🐎 Projeto RANCHO NEVES
Documentação completa da infraestrutura de rede — RN
Rede 2.5G • Active Directory (Linux) • TrueNAS • Jellyfin • WireGuard • VLANs
📋 Visão Geral
A rede RANCHO NEVES (RN) é uma infraestrutura corporativa independente, construída sobre o MikroTik hEX (RouterOS v7), com os seguintes componentes:
- 🌐 Internet via modem NIO ZTE ZXHN F6600P (1 Gbps, sem bridge)
- 🔐 Active Directory em Linux (Samba no Debian 13) — domínio
ranchoneves.com.br - 🧱 Firewall OPNsense com regras de isolamento por VLAN
- 📦 TrueNAS Scale RAID-Z1 (3×3TB) integrado ao AD
- 🎬 Jellyfin no ZimaOS para streaming de filmes e músicas
- 📡 Wi-Fi 6 + Mesh Intelbras cobrindo SEDE e CAMPO
- 📹 Câmeras IP + NVR com controle de acesso
- 🔗 VPN WireGuard site-to-site Matriz × Filial
- 📊 Zabbix + NetBox para monitoramento e documentação
- ⚡ Backbone de 2.5 Gbps na rede interna
🔗 Topologia da Rede
INTERNET
|
[NIO Modem ZTE F6600P]
IP: 192.168.100.1
(Modo WLAN - sem bridge)
|
Porta LAN 1
|
┌─────────────────┐
│ OPNsense WAN │
│ DHCP (NIO) │
│ OPNsense LAN │
│ 172.16.0.1/30 │
└────────┬────────┘
│
┌────────┴────────┐
│ MikroTik hEX │
│ WAN: 172.16.0.2 │
│ LAN: VLANs 10-70│
│ Gateway: .10.1 │
└────────┬────────┘
│ eth2 (TRUNK)
┌────────┴────────┐
│ Hisource 2.5G │
│ Switch Core │
└──┬──┬──┬──┬──┬──┘
┌──────┘ │ │ │ └──────────┐
[Cudy GS108E] │ │ │ [ZimaOS+Jellyfin]
Managed .50.2 │ │ │ .50.40
│ [Proxmox]│[TrueNAS]
┌────┼────┐ .50.10 .50.30
│ │ │
[TP- [Keep [Mercusys
Link] Link MR70X]
8p PoE WiFi 6
Giga 8p .10.100
│ │ │
PCs Câmeras [Intelbras Mesh]
Impr NVR .20.101/.102
🌐 Plano de IPs e VLANs
| VLAN | Nome | Sub-rede | Gateway | Finalidade |
|---|---|---|---|---|
| 10 | SEDE | 192.168.10.0/24 | 192.168.10.1 | Administradores, PCs, rede principal |
| 20 | CAMPO | 192.168.20.0/24 | 192.168.20.1 | Área externa, mesh, lavanderia |
| 30 | VISITANTES | 192.168.30.0/24 | 192.168.30.1 | Rede guest isolada |
| 40 | CAMERAS | 192.168.40.0/24 | 192.168.40.1 | Câmeras IP e NVR |
| 50 | SERVIDORES | 192.168.50.0/24 | 192.168.50.1 | Servidores físicos e VMs |
| 60 | IOT | 192.168.60.0/24 | 192.168.60.1 | Alexa, lâmpadas, automação |
| 70 | MIDIA | 192.168.70.0/24 | 192.168.70.1 | TVs, streaming, Jellyfin |
IPs Fixos dos Equipamentos
| Equipamento | IP | VLAN |
|---|---|---|
| MikroTik hEX (WAN) | 172.16.0.2/30 | — |
| MikroTik hEX (bridge) | 192.168.10.1 | 10 |
| OPNsense LAN | 172.16.0.1/30 | — |
| Proxmox | 192.168.50.10 | 50 |
| AD/DNS/DHCP (Debian VM) | 192.168.50.11 | 50 |
| TrueNAS Scale | 192.168.50.30 | 50 |
| ZimaOS + Jellyfin | 192.168.50.40 | 50 |
| Zabbix (VM) | 192.168.50.50 | 50 |
| NetBox (VM) | 192.168.50.51 | 50 |
| Cudy GS108E | 192.168.50.2 | 50 |
| Mercusys MR70X | 192.168.10.100 | 10 |
| Intelbras Twibi A | 192.168.20.101 | 20 |
| Intelbras Twibi B | 192.168.20.102 | 20 |
| NVR WiFi 8CH | 192.168.40.200 | 40 |
🔧 MikroTik hEX (E50UG) — Reset e Configuração
Reset de Fábrica
Antes de começar, o MikroTik deve ser resetado para o padrão de fábrica.
