Network Security
Firewalls, VPNs, hardening, monitoring, and secure design.
Private DNS for Homelabs Without Leaking Internal ServicesNew!!
A private DNS guide for homelabs: use home.arpa, split-horizon DNS, VPN DNS, and DNS-01 certificates without leaking internal service inventory.
It Is Always DNS: Pi-hole, AdGuard Home, Technitium, and the SPOF ProblemNew!!
A practical DNS design guide for Pi-hole, AdGuard Home, and Technitium that avoids the single-point-of-failure trap.
Nginx Proxy Manager vs Caddy vs Traefik: A Reverse Proxy Decision Tree
A reverse proxy decision tree for homelabs: when to pick Nginx Proxy Manager, Caddy, Traefik, or raw NGINX.
Tailscale vs WireGuard vs Cloudflare Tunnel vs Reverse Proxy
A practical remote access comparison: Tailscale, raw WireGuard, Cloudflare Tunnel, and reverse proxies solve different homelab problems.
The Cisco Catalyst Smart Switch Story: C9350, C9550, Silicon One, and the AI-Ready Campus
Cisco’s Smart Switch story is bigger than one SKU. It connects C9350 access, C9550 aggregation and core, Silicon One, IOS XE, telemetry, security, post-quantum readiness, and AI-era campus design.
Cisco Live 2026 Lab Build: A Small-Scale Reference Architecture
A small-scale lab architecture for testing Cisco Live 2026 ideas: segmentation, SD-WAN concepts, Secure Access patterns, telemetry, AgenticOps workflows, and change validation.
Branch Network Design for the AI Era
AI-era branch design needs SD-WAN, SSE, secure access, local resilience, application steering, Wi-Fi capacity, segmentation, and experience telemetry.
A Practical Post-Quantum Readiness Checklist for Network Teams
A practical checklist for network teams preparing for post-quantum cryptography: inventory, risk ranking, platform support, certificates, VPNs, secure boot, and refresh planning.
Resilience Planning for Cisco Networks: Patch, Shield, Replace, or Segment
A practical resilience model for Cisco networks should classify each exposure into patch, shield, replace, or segment, with owners, deadlines, and evidence.
Remote Access Without Opening Router Ports: Safer Homelab Access With Tailscale and Cloudflare Tunnel
Reach homelab services remotely with tailnets, tunnels, access policies, DNS, MFA, and clear rules for what should stay private.
