4 ms·
> Is your printer an IoT device? Is your Echo an IoT device? >I'd say yes to both, and so the problem would persist. My IoT LAN is configured to keep each dev
by kxrm 3y ago
> Is your printer an IoT device? Is your Echo an IoT device?
>I'd say yes to both, and so the problem would persist.
My IoT LAN is configured to keep each device within the subnet isolated from one another. So while they might share a subnet, they aren't able to snoop on each other. They also do not share the same switch.
- fmajid 3y agoOut of curiosity, how do you achieve that? One VLAN per IoT device?
- T3OU-736 3y agoNot OP. This is done via "L2 Isolation". WiFi access points typically have this setting, as do some wired switches (ex: Cisco's PVLAN)
- Fnoord 3y agoManaged switch with VLAN, WLAN AP with VLAN. My Ubiquiti networking stuff does this but if you want decent priced 10 gbit managed switch you're SOL. You'll end up with China stuff.
- nopurpose 3y agoOld Brocade switches are quite feature rich, but still affordable.
- fmajid 3y agoI do have Ubiquiti, actually, including two 8x10G SFP+ USW-Aggregation, but AFAIK all devices within a VLAN can still communicate with one another. In an ideal world I'd want them to be completely isolated from one another unless I explicitly set up an ACL allowing access.
- Fnoord 3y agoWithin a VLAN, sure, but that is why you should use separate VLANs. Because when you use the same one, you explicitly say: I want those devices to be able to connect to each other. I just use two. One for IoT, guest WiFi, etc. And one for our server, laptops/PC, and mobile devices. But ideally I'd fine grain it further.
- fmajid 3y agoRight, so one VLAN per group of IoT devices you want to segregate together, e.g. a bunch of security cameras and their NVR would go in one VLAN, a sprinkler controller on a separate VLAN, and so on. I'm on a single VLAN and associated WLAN for all my IoT devices but I would also like to segregate them further. The 4-WLAN limit on Unifi does limit what can be done, however.
- Fnoord 3y agoYou can do client isolation on the WAP. If you do this, the clients cannot contact each other. Then, on the switch you can assign like 4k VLANs. But I'm not sure how to do that. Because all the data arrives on the same port. But in theory, you have a DHCP server for say a /24 and you could give each of those IPs their own VLAN. FWIW, I try to use wired as much as possible. Although for security cameras people like to use PoE and I think if you can get physical access to the PoE port, you can also try a MITM or a physical sniffer for examples see the stuff Hak5 sells.