๐ Network Architecture โ PentAGI Stack
Complete Network Design ยท VLAN Layout ยท WireGuard Tunnels ยท Deployment
1. Overview & Subnet Design
Core principle: The VPS is the hub. Everything connects outbound via WireGuard to the VPS, which has a static IP. No static IP needed at home or in the field.
IP Allocation
| Scope | Network | Purpose |
| WireGuard | 10.100.0.0/16 | Tunnel net โ all WireGuard peers get an IP here |
| 10.100.0.1 | VPS (Hostinger) |
| 10.100.1.1 | Home (Protectli pfSense) |
| 10.100.2.1 | Field (Mudi GL-E750V2) |
| Home VLANs | 10.1.x.0/24 | Home network behind Protectli |
| 10.1.0.0/24 | VLAN 1 Management (native) |
| 10.1.1.0/24 | VLAN 20 Trusted โ daily machines |
| 10.1.2.0/24 | VLAN 30 DMZ โ services |
| 10.1.3.0/24 | VLAN 40 IoT โ isolated |
| 10.1.4.0/24 | VLAN 60 Field Ops (home-side) |
| Field Net | 10.2.x.0/24 | Behind Mudi (4G LTE / field) |
| 10.2.1.0/24 | GTi15 Ultra + RTX 5060 Ti |
| 10.2.2.0/24 | BOSGAME P3, Pi 5s, Pineapple Pager |
โโ Home โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Ziply Fiber (dynamic IP) โ
โ โ โ
โ โโโโโดโโโ Protectli FW2B (pfSense) โโโโโโโโโโโโโโโโโโ โ
โ โ WAN: dhcp (Ziply) LAN: 10.1.0.0/16 โ โ
โ โ WireGuard Client โ VPS (10.100.1.1) โ โ
โ โ Firewall + inter-VLAN routing โ โ
โ โ โ โ
โ โ โโโ TP-Link TL-SG108E (managed switch) โโโโโโโ โ โ
โ โ โ Port 1: Trunk (tagged VLANs to Protectli) โ โ โ
โ โ โ Port 2: VLAN 20 Trusted โ โ โ
โ โ โ Port 3: VLAN 30 DMZ โ โ โ
โ โ โ Port 4: VLAN 40 IoT โ โ โ
โ โ โ Port 5: VLAN 60 Field Ops โ โ โ
โ โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ WireGuard (outbound โ no static IP needed) โ
โโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โโโโโโโโดโโ VPS (Hostinger) โ 10.100.0.1 โโโโโโโโโโโโโโโโโโโโโ
โ Hermes Agent ยท WWV Globe ยท PentAGI C2 โ
โ WireGuard Server (static IP, port 51820) โ
โ Bright Data Proxy (residential exit) โ
โ Docker: PentAGI stack, WWV, Traefik โ
โโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ WireGuard (outbound over 4G LTE)
โโโโโโโโดโโ Mudi GL-E750V2 โ 10.100.2.1 โโโโโโโโโโโโโโโโโโโโโ
โ 4G LTE uplink / field operations โ
โ WireGuard Client โ VPS โ
โ โ
โ โโโ Field LAN (10.2.0.0/16) โโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ 10.2.1.0/24 GTi15 Ultra + RTX 5060 Ti (big LLM) โ โ
โ โ 10.2.2.0/24 BOSGAME P3 + Pi 5s + Pineapple โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
2. Home Network (Protectli + TL-SG108E)
Hardware
| Router/Firewall | Protectli Vault FW2B โ pfSense CE |
| CPU | Intel Dual Core (Celeron J3160 or N6000 depending on gen) |
| RAM | 8 GB DDR3 |
| Storage | 120 GB mSATA |
| Switch | TP-Link TL-SG108E โ 8-port Gigabit Smart Switch |
| ISP | Ziply Fiber (dynamic IP, no static) |
Cabling
| From | To | Connection |
| Ziply ONT | Protectli WAN (port 0) | Ethernet |
| Protectli LAN (port 1) | TL-SG108E Port 1 | Trunk (tagged VLANs) |
| TL-SG108E Port 2 | โ | VLAN 20 Trusted (your machines) |
| TL-SG108E Port 3 | โ | VLAN 30 DMZ |
| TL-SG108E Port 4 | โ | VLAN 40 IoT |
| TL-SG108E Port 5 | โ | VLAN 60 Field Ops |
| TL-SG108E Port 6-8 | โ | Spare |
3. TL-SG108E VLAN Configuration
Access the web UI: Default IP is 192.168.0.1. Set a static IP on your machine in the 192.168.0.x range to reach it initially, then change the switch's IP to 10.1.0.100 (VLAN 1 management subnet).
