Create a WireGuard plus Split DNS Lab for Secure Remote Access to Self-Hosted Services
Build a two-client WireGuard lab with split DNS, explicit routing, resolver selection, firewall/NAT boundaries, and deterministic failover/teardown tests.
Labs Pillar
Pi-hole, split DNS, DHCP, VLAN-aware services, network visibility, and practical edge services.
Build a two-client WireGuard lab with split DNS, explicit routing, resolver selection, firewall/NAT boundaries, and deterministic failover/teardown tests.
Build a small-office monitoring path that proves one SNMP device, one syslog event, and one routed alert end to end instead of installing three disconnected products.
Build a parameterized PowerShell health-check pack with testable AD, DNS, DHCP, and certificate functions, structured results, and controlled negative tests.
Build an ntopng visibility dashboard around one explicit traffic-observation topology, then prove traffic from the intended VLANs actually reaches the sensor and is attributed correctly.
Collect DHCP scopes/leases and DNS records read-only, then run explicit stale/conflict checks instead of changing execution policy or treating raw exports as an audit conclusion.
Build an independent secondary Pi-hole resolver, align the settings that should match the primary, and test both resolvers before advertising them together to clients.
Build a WireGuard transport to a hardened jump host, then enforce MFA at the administrative login boundary instead of implying that WireGuard itself provides MFA.