Skip to content
Oznog

Rung 5: the edge and the second site

Your network becomes yours. You decide which devices may talk to what, and guests and smart-home gadgets get wifi networks of their own, away from your own machines. A copy of the data that matters lives at a second place, such as a relative's house, so even losing the whole house does not lose it.

Status. The three wifi networks are built and tested on the bench (20260928); the rest of the rung is designed, not yet built.

What you get #

  • A router you control at the edge. The site controls DHCP, keeps reservations in the repository and writes leases into DNS. Its firewall rules can be read, backed up and monitored. With no double NAT (two routers in a row, each translating addresses), remote access connects directly and IPv6 works.
  • Three wifi networks: main, guest and IoT, each kept apart by the router. Built and tested on the bench; see below.
  • A full authoritative DNS server, one that holds your zone itself, in place of the simple resolver.
  • A second site that receives an hourly, one-way, encrypted replica of the datasets that matter.

Buy. A router you control, such as the OpenWrt One the bench has used since rung 0 ($145.99 on 20260928), promoted to the site’s edge. If you already run one, this rung buys no router. Add an access point if the consumer router cannot be demoted, and for the second site a rescued box with its own drives ($300) or a second infra box ($2,540).

A blue metal router with three black antennas, between a mini PC and a laptop
The bench's router, an OpenWrt One: the household router from rung 0, and the site's edge at rung 5. Photographed 20260928.

What still fails. The switch and the UPS are still single, and every application still runs on the one infra box. The second site holds a copy of the data, not a running copy of the services.

What comes next. Rung 6 puts a dedicated firewall at the edge, for a site that wants the network itself to be as trustworthy as the boxes on it, and this router becomes its wifi access point.

This rung is a branch. A site can take it before rung 4 , or take the second site before the edge.

Decisions and options #

Three wifi networks: main, guest and IoT. Built on the bench’s router on 20260928, tested, then switched off with the configuration kept (as built ).

networkwho joins itmay reachmay not reach
main (trusted)your own laptops and phoneseverything a wired box on the LAN may, including the site’s services by namenothing extra
guestvisitorsthe internetyour LAN, the router’s own services, IoT, other guests, the tailnet (your remote-access network)
IoTsmart-home devices: cameras, plugs, speakers, televisionsthe internetthe same as guest; your own devices on main may open connections into IoT to control them, and IoT may open none back

Why: visitors’ devices and smart-home gadgets are the least trusted things in a house. You do not control their software, and many gadgets never get a security update. On networks of their own, a compromised camera or a visitor’s infected laptop cannot reach your servers, your files or each other.

How it is built, without VLANs (tagged network segments; see below):

  • Guest and IoT are each a routed segment of their own, with its own address range and a bridge that holds only its wifi interface, so nothing on a wire changes.
  • The router’s firewall lets each segment reach only the internet, plus DHCP and DNS at the router’s own address on that segment. It also rejects every private address and the tailnet beyond the internet side, so a guest gets a fast “refused”.
  • Devices on guest and IoT cannot see each other: the access point isolates its clients.
  • Guest and IoT get a second DNS server on the router that forwards only to the internet and knows none of the site’s names, so they cannot learn them or use DNS as a way in.
  • WPA2 and WPA3 mixed, so older phones and IoT devices still join; WPA3 devices use WPA3.

Would change it: many IoT devices speak only 2.4 GHz. The bench put all three networks on 5 GHz; add the IoT network on the 2.4 GHz radio when you have such a device. Devices that must talk to each other locally (casting, hubs) need client isolation off on IoT. And when a real controller exists, narrow “main may reach all of IoT” to named hosts and ports.

Proof: 93 checks, none failed, on 20260928, from a mini PC joining each network in turn over wifi. Main reached the LAN and the site’s names; guest and IoT reached the internet and were refused everything else, including the site’s names. Isolation between two guests was checked on the access point’s side only; a two-client test with a phone is still to do.

This needs only a router you control, so it can be done at any rung. It is listed here because rung 5 is where the router becomes the site’s edge.

VLANs are not part of this rung by default. A three-box site has one credible reason to segment: devices it does not trust on the same wire as the boxes. Take it only when that is true.

DNS moves to a full authoritative server when the router starts handing out leases. Do the migration as a copy, a verification from a third machine, and only then a cut-over.

The second site holds a replica, close at hand. The cloud bucket from rung 0 already survives a house fire, but restoring a whole site from it is slow. The hourly replica keeps a recent copy of the datasets that matter within reach.

Costs and measurements #

Estimated from the Seed’s design prices (US, checked 20260920; costs ): $550 lean and $2,840 full, for the router (an OpenWrt One, $145.99 on 20260928), an access point and the replica box; the VLAN step ($250 to $400) is not included. Through rung 5: $4,440 lean and $11,620 full.

No measurements yet.

Runbooks #

Not yet written; they come when the rung is built.

Configuration #

Not yet written; it comes when the rung is built.

Before it: Rung 4b: many kinds of models behind one gateway . After it: Rung 6: a dedicated firewall . The whole ladder: the Seed .

Source: node0-seed rungs/5-edge/README.md at 731a1af, generated by tools/seed-rungs.py; edit the README, not this page. Part of oznog.com/node0.