tail -f felipe-ra.com

Blog / Architecture

Architecture · Networks

Cornerstone of my homelab

How starting to study cybersecurity made me notice the possible entry points into my home network, which led me to build a complete closed LAN with an old router and to understand enterprise infrastructure through my own network.

01Me, my first victim

When you take up a sport or a new discipline, the first thing you do is train, try out new ideas, new concepts, new techniques. You will never go to the Olympics right after learning how to swim or how to do a flip, not without hurting yourself or hurting others in the process.

In cybersecurity it works out much the same way. The first thing you try to do is break your own wifi, your own devices, look into your digital footprint, change your passwords, find vulnerabilities in yourself, etc. That is why the first thing I did was to check exactly what I had closest at hand. My own network.

This led me to study not only how they work, but also to look for vulnerabilities in my day to day, in my devices and my accounts.

That exercise made me realize something.

02Why I decided to do it

A very common gap in home networks are the technologies that are there to make our lives easier, but that we don't notice. The ones we connect to the network once and that do only one thing (or so we think as customers), known as IoT (Internet of Things) technologies, which are things as simple and everyday as smart lights, ip cameras you can watch from your phone, smart switches and even assistants like alexa.

These are the back doors that are often left with the keys in them, through bad configurations, for attackers who manage to compromise them over the internet, and the access those devices have to your entire home network compromises not only the devices themselves, but also your computers, phones, televisions, cameras and even alarms that may be using the network so you can control them from your phone without having to be in the room.

03The idea

Since those IoT devices already exist in my house and I had no intention of throwing them in the trash and losing the money I had spent, I had to start looking for solutions. All with the idea of going on using them, but with the peace of mind that not just anyone could talk to them.

That is why I started studying how companies or businesses do it when they need this kind of security for employee access cards, closed circuit surveillance cameras and alarms.

That led me to an answer, a LAN (Local Area Network), which are commonly used for these purposes, but I also didn't want to have to implement an expensive and complex network connecting all my devices (considering several of them only communicate over wifi). That is why I had to look for another solution. Simpler, cheaper and suited to the scale I was working at.

04Old hardware, new purpose

Just like I did in an earlier project with NABU, which is the name of my private server built from an old second hand notebook, and which is named after the Mesopotamian god of writing (the name sounded fitting to me for a server that spends its time writing information constantly) and at the same time after the planet from the Star Wars series (Naboo, which sounds the same as nabu), I had to look for low cost solutions to pull this off.

That is why I thought, why not simply create a new network with an old router? Well, in simple terms (although it was more work than I expected) that is what I did. I took an old router, more than 3 or 4 years old if my memory serves me right, that some ISP never came to collect when we cancelled the service. And taking advantage of the fact that it had newer technologies such as WPA2, a fiber optic input and dual band 2.4 and 5 GHz, I managed to implement a completely closed network with no internet access, since I didn't need it, I only needed to trick my devices into connecting to a wifi that would let me configure them from another machine inside the same network.

The real problem is, how do I reach those devices when I'm away? How do I keep whoever gets into the network from seeing the whole map?

05I had to learn and apply

This is where the project took a pretty steep learning curve, since I had never worked with networks at the level of infrastructure implementation. So I had to learn about UFW (Uncomplicated Firewall) rules that would let me control access and traffic for every device inside the network.

On top of that, if I wanted to keep scaling this project, to control it from outside and to have something genuinely functional that worked without me being there connected to the network, I needed an intermediary. The answer was simple, Nabu, which already acted as an entry point into my house through a tailscale network that lets me connect from my devices to NABU wherever it is, would act as the central node for access and traffic control inside my LAN.

How did I do it? By giving Nabu a usb network adapter so it would have 2 interfaces. One connected to my main ISP network (the usb adapter) that I could use to connect from outside over tailscale from my phone, and one interface connected to my LAN straight by cable to the router (the notebook's own network card).

What did I get out of this? A completely closed network, only reachable if you are physically within range of the router and get past the router's access password, or get past NABU's firewall and the tailscale network, and only then see my IoT devices.

06What it does today

The question that comes up most naturally is, is all this worth it just to turn on the lights in my house from a distance? The short answer is yes, but not for the obvious reasons.

These days my LAN isn't only there to host my IoT devices. As is normal in cybersecurity, you constantly need to be breaking systems to practice or to get to know new concepts and topics. Which are even more educational if you can set them up yourself and not depend on platforms like hackthebox or tryhackme that, even though they are excellent schools and I use them alongside this to sharpen up, don't let you understand how they are built. That is why inside the network I can constantly play with different devices, raspberry pi, old notebooks, esp32 and anything else I might want, without having to. First, connect to the internet. And second, affect any third party, which besides being completely illegal, my own moral compass won't let me do.

Today this has turned into my playground, my security system and my way of understanding how networks work at a large enterprise scale but in "pocket" size, by having it in my own house.

This architecture has let me be more proactive with my studying, because if I come across new concepts, new ways of organizing and running my network, new technologies or even new fields to study like forensics (which has me quite intrigued to explore these days), I can do it without being afraid to try, break, rebuild, and edit those concepts until I understand them completely.

07It isn't perfect

Like any system, this one has flaws that are plain to see, which is why I took some initial preventive measures. The most obvious one is proximity access: someone within range of the router can try to get straight into the LAN, without going through any of the controls and rules I set up in Nabu. I mitigated this by hiding the network name so it doesn't show up in the list on a phone or a notebook. But let's be honest, I don't consider that security, just basic concealment so the curious neighbor who can see my network at a glance, and it does absolutely nothing against someone with tools, because a network scan with nmap or a bit of wardriving makes the network show up all the same. What does work is in the router's configuration: I disabled WPS, which is what allows attacks like Pixie Dust, and I ruled out WEP, where capturing IVs packets is a direct way into the LAN. That is where the defense is real. And there are still things on the list. Today the IoT devices are isolated from the rest of my house, but they can still see each other. If one falls, the next one is right there. I also don't log what happens inside the segment, so if something odd were to happen, I would find out late or not at all.

Lastly, migrating to WPA3 is on my agenda, but honestly, none of this keeps me up at night for now. That is exactly the point. I started down this road by becoming my own first victim, testing against the only thing I could break without asking anyone for permission. Today I'm still my first victim, but in a place built on purpose for that, where making mistakes costs no one anything. That difference is the whole project in a nutshell. The details of the rules, the zone diagram and how traffic ended up flowing between them I'm going to tell in another post, because it's worth a full one. In the meantime, if you see something you would do differently, or a flaw I'm missing, write to me at blog@felipe-ra.com. Corrections and suggestions are appreciated.