Isolating a Pentest Lab the Right Way: VLANs, Default Deny, and Proof

Challenge: run offensive security tools at home without any risk to the production LAN.

Action: built an isolated Kali segment behind a dedicated VyOS zone with default-deny firewall policy, no-uplink bridge, and jump-host-only access.

Result: containment verified empirically - internet egress works, 100% of lateral traffic to the home network is dropped and logged.

Skills: network segmentation, firewall policy design, VyOS, threat containment, verification testing.


If you're practicing offensive security at home, the lab must be provably isolated, not "probably fine." Mine runs a dedicated Kali VM on a bridge with no physical uplink, behind a VyOS firewall segment built default-deny.

Design

  • Hypervisor bridge with no physical NIC attached, so the segment only exists behind the router
  • Dedicated /24 with the router as the only way out
  • Firewall ruleset: internet egress allowed, all routes to the home LAN dropped
  • VPN egress (WireGuard) for external lab work, toggled manually instead of always-on

Prove the isolation

The rule that matters isn't the one you wrote. It's the one the packets hit. Verification was empirical: from the lab box, internet reachable; every host on the home LAN, 100% packet loss; firewall counters incrementing on the drop rule while the tests ran. Screenshots and counters, not assumptions.

Operational discipline

  • Credentials for lab systems stored outside the lab, rotated when exposed
  • Scheduled patching for the attack box because offensive tooling is still software with CVEs
  • Storage watchdogs, because a full thin-pool takes down the lab exactly when you're mid-exercise

Practice targets are authorized-only: TryHackMe rooms (SSRF, IDOR, security fundamentals), intentionally vulnerable apps like DVWA and Juice Shop, and my own infrastructure. The habit that transfers to real network security work isn't the exploit. It's the segmentation, the verification, and the discipline.