What's new

Separating out your IoT devices, setting up VLANs

nodle

Administrator
Staff member
Member
How many of you separate out your IoT devices to separate network or VLAN to keep them off your main network? I have been wanting to do this and I don't think it's too hard to do depending on your router (if it's capable) and just basically reconnecting the devices to the newly created IoT network.
 
@ryanator did you ever get your VLANs set up? When my new router gets here, I am going to create about 3 new VLANs.
 
@ryanator did you ever get your VLANs set up? When my new router gets here, I am going to create about 3 new VLANs.

Yes I did. The newer firmware's relied on putting in the subnet address in the CIDR format of 192.168.2.1/24 whereas all the manuals I found had a separate field to denote it ( /24 would be defaulted to /0. I initially missed it so all my devices picked an incorrect address from dhcp.
 
Yes I did. The newer firmware's relied on putting in the subnet address in the CIDR format of 192.168.2.1/24 whereas all the manuals I found had a separate field to denote it ( /24 would be defaulted to /0. I initially missed it so all my devices picked an incorrect address from dhcp.
How many VLANs can you enable? What was your layout like?

  • Default wireless clients
  • IoT clients
  • Extra?
I am thinking about throwing all my kid's stuff on their own, and then enabling Safe Search and content filtering only on their VLAN.
 
I just found out that Ubiquity has a neat little feature called VLAN magic, where you can assign a new network, then just go into topography, highlight which devices you want moved to the new network, and it will take over and move them. You don't have to create a new SSID and then have it paired with the new network, and then have the devices reconnect to the new SSID. This will move everything for you.

VLAN Magic: a Shortcut for Smaller Sites​

VLAN Magic simplifies VLAN creation by assigning VLANs directly via MAC address, all at once.

  1. In Network, click Topology on the left navigation bar.
  2. Click the “⊕” symbol to open the Create Virtual Network panel.
  3. Name the VLAN and select devices from the topology.
  4. (Optional) Enable network isolation or block internet access.
  5. Click Apply Changes.

 
How many VLANs can you enable? What was your layout like?

  • Default wireless clients
  • IoT clients
  • Extra?
I am thinking about throwing all my kid's stuff on their own, and then enabling Safe Search and content filtering only on their VLAN.
I think DD-WRT allows a theoretical limit of over 4000, further reduced by my older router's Broadcom chip to 100+. The GUI may limit to 15 or so, with the rest needing to be scripted through a startup command and such.

By default, VLAN 0 has nothing, VLAN 1 is the default for the onboard physical ports, and VLAN 2 is for the WAN port. I only created two extra VLANs. I created several wireless virtual access points and grouped the VAPs and VLAN's into bridges, where they then get the segregation and policies. It's in the bridges where I tell it what subnet I want it to be in to separated traffic and can put script in the firewall command section to allow certain MACs or IPs to allow access to another subnet if needed (printers, etc..).

My layout plan was to have the default subnet (bridge) with no VPN, subnet with VPN, and guest subnet. Notice that I can group the virtual wireless SSIDs with or without a VLAN in a bridge and a user can wirelessly connect to what SSID needed. That way I don't need to worry MACs or IPs (allow or restriction).

I used openDNS for content filtering, which only works using my default ISP, non-VPN address. You may be wondering why that matters, I think it would be nice to still have content filtering on VPN as an option, but even the VPN supplier's content filtering didn't seem to work.
 
Last edited:
Well I got mine mostly done, I was up all night creating the networks, creating the new access points, and applying content filtering to some. Thankfully UnFi has some easy things to help with, like a default IoT category that switching to an only WPA2 and 2.4ghz band for compatibility. They also have an easy Guest network that acts like a Hotspot portal, where you can even customize the login page if you like. The biggest pain was reconnecting everything to the new SSIDs. But once it's done it's done. The also have an easy network isolation button so that networks can't talk with each other.
 
One thing to keep in mind is cross talk without opening firewall holes and directing traffic is locked out. For example, my Bose soundbar is on my IoT network, and my app for it is on my phone, which is connected to my primary network, so they can't see each other. AirPlay, Sonos, and other related things will not work without being connected to the same network. Not a big deal to me since I never use the app anyway, and it pushed its own updates down at nighttime.
 
Back
Top