Step 1: Reset & Configure Management IP
# Connect to the switch web UI at 192.168.0.1
# Default credentials: admin / admin
# Go to System โ System Info โ IP Address
# Change to Static: 10.1.0.100 / 255.255.255.0 / Gateway: 10.1.0.1
Step 2: Create VLANs
# Go to VLAN โ 802.1Q VLAN โ Create
VLAN 20 Name: Trusted
Tagged: Port 1
Untagged: Port 2
VLAN 30 Name: DMZ
Tagged: Port 1
Untagged: Port 3
VLAN 40 Name: IoT
Tagged: Port 1
Untagged: Port 4
VLAN 60 Name: FieldOps
Tagged: Port 1
Untagged: Port 5
Step 3: Set PVID per Port
# Go to VLAN โ 802.1Q VLAN โ PVID Setting
Port 1: 1 (trunk โ carries all VLANs)
Port 2: 20 (untagged VLAN 20)
Port 3: 30 (untagged VLAN 30)
Port 4: 40 (untagged VLAN 40)
Port 5: 60 (untagged VLAN 60)
Ports 6-8: 1 (VLAN 1 / management)
4. pfSense Configuration
4.1 Enable VLANs in pfSense
# Interfaces โ Assignments โ VLANs โ Add
VLAN Tag: 20 Description: Trusted
VLAN Tag: 30 Description: DMZ
VLAN Tag: 40 Description: IoT
VLAN Tag: 60 Description: FieldOps
4.2 Assign Interfaces
# Interfaces โ Assignments
LAN (native): 10.1.0.1/24 (VLAN 1 โ Management)
OPT1 (VLAN 20): 10.1.1.1/24 (Trusted)
OPT2 (VLAN 30): 10.1.2.1/24 (DMZ)
OPT3 (VLAN 40): 10.1.3.1/24 (IoT)
OPT4 (VLAN 60): 10.1.4.1/24 (Field Ops)
4.3 Firewall Rules
# Firewall โ Rules โ per interface
WAN (Internet):
Allow UDP 51820 # WireGuard outbound (auto)
Trusted (VLAN 20):
Allow Any โ Any (to all except IoT)
DMZ (VLAN 30):
Allow Any โ Any # Services can reach out
Allow TCP 22,443 from 10.1.1.0/24 # Admin SSH/HTTPS from Trusted
IoT (VLAN 40):
Allow Any โ WAN only # Internet egress only
Block Any โ RFC1918 # No access to private nets
Field Ops (VLAN 60):
Allow TCP 22 from 10.1.1.0/24 # SSH from Trusted to Pi 5s
Allow Any โ WAN # Outbound internet
4.4 Outbound NAT
# Firewall โ NAT โ Outbound โ Hybrid Outbound NAT
# pfSense will auto-add rules for each VLAN
# Each VLAN's traffic will NAT to the WAN IP
5. WireGuard Tunnels
5.1 VPS โ WireGuard Server
# On the Hostinger VPS (10.100.0.1)
apt install wireguard
mkdir -p /etc/wireguard && cd /etc/wireguard
wg genkey | tee server.key | wg pubkey > server.pub
cat > /etc/wireguard/wg0.conf << 'WGEOF'
[Interface]
Address = 10.100.0.1/16
ListenPort = 51820
PrivateKey = $(cat /etc/wireguard/server.key)
# PostUp/postDown for iptables to NAT between WireGuard and Docker
PostUp = iptables -A FORWARD -i wg0 -j ACCEPT
PostUp = iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i wg0 -j ACCEPT
PostDown = iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
# โโ Home (Protectli pfSense) โโโโโโโโโโโโโโโโโโโโโโโโโโ
[Peer]
PublicKey = <home_public_key>
AllowedIPs = 10.100.1.1/32, 10.1.0.0/16
PersistentKeepalive = 25
# โโ Field (Mudi GL-E750V2) โโโโโโโโโโโโโโโโโโโโโโโโโโโ
[Peer]
PublicKey = <mudi_public_key>
AllowedIPs = 10.100.2.1/32, 10.2.0.0/16
PersistentKeepalive = 25
WGEOF
systemctl enable --now wg-quick@wg0
5.2 Home โ pfSense WireGuard Client
# pfSense web UI:
# System โ Package Manager โ Available โ Install wireguard
# VPN โ WireGuard โ Tunnels โ Add
Enabled: โ
Description: VPS Tunnel
Listen Port: 51820
Interface Address: 10.100.1.1/16
Private Key: (generate)
# VPN โ WireGuard โ Peers โ Add
Enabled: โ
Tunnel: VPS Tunnel
Public Key: (VPS server's public key)
Allowed IPs: 10.100.0.0/16, 10.2.0.0/16
Endpoint: VPS_PUBLIC_IP:51820
Persistent Keepalive: 25
Important: Add a firewall rule on the WAN interface to allow UDP outbound to the VPS IP on port 51820. pfSense usually auto-adds this, but verify in Firewall โ Rules โ WAN.
