I'm posting this to the Asuswrt-Merlin forum because I use it on my Asus 68u. Thanks @Merlin, I have donated a few times
I would ask the forum for some help in configuring my network. I'm becoming more and more concerned with security that hence the desire to make some changes.
Below is a picture of my layout and representative devices.
Objectives:
1) All devices have access to the internet
2) My iMac and iPhone has access to all devices
3) Some devices like the Chromecast can access my NAS (note the NAS has four NICs on it)
4) No devices can access my PCs (except as in #2, my iPhone can)
5) The Apple TV must be able to access the Ecobee
6) The TV must be able to access the NAS
Extra Credit:
7) VPN into my Asus and restrict the VPN to only accessing the NAS.
The managed switches I have can do either port based vLANs or 802.1q vLANs. If need be, I could move my LAN2 to connect with the 24-Port switch instead of the router if that makes things easier.
Since my iPhone must have access to everything, should I use vLANs or should I consider two private networks - 192.x & 10.x. ?
I would need to some how need to bridge them for my iPhone to get access to both networks (not sure if technically possible, but I'm not a network guy )
Thanks for all suggestions (any and sample scripts )
I would ask the forum for some help in configuring my network. I'm becoming more and more concerned with security that hence the desire to make some changes.
Below is a picture of my layout and representative devices.
Objectives:
1) All devices have access to the internet
2) My iMac and iPhone has access to all devices
3) Some devices like the Chromecast can access my NAS (note the NAS has four NICs on it)
4) No devices can access my PCs (except as in #2, my iPhone can)
5) The Apple TV must be able to access the Ecobee
6) The TV must be able to access the NAS
Extra Credit:
7) VPN into my Asus and restrict the VPN to only accessing the NAS.
The managed switches I have can do either port based vLANs or 802.1q vLANs. If need be, I could move my LAN2 to connect with the 24-Port switch instead of the router if that makes things easier.
Since my iPhone must have access to everything, should I use vLANs or should I consider two private networks - 192.x & 10.x. ?
I would need to some how need to bridge them for my iPhone to get access to both networks (not sure if technically possible, but I'm not a network guy )
Thanks for all suggestions (any and sample scripts )