1
Desconecte o cabo de alimentação do MikroTik
2
Pressione e segure o botão RESET (ao lado da entrada de energia)
3
Conecte a alimentação enquanto mantém o botão pressionado
4
Continue segurando por ±10 segundos até o LED USR piscar
5
Solte o botão — o MikroTik reiniciará com configuração de fábrica (IP: 192.168.88.1)
Primeiro Acesso (WinBox)
Após reset: IP 192.168.88.1 — Usuário: admin — Senha: (em branco)
Conecte um PC na porta eth2 com IP fixo 192.168.88.2/24. Abra o WinBox e conecte.
Configuração Completa (CLI)
# Definir identidade /system identity set name="RN-MikroTik" # Criar usuário seguro /user add name="anderson" password="SuaSenhaForte!2026" group=full /user remove admin # Renomear interfaces /interface ethernet set [find default-name=ether1] name=WAN-OPNsense set [find default-name=ether2] name=LAN-TRUNK set [find default-name=ether3] name=eth3 set [find default-name=ether4] name=eth4 set [find default-name=ether5] name=eth5 # IP WAN (atrás do OPNsense) /ip address add address=172.16.0.2/30 interface=WAN-OPNsense # Rota padrão /ip route add gateway=172.16.0.1 # DNS /ip dns set servers=192.168.50.11,8.8.8.8 allow-remote-requests=yes
# Criar Bridge VLAN-aware
/interface bridge add name=bridge-RN vlan-filtering=yes
# Adicionar porta trunk
/interface bridge port add bridge=bridge-RN interface=LAN-TRUNK pvid=10
# Criar VLANs
/interface vlan add name=vlan10-SEDE vlan-id=10 interface=bridge-RN
/interface vlan add name=vlan20-CAMPO vlan-id=20 interface=bridge-RN
/interface vlan add name=vlan30-VISITANTES vlan-id=30 interface=bridge-RN
/interface vlan add name=vlan40-CAMERAS vlan-id=40 interface=bridge-RN
/interface vlan add name=vlan50-SERVIDORES vlan-id=50 interface=bridge-RN
/interface vlan add name=vlan60-IOT vlan-id=60 interface=bridge-RN
/interface vlan add name=vlan70-MIDIA vlan-id=70 interface=bridge-RN
# IPs de Gateway
/ip address add address=192.168.10.1/24 interface=vlan10-SEDE
/ip address add address=192.168.20.1/24 interface=vlan20-CAMPO
/ip address add address=192.168.30.1/24 interface=vlan30-VISITANTES
/ip address add address=192.168.40.1/24 interface=vlan40-CAMERAS
/ip address add address=192.168.50.1/24 interface=vlan50-SERVIDORES
/ip address add address=192.168.60.1/24 interface=vlan60-IOT
/ip address add address=192.168.70.1/24 interface=vlan70-MIDIA
# Configurar VLANs na bridge
/interface bridge vlan add bridge=bridge-RN tagged=LAN-TRUNK,bridge-RN \
vlan-ids=10,20,30,40,50,60,70
# Pools de IP
/ip pool add name=pool-SEDE ranges=192.168.10.50-192.168.10.199
/ip pool add name=pool-CAMPO ranges=192.168.20.50-192.168.20.199
/ip pool add name=pool-VISITANTES ranges=192.168.30.50-192.168.30.199
/ip pool add name=pool-CAMERAS ranges=192.168.40.50-192.168.40.199
/ip pool add name=pool-IOT ranges=192.168.60.50-192.168.60.199
/ip pool add name=pool-MIDIA ranges=192.168.70.50-192.168.70.199
# Servidores DHCP
/ip dhcp-server add name=dhcp-SEDE interface=vlan10-SEDE address-pool=pool-SEDE
/ip dhcp-server add name=dhcp-CAMPO interface=vlan20-CAMPO address-pool=pool-CAMPO
