I maintain a double stack since 5 years and apart of some small nuisance I never had a real problem.
Ipv6 has been with us for more than 20 years, and It is true that to have that fine grain control in ipv6 you will need to go to a prosumer devices, but those are not that expensive and if you have a home lab you should check on them anyway....
The amount of swap used is not a good indicative, you need to check if there is a big exchange of data per second/minute. This is the only indicative of an out of memory system.
Sometimes, some regions of data memory "age" in ram without any access for a long periods of time, the the kernel here has two options, it could destroy the region knowing it could recreate it when needed (with some cpu overhead) or moved this to a swap file when the ram structure already in the swap file and release than section.
Which regions are good candidates for this? Buffers, specially in the fs, code region used for processes or even data sections of a long sleeping process...
Checking your data, if those 5gb are created over a long period of time I would not care a lot about it. Remeber how big the swap is, isn't that important vs real traffic (in or out) to it
OK, then assuming that you already discarded to run 2 cables and others in this thread provided a very good guide of how to do vlan, I can only recommend to setup some aggregation channels in your opnsense box and some switches to at least mitigated the performance hit.
Not now, of course, first you need yiur setup working
My setup is "simple" and all these monitoring functions are performed in my opnsense box with the telegram plugin.
Most of the alerts are pretty basic and are done into the FW level or the outbound basic logging. So opnsense with the basic tooling is just enough.
I have in my todo to connect the logging system from opnsense to a proper Prometheus/grafana system to really have proper log of several days without having an impact on the FW but I never find the time to do it (lazyness problem)
Segment the network as much as feasible, forbid the communication between the segments via FW rules, and set an alert when those rules are triggered.
For example: your dmz should never initiate any type of communication with your lan segment, your lan segment should not try to access services outside ports 80/443, your dns should log all resolutions performed and it would be nice to have at least a black list.
None of them should have dns over tls, and for specific hosts and networks segments, new domains with very looong active but idle connections should trigger an alert.
My personal opinion is that for a homelab is not realistic to perform a dpi to check that there is not an active attack ongoing, neither from the raw processing power, either from the human effort side, your best chance is to alert when something unusual is happening and then adjust your rules of the are false positives
The only thing I can tell is that it is totally worthless.
Because you can not have an uga ipv6, then obviously you will have an ula served via dhcpv6 with ipv4 local address (double stack).
And in this point you will realize that most computers implementation select which ip address to use following prio: ipv6 uga -> ipv4 -> ipv6 ula
So even if you do all the things right, your clients will not use it because ipv4 is there and you cannot deselect it because I assume you still want connectivity
I think you are missing the point how easy is to fuck things up in a console with truenas when trying to activate de duplication or making a backup VS the same thing in a user friendly, already tested private solution. Of course from the noob point of view.
Installing truenas when having no idea about almost anything is cumbersome, dealing with the millions options (some of them incompatible between them) is frustrating, cryptic error codes are discouraging....
You want people jump in? Then make it easy for them, lower the entry barrier, if not, you will find yourself alone in your ivory tower.
The exact same ia true for you synology NAS. + the limitations on how synology thinks you should do backups vs how it actually suits you.
If you already know how to setup a proper backup system, balancing the pros and cons, with a robust and solid way to avoid data loss, then you don't qualify for noob.
If you don't know any of that and still makes yiur backup system, that's the recipe of the disaster and you have real probabilities of losing data with nay option to recover.
I see your point but in this world there is only 2 options, or you have the skills, the knowledge and the time to do it by yourself, or you need to outsource it.
Assuming that the op is a real noob it is clear that the 2 first prerequisites are missing making that option unacceptable, then you can only go to the buy something easy enough for the general public.
And in top of that, in a homelab, the most sacred thing is the data, not the service, the data. If you misconfigure a nas or the automated backup system it could lead into the worst scenario: the data is lost forever.
Weighting everything I still recommend what I did. Although if instead of synology you prefer ugreen or asustor... Well that's depends of your taste
Got it, I thought it was a last segment attack (image substition) but now I see you are aiming to a fully supply chain attack.
And if you find an nswer to that, please let me know because this things have virtually not a solution that ticks all boxes