The whole security model starts at the network. One firewall everything routes through, three trust zones that can’t reach each other, and exactly one authenticated way in from outside. This page is the design — the addressing plan, the trust boundaries, and the actual firewall policy — not the parts list (that’s the lab overview). Home-LAN and public-IP specifics are deliberately left off; what’s here is the lab-internal design the posts already walk through, box by box.