Homelab VLAN Segmentation
Split a home network into isolated VLANs for trusted, IoT, guest, server, and management traffic, with trunk config and firewall rules for UniFi, pfSense/OPNsense, and MikroTik.
- What
- Split a home network into isolated VLANs for trusted, IoT, guest, server, and management traffic, with trunk config and firewall rules for UniFi, pfSense/OPNsense, and MikroTik.
- Cost
- Free
- Needs
- Use "Homelab VLAN Segmentation" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: the single most impactful home-network security upgrade, spelled out for Muse to execute with you. The design template splits a flat network into five VLANs: trusted for PCs and phones, IoT for smart devices, servers for NAS and self-hosted gear, guest for visitor Wi-Fi, and management for the network gear's own web UIs, each with its own subnet and gateway. The skill walks through switch trunk configuration, access ports, SSID-to-VLAN mapping on the access points, and the firewall rules that isolate segments without removing existing protections: IoT cannot reach trusted or servers, guests get internet only. Worked examples cover a typical UniFi Dream Machine setup and pfSense/OPNsense and MikroTik variants. Troubleshooting covers inter-VLAN routing failures and the classic lockout (apply during a maintenance window, verify connectivity between segments after each step). By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: misconfigured firewall rules can cut your own access, keep a console cable or direct path to the router; VLANs segment traffic, they do not patch vulnerable devices. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Homelab VLAN Segmentation" with your Muse. Prerequisites: none to install. Pure guidance; you need a managed switch and VLAN-capable router/AP (UniFi, pfSense/OPNsense, or MikroTik). 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/homelab-vlan-segmentation/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Plan VLAN segmentation for my network: [list your gear and devices]." 3. Work through the design template with Muse, then apply it in a maintenance window, verifying connectivity after each step. Tip: start with a written plan before touching any config; the skill's template is the checklist. Safety: a skill is plain-text instructions; it runs nothing by itself. Keep a direct path to your router before changing firewall rules.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.