/ip dhcp-server add name=dhcp-VISITANTES interface=vlan30-VISITANTES address-pool=pool-VISITANTES
/ip dhcp-server add name=dhcp-CAMERAS interface=vlan40-CAMERAS address-pool=pool-CAMERAS
/ip dhcp-server add name=dhcp-IOT interface=vlan60-IOT address-pool=pool-IOT
/ip dhcp-server add name=dhcp-MIDIA interface=vlan70-MIDIA address-pool=pool-MIDIA
# Redes DHCP
/ip dhcp-server network add address=192.168.10.0/24 gateway=192.168.10.1 \
dns-server=192.168.50.11,8.8.8.8 domain=ranchoneves.com.br
/ip dhcp-server network add address=192.168.20.0/24 gateway=192.168.20.1 \
dns-server=192.168.50.11,8.8.8.8 domain=ranchoneves.com.br
/ip dhcp-server network add address=192.168.30.0/24 gateway=192.168.30.1 \
dns-server=8.8.8.8
/ip dhcp-server network add address=192.168.40.0/24 gateway=192.168.40.1 \
dns-server=192.168.50.11,8.8.8.8
/ip dhcp-server network add address=192.168.60.0/24 gateway=192.168.60.1 \
dns-server=8.8.8.8
/ip dhcp-server network add address=192.168.70.0/24 gateway=192.168.70.1 \
dns-server=192.168.50.11,8.8.8.8
# NAT Masquerade
/ip firewall nat add chain=srcnat out-interface=WAN-OPNsense action=masquerade
# Isolar VISITANTES
/ip firewall filter add chain=forward src-address=192.168.30.0/24 \
dst-address=192.168.0.0/16 action=drop comment="Visitantes isolados"
# Isolar CAMERAS (só servidores acessam)
/ip firewall filter add chain=forward src-address=192.168.40.0/24 \
dst-address=!192.168.50.0/24 action=drop
# Isolar IOT
/ip firewall filter add chain=forward src-address=192.168.60.0/24 \
dst-address=192.168.10.0/24 action=drop
/ip firewall filter add chain=forward src-address=192.168.60.0/24 \
dst-address=192.168.50.0/24 action=drop
# SEDE acesso total
/ip firewall filter add chain=forward src-address=192.168.10.0/24 \
dst-address=192.168.0.0/16 action=accept
# SERVIDORES acesso total
/ip firewall filter add chain=forward src-address=192.168.50.0/24 \
dst-address=192.168.0.0/16 action=accept
# Conexões estabelecidas
/ip firewall filter add chain=forward connection-state=established,related action=accept
# Drop final
/ip firewall filter add chain=forward action=drop comment="Drop restante"
🔀 Switch Cudy GS108E — VLANs na Interface Web
1
Acesso inicial: Conecte PC com IP 192.168.2.10/24. Acesse
http://192.168.2.1 — Login: admin / admin2
Alterar IP: System → IP Settings → IP: 192.168.50.2 / Máscara: 255.255.255.0 / Gateway: 192.168.50.1
3
VLANs: VLAN → 802.1Q VLAN → Habilitar VLAN Mode
Mapeamento de Portas
| Porta Cudy | Conectado a | VLAN(s) | Modo |
|---|---|---|---|
| Porta 1 | Hisource 2.5G (uplink) | 10203040506070 | Tagged (trunk) |
| Porta 2 | TP-Link LS1008G | 10 | Untagged PVID 10 |
| Porta 3 | KeepLink PoE | 40 | Untagged PVID 40 |
| Porta 4 | Mercusys MR70X | 1030 | Hybrid |
| Porta 5 | Intelbras Twibi A | 20 | Untagged PVID 20 |
| Porta 6 | Intelbras Twibi B | 20 | Untagged PVID 20 |
| Porta 7 | TV/Mídia | 70 | Untagged PVID 70 |
| Porta 8 | TV/Mídia | 70 | Untagged PVID 70 |
⚡ Switch Hisource 2.5G (Core)
Não gerenciável. Seletor físico na traseira: posição VLAN.
