Security & Best Practices

The Setup Checklist

Essential architectural rules, network hardening techniques, and pitfalls to avoid when engineering your homelab.

Recommended Dos

Hardening & Isolation Guidelines

Best Practice
  • Isolate IoT Devices on a Dedicated Network / VLAN

    Place smart home gear on an isolated Virtual LAN (VLAN) or dedicated IoT wireless segment.

    Why: If a budget camera or bulb is compromised, VLAN rules prevent attackers from pivoting to primary devices or server subnets.
  • Change Default Credentials Immediately

    Never leave default admin logins active. Assign high-entropy, unique credentials across web GUIs, IPMI, and management dashboards.

  • Enable Multi-Factor Authentication (MFA)

    Enforce TOTP/Hardware-key 2FA on every portal (e.g., Home Assistant, Proxmox VE, cloud dashboards, and domain registrars).

  • Restrict Outbound Internet Access & Disable UPnP

    Block unneeded WAN access for local-first smart gear. Disable UPnP on router firewalls to prevent automated inbound mapping.

  • Keep Firmware & Hypervisors Updated

    Establish regular schedule windows for updating container images, OPNsense packages, and microcode patches.

Critical Don'ts

Security Risks & Common Pitfalls

Avoid
  • Port Forward Internal Services Directly

    Do not open raw HTTP, RTSP, or SSH ports to the public internet using standard router port forwarding.

    Better Approach: Utilize modern mesh VPNs like Tailscale or encrypted Cloudflare Tunnels.
  • Overcrowd 2.4GHz Wi-Fi Frequencies

    Avoid flooding Wi-Fi channels with hundreds of budget Wi-Fi bulbs. Standardize on dedicated mesh protocols like Zigbee, Z-Wave, or Matter over Thread.

  • Over-Grant Companion App Permissions

    Restrict mobile app telemetry and permissions (location tracking, contacts, or microphone access) unless explicitly necessary for local automation.

  • Deploy Unbranded Hardware in Sensitive Areas

    Avoid closed-source, unbranded IP cameras or locks lacking verified security patch histories or local API access support.