My current network is nice enough and functional, but ugly from a redundancy and design point of view. I currently have a flat network:
ISP: YouFibre business 2000 symmetric FTTP with /29 IPv4 routed over /31, and /48 IPv6.
Router: Whitebox x86 - Beelink EQ12 with 2x 2.5Gb Intel I225V (B3 revision, aka fixed 'I226' edition), Intel N100 4 core CPU and 16GB RAM.
Running OPNsense (soon VyOS, now my config script is written) with fq_codel QoS - hence the slight drop in headline speed to control latency under load.
Access switch - downstairs: YuanLey 9 port PoE(at) switch with 8x 2.5Gb copper and 1x 10Gb SFP+
WiFi: Ruckus R710 Dual-band 4X4:4 802.11AC Wave2 AP, powered over PoE(at) from the downstairs switch
I have most of the homelab stuff upstairs. Proxmox server (AMD Ryzen 5500U 6c12t 32GB RAM - running Podman for AGH-sync and Vaultwarden, *arr stack, SABnzbd, Emby/Jellyfin/Plex), Synology NAS (40TB for media storage over NFS), Radxa ROCK 5B running Armbian for secondary DNS, Raspberry Pi 3B+ running AlmaLinux 9.6 and currently unemployed.
The new network is only in the planning stages, but my current proposal is to move to a proper collapsed core (tier 2) network with a solid 10Gb core/distribution switch (Mikrotik CRS305-1G-4S+IN maybe?). I can then move the two existing 2.5Gb units to being straight access switches. That way I can move the existing AOC single mode fibre uplink to the new core switch, add in a multimode or DAC link for the other switch and add one for the router. The router itself will be upgraded to either an Alta Labs Route10 (dual SFP+, 10Gb firewall and NAT with 10Gb IPS) or a CR3000 whitebox with Intel X710-DA2 or Mellanox ConnectX-4 to give scope for WAN upgrades to 10Gb and beyond, at which time I only have to upgrade the two access switches as LAN devices/servers catch up on the NIC side.
Core/distribution switch wise, the CRS305-1G-4S+IN seems the best fit, with a small form factor and multiple SFP+ ports at only £85. Open to ideas, however?
WiFi by the venerable Ruckus Unleashed enterprise box is currently 'fine' (>500Mbps per client) but will be upgraded to WiFi 7 as time and budget permits.
I'm running DNS on-prem with AdGuard Home (DoT to upstreams, DoH, DoQ and DoT to clients via iOS profiles etc). Locally, split DNS pushes traffic to the LAN IP of the DNS server, and globally
The proposed changes are roughly as follows:
Does anyone care to offer any critique, comment or ideas? I'd be glad of the feedback. Thanks!
ISP: YouFibre business 2000 symmetric FTTP with /29 IPv4 routed over /31, and /48 IPv6.

Router: Whitebox x86 - Beelink EQ12 with 2x 2.5Gb Intel I225V (B3 revision, aka fixed 'I226' edition), Intel N100 4 core CPU and 16GB RAM.
Running OPNsense (soon VyOS, now my config script is written) with fq_codel QoS - hence the slight drop in headline speed to control latency under load.
Access switch - downstairs: YuanLey 9 port PoE(at) switch with 8x 2.5Gb copper and 1x 10Gb SFP+
} Uplinked over 20 metres of single mode LC fibre with 5dB attenuator, BiDi QSFPTECH 10Gb transcievers (Note to Dons: That's the OEM not a competitor)
Access switch - upstairs: YuanLey 10 port switch with 8x 2.5Gb copper and 2x 10Gb SFP+WiFi: Ruckus R710 Dual-band 4X4:4 802.11AC Wave2 AP, powered over PoE(at) from the downstairs switch
I have most of the homelab stuff upstairs. Proxmox server (AMD Ryzen 5500U 6c12t 32GB RAM - running Podman for AGH-sync and Vaultwarden, *arr stack, SABnzbd, Emby/Jellyfin/Plex), Synology NAS (40TB for media storage over NFS), Radxa ROCK 5B running Armbian for secondary DNS, Raspberry Pi 3B+ running AlmaLinux 9.6 and currently unemployed.
The new network is only in the planning stages, but my current proposal is to move to a proper collapsed core (tier 2) network with a solid 10Gb core/distribution switch (Mikrotik CRS305-1G-4S+IN maybe?). I can then move the two existing 2.5Gb units to being straight access switches. That way I can move the existing AOC single mode fibre uplink to the new core switch, add in a multimode or DAC link for the other switch and add one for the router. The router itself will be upgraded to either an Alta Labs Route10 (dual SFP+, 10Gb firewall and NAT with 10Gb IPS) or a CR3000 whitebox with Intel X710-DA2 or Mellanox ConnectX-4 to give scope for WAN upgrades to 10Gb and beyond, at which time I only have to upgrade the two access switches as LAN devices/servers catch up on the NIC side.
Core/distribution switch wise, the CRS305-1G-4S+IN seems the best fit, with a small form factor and multiple SFP+ ports at only £85. Open to ideas, however?
WiFi by the venerable Ruckus Unleashed enterprise box is currently 'fine' (>500Mbps per client) but will be upgraded to WiFi 7 as time and budget permits.
I'm running DNS on-prem with AdGuard Home (DoT to upstreams, DoH, DoQ and DoT to clients via iOS profiles etc). Locally, split DNS pushes traffic to the LAN IP of the DNS server, and globally
dns.mydomain.com
has A and AAAA records for the 10Gb VPS in Manchester, which has <2ms ping to my home and runs Nginx to load balance DNS traffic. If my home DNS goes down, it falls back to my secondary home DNS. If that (or WAN!) fails, the VPS itself has an instance running to pick up the slack until my home servers are back up. The proposed changes are roughly as follows:

Does anyone care to offer any critique, comment or ideas? I'd be glad of the feedback. Thanks!