4 ms·
This is why IoT devices on my network get their own subnet and they are blocked from communicating with anything but what I allow them to communicate with, incl
by kxrm 3y ago
This is why IoT devices on my network get their own subnet and they are blocked from communicating with anything but what I allow them to communicate with, including the Internet.
Also I want to make it clear, it shouldn't have to be this way. Devices should be transparent about how they function, but sadly they are not.
- t0bia_s 3y agoAlso you can use DNS filter like NextDNS.io to block specific domains. How you setup your LAN printer from subnet to get data from your your main subnet?
- miki123211 3y agoIs your printer an IoT device? Is your Echo an IoT device? I'd say yes to both, and so the problem would persist. One way to solve this would be to put every single device on a separate vlan (like some public networks do). Just like NAT, that approach certainly has its advantages for the average user from a security perspective, but forces centralization and usage of third-party servers where it shouldn't be required. Maybe what we need is a "network administration protocol" that would give you pop-ups on your phone when devices tried to discover what's on your network.
- kxrm 3y ago> Is your printer an IoT device? Is your Echo an IoT device? >I'd say yes to both, and so the problem would persist. My IoT LAN is configured to keep each device within the subnet isolated from one another. So while they might share a subnet, they aren't able to snoop on each other. They also do not share the same switch.
- fmajid 3y agoOut of curiosity, how do you achieve that? One VLAN per IoT device?
- T3OU-736 3y agoNot OP. This is done via "L2 Isolation". WiFi access points typically have this setting, as do some wired switches (ex: Cisco's PVLAN)
- Fnoord 3y agoManaged switch with VLAN, WLAN AP with VLAN. My Ubiquiti networking stuff does this but if you want decent priced 10 gbit managed switch you're SOL. You'll end up with China stuff.
- nopurpose 3y agoOld Brocade switches are quite feature rich, but still affordable.
- fmajid 3y agoI do have Ubiquiti, actually, including two 8x10G SFP+ USW-Aggregation, but AFAIK all devices within a VLAN can still communicate with one another. In an ideal world I'd want them to be completely isolated from one another unless I explicitly set up an ACL allowing access.
- Fnoord 3y agoWithin a VLAN, sure, but that is why you should use separate VLANs. Because when you use the same one, you explicitly say: I want those devices to be able to connect to each other. I just use two. One for IoT, guest WiFi, etc. And one for our server, laptops/PC, and mobile devices. But ideally I'd fine grain it further.
- fmajid 3y agoRight, so one VLAN per group of IoT devices you want to segregate together, e.g. a bunch of security cameras and their NVR would go in one VLAN, a sprinkler controller on a separate VLAN, and so on. I'm on a single VLAN and associated WLAN for all my IoT devices but I would also like to segregate them further. The 4-WLAN limit on Unifi does limit what can be done, however.
- doubleg72 3y agoPeer to peer isolation is what your missing
- tracker1 3y agoYou can enable WiFi isolation in most access points. I've thought about a second AP and lan in my router for this reason. My current AP puts guests on a separate subnet not sure how well isolated though.
- oakwhiz 3y agoWhat would make more sense, but is harder to do, is to use bridge filtering instead of assigning unique VLANs per device.
- patrickdavey 3y agoI keep seeing this suggestion (put devices on a subnet, lock them out of everything else)... Do you have a link or guide to help me understand how to set this up. It seems like a great idea!
- netsharc 3y agoThe cheapest way would be to go to your WiFi router and look for "Guest WiFi" settings, hope it's not too cheap that this functionality isn't included, activate said network, and put the devices on the guest WiFi. More complicated settings involve the keyword "VLAN", afaik most home routers don't have this.
- t0bia_s 3y agoHow would you send a data to printer that is in separate subnet?
- kxrm 3y agoUnfortunately I do not have a guide, perhaps this would be a good idea for a blog post? I'll write something up when I have a free weekend. Keep in mind that a lot of this will be heavily dependent on what kind of router and LAN configuration you have.
- sys_64738 3y agoThis is a smart idea now you mention it. Those internet of sh!t devices are back doors onto your network.
- Waterluvian 3y agoThis is a good idea that’s inaccessible to >99% of customers. That’s the part that frustrates me. We save ourselves but these companies just couldn’t care less about our teeny tiny slice of the pie.