# vault # Physical Hardware ![](https://bookstack.swigg.net/uploads/images/gallery/2021-10/protectli-fw2.jpg)## Basic Components [Proectli Vault](https://protectli.com/product/fw1/) ### Compute #### Processor [Intel Celeron Bay Trail-D J1800](https://ark.intel.com/content/www/us/en/ark/products/78866/intel-celeron-processor-j1800-1m-cache-up-to-2-58-ghz.html) - Provides excellent mix between performance and efficiency using only 10W.
Cores / Threads2 / 2
Base Frequency2.41 GHz
Burst Frequency2.58 GHz
Cache1MB L2 Cache
TDP10W
#### GPU Intel HD Graphics for Intel Atom Processor Z3700 Series
Base Frequency688 MHz
Burst Frequency792 MHz
QuickSync VideoYes
### Motherboard
Form FactorProprietary
CPUSoldered Intel Celeron J1800
Chipsetunknown
Memory1x DDR3L 1333MHz SODIMM, 1.35v, Max 8GB
Video1x VGA
Networking2x Intel Gigabit 82583V 1GbE
PCInone
Storage- 1x mSATA
USB- 1x External USB 2.0 (Type-A) - 1x External USB 3.0 (Type-A) - 1x Internal USB 2.0 (mPCIe)
COM1\*RS232
### Memory
Slot 1 ![](https://bookstack.swigg.net/uploads/images/gallery/2021-03/scaled-1680-/timetec-ddr3-1866.png)Timetec Hynix IC 8GB DDR3L 1333MHz (1x8GB) - 2Rx8 Dual Rank - CAS Latency 13 - 1.35V
### Case n/a ### Storage
SATA1 ![](https://bookstack.swigg.net/uploads/images/gallery/2021-03/scaled-1680-/dogfish-ssd.png)Dogfish 64GB mSATA MLC SSD
### Cooling n/a ### Power Supply n/a ### UPS n/a ## Add-On Cards
mPCIe (USB) ![](https://bookstack.swigg.net/uploads/images/gallery/2021-03/intel-ax200.png)Protectli Wifi Adapter - Wireless B/G/N at 2.4Ghz - USB Channel communication
# Base Install ## Operating System --- [Proxmox Virtual Environment](https://www.proxmox.com/en/) 6.x ## Configuration

Proxmox configuration has been transitioned to being automated by an [Ansible Role](https://gitlab.swigg.net/dustins/ansible/-/blob/master/proxmox.yml)

# Configuration (deprecated) ## DHCP Server
DomainSubnetGateway
hermz10.0.0.0/2110.0.1.1
### IP Reservations A few reservations were setup to ensure certain interfaces get a static IP address assigned to make managing these machines/devices easier.
MAC AddressClient IdIP AddressDescription
`02:1c:83:7d:15:8e`firewall10.0.1.1PfSense firewall
`02:1c:83:7d:15:8e`pihole10.0.2.2Pi-hole DNS
`02:1c:83:7d:15:8e`wireguarded10.0.2.2wireguarded
`b4:fb:e4:8f:f9:74`10.0.2.99Ubiquiti UniFi Switch 8
`e0:d5:5e:63:fe:30`blackbox10.0.3.2[blackbox](https://bookstack.swigg.net/books/blackboxhermz) proxmox management
`e0:d5:5e:63:fe:30`mini10.0.3.3[mini](https://bookstack.swigg.net/books/minihermz) proxmox management
`d0:a6:37:ed:8c:7f`silverbook10.0.4.4Dustin's MacBook Pro (wifi)
`82:13:00:9c:c7:00`10.0.4.5thunderbolt ethernet adapter
`32:cc:fb:a3:1a:57`docked10.0.44.4docker services
## DNS Resolver DNS overrides were setup to allow accessing some services directly across the LAN instead of going through the router.
Home Domain Address/Alias Description
No overrides are currently being used
## Firewall/NAT
InterfaceProtocolDestinationPort(s)
WANIPv4 TCPdocked.hermz80 *(HTTP)* 8080 *(HTTP alternative)* 443 *(HTTPS)* 8443 *(HTTPS alternative)*
WANIPv4 TCPdocked.hermz2222 *(SSH alternative)*
WANIPv4 TCP/UDPwireguarded.hermz51820 *(Wireguard)*
## Dynamic DNS
InterfaceServiceHostname
WANNamecheap@.swigg.net
WANNamecheap\*.swigg.net
WANNamecheap@.dustins.site
WANNamecheap\*.dustins.site
WANNamecheap@.notgandhi.com
WANNamecheap\*.notgandhi.com
# VM / firewall (needs verification) ## Description This VM is for running [VyOS](https://en.wikipedia.org/wiki/VyOS) to act as a [firewall](https://en.wikipedia.org/wiki/Firewall_(computing))/[router](https://en.wikipedia.org/wiki/Router_(computing)) for the network. Originally this machine was running [pfSense](https://en.wikipedia.org/wiki/PfSense) (which is excellent) but that is based on [FreeBSD](https://en.wikipedia.org/wiki/FreeBSD) and I wanted a firewall/router based on [Linux](https://en.wikipedia.org/wiki/Linux). ## Configuration ### Resources
HostnameCPUMemory
firewall2 vCPU512MB
### Storage
DiskControllerSizePurpose
vpool-zfs:vm-104-disk-0ide01MEFI
### Networking #### Interfaces
IDNameBridgeIP Address
net0n/avmbr0(DHCP)
net1n/avmbr110.0.1.1/21
# VM / homeassistant ![](https://upload.wikimedia.org/wikipedia/commons/thumb/6/6e/Home_Assistant_Logo.svg/220px-Home_Assistant_Logo.svg.png)## Description This VM is for running [HomeAssistant](https://www.home-assistant.io/) which acts as the control system for smart home devices with focus on local control and privacy. ## Configuration ### Resources
HostnameCPUMemory
homeassistant2 vCPU4096MB
### Storage
DiskControllerSizePurpose
vpool-zfs:vm-104-disk-0ide01MEFI
### Networking #### Interfaces
IDNameBridgeIP Address
net0n/avmbr0(DHCP)