So as to not bury the lede, we bought a house this past April! πŸŽ‰ This is the realization of a long time dream for the wife and I. It has resulted in a lot of work that has distracted me from other side projects, writing, and even mere day to day routine for a time. The montage scene includes the closing, a full sewer line replacement, AC replacement, dishwasher and disposal installs, some minor structural and insulation repairs in a crawlspace under an addition, painting, the move, the unpacking, and _many_ trips to Hammerbarn. What's relevant here is I was able to get an electrician in to pull some Cat6, staging drops for APs, cameras, and a couple wall jacks around the place. I've done a lot of reading and note-taking in the past couple months as I plan for the network and equipment. Since half of this written already, and I've done a shit job of writing anything personally of late, I figure it's good fodder for a post. # Why the upgrades? Our network that's made the jump over from our old apartment to the house already had some prosumer kit. A [Firewalla Gold](https://firewalla.com/products/firewalla-gold) was already running the show with VLANs for trusted, semi-trusted, and a couple different flavors of untrusted (work, IoT, and guest) devices, and a set of Eero 5's in bridge mode formed a mesh WiFi network. This was perfectly good for our needs, even if the Eeros are starting to fall behind on their 802.11 letter. I've had some conversations with my boss and skip level recently about professional development. One of the items I self-identified was that because I came up through the risk side of IT and security, I feel that while I can understand and speak to some of the more technical aspects of security I've never actually been "hands on keyboard" with more modern tooling. Professionally we're addressing that by getting me more involved in operations and infrastructure projects. While this home networking project doesn't mesh neatly with my day job's responsibilities, I do think it is an opportunity both to future-proof the home network and for me to get hands on time in an ops-y sysadmin-y way, even if it is just as a homelab. # To Lack Rack, or not to Lack Rack? For those unfamiliar, IKEA offers a low cost side table called the [Lack](https://www.ikea.com/us/en/p/lack-side-table-black-brown-80104268/) which just so happens to be wide enough between the legs to fit standard 19" rack mount equipment, up to 8U worth per table. I found no shortage of inspiration and guidance on the art of the Lack Rack, some of the most helpful links are below with a special nod to Baker Street Forensics for their excellent posts. - [A relatively low profile Lack Rack seen on r/Ubiquiti](https://www.reddit.com/r/Ubiquiti/comments/vvzhym/799_ikea_lack_rack/) - [DIY Home Network Rack – the Lack Rack – Baker Street Forensics](https://bakerstreetforensics.com/2022/02/28/diy-home-network-rack-the-lack-rack/) - [Lack Rack Updates – Baker Street Forensics](https://bakerstreetforensics.com/2022/09/03/lack-rack-updates/) - [Lack Rack part III: the Final chapter – Baker Street Forensics](https://bakerstreetforensics.com/2022/09/08/lack-rack-part-iii-the-final-chapter/) - [Steampunk or Cyberpunk ? – Baker Street Forensics](https://bakerstreetforensics.com/2023/06/05/steampunk-or-cyberpunk/) - [LackRack - Eth0Wiki](https://wiki.eth0.nl/index.php/LackRack) - [List of IkeaRacks - Eth0Wiki](https://wiki.eth0.nl/index.php/List_of_IkeaRacks) There's just a couple problems. The legs are honeycomb / semi-hollow and the max weight rating on the table top is only 55lbs. If I load one of these down with 8U worth of kit, how long can I reasonably expect the legs to hold up? If I rearrange things and make upgrades, will I be further weakening the legs with every removed and reapplied screw? This sent me down a path of planning to reinforce a Lack. You can follow the lead of u/[RepresentativeAsk798](https://www.reddit.com/user/RepresentativeAsk798/) and make a "[Lack Rack Pro](https://www.reddit.com/r/lackrack/comments/19fiqxu/lack_rack_pro/)". But lacking (har har) my own 3D printer to make the bracket, and facing the need to purchase two Lacks, bolts, some 18U rails, buy a couple beers for someone to print me the