4 ms·
I second the isolated VLAN approach. I host all my public-facing sites in a VLAN specifically made for that, which grants no access to anything private.
by pak9rabid 4y ago
I second the isolated VLAN approach. I host all my public-facing sites in a VLAN specifically made for that, which grants no access to anything private.
- bonestamp2 4y agoI third. I've got our computers and phones on one VLAN, everything else is on a separate VLAN (streaming boxes, cameras and other smart home crap, guest devices, etc).
- znpy 4y agoI did but a /slightly/ more expensive but web-managed switch with the precise idea of playing with vlans... Needless to say, I never "found time" to actually do it :) One day I will. In the meantime, could you please drop some links to some good introductory pages ? Thanks!
- bonestamp2 4y agoI'm using a ubiquiti managed switch and three ubiquiti access points. Basically, you setup VLANs in the Unifi management software and then you can assign ports on the switch and Wi-Fi profiles to a particular VLAN. From there, any device that connects to one of those ports or wi-fi networks will use the assigned VLAN. The access points are great because you can create several wi-fi networks and then the software provisions them to how ever many access points and switches you have, so you don't have to login to each one and set them up separately. Any links I sent would be specific to Ubiquiti, but happy to do so if you plan to use their hardware.