I have walked into SMB customers that don't have any documentation on VLANs and I usually remove them. Thanks again

JohnHessGA
Автор

Good video, off topic question, are you going to review the new PFSENSE 24.11 update?

jerrystanwick
Автор

Hey Tom! Is that CGNAT vlan just a name indicating you are simulating a CGNAT/WAN for the virtual pfsense or is that an actual CGNAT network where your ISP is handing out the addresses for your virtual pfsense?

NIC_Pineiro
Автор

I guess we could do the same thing but with a virtualized unifi controller instead of pfsense. I was thinking about doing this for using terraform to provision my network.

dillanteagle
Автор

Kinda off topic but how do you manage user credentials for pc login and network shares? Is that case by case basis or do you always run AD?

RandomTechWZ
Автор

@Tom - Did you get permission from the Elders of The Internet to use a picture of The Internet in your diagram??? 😅

scorpjitsu
Автор

Bit of along shot here, but asking, can I use the unifi flex mini 2.5gb network switch, like a normal switch, or do I have to have other ubiquiti hardware for it to work ?
Been trying to find answers on tinternet without any luck
Cheers

sykotikangell
Автор

I wish I could wrap my head around why VLAN tags are needed on top of using different IP ranges/subnets for things. I know I'm missing something, I just can't figure out what. 😆

lifefromscratch
Автор

Which access points are you using in the lab

arturorubio-wm
visit shbcf.ru