I'm setting up a new home network in order to add internet-disabled security cameras and to better isolate internet-enabled IOT devices. I'm tech savvy but new to networking so I've spent the past few weeks trying to learn and plan as much as I can. My understanding is that normal consumer WIFI routers don't support this and that I need a managed switch with VLAN support. In addition, now that a normal WIFI router is out of the picture (unless there is some way to still use one?) I need to replace that functionality with something like OPNsense and some APs. Based on this understanding I have created a diagram with the two best options I've been cable to come up with so far. On the left I have a single switch "primary" switch and on the right I have a nearly identical setup but with a pair of "primary" switches.
* If you notice that the single switch diagram is using 9/8 ports that's because 1 or 2 good AP is likely sufficient and therefore I only need 7 or 8 ports. I wanted to show 3 APs which exceeds the available ports to help visualize alternate switch combinations that would support additional devices.
I think either of my plans would work but I have this nagging feeling that there is a better option right in front of me that I just can't see. It seems like a single higher end ~16 port switch would be better but I can't seem to find anything that is multi-gig, managed, AND has 2-4 poe++ for under $1k. Trying to find alternatives like only having multi-gig on uplinks or using poe injectors instead of poe switches adds up to about the same cost or has significantly reduced features for no real savings. I just can't seem to find any combination of devices that beats one or two MS108EUP at $280 each.
I'm also torn between a dedicated router box like the R86S or just hosting OPNsense in a Proxmox VM on my automation pc. It has plenty of resources but only a single 2.5g NIC. I'd either need to use a single cable (security concerns), add a USB NIC (I guess these are bad), or maybe swap the unnecessary M2 A+E WIFI module with a NIC (which may not be possible if the WIFI module also controls the 2.5 LAN port like they sometimes do). Or maybe there IS some way to use a normal WIFI router as the internet connection (and AP?) but still use an OPNsense VM and VLANs to get the isolation and security that I want?
At this point I'm not really sure and I'm going in circles. Anyone have any suggestions?
* If you notice that the single switch diagram is using 9/8 ports that's because 1 or 2 good AP is likely sufficient and therefore I only need 7 or 8 ports. I wanted to show 3 APs which exceeds the available ports to help visualize alternate switch combinations that would support additional devices.
I think either of my plans would work but I have this nagging feeling that there is a better option right in front of me that I just can't see. It seems like a single higher end ~16 port switch would be better but I can't seem to find anything that is multi-gig, managed, AND has 2-4 poe++ for under $1k. Trying to find alternatives like only having multi-gig on uplinks or using poe injectors instead of poe switches adds up to about the same cost or has significantly reduced features for no real savings. I just can't seem to find any combination of devices that beats one or two MS108EUP at $280 each.
I'm also torn between a dedicated router box like the R86S or just hosting OPNsense in a Proxmox VM on my automation pc. It has plenty of resources but only a single 2.5g NIC. I'd either need to use a single cable (security concerns), add a USB NIC (I guess these are bad), or maybe swap the unnecessary M2 A+E WIFI module with a NIC (which may not be possible if the WIFI module also controls the 2.5 LAN port like they sometimes do). Or maybe there IS some way to use a normal WIFI router as the internet connection (and AP?) but still use an OPNsense VM and VLANs to get the isolation and security that I want?
At this point I'm not really sure and I'm going in circles. Anyone have any suggestions?