• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Smart Thermostat - Passing and Blocking Data

Scheduled Pinned Locked Moved Firewalling
7 Posts 3 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    coffeecup25
    last edited by coffeecup25 May 26, 2021, 8:58 PM May 26, 2021, 8:57 PM

    I plan to install an ecobee3 lite wifi thermostat soon. It's low cost thanks to a $100 electric company rebate. My concern is iot security as it is rumored to be.

    I think it will be no big deal. Advice welcome.

    Every device on my network has a static address. The ecobee3 will also have a static address. I plan to make sure it can only address Android phones and not the home servers or any other device. A rule or set of rules should do it I believe ... Pass to Android, block to everything else on LAN. Is it that easy?

    Assuming the worst, can a linux thermostat access a windows server using smb? Or would the mfgr remove that feature as unneeded? What are the real world problems. Seriously .... not hysterical replies from someone just guessing? Yes, also I know about the deep voices coming from baby monitors.

    I also plan to use 2FA on the ecobee3.

    Thank you.

    K 1 Reply Last reply May 26, 2021, 9:28 PM Reply Quote 0
    • K
      KOM @coffeecup25
      last edited by May 26, 2021, 9:28 PM

      @coffeecup25 Create a new IoT SSID, vlan on the AP and vlan on pfSense then put all these smart nonsense devices on that network. This assumes you're using a decent AP that supports multiple SSIDs and vlans. If your network is currently flat then you can't isolate with firewall rules. You need to create a new network, put the ecobee, smart tv, roku etc on it and then you can manage intra-network traffic with firewall rules.

      1 Reply Last reply Reply Quote 0
      • C
        coffeecup25
        last edited by coffeecup25 May 26, 2021, 10:46 PM May 26, 2021, 10:39 PM

        I can do that. In fact, I already have a VLAN prepared.

        But, why go to all that trouble if a couple of rules can do the job?

        That's the original question.

        My research has turned up VLANS, hysterical non answers, over-complicated gobbledygook, talking baby monitors, and nothing very useful in the real world.

        What real world risks exist with a wifi thermostat that don't exist with my ROKU, which exists happily on the LAN. And can they be realistically eliminated by some LAN rules?

        Assume ecobee is hacked, what might they realistically be able to get at on my network? Can rules help?

        K 1 Reply Last reply May 26, 2021, 10:43 PM Reply Quote 0
        • K
          KOM @coffeecup25
          last edited by May 26, 2021, 10:43 PM

          @coffeecup25 In general, yes, firewall rules can control traffic that passes between networks. It can't control clients on the same network talking to each other.

          C 1 Reply Last reply May 26, 2021, 10:50 PM Reply Quote 0
          • C
            coffeecup25 @KOM
            last edited by coffeecup25 May 26, 2021, 10:54 PM May 26, 2021, 10:50 PM

            @kom

            Assume LAN rule. ecobee specific address ok to talk to android phone, specific address.

            Assume LAN rule, ecobee specific address blocked from LAN all addresses all protocols.

            Rules list goes on normally after that.

            This looks like ecobee can communicate with WAN, android phone and nobody else.

            pfsense allows this quite easily. Does it work as I think it does?

            How does ecobee talk to anything else in that config?

            S 1 Reply Last reply May 26, 2021, 11:01 PM Reply Quote 0
            • S
              SteveITS Galactic Empire @coffeecup25
              last edited by May 26, 2021, 11:01 PM

              @coffeecup25 said in Smart Thermostat - Passing and Blocking Data:

              How does ecobee talk to anything else in that config

              On which network is the ecobee and the Windows PC? If they are both on LAN, then it can talk directly to the IP of the PC, and the packets will not touch pfSense at all. To have pfSense route/block traffic the packets have to go through pfSense, so they have to be on separate networks with pfSense in the middle.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              C 1 Reply Last reply May 26, 2021, 11:04 PM Reply Quote 0
              • C
                coffeecup25 @SteveITS
                last edited by coffeecup25 May 26, 2021, 11:08 PM May 26, 2021, 11:04 PM

                @steveits

                Got it.

                They're talking over the switch. Thanks.

                VLAN or don't use as wifi thermostat are only choices unless I leave on home LAN.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received