Riko
Occasional Visitor
Vlan hopping and mitigation:
en.wikipedia.org
Mitigation is better than no Mitigation. However, Mitigation doesn't work in the real world. Attackers are not stupids. Attackers use vulnerability. That's why Physical Network Separation is needed. Home use? VLAN is fine. It feels better. Users may feel they are safe.Vlan hopping and mitigation:
VLAN hopping - Wikipedia
en.wikipedia.org
So that would mean additional hardware and building up a separate LAN network for IoT? If that's needed, i think i am going to pass.VLAN for security is useless. Have you heard about Hopping? Physical Network Separation is needed.
Yes. Unless your IoT devices don't effect anything on your network. Sometimes IoT devices broadcast horrible packets to everywhere. It occurs network issues.So that would mean additional hardware and building up a separate LAN network for IoT? If that's needed, i think i am going to pass.
It can be as simple as you using a second network non-VLAN by using a second LAN port in Pfsense if you have an extra port in your NIC in your Pfsense router.So that would mean additional hardware and building up a separate LAN network for IoT? If that's needed, i think i am going to pass.
Is it safe to allow IoT devices to access the internet?
I've always wondered about that. I tend to block internet to all my IoT devices as I think it's more secure.
Is there a real security risk to allow Iot devices to have access to the internet even if they are on a separate network and isolated?
I have seen that some iot devices are able to be controlled by an app when internet is blocked, but they need to be connected to the main network. If they are on a vlan, for example, they do not work when blocking internet access. Why would that be?AFAIK IoT devices need the internet to connect to their respective servers to be able to be controlled by an app
Why would that be?
how come those iot devices work fine with the internet blocked when they are connected to the main wifi network?
But, when they are connected to a wifi network that is on a different subnet (using vlan), they do not work if internet access is disabled.
How does this work with things like Roborock vacuums were they need access via the internet - the app doesn’t locally connect.,,I use a IOT vlan for all my smarthome stuff.
They can not go to the Internet. If something needs to update i give it temporary access to internet for updating only.
I am on my LAN or WLAN vlan i can connect to the smarthome devices.
But not the way around smarthome devices can not reach anything.
Why would a Tuya smart switch need an IoT lan - it’s a switch… or am I missing something…I don't use mesh. My wifi devices roam between my accesspoints that are mounted on different places in my house.
The IOT Wifi SSID i use sometimes for specific Tuya smart switches with regular wpa2-psk works very well.
It ends in my IOT vlan just like the other IOT devices.
I don't see the need for a separate radio for that.
You can already do that with for example Ubiquiti Unifi accesspoints.
As you can see on the image below my normal users ssid is on 5ghz only channel 42 and 155 with wpa2-eap.
The IOT SSID is on 2.4ghz only channel 1 and 11 with wpa2-psk.
I have no problem connecting any 2.4ghz smart device to my IOT wifi.
View attachment 55412
Thread starter | Title | Forum | Replies | Date |
---|---|---|---|---|
W | I need some help with a new router and network card | Routers | 12 | |
Z | Router recommendation need. | Routers | 26 | |
S | Pro-sumer WiFi 6/6E routers with support for VLAN, VPN, SSH, and some custom firmware | Routers | 55 |
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!