• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Isolating IoT via firewall rules

Scheduled Pinned Locked Moved Firewalling
16 Posts 7 Posters 4.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    forprocessing
    last edited by Feb 19, 2017, 7:13 PM

    Damn, good point… I did not think of that.... So, no way to stop devices on the same LAN segment from seeing other devices? (other than VLAN).... No way to force even local traffic for select devices to go through pfSense?

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Feb 19, 2017, 8:00 PM

      If your switch supports private vlans.  U should just isolate all your iot to their own vlans.  Real APs and smart switches really work ;) even for the home network and are not all that expensive for even tight budgets

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • F
        forprocessing
        last edited by Feb 20, 2017, 2:44 AM

        Thank you for responding! I hear you - what you described is the right way to go. The only reason I am looking for alternative solutions - existing equipment. I have 2 eero units, in a bridged mode. Eero makes an excellent mesh product, but it does not allow for multiple SSIDs, etc. Now I understand that getting managed switch, doing the VLAN thing and adding VLANs on AP would be the right way to go. Mind you - did not have a clue about all of this a week ago but learned by reading this great forum and asking stupid questions ;-)

        Problem is - Eero does not do any of the VLAN/ multiple SSIDs stuff…. and I am reluctant to chuck Eero away. So, was figuring out if there is any other way to fence off IoT - all of which connect via WiFi. Looks like there is no substitute for proper AP that can do VLANs. But I do not know of a solution that would be great at mesh AND support VLANs.

        1 Reply Last reply Reply Quote 0
        • D
          Derelict LAYER 8 Netgate
          last edited by Feb 20, 2017, 3:18 AM

          In order to isolate at layer 2 you need layer 2 gear that supports some form of isolation.

          pfSense (or any layer 3+ firewall/router) cannot help you.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Feb 21, 2017, 8:19 PM

            All I can suggest is sell that eero crap and get something that does vlans.  That sort of thing might be great for typical home user that just wants all their shit connected and doesn't care about any sort of security.

            That they put out a product at that price point that doesn't support vlans just blows my mind..  The netgear orbi stuff same boat no vlan support.

            If you want to secure your network and isolate different wifi devices like iot and or guest user devices, etc.  Then your going to need vlans.  So your going to want need AP that support vlans.  Or you going to have to do it old school and use different AP for each network. So you could still use your eero for say your devices network.  And then get other AP for your iot/guest users.

            I see a thread from like a year ago with eero asking about vlans.. Last update was they don't talk about future dev, but seemed to hint from year ago that might be something in future version.. I doubt it - or why didn't they put it out from the get go..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • J
              jahonix
              last edited by Feb 21, 2017, 9:17 PM

              @forprocessing:

              … and I am reluctant to chuck Eero away.

              Really, why?
              Never heard of them before so I went to their site and saw: "Alexa, manage my WiFi"  :o
              Honestly, it doesn't get much dumber.
              Go to eBay and buy a used Ruckus 7372 or the like. And while you're there, sell this piece of PR madness.

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Feb 21, 2017, 9:27 PM

                What could you do on your wifi via voice?  While I am a fan of alexa and the new voice control stuff generally speaking.  I love controlling my lights with it, and love to have it set timers and search for stuff on the internet.  Love my morning weather and news via simple voice command.  Can even change the temp in the house via voice - at a loss to what I would do with my wifi network??

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • D
                  Derelict LAYER 8 Netgate
                  last edited by Feb 21, 2017, 10:01 PM

                  The irony of an IoT Wi-Fi device not being capable of segmenting IoT Wi-Fi.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • J
                    jahonix
                    last edited by Feb 21, 2017, 10:59 PM

                    @johnpoz:

                    What could you do on your wifi via voice?

                    Give away one more piece of privacy
                    No, sorry, the application is that when you buy a new FireTV stick, it is not only pre-registered with your a-z account but with your SSID and password as well. A user shouldn't have to enter that on his own…

                    The only use is marketing and the eeror site is full of that.

                    1 Reply Last reply Reply Quote 0
                    • N
                      NOYB
                      last edited by Feb 22, 2017, 5:09 AM

                      You know what IoT makes me think of.  The Replicators on Stargate SG-1 series.  I know kinda silly isn't it.  But once those IoT things take over the world it might not seem so silly anymore.

                      https://en.wikipedia.org/wiki/Replicator_(Stargate)

                      1 Reply Last reply Reply Quote 0
                      • W
                        Wim
                        last edited by Feb 22, 2017, 1:03 PM

                        This is an interesting question for my situation too… which is double NAT (since I'm forced to use my ISP's router with DHCP/NAT).

                        Now, the Gateway on my pfSense router has the IP of my ISP's router (it was set that way by default).

                        Does this mean that, in this case, I'm able to block devices on my second LAN (devices behind pfSense) to block?

                        Maybe a stupid question, but just trying to learn.

                        1 Reply Last reply Reply Quote 0
                        • R
                          raidflex
                          last edited by Feb 22, 2017, 4:01 PM

                          I have had good success with the Ubiquiti Unifi  AC-Pro AP which is reasonably priced and you can setup multiple SSID's/Vlan's. There are also less expensive AP's with less range if you want to go the multiple AP route.  You would still need a managed switch, I would recommend the Cisco SG300 series, again not too pricey and perfect for a home environment.

                          1 Reply Last reply Reply Quote 0
                          • F
                            forprocessing
                            last edited by Feb 22, 2017, 4:42 PM

                            Here is what I cannot figure out about ubiquity. I know APs offer