brackets, and then take the time to assemble it all, wouldn't it just be cheaper to buy a purpose built rack? .... .... .... So anyway I bought a [15U Navepoint rack](https://navepoint.com/navepoint-15u-450mm-depth-wallmount-networking-cabinet-consumer-series/). # What's in the rack? Without going into the details of the home and camera placements (not a great idea to share those in public), our plan for cameras and WiFi coalesced around two APs, some camera drops, and a doorbell, with potential to add cameras later if/where/as needed. These would all be run off of PoE wherever possible. I waffled a fair bit on how to deliver the PoE, flip flopping between maintaining the current Firewalla Gold and adding a PoE switch, or springing for a [Ubiquiti Dream Machine SE](https://store.ui.com/us/en/collections/unifi-dream-machine/products/udm-se). I initially considered [Reolink](https://reolink.com/) as the frontrunner for the cameras and doorbell between hardware, cost, and their app. But, I was not pleased with Reolink's relatively basic NVR offerings and was instead considering a Synology NAS and their [Surveillance Station](https://www.synology.com/en-us/surveillance) application. Between cost of the NAS, drives, and licenses, this would quickly balloon in cost and I felt may overtake Ubiquiti. Plus the strong reviews that Ubiquiti kit "just works" (at least for the most part) compared to bodging together products from multiple vendors, Ubiquiti won me over. What has actually wound up in the rack at the time of this writing are the modem, a Ubiquiti Dream Machine SE, a Tripp-Lite ISOBAR PDU, a Cyberpower UPS, 2x 24 port patch panels (overkill but in case of future expansion), a Dell 9020M which runs Proxmox VE, a 2U drawer unit for cable and fittings storage, and a shelf. A Ubiquiti 24 port PoE switch is the most recent addition, facilitating the addition of another AP to provide better coverage in the basement and front of house, and provide more PoE ports for the remaining cameras. Yes, yes, I know. I'm literally the meme of the selfhoster / homelab guy who's picked all the easiest, high brand awareness stuff. But the fact it's easy to work with is perfect for my immediate needs and it's a platform to grow and learn on. I've got kids and work after all, at the end I need it all to play nice and not be a constant maintenance project. ## Rack Layout I threw this table together early in the planning process to help me understand the rack layout. Initial plan looked something like this. | | | | |---|---|---| |Zone|Contents|Notes| |TOP||| |1-15|Patch Panel 24 port -1|Primary drops| |1-14|Patch Panel 24 port -2|Redundant drops & special (e.g. doorbell chime on 3*)| |1-13|Firewalla Gold|Work network - 1gbps off modem| |1-12|Dream Machine Pro|Home Network - 2.5gbps off modem| |1-11|Reserved for PoE Switch|Future upgrade when more cameras are added| |1-10|Modem|| |1-9|Philips Hue|| |1-8|Shelf|Swap out for NVR at future time| |1-7|Dell 9020M|Runs Proxmox and Home Assistant| |1-6|ISOBAR PDU|| |1-5|BLANK BLANK BLANK|Save space for oversized bricks| |1-4|Drawer 2U|| |1-3|Drawer 2U|| |1-2|UPS|| |1-1|UPS|| |Base|Base|| But we all know no plan survives contact with reality. Thankfully these realizations didn't have a dollar value associated. First, I had planned to have ISP drop into the Modem, then the 2.5gbps out to the Dream Machine and the 1gbps out to the Firewalla. In theory this would let me connect my work devices to the Firewalla, segregating them off via hardware completely from our personal, lab, and IOT devices. Unfortunately, Comcast and/or Arris don't play nice with this approach, only one of those outputs from the modem can be in use at a time. So the Firewalla is now sitting in a box, waiting for use in another project. Second, I found some of the Cat6 drops which come up from below the rack were just a touch short. They could still plug into the patch panels at the top of the rack, but I had concerns that if e.g. a Dream Machine slotted below them it would put too much strain on the cables. I decided not to risk it and moved the patch panels towards the bottom of the rack, above the UPS. > [!note] Updated Oct. 2026 > Two years of "future upgrades" later, the old current-state table