I do not currently use a VPN but I am thinking of getting Proton VPN, I do however use different forks of Debian on most things. All of my IoT things do not have access out of my 10.6.66.0 vLAN (which has its own wifi) and most do not have access to the WAN. I use Home Assistant for most things on my 10.0.69.0 homelab vLAN (does not have wifi it is all wired) to reach into the IoT vLAN to do stuff which has limits to my personal vLAN 10.42.0.0 (Does have its own wifi). My guest vLAN 10.4.20.0 (Does have its own wifi but does not have eth) does not have acess to anything other than the WAN, just for shits and giggles I have a child friendly vLAN 10.6.7.0 (Does have its own wifi but does not have eth) that only has wifi and does not acess to anything other than the WAN during certain times. My personal wireguard vLAN 10.69.42.0, has the same acess as my personal vLAN, and my guest wireguard vLAN has the same acess as my guest vLAN but limits them to 2 hours before OpenWRT kicks them off.
I do not use my ISPs firewall/router just the fiber modem into my OpenWRT firewall. The DNS I use is two piholes with unbound.
I do not currently use a VPN but I am thinking of getting Proton VPN, I do however use different forks of Debian on most things. All of my IoT things do not have access out of my 10.6.66.0 vLAN (which has its own wifi) and most do not have access to the WAN. I use Home Assistant for most things on my 10.0.69.0 homelab vLAN (does not have wifi it is all wired) to reach into the IoT vLAN to do stuff which has limits to my personal vLAN 10.42.0.0 (Does have its own wifi). My guest vLAN 10.4.20.0 (Does have its own wifi but does not have eth) does not have acess to anything other than the WAN, just for shits and giggles I have a child friendly vLAN 10.6.7.0 (Does have its own wifi but does not have eth) that only has wifi and does not acess to anything other than the WAN during certain times. My personal wireguard vLAN 10.69.42.0, has the same acess as my personal vLAN, and my guest wireguard vLAN has the same acess as my guest vLAN but limits them to 2 hours before OpenWRT kicks them off.
I do not use my ISPs firewall/router just the fiber modem into my OpenWRT firewall. The DNS I use is two piholes with unbound.
deleted by creator