5.3 Field โ Mudi WireGuard Client
# GL-E750V2 web UI (192.168.8.1):
# VPN โ WireGuard Client โ Add
Name: VPS Tunnel
Private Key: (generate via button)
Address: 10.100.2.1/16
DNS: 1.1.1.1
Endpoint: VPS_PUBLIC_IP:51820
Allowed IPs: 10.100.0.0/16, 10.1.0.0/16, 10.2.0.0/16
Persistent Keepalive: 25
Route Allowed IPs: โ
# Peer:
Public Key: (VPS server's public key)
5.4 Route Table Summary
| Peer | Can Reach | Through |
| Home (10.100.1.1) | 10.100.0.0/16, 10.2.0.0/16 | VPS tunnel |
| Field (10.100.2.1) | 10.100.0.0/16, 10.1.0.0/16 | VPS tunnel |
| VPS (10.100.0.1) | 10.100.0.0/16, 10.1.0.0/16, 10.2.0.0/16 | Direct |
6. VPS Server Setup
Running Services
| Service | Port | Access |
| Hermes Agent | CLI + Dashboard :4860 | Via WireGuard from Home/Field |
| WorldWideView | :3001 (HTTPS) | Via WireGuard from Home/Field |
| PentAGI | :8443 (HTTPS) | Via WireGuard from Home/Field |
| Traefik | :80/:443 | Public (for Let's Encrypt) |
| WireGuard | :51820 (UDP) | All WireGuard peers |
Routing for Docker Services
# Docker containers need to route through WireGuard
# Add VPS's wg0 interface to docker bridge or use --net=host
# Or: use Traefik labels to route traffic through the tunnel
# Enable IP forwarding on VPS:
sysctl -w net.ipv4.ip_forward=1
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
7. Mudi (GL-E750V2) Configuration
Initial Setup
- Insert SIM card for 4G LTE
- Power on Mudi, connect to its WiFi or plug into the LAN port
- Open
http://192.168.8.1 in a browser
- Set up the 4G LTE connection in the web UI
- Go to Network โ LAN and set IP to
10.2.1.1/24
WireGuard Tunnel
# VPN โ WireGuard Client
# Add tunnel with the settings from section 5.3 above
# Also enable "Kill Switch" to route all non-WireGuard traffic
# through 4G LTE (prevents leaking unencrypted traffic)
Field Devices Behind the Mudi
| Device | Assigned IP | Purpose |
| Mudi LAN | 10.2.1.1 | Router |
| GTi15 Ultra | 10.2.1.10 (static) | Big LLM, PentAGI node |
| BOSGAME P3 | 10.2.2.10 (static) | Field relay, Bonsai 27B |
| Pi5-1 | 10.2.2.20 (static) | Wireless attack (primary) |
| Pi5-2 | 10.2.2.21 (static) | Wireless attack (deauth/recon) |
| Pineapple Pager | 10.2.2.30 (static) | Rogue AP |
8. BOSGAME P3 Field Relay Deployment
Recommended Model: Ternary Bonsai 27B
| Metric | Value |
| Model | Prism ML Ternary-Bonsai-27B |
| Deployed size | ~7.2 GB (from 54 GB FP16 โ 9.4ร smaller) |
| Context window | 262K tokens |
| Quality retained | 94.6% of FP16 (80.49 benchmark avg) |
| Math | 93.40 avg โ 96.06 GSM8K, 87.5 AIME 2026 |
| Coding | 85.96 avg โ 93.9 HumanEval+, 82.75 LiveCodeBench |
| Agentic tool use | 74.01 โ BFCL v3 74.41, ฯยฒ-Bench 73.61 |
| Undelying arch | Qwen3.6-27B (hybrid attention: 75% linear, 25% full) |
| Throughput on P3 | ~10-15 tok/s (780M iGPU estimate) |
| License | Apache 2.0 |
| Format | GGUF Q2_0_g128 (ternary) |
Fits the BOSGAME P3's 32GB RAM with ~19-22 GB headroom for OS and tools. The 262K context window captures full pentesting session data including Pi 5 execution logs. Uses Prism ML's llama.cpp fork with custom low-bit CUDA/Metal kernels.
Deployment Script
The script does everything: installs Ubuntu Server prerequisites, Ollama, downloads the model (~7.2 GB), configures the firewall for VLAN 60 access, and runs a verification test.
