Packet Path/

Build a Home Lab That Actually Gets You Hired

A managed switch, a real router, a Raspberry Pi, and free virtualization software. Here's the lab that teaches real skills — without the loud, power-hungry mistakes everyone warns about.

Labs · Beginner · 15 min · September 30, 2026

Isometric illustration of a compact home network lab with a rack, switch, and desk

Why a lab beats another course

Interviewers have a tell for candidates who only watched videos: they describe protocols but freeze on "walk me through a packet that leaves your VLAN and arrives somewhere else." A lab builds the muscle that answers that fluently. And you do not need a rack, a closet, or a second mortgage — a small desk's worth of gear plus free virtualization covers the entire CCNA and most of CCNP.

The hardware core

Three physical pieces and one cable. Everything else, virtualize.

RolePickWhy
RouterMikroTik hEX (RB750Gr3)Runs RouterOS: real OSPF, BGP, NAT, firewall. Quiet, cheap to run, and the whole protocol stack is unlocked.
Managed switchTP-Link TL-SG108E or Ubiquiti Switch Flex MiniVLANs, trunks, port mirroring — the entire switching fundamentals set. Go Cisco CBS350 if your career is Cisco-shaped.
ServerRaspberry Pi 5Silent, sips power, and runs Pi-hole DNS, a DHCP server, syslog, and Docker containers for weeks without complaint.
CableUSB-to-serial console cableThe day anything stops pinging, the console port is how adults reach the CLI.

Full details and links are on the gear page. Start with the switch and Pi if budget is tight; add the router when you reach real routing protocols.

Virtualize the rest — mostly free

What not to buySkip vintage rack gear — old Catalyst 3750s and datacenter switches are loud, draw hundreds of watts, and do not teach you anything a modern small managed switch doesn't. Your electricity meter is not a curriculum.

Five projects that end up on resumes

  1. VLAN segmentation that actually works. Management, wired, IoT, guests, lab — inter-VLAN routing on the hEX, DHCP per VLAN, firewall rules between them. This is one interview answer for ten questions.
  2. Pi-hole DNS with DHCP failover. The Pi becomes your network's brain: DNS filtering, static DHCP leases for lab gear, and a dashboard you screenshot later. Pair it with docs.pi-hole.net for the strict-privacy setups.
  3. A WireGuard tunnel to a cheap VPS. Site-to-site crypto, policy routing, NAT exemption — production skills in an evening, and proof you understand crypto beyond clicking a GUI.
  4. Monitoring that pages you. Uptime checks from the Pi against your lab devices; SNMP walk practice; syslog from the switch and router. "I caught loops before they caught me" is a true story here.
  5. A troubleshooting portfolio. Break the lab on purpose — mismatched native VLANs, a switch loop without STP, DNS pointing nowhere — capture the Wireshark traces, write up the diagnosis. Three of these is an interview portfolio.

A sane VLAN plan to start from

VLANNameSubnetNotes
10mgmt192.168.10.0/24Switch, router, Pi management only
20users192.168.20.0/24Your real devices
30lab192.168.30.0/24Where the chaos lives
40iot/guest192.168.40.0/24Tight firewall rules; internet-only
Safety firstNever expose lab management interfaces to the internet, and never open your resolver (port 53) to the world — open DNS becomes a DDoS amplifier. VPN back home instead.
Key takeaways

Keep reading