| Porta Hisource | Conectado a | Velocidade |
|---|---|---|
| Porta 1 | MikroTik eth2 (LAN-TRUNK) | 1G |
| Porta 2 | Proxmox Server (NIC 10G #1) | 2.5G |
| Porta 3 | Cudy GS108E Porta 1 | 1G |
| Porta 4 | TrueNAS Server | 2.5G |
| Porta 5 | ZimaOS Server | 2.5G |
| Porta 6 | OPNsense (LAN) | 2.5G |
🖥️ Servidor 1: Proxmox + VM Debian (Active Directory)
Instalação do Proxmox
# IP: 192.168.50.10/24 | Gateway: 192.168.50.1 | DNS: 192.168.50.11
# Hostname: pve.ranchoneves.com.br
# Editar /etc/network/interfaces:
auto vmbr0
iface vmbr0 inet static
address 192.168.50.10/24
gateway 192.168.50.1
bridge-ports enp1s0
bridge-stp off
bridge-fd 0
bridge-vlan-aware yes
VM Debian — Active Directory (Samba AD DC)
# VM: ID 100, 8GB RAM, 4 CPU, 64GB disco, IP 192.168.50.11
# Instalar pacotes
sudo apt install -y samba smbclient winbind krb5-config krb5-user \
libpam-winbind libnss-winbind bind9 bind9utils dnsutils ntp
# Editar /etc/hosts
# 127.0.0.1 localhost
# 192.168.50.11 dc01.ranchoneves.com.br dc01
# Provisionar domínio
sudo samba-tool domain provision --use-rfc2307 --interactive
# Realm: RANCHONEVES.COM.BR
# Domain: RANCHONEVES
# DNS Forwarder: 8.8.8.8
# Administrator Password: SUA_SENHA_FORTE!
# Copiar kerberos e iniciar
sudo cp /var/lib/samba/private/krb5.conf /etc/krb5.conf
sudo systemctl enable samba-ad-dc --now
# Criar OUs e usuários
samba-tool ou create "OU=Usuarios,DC=ranchoneves,DC=com,DC=br"
samba-tool ou create "OU=Grupos,DC=ranchoneves,DC=com,DC=br"
samba-tool group add Administradores
samba-tool user create anderson SenhaForte!2026 --ou="OU=Usuarios"
samba-tool group addmembers Administradores anderson
RSAT nas Estações Windows
PowerShell (Admin):
Get-WindowsCapability -Name RSAT* -Online | Add-WindowsCapability -Online🧱 Servidor 2: OPNsense Firewall
# WAN (conectada ao NIO): DHCP (192.168.100.x) # LAN (conectada ao MikroTik): 172.16.0.1/30 Regras de Firewall (LAN): ✓ LAN net → Internet (any) ✓ DNS → 192.168.50.11:53 ✗ Bloquear acesso ao modem NIO (192.168.100.0/24) NAT Outbound: Hybrid → WAN interface address
📦 Servidor 3: TrueNAS Scale
# IP: 192.168.50.30/24 | RAID-Z1: 3×3TB = ~6TB úteis Datasets: 📁 filmes → SMB: Filmes (acesso: Midia=Full, Colaboradores=Read) 📁 musicas → SMB: Musicas (acesso: Midia=Full, Colaboradores=Read) 📁 academicos → SMB: Academicos (acesso: anderson+tatiane=Full) 📁 visitantes → SMB: Visitantes (acesso: Admin=Full, Visitantes=Modify) 📁 backups → SMB: Backups (acesso: Admin=Full) Integração AD: Credentials → Directory Services → Active Directory Domain: RANCHONEVES.COM.BR | Account: administrator
🎬 Servidor 4: ZimaOS + Jellyfin
# IP: 192.168.50.40/24 # Jellyfin na porta 8096 docker run -d --name=jellyfin \ -p 8096:8096 -p 8920:8920 \ -v /mnt/jellyfin/config:/config \ -v /mnt/truenas/filmes:/media/filmes:ro \ -v /mnt/truenas/musicas:/media/musicas:ro \ --restart unless-stopped \ jellyfin/jellyfin:latest # Acesso local: http://192.168.50.40:8096 # Acesso externo: Port Forward no OPNsense WAN:8096 → 192.168.50.40:8096
📡 Roteador Wi-Fi 6 Mercusys MR70X
Modo: Access Point (NÃO roteador!)
