Skip to content
Annas Ali

Personal lab

Hybrid on-prem infrastructure & secure remote access lab

Proxmox cluster, Active Directory and a WatchGuard perimeter, linked to AWS over IPsec with automatic DR failover. Legacy client VPN replaced by Cloudflare Zero Trust.

  • Proxmox
  • Active Directory
  • WatchGuard
  • IPsec VPN
  • Cloudflare Zero Trust
  • Terraform
  • Ansible

Why a lab

Most of my day job is cloud-native, but a lot of real infrastructure is still hybrid: identity in Active Directory, a physical firewall at the edge, VPNs into a VPC, and a remote-access story that has to work for people who aren’t engineers. I built this lab to run that whole stack end to end, from bare-metal virtualization up to identity-based access.

Hybrid lab topologyON-PREM LABAWSCLOUDFLAREWatchGuard FireboxVLANs · NAT · Mobile VPNProxmox VEZFS · cloud-init · TerraformActive Directory2 DCs · DNS · DHCP · GPOProxmox Backup Serverscheduled VM backupsNPS / RADIUSMobile VPN (IKEv2) authcloudflaredoutbound-only tunnelAWS VPCprimary regionDR VPCsecondary regionZero TrustAccess (Okta) · Gateway DNSRemote usersWARP clientBOVPN · IPsecDR tunnelbackupsRADIUS → ADtunnelWARP
WatchGuard is the perimeter and VPN head-end; cloudflared connects internal apps outbound to Cloudflare, so no inbound ports are open.

Compute & storage

  • A Proxmox VE cluster on ZFS storage, with cloud-init VM templates.
  • VMs provisioned with Terraform and configured with Ansible, so rebuilding a host is a pipeline run, not a checklist.
  • Scheduled backups to Proxmox Backup Server.

Identity

  • Active Directory on Windows Server with two domain controllers, plus DNS, DHCP, OUs, GPOs and security groups.
  • Linux hosts joined to the domain with realmd / SSSD, so there’s one identity source for both Windows and Linux.

Perimeter & VPN

  • A WatchGuard Firebox as the perimeter firewall: VLAN segmentation, NAT and firewall policies.
  • Mobile VPN (IKEv2) for users, authenticated against AD through RADIUS / NPS.
  • A site-to-site IPsec VPN (WatchGuard BOVPN) from on-prem to an AWS VPC.
  • A DR tunnel to a secondary region with automatic failover. The failover runbook is documented and tested.

Zero Trust remote access

The legacy client VPN for internal apps was replaced with Cloudflare Zero Trust:

  • WARP client enrollment for users.
  • Cloudflare Tunnel (cloudflared) for internal apps. The tunnel is outbound-only, so the firewall exposes no inbound ports.
  • Identity-based Access policies through Okta.
  • Gateway DNS filtering.

Stack

Proxmox VE · Proxmox Backup Server · ZFS · Terraform · Ansible · Windows Server / AD DS · realmd / SSSD · WatchGuard Firebox · IPsec (BOVPN) · RADIUS / NPS · Cloudflare Zero Trust (WARP, Tunnel, Access, Gateway) · Okta · AWS VPC

Next case study

Serverless Jenkins on AWS Fargate →