# On the BOSGAME P3 after fresh Ubuntu Server 24.04 LTS install:
curl -sL https://setup.pentagi.dev/deploy-field-relay.sh | sudo bash
# Or copy the script from the pentagi skill repo:
sudo bash scripts/deploy-field-relay.sh
What the script installs:
- System packages (build tools, networking, Python)
- Firewall (UFW) โ SSH from Trusted VLAN, Ollama from DMZ + Field VLANs
- Ollama with systemd override (listen all interfaces, 24h keep-alive)
- Downloads Ternary Bonsai 27B GGUF from HuggingFace
- Creates Modelfile with 262K context config
- Imports into Ollama as
bonsai-27b
- Verification test
9. Bright Data Proxy Integration
Bright Data provides residential proxy exit nodes. Use them to route OSINT/Shodan traffic through real residential ISPs, avoiding rate limits and geo-blocking.
On the VPS
# Set up a SOCKS5 proxy tunnel through Bright Data
# Bright Data provides a proxy endpoint like: brd.superproxy.io:22225
# Test the proxy:
curl -x socks5://customer-YOUR_ZONE:YOUR_PASS@brd.superproxy.io:22225 \
https://api.shodan.io/shodan/host/8.8.8.8?key=SHODAN_KEY
For PentAGI Field Operations
The BOSGAME P3 and Pi 5s can route traffic through the VPS proxy:
# Via the WireGuard tunnel:
# Pi 5 โ WireGuard โ VPS โ Bright Data โ Target
# On the VPS, set up a local SOCKS5 forward:
ssh -D 1080 -N -f user@localhost
# Or use a transparent proxy with iptables on the VPS
# to route specific traffic through Bright Data
Integration Points
| Source | Destination | Through | Reason |
| Pi 5s / BOSGAME | Shodan API | Bright Data | Residential IP, not VPS โ avoids rate limits |
| Pi 5s | Target OSINT | Bright Data | OPSEC โ traffic appears residential |
| PentAGI | External APIs | Bright Data or Direct | Configurable per workflow |
10. Model Recommendations by Hardware
| Priority | Model | Size | Target Hardware | Purpose |
| โ Set | Ternary Bonsai 27B | 7.2 GB | BOSGAME P3 (32 GB) | Field reasoning, 262K context |
| #1 | GPT-OSS 20B | 14 GB | GTi15 (RTX 5060 Ti) | OpenAI reasoning + agentic, fits 16 GB VRAM |
| #2 | Devstral 24B | 14 GB Q4 | GTi15 (RTX 5060 Ti) | #1 open-source coding agent (46.8% SWE-Bench) |
| #3 | Qwen3 32B | ~19 GB Q4 | GTi15 (offload to 96 GB) | Strong general reasoning, ~3 GB spills at PCIe speed |
| Extra | Phi-4-mini | 2.5 GB Q4 | Pi 5 8GB (future) | Edge inference on execution nodes |
GTi15 + EX Pro dock: Full PCIe 5.0 connection to the RTX 5060 Ti 16 GB. The GTi15 has 96 GB DDR5 system RAM. With CUDA unified memory, models that overflow VRAM can offload layers into the 96 GB system pool at full PCIe bandwidth. This makes Qwen3 32B and even 70B-class models (Llama 3.3, Qwen3 72B) usable via partial GPU offload.
11. Deployment Scripts
BOSGAME P3 Field Relay
# /opt/data/scripts/deploy-field-relay.sh
# Run on fresh Ubuntu Server 24.04 LTS
# Does: system setup โ Ollama โ Bonsai 27B โ verify
curl -sL https://short.url/deploy-field-relay.sh | sudo bash
GTi15 PentAGI Node (when hardware arrives)
# Install PentAGI + LLM models
# 1. Ubuntu Server 24.04 LTS
# 2. NVIDIA drivers + CUDA for RTX 5060 Ti
# 3. Ollama for local models
# 4. Docker + PentAGI stack
# 5. Connect to VPS via WireGuard
# NVIDIA drivers:
sudo ubuntu-drivers autoinstall && sudo reboot
# Ollama:
curl -fsSL https://ollama.com/install.sh | sh
# Download models (see section 10):
ollama pull gpt-oss:20b
ollama pull devstral:24b
Full Network Bootstrap (tl;dr)
- Configure TL-SG108E with VLANs (section 3)
- Set up pfSense โ VLAN interfaces, firewall rules, WireGuard (sections 4-5)
- Set up VPS WireGuard server + add peer keys (section 5.1)
- Set up Mudi โ 4G LTE, WireGuard client, LAN subnet (section 7)
- Deploy BOSGAME P3 โ run deploy script (section 8)
- Deploy GTi15 โ Ubuntu + NVIDIA + Ollama + PentAGI
- Wire Bright Data into OSINT workflows (section 9)
Generated for PentAGI Stack ยท last updated July 2026