{"enrichment":{"faq":[{"a":"networking guides you through VLAN segmentation by trust level to isolate devices and services. Start by identifying your trust zones\u2014management, trusted devices, IoT, and guest networks\u2014then configure VLAN IDs on your switch and router. Use firewall rules to control inter-VLAN traffic, allowing only necessary communication paths. This prevents compromised IoT devices from accessing sensitive services and limits lateral movement during security incidents.","q":"How to set up VLANs for a home network with networking?"},{"a":"networking covers firewall configuration across nftables, OPNsense, and pfSense. Start with a default-deny policy, then explicitly allow required traffic by source, destination, and port. For nftables, define tables and chains for ingress/egress filtering. In OPNsense, use the GUI to create rules tied to interfaces and VLANs. Apply stateful inspection to track connections and block unsolicited inbound traffic. Document your ruleset for auditability.","q":"What firewall rules should I use with nftables or OPNsense in networking?"},{"a":"networking covers VPN deployment with both WireGuard and Tailscale. WireGuard offers lower overhead and direct peer-to-peer connections; use it when you control both endpoints and want minimal latency. Tailscale provides easier setup, NAT traversal, and centralized key management through its coordination server; choose it for mixed environments or when simplicity matters. networking guides configuration, key rotation, and access policies for each.","q":"How does networking help with WireGuard versus Tailscale VPN?"},{"a":"networking teaches DNS architecture using Pi-hole or AdGuard Home for filtering and blocking. Set up split-horizon DNS to resolve internal hostnames (like services.local) to private IPs for internal clients and external IPs or block them for external queries. Configure your DHCP server to point clients to your DNS resolver, then add blocklists and custom records. This prevents DNS leaks and allows seamless access to self-hosted services.","q":"How do I configure DNS filtering and split-horizon resolution with networking?"},{"a":"networking guides reverse proxy configuration with Caddy and Traefik, plus TLS automation via Let's Encrypt and ACME. Set up your reverse proxy to accept external traffic, route it to internal services, and terminate TLS. Use wildcard certificates for multiple subdomains and automate renewal. networking covers certificate pinning, HSTS headers, and integration with Docker for container-based deployments.","q":"What does networking cover for reverse proxy and TLS certificate setup?"},{"a":"networking covers SSH hardening with key-based auth, non-standard ports, and fail2ban to block brute-force attempts. It includes IDS/IPS setup with Suricata and CrowdSec to detect intrusions and anomalies. Add network monitoring with Prometheus and Grafana to track traffic patterns and alert on suspicious activity. These layers detect and respond to threats before they compromise your infrastructure.","q":"How can networking help harden SSH and monitor network security?"}],"shadow_tags":["self-hosted-infrastructure","network-segmentation","zero-trust-security","vpn-tunneling","dns-filtering","reverse-proxy-routing","certificate-automation","threat-detection","access-control","infrastructure-monitoring"],"summary_rewrite":"This skill guides you through building production-grade network infrastructure for self-hosted environments. It covers VLAN segmentation by trust level, firewall configuration across nftables, OPNsense, and pfSense, DNS architecture with Pi-hole and AdGuard Home, reverse proxies like Caddy and Traefik, VPN setup with WireGuard and Tailscale, certificate automation, and security hardening patterns. Use it whenever you're designing, implementing, or troubleshooting network topology, access control, or encrypted communications."},"files":[{"bytes":20896,"path":"plugins/infrastructure/skills/networking/SKILL.md","sha256":"ecd25dd239a2f094f964361b46f9ef5d66b81c875f2ad8987ac146bdc5b9c165","url":"https://skillfed.io/files/xobotyi/cc-foundry/networking/b00e301e/SKILL.md"}],"id":"xobotyi/cc-foundry/networking","links":{"html":"https://skillfed.io/xobotyi/cc-foundry/networking","md":"https://skillfed.io/xobotyi/cc-foundry/networking.md","repo":"https://github.com/xobotyi/cc-foundry"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":0,"language":"JavaScript","last_updated":"2026-07-10","license":"MIT","name":"networking","publisher":"xobotyi","stars":18},"relations":{"similar":[{"id":"affaan-m/ECC/homelab-vlan-segmentation"},{"id":"affaan-m/ECC/homelab-network-setup"},{"id":"affaan-m/ECC/homelab-network-readiness"},{"id":"yaklang/hack-skills/network-protocol-attacks"},{"id":"affaan-m/ECC/homelab-wireguard-vpn"},{"id":"mingchen666/Reviva/computer-network-learning"},{"id":"notque/vexjoy-agent/public-web-deploy"},{"id":"rand/cc-polymath/discover-networking"},{"id":"hypnguyen1209/offensive-claude/network-attack"},{"id":"HKUDS/CLI-Anything/cli-anything-adguardhome"}]},"slug":{"owner":"xobotyi","repo":"cc-foundry","skill":"networking"},"version":"b00e301e"}
