MightyDuck
New Around Here
Hi there! 
I have an Asus RT-AC68U which have asusuwrt-merlin on it, and have some IoT devices (led-strip controller, air consitioneer, etc, amazon echo, harmony hub, connected all via 2.4GHz wifi) and computers/nas/smartphones (connected via ethernet and 5GHz wifi), and now I will install an Access point (Netgear wac124) instead of my non-smart switch.
What would be the easiest way to make my network a little more secure?
The smarthome devices need to see the internet and each other, but they musn’t see the main devices.
The computers need to access the internet, each other AND should see the smarthome devices (to keep their apps working on local network).
I have a developer a background, I love my IT, but iptables is just outside my knowledge. :/
I’ve looked around here and there and found two ideas.
Since I’m not familiar with iptables thus the second idea would fit my knowledge better, but I wiuld need some help in that too. If only the first point would fit the requirements then I would need a little more help.
Thanks for any advice!

I have an Asus RT-AC68U which have asusuwrt-merlin on it, and have some IoT devices (led-strip controller, air consitioneer, etc, amazon echo, harmony hub, connected all via 2.4GHz wifi) and computers/nas/smartphones (connected via ethernet and 5GHz wifi), and now I will install an Access point (Netgear wac124) instead of my non-smart switch.
What would be the easiest way to make my network a little more secure?
The smarthome devices need to see the internet and each other, but they musn’t see the main devices.
The computers need to access the internet, each other AND should see the smarthome devices (to keep their apps working on local network).
I have a developer a background, I love my IT, but iptables is just outside my knowledge. :/
I’ve looked around here and there and found two ideas.
- Try it with guest network (which is basicly a pre-setuped vlan to my understanding), but I’m not sure if they can see each other AND the main devices can see them too. Maybe it would need just an additional iptable rule
- Manually set up 2 vlan (and leave the guest channel to the real guests)
Since I’m not familiar with iptables thus the second idea would fit my knowledge better, but I wiuld need some help in that too. If only the first point would fit the requirements then I would need a little more help.

Thanks for any advice!
Last edited: