Internet
EXTERNAL — Untrusted upstream network.
ENGINEERING PROJECT / Foundation Design
A phased enterprise reference environment for infrastructure, identity, network security, observability, and recovery engineering.
01 / Context
EXECUTIVE SUMMARY — Project RedForge is developing an enterprise home lab as a controlled environment for infrastructure administration, security engineering, monitoring, and incident-analysis practice. The current deliverable is the approved logical design and documentation system. It is not a representation of a completed production environment.
BUSINESS GOALS — The lab is intended to provide repeatable engineering scenarios, reduce risk through isolated testing, demonstrate traceable technical decision-making, and create a durable platform for future Active Directory, Splunk, vulnerability-management, automation, and threat-hunting projects.
ENVIRONMENT OVERVIEW — The target state uses a virtualized compute layer behind a policy-enforcing firewall. Dedicated VLANs separate management, servers, clients, security testing, and DMZ workloads. Identity, DNS, DHCP, certificate services, monitoring, and backup are introduced through phased change records.
OPERATING MODEL — Every capability moves through Planned, In Progress, Implemented, and Validated states. Implementation claims require configuration records and sanitized evidence; performance or reliability claims require recorded measurements. No such metrics are asserted in this report.
INFRASTRUCTURE COMPONENTS — PLANNED. A dedicated firewall, a Proxmox virtualization host, Windows Server and Linux guests, Windows 11 and Kali Linux endpoints, and a Splunk-based monitoring tier form the documented target platform. Hardware models and capacity values remain intentionally unspecified until procurement and validation are complete.
SERVER INVENTORY — PLANNED. DC01 is reserved for Active Directory Domain Services and DNS, MGMT01 for DHCP and administration, SIEM01 for Splunk, LNX01 for Linux services, and PKI01 for future certificate services. These names are design identifiers only and are not evidence of deployed systems.
SERVICES INVENTORY — PLANNED. Active Directory Domain Services, DNS, DHCP, centralized logging, SIEM analysis, backup, and administrative access are planned. Certificate services and hybrid-cloud connectivity remain future capabilities.
SECURITY STACK — IN PROGRESS. The design combines firewall policy enforcement, VLAN isolation, least-privilege administration, centralized identity, endpoint logging, Splunk analysis, backup controls, and documented trust boundaries. Product configuration and control validation remain pending.
MONITORING STACK — PLANNED. Windows Event Logs, Sysmon telemetry, Linux system logs, and firewall events will feed a centralized Splunk pipeline. No ingestion rate, retention, detection, or coverage metrics are asserted.
IDENTITY SERVICES — PLANNED. A single-forest Active Directory design will provide centralized authentication and policy management. Administrative tiers, service accounts, Group Policy, and recovery procedures require implementation and testing.
DNS — PLANNED. Active Directory-integrated DNS is the target for internal name resolution. Forwarding, scavenging, logging, and recovery settings remain to be validated.
DHCP — PLANNED. Centralized DHCP scopes will align with approved VLANs and reserve infrastructure addresses. Scope options, exclusions, failover, and lease policy remain undecided.
CERTIFICATE SERVICES — FUTURE. An offline-root and issuing-CA pattern is under consideration. No certificate authority or enterprise PKI is represented as deployed.
LOGGING PIPELINE — PLANNED. Endpoint and infrastructure telemetry will traverse controlled network paths to SIEM01, where parsing, retention, alerting, and access controls will be tested before operational use.
BACKUP AND DISASTER RECOVERY — PLANNED. The target strategy includes versioned configuration exports, scheduled virtual-machine backups, protected copies outside the primary datastore, documented recovery dependencies, and periodic restoration exercises. Recovery time and recovery point objectives remain undefined until workload criticality and measured restore performance are available.
REFERENCES — VERIFIED SOURCES. The report links to Microsoft, Netgate, Proxmox, and Splunk documentation used to frame the design. References inform the architecture; they do not constitute implementation evidence.
02 / Requirements
03 / System Design
EXTERNAL — Untrusted upstream network.
PLANNED — Routing, segmentation, policy, DHCP, VPN, and network logging.
PLANNED — Restricted zone for future published services.
IN PROGRESS — Administrative interfaces and controlled operator access.
IN PROGRESS — Identity, network, monitoring, and platform services.
IN PROGRESS — Managed Windows 11 workstations.
IN PROGRESS — Isolated Kali Linux and authorized test systems.
PLANNED — Windows Server providing AD DS and integrated DNS.
PLANNED — Scoped address allocation and option management.
FUTURE — Internal certificate enrollment and trust services.
PLANNED — Centralized ingestion, search, dashboards, and detections.
PLANNED — Utility, automation, and telemetry workload.
PLANNED — Managed domain endpoint.
PLANNED — Isolated authorized assessment endpoint.
FUTURE — Controlled hybrid identity, logging, and network integration.
internet→ Untrusted edge →firewallfirewall→ Restricted inbound policy →dmzfirewall→ Administrative policy →managementfirewall→ Service policy →server-vlanfirewall→ User egress and service access →client-vlanfirewall→ Isolated test policy →lab-vlanserver-vlan→ AD DS and DNS →domain-controllerserver-vlan→ Address services →dhcpserver-vlan→ Future PKI →certificate-authorityclient-vlan→ Authentication and policy →domain-controllerlab-vlan→ Authorized testing →kalifirewall→ Network telemetry →splunkdomain-controller→ Identity and DNS logs →splunkserver-vlan→ Future hybrid connection →cloud04 / Stack
Typed project record, editable diagrams, status taxonomy, and evidence placeholders are version controlled.
Target virtualization platform for Windows and Linux workloads; deployment evidence pending.
Target routing, VLAN termination, policy enforcement, DHCP relay/service, VPN, and traffic logging role.
Designated administrative plane for hypervisor, firewall, and management interfaces.
Target zone for domain, certificate, logging, monitoring, and application services.
Target zone for managed Windows 11 workstations and user policy testing.
Isolated target zone for Kali Linux, security tooling, and controlled testing.
Restricted target zone for future externally exposed laboratory services.
Target platform for AD DS, DNS, DHCP, and AD CS roles.
Target platform for infrastructure utilities, automation, and selected monitoring services.
Target managed endpoint for domain join, policy, certificate, logging, and security validation.
Target isolated assessment workstation; use limited to authorized lab validation.
Target identity authority for accounts, computers, groups, Kerberos, LDAP, and Group Policy.
Target internal name resolution and controlled address allocation with documented dependencies.
Future internal PKI for certificate enrollment, service identity, and trust testing.
Target SIEM and logging platform for Windows, Linux, firewall, DNS, DHCP, and identity telemetry.
Target protected backup location with retention and restoration procedures.
Future controlled extension for cloud identity, logging, and network-security scenarios.
05 / Delivery
IMPLEMENTED — Established the reusable project experience, typed content model, authoring standards, and editable SVG architecture package.
IN PROGRESS — Defining VLANs, trust boundaries, service dependencies, server inventory, and traffic-flow requirements.
PLANNED — Install the hypervisor and firewall, create initial networks, record configurations, and validate administrative access.
PLANNED — Deploy Windows Server, AD DS, DNS, DHCP, managed clients, and administrative policy.
PLANNED — Deploy Splunk, define source onboarding, validate transport, and document retention decisions.
FUTURE — Evaluate AD CS, backup restoration exercises, recovery runbooks, and a controlled cloud connection.
06 / Decisions
IN PROGRESS — The target design must represent enterprise boundaries without claiming production scale or resilience.
ResolutionUse phased capacity planning, explicit workload priorities, resource reservations where justified, and evidence-based scaling decisions.
IN PROGRESS — Identity, DNS, DHCP, PKI, logging, backup, and monitoring have ordering and recovery dependencies.
ResolutionMaintain a dependency map, deploy core network services before dependent workloads, and validate each phase before adding the next service.
IN PROGRESS — Permissive laboratory rules would reduce the value of segmentation exercises.
ResolutionAdopt default-deny inter-zone policy, document required flows, and approve exceptions against named services and validation cases.
IMPLEMENTED — Engineering records must demonstrate work without exposing credentials, private addressing, secrets, or unsafe configurations.
ResolutionUse sanitized diagrams, redaction review, scoped screenshots, and placeholders until publishable evidence is available.
07 / Retrospective
Documentation is a control
IMPLEMENTED — Status-qualified records prevent planned capabilities from being represented as deployed or validated.
Boundaries precede workloads
IN PROGRESS — VLANs, administrative paths, and permitted flows should be defined before services are placed into zones.
Identity depends on foundational services
PLANNED VALIDATION — AD DS design must account for DNS, time synchronization, certificate, backup, and recovery dependencies.
Recovery claims require exercises
PLANNED VALIDATION — Backups alone do not demonstrate recoverability; restoration procedures and measured tests are required.
08 / Artifacts
PLANNED — A guided design review will be recorded after architecture approval.
PLACEHOLDER — No deployment walkthrough exists because the infrastructure milestone is not complete.
DESIGN EXAMPLE — A proposed machine-readable inventory for future connectivity validation; not executed evidence.
environment: enterprise-home-lab
status: planned
zones:
- management
- server
- client
- lab
- dmz
checks:
- dns-resolution
- dhcp-allocation
- identity-authentication
- telemetry-delivery
- backup-restoration
Editable RedForge target-state network topology.
Editable identity, infrastructure, and monitoring service design.
Official reference for Active Directory Domain Services concepts.
Official reference for future certificate-services design.
Official reference for planned pfSense VLAN configuration.
Official platform administration reference.
Official reference for planned logging and SIEM services.
09 / Next