“Networking is hard. Let’s go shopping.” — Barbie
Thanks @Belfry. I am surprised and feel guilty that this turned out to be such an easy thing.
Inspired by this and @Kangie’s suggestion that vLANS seem complicated but are easy once you get your head around it I have spent the last week playing with my network. After making multiple changes I am back to where I started.
In summary (read TL:DR), my conclusion from all this is that making network changes involving these technologies requires careful planning, the right equipment and a test suite to determine what you break with each change.
In detail, I think the Draytek is a very capable router and will stick with it. Having said that my N100 acting as a home for an OPNsense install is coming today or tomorrow. I will bring it to HLB on Thursday night.
I run various servers at home mainly in docker containers. The docker servers are vms on proxmox on the main backbone. I have an arrs suite which the TVs and laptops can access. It runs over the net via a dedicated VPN. I have various cameras around and in the house. They talk to a motioneye docker server. Some of these cameras are wired and some wireless.
I have two old EdgeRouters X that can do vLANS. I note that there is an update to the interface to make it more consistent with modern Unifi GUIs. That is cool but they are tiny routers and definitely fiddly to configure.
My access points are an Ubiquiti U6-mesh and a FlexHD. They both stopped working during the week after running an overnight upgrade. That was fun!
It turned out that my docker Unifi controller was end of life at the end of 2023 and admittedly I had not looked at it since then. The upgrade to the new version that cleaves the monogodb server into its own container was straight forward. Straight forward in the techie sense that after you tried a few things, read some documentation, tried a few more things and then did exactly what the documentation said, it worked.
The pi hole had had various lists added to it as we have previously organised. Turning on the Draytek redirection made my desktop connection essentially unusable. I reverted to no DNS redirection.
During the course of the week the arrs suite became flaky, the cameras could not be connected to the back end and the spouse became irritable with frequent reboots of the router.
My plan when my new requirement comes is to sit down with a big piece of paper and map out what needs to be done, work out how to test if a particular change breaks one of my “essential” services and try one thing at a time.
Wish me luck.

