What's new

Do i need an IoT VLAN

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

My pfSense system has 4x 2.5gbps ports.
1 for WAN and 2 ports for the 2 nic LAG to the switch.
1 have only one unused port left.

I like to learn networking best practices and to prevent, mitigate vulnerabilities that comes with the territory.

"Not flying is always safer then flying."

 
Last edited:
VLAN for security is useless. Have you heard about Hopping? Physical Network Separation is needed.
So that would mean additional hardware and building up a separate LAN network for IoT? If that's needed, i think i am going to pass.
 
So that would mean additional hardware and building up a separate LAN network for IoT? If that's needed, i think i am going to pass.
Yes. Unless your IoT devices don't effect anything on your network. Sometimes IoT devices broadcast horrible packets to everywhere. It occurs network issues.
 
Last edited:
So that would mean additional hardware and building up a separate LAN network for IoT? If that's needed, i think i am going to pass.
It can be as simple as you using a second network non-VLAN by using a second LAN port in Pfsense if you have an extra port in your NIC in your Pfsense router.

But the other thing is if you use a VLAN with its own network it can be just as safe as a separate network. You just need to add a blocking ACL, maybe a couple, on a Cisco switch. This may not be true on other L3 switches as I have not used them, so I don't know. I am not sure a L2 switch will be as safe. I can think of ways a L2 switch would not be as safe.
 
Last edited:

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top