no longer resembled anything actually bolted into the rack. The table below reflects the rack as of October 2026 β€” the planning tables above are preserved as a historical record. | | | | |---|---|---| |Zone|Contents|Notes| |TOP|Access Point (UK Ultra)|WiFi 7 AP covering the basement| |1-14 / 1-15|UniFi PDU Pro|2U unit| |1-13|"Kain" & "Ward"|Dell OptiPlex micros running Proxmox VE| |1-11 / 1-12|Drawer 2U|Cables and fittings| |1-10|Philips Hue + Lutron bridges, RPi4B "Hecteyes"|Pi runs Docker: CommaFeed, Uptime Kuma, Wastebin| |1-9|Modem|Arris S33| |1-8|UNVR|Dedicated UniFi Protect recorder| |1-7|UNAS Pro ("Aranea")|Runs UniFi Drive| |1-6|UNAS Pro|Second storage node| |1-5|Dream Machine SE ("Estinien")|Runs UniFi Network and Talk| |1-4|PoE Core Switch|UniFi Pro Max 24 PoE| |1-3|Patch Panel 24 port|APs, cameras, and drops| |1-1 / 1-2|UPS|Single 2U unit| |Base|Base|| And yes, the servers are named after Final Fantasy XIV characters. If you're going to be a homelab clichΓ©, commit to the bit. # What are you _doing_ with this setup? Best to think of this question in three components: network, surveillance, and the homelab. ## Network The household network centers on the UDM which handles routing, firewall, etc. It enforces VLANs similarly to how I had the Firewalla configured. Devices are assigned to VLANs based on whether they are Trusted, Semi-trusted, or Untrusted. E.g. work and guest devices are untrusted and their VLANs are isolated from all other VLANs. Some types of IOT devices are presently in a semi-trust VLAN while I tinker with firewall rules to make them easier to interact with. Our personal devices and the household infrastructure such as VMs, cameras, etc. are in Trusted VLANs. The UDM has also picked up UniFi Talk duty using [voip.ms](http://voip.ms) as a third party provider, providing us with functionally a home phone line. By current calculation, the UPS will run everything in the rack for 1 hour in a power loss scenario. More than enough time to gracefully shutdown, and with the relative rarity of blackouts and brownouts here well up to the task of keeping us online. WiFi is presently provided by a pair of U7 Pros covering the main living areas and upstairs, with UK Ultras handling the basement and my office. One of the U7 Pros is biased rearward in the home to provide coverage into the back deck and yard. When I first wrote this post, the joke was that there was a grand total of _maybe_ three devices on the market that could speak WiFi 7. Now it's becoming standard in flagship phones and laptops, so the future proofing is paying off already. The garage is now bridged back to the house over a UniFi Building Bridge; admittedly overkill for the distance in question, but give rock-solid reliable connection for a U6+ AP, a [ratgdo]([https://ratcloud.llc/)](https://ratcloud.llc/), and a trio of cameras. ## Surveillance Camera drops and junction boxes are all in place, and the cameras have been going in as funds allow. There are eight of them now, plus the doorbell. The "future upgrade" of offloading the recording load off the UDM happened too: a dedicated UNVR now runs UniFi Protect, with proper drive redundancy via RAID 1 plus a hot spare. Ubiquiti's [G4 Doorbell Pro](https://store.ui.com/us/en/products/uvc-g4-doorbell-pro) was the first Protect family device I installed once the Cat6 was in place and it's a really, really sweet piece of kit. Showing gifs on the screen is icing on an already great product cake. I would say that if, like me, you have an install location without a large hole behind the unit to accommodate the rj45 connector / rubber housing, you may want to obtain an aftermarket mount. ([Here's what I used](https://www.etsy.com/listing/1270278038/angled-mount-for-ubiquiti-unifi-protect)) ## Homelab > [!note] > This section was originally written in Sept. 2024, edited as of Sept. 27, 2026 in conjunction with the move of this site to Obsidian Publish, and refreshed again in Oct. 2026 to bring it current. I make no representation about this staying up to date, and expect it to be superseded by another post eventually. The Homelab outgrew "modest" surprisngly fast. The original Dell OptiPlex micro now has a sibling, and between the two of them ("Kain" and "Ward") they run [Proxmox VE](https://www.proxmox.com/en/proxmox-virtual-environment/overview), hosting [HomeAssistant](https://www.home-assistant.io/), Jellyfin, and Gravwell. The lightweight always-on services live on a Raspberry Pi 4 ("Hecteyes") running Docker: [CommaFeed](https://www.commafeed.com/#/welcome), [Uptime Kuma](https://uptime.kuma.pet/), and Wastebin. The "eventually" items from the original version of this post mostly materialized too, just not the way I'd planned: the TrueNAS ambition lost out to UniFi, fulfilled by a UNAS Pro. Jellyfin won out in the face of Plex's licensing shenanigans, hosted from one of the Proxmox boxes with me Of note, [tteck's Proxmox VE Helper-Scripts](https://github.com/community-scripts/ProxmoxVE) were a HUGE help in getting all this started, providing me a platform to work from to see results quickly so that my ADHD brain wouldn't abandon the project too soon, while also finding what I still have to learn and do manually. Sadly, tteck passed away in 2024, but the project was handed over to the community and lives on via [https://community-scripts.org/](https://community-scripts.org/) . It is still my first stop for standing up (or tearing down) new LXC containers. HomeAssistant is the main tool I wanted to start selfhosting for, as this is allowing us to tie multiple home automation / IOT products together under one app (The wife really likes this). Without it, we'd be using nine different apps in different contexts around the home. Maybe half of that was able to integrate into Google Home or Homekit, but not both. The automations have multiplied since the original post: exterior lights at sunset, the downstairs hallway tied to motion sensors and the side door sensor, morning lights timed for right before the wife heads downstairs, and the garage door got the full treatment via a ratgdo so HA knows (and can tell us) whenever it opens or closes and can automagically lock out the remotes overnight. The current rabbit hole is dashboards: there's a whole set of them now, built on Mushroom cards via HACS, covering everything from room controls to the server rack... and, naturally, one just for watching airplanes. ... on that note because we're in relatively close proximity to O'Hare International Airport, I allocated a spare drop in the attic for a [PiAware](https://www.flightaware.com/adsb/piaware/) ADS-B receiver feeding [FlightAware](https://www.flightaware.com/), with the PiAware's local dashboard piped into HomeAssistant as a single webpage dashboard. Longer term when we renovate the first floor of our home, I want to add a digital signage display that can operate in a kiosk mode showing a full screen browser page serving HomeAssistant's dashboard(s) for controlling rooms and viewing the outside cameras. The newest item on the whiteboard is power efficiency; the Dells are old and thirsty under load. I'm eyeing a low-power mini PC (likely a Mac mini) to take on Jellyfin with a local LLM experiment on the side to help manage the homelab, (especially patching), while keeping at least one Proxmox node around for the services that need it. # Miscellany A couple parting items that didn't fit elsewhere: Given the amount of reorganizing and shifting stuff around in the rack I did, a set of [RackStuds](https://www.rackstuds.com/) were an absolute lifesaver. This is not sponsored, I have no relationship with RackStuds, I just know I would've been hating my choices if I was futzing with cage nuts at points in this project and these things were a huge timesaver. If you've got the disposable income to throw at it and no access to a 3D printer yourself, Etsy was a surprisingly great source for 3D rack mount kits for various devices that would otherwise have had to sit on a shelf unit. I snagged one for the [modem](https://www.etsy.com/listing/1604798414/1u-rack-mount-for-arris-surfboard-s33) and another for the [Philips Hue](https://www.etsy.com/listing/891257372/philips-hue-smart-hub-1u-rack-mount) bridge. If, like me, the rack is going to be in the same room as your workspace, spend the money on some variable speed fans to replace whatever ships stock with your rack. Your ears will thank you. Doubly so considering my office doubles as the guest room. πŸ™ƒ