The ZeroPoint Lab
A real lab, documented in full.
This is the working example behind the advice: every hop from the ISP to a VM, plus the hypervisors, services, and segmented networks actually running here. Updated by hand and deliberately public-safe.
Updated by hand · As of 2026-09-22
Full topology
The whole network, end to end.
Internet edge, gateway, wireless clients, VLANs, switches, hosts, and running workloads in one sanitized view.
Swipe to explore the full diagram
Centerpiece
Click any node for detail.
ISP
Internet
The WAN link everything else on both networks depends on.
Hypervisors
Proxmox nodes
Two nodes, clustered, running the virtual machines and containers below.
HP EliteDesk Mini
- Cores
- 6c
- Memory
- 3.4 / 7.5 GB
- Guests
- 1/2 running
HP EliteDesk Mini
- Cores
- 6c
- Memory
- 6.0 / 15.4 GB
- Guests
- 2/2 running
Workloads
Virtual machines & containers
Shown by role rather than hostname — enough to see what the lab does without handing out a map of it.
| Status | Service | Role | Node |
|---|---|---|---|
| Running | Internal Dashboard | Monitoring | pve01 |
| Running | Mesh VPN | Remote Access | pve02 |
| Running | Identity & SSO | Authentication | pve02 |
Two networks, on purpose
Home network & Cisco lab
The house runs on UniFi. The Cisco lab hangs off a dedicated link, but OPNsense gives it its own routing domain and firewall policy — used purely for learning, and never trusted by the home VLANs.
Home Network
ISP → UniFiHardware
UniFi Cloud Gateway Ultra
Routing, firewall, and the UniFi OS console
UniFi Flex Mini
Compact managed switch feeding the AP
UniFi U7 Lite
Broadcasts the Trusted, IoT & Guest SSIDs
Core devices — full access to internal services.
Smart-home devices, isolated from trusted traffic.
Internet-only, walled off from every other segment.