IP: 192.168.10.100 | Gateway: 192.168.10.1 | DHCP: DESABILITADO SSID 2.4GHz: RN-SEDE | Senha: F9rf6G2$RA | WPA2+WPA3 SSID 5GHz: RN-SEDE-5G | Senha: F9rf6G2$RA | WPA2+WPA3 SSID IoT: RN-IOT | VLAN 60 | Somente 2.4GHz Conexão: Porta LAN MR70X → Porta 4 do Cudy GS108E
🕸️ Mesh Intelbras Twibi Giga+
Unidade A (Principal): 192.168.20.101 → Porta 5 Cudy Unidade B (Satélite): 192.168.20.102 → Porta 6 Cudy Modo: Access Point (Mesh) | DHCP: Desabilitado SSID 2.4G: RN-CAMPO | SSID 5G: RN-CAMPO-5G VLAN: 20 (CAMPO)
🔐 WireGuard Site-to-Site (Matriz × Filial)
Matriz (MikroTik hEX)
/interface wireguard add name=wg-filial listen-port=13231
/ip address add address=10.99.99.1/30 interface=wg-filial
/interface wireguard peers add interface=wg-filial \
public-key="CHAVE_PUBLICA_FILIAL" \
allowed-address=192.168.20.0/24,10.99.99.2/32 \
endpoint-address=45.168.134.174 endpoint-port=13231 \
persistent-keepalive=25
/ip route add dst-address=192.168.20.0/24 gateway=wg-filial
Filial (MikroTik RB941)
/interface wireguard add name=wg-matriz listen-port=13231
/ip address add address=10.99.99.2/30 interface=wg-matriz
/interface wireguard peers add interface=wg-matriz \
public-key="CHAVE_PUBLICA_MATRIZ" \
allowed-address=192.168.10.0/24,192.168.50.0/24,10.99.99.1/32 \
endpoint-address=IP_PUBLICO_MATRIZ endpoint-port=13231 \
persistent-keepalive=25
Para obter a chave pública:
/interface wireguard print no terminal do MikroTik🛡️ Resumo das Regras de Firewall
| De | Para | Ação | Observação |
|---|---|---|---|
| SEDE (VLAN 10) | Todas VLANs | ✅ Permitir | Admin acesso total |
| SERVIDORES (VLAN 50) | Todas VLANs | ✅ Permitir | Servidores acesso total |
| VISITANTES (VLAN 30) | Rede interna | ❌ Bloquear | Só internet |
| IOT (VLAN 60) | SEDE + SERVIDORES | ❌ Bloquear | Só internet + Jellyfin |
| CAMERAS (VLAN 40) | Fora SERVIDORES | ❌ Bloquear | Isolamento total |
| CAMPO (VLAN 20) | CAMERAS | ⚠️ Parcial | RTSP/Web apenas |
| MIDIA (VLAN 70) | Internet | ✅ Permitir | Streaming |
📊 Monitoramento: Zabbix + NetBox
Zabbix VM: 192.168.50.50 — http://192.168.50.50/zabbix Monitorar: MikroTik (SNMP), servidores (agent), switches (ICMP) NetBox VM: 192.168.50.51 — http://192.168.50.51 Documentar: Sites, dispositivos, IPs, VLANs, conexões
🗣️ Alexa e Automação IoT
VLAN 60 (IOT) — 192.168.60.0/24 SSID dedicado: RN-IOT (somente 2.4GHz) Dispositivos: • Amazon Echo (Alexa) • Lâmpadas inteligentes • Controlador de portão • Interruptores smart Regra especial: Alexa pode acessar Jellyfin (:8096) para controle de mídia
✅ Sequência de Implementação
1
Resetar MikroTik e configurar (IPs, VLANs, DHCP, NAT, firewall)
2
Conectar e configurar switches: Hisource 2.5G, Cudy GS108E (VLANs), TP-Link, KeepLink PoE
3
Instalar OPNsense entre NIO e MikroTik, configurar regras básicas
4
Instalar Proxmox, criar VM Debian, provisionar Active Directory (Samba AD DC)
5
Instalar TrueNAS, criar pool RAID-Z1, datasets, integrar ao AD
6
Instalar ZimaOS + Jellyfin, conectar aos datasets do TrueNAS
7
Configurar Wi-Fi: Mercusys MR70X (AP), Intelbras Twibi Mesh
8
Conectar câmeras e NVR ao KeepLink PoE (VLAN 40)
9
Configurar WireGuard site-to-site Matriz ↔ Filial
10
Zabbix + NetBox para monitoramento e documentação
11
Alexa + IoT na VLAN 60, testar isolamentos e ajustes finais
🐎 Projeto RANCHO NEVES — Documentação v1.0 — Julho 2026
Domínio: ranchoneves.com.br | Rede: RN