// HOMELAB INFRASTRUCTURE REGISTRY

Project Cerberus

Hardware & Infrastructure Documentation

5
Active Devices
2
Planned Phase
1
Retired Units

Project Cerberus is my enterprise-style homelab, built to strengthen hands-on skills across infrastructure, networking, virtualisation and cybersecurity. The goal is to create an environment that feels as close to real-world IT as possible, a place to build, test, troubleshoot and document systems properly.

This is not just hardware sitting on a rack. Each phase is tracked and documented through Notion, including implementation steps, issues encountered, troubleshooting, fixes applied and lessons learned along the way.

Filter //
Active Hardware
05 UNITS
🖥️
Dell PowerEdge R620
// "DEKU" // COMPUTE NODE //
● Active
// click to expand
Virtualisation Host / Lab Compute Node

Forms part of the main compute layer in the lab, used for virtualisation, infrastructure services and general hands-on server administration. Provides a solid enterprise platform for building and managing virtual machines, testing server roles and running supporting lab workloads.

// Primary Use Cases
Hosting VMsInfrastructure Services Server Workload TestingSysadmin SkillsCore Lab Services
NOTE//
Core part of the compute layer. Used to support realistic infrastructure testing and service deployment.
🖥️
HPE ProLiant DL380 Gen9
// "HYRULE" // ENTERPRISE HOST //
● Active
// click to expand
Main Enterprise Workload Host / Future FC Storage Platform

One of the key servers in the lab, a major platform for virtualisation and enterprise-style workload hosting. Plays an important future role in the storage side of the environment, planned for direct Fibre Channel connectivity to the HPE MSA 2040 when that phase is implemented.

// Primary Use Cases
Core Virtual WorkloadsInfrastructure Services Enterprise PlatformFuture FC Storage
NOTE//
Central to future storage expansion plans. Important part of the long-term infrastructure design.
🌐
Cisco Catalyst 2960X 48-Port
// LAYER 2 ACCESS SWITCH //
● Active
// click to expand
Layer 2 Access Switching / Current Network Backbone

Provides the main switching function within the lab, supporting network connectivity across the entire environment. Used for VLAN-based switching, device connectivity and general network structure while the wider routing and segmentation design continues to evolve.

// Primary Use Cases
Layer 2 SwitchingVLAN Connectivity Access LayerDevice Distribution
NOTE//
Current main switch in active use. Supports existing network design while L3 plans are being developed.
🔥
FortiGate 300D
// PERIMETER FIREWALL //
● Active
// click to expand
Firewall / Perimeter Security / Access Control

The main firewall platform in the lab, lines up strongly with the Cerberus theme of controlled access and defensive design. Supports traffic filtering, policy control and secure access while giving hands-on exposure to enterprise firewall administration and segmented network security.

// Primary Use Cases
Perimeter SecurityTraffic Filtering Policy ControlVLAN-Aware AccessSecure Remote Access
NOTE//
Core security component. Replaced the MikroTik hEX S as the active edge security platform.
🗄️
12U Open Air Rack
// PHYSICAL INFRASTRUCTURE //
● Active
// click to expand
Physical Infrastructure Housing

Forms the physical base of the homelab and provides a structured way to mount and organise core equipment. Makes the setup more manageable, easier to document and closer in feel to a proper infrastructure deployment.

// Primary Use Cases
Hardware HousingPhysical Organisation Cable ManagementLab Presentation
NOTE//
Open air rack. Forms the physical backbone of the active setup.
Inactive / Previously Used
01 UNIT
📡
MikroTik hEX S
// PREVIOUS EDGE ROUTER //
○ Offline
// click to expand
Previous Edge Router / Routing Platform

Used as the initial edge router in the lab before the FortiGate 300D was implemented. Provided the original routing and edge-network function during the earlier stages of the homelab build, useful for testing routing concepts, connectivity and general network design.

// Previous Use Cases
Initial Edge RoutingConnectivity Testing WAN-Style ConfigEarly Lab Network Design
NOTE//
Currently offline. Migrated to FortiGate 300D. Retained as part of project history and design evolution.
Planned / Implementation Phase
02 UNITS
💾
HPE MSA 2040
// SHARED STORAGE PLATFORM //
◈ Planned
// click to expand
Shared Storage Platform / Future Implementation

Part of the next planned phase of Project Cerberus, intended to bring shared storage into the lab environment. Planned for Fibre Channel connectivity directly to the HPE DL380 Gen9, moving the lab closer to a realistic enterprise storage and virtualisation model.

// Planned Use Cases
Shared VM StorageCentralised Storage SAN-Style LearningAdvanced Infra Design
NOTE//
In planning phase. Connects via Fibre Channel to DL380 Gen9. Not yet part of the active setup.
🌍
Cisco Catalyst 3650 48P PoE+
// FUTURE L3 SWITCH //
◈ Planned
// click to expand
Future Layer 3 Switching / Inter-VLAN Routing Platform

Planned as the future upgrade path for the network design, migration from the current Layer 2 switching model to a dedicated Layer 3 approach. Will support inter-VLAN routing at the switch layer and create a more enterprise-style network structure without relying on the firewall for all routing decisions.

// Planned Use Cases
Layer 3 SwitchingInter-VLAN Routing Internal Traffic HandlingNetwork SegmentationEnterprise Architecture
NOTE//
In planning phase. Intended move from L2 to dedicated L3 switching for stronger segmentation and performance.
Documentation & Project Tracking

Project Cerberus is documented as an active technical project ,not just a collection of hardware. Each stage is tracked with a focus on structure, visibility and lessons learned throughout the build process. This creates a proper record of the lab's development and makes it easy to show not just what was built, but how it was built, what went wrong and how those issues were resolved.

Project Goals
Hardware Inventory
Implementation Steps
Config Changes
Issues Encountered
Troubleshooting
Fixes Applied
Lessons Learned
Future Planning
Core Skills Developed
Infrastructure & Systems Administration
Networking & Segmentation
Virtualisation & Platform Engineering
Cybersecurity & Access Control
Technical Documentation
Troubleshooting & Root Cause Analysis
Implementation Roadmap
01
Network and infrastructure foundations ,VLANs, FortiGate, Cisco, Proxmox, storage
✓ Complete
02
Internal DNS, reverse proxy and wildcard certificate
✓ Complete
03
WireGuard VPN ,remote access through double-NAT environment
✓ Complete
04
Snipe-IT replatform ,Docker host migration with ISO 27001-aligned design
✓ Complete
05
Wazuh SIEM ,deployment and endpoint telemetry
✓ Complete
06
Wazuh SOC pipeline ,Shuffle orchestration and DFIR-IRIS incident handling
↳ In Progress
07
Windows enterprise lab ,Active Directory, DNS, GPO, PKI, file services
⏭ Planned
08
Purple team range ,isolated attack and defence VLANs with Kali and Wazuh detection tuning
⏭ Planned
09
Docker and Kubernetes / k3s ,containerisation and cloud-native learning
⏭ Planned
10
Azure, Entra ID, Intune and hybrid cloud integration
⏭ Planned
11
HPE MSA 2040 shared storage via Fibre Channel to DL380 Gen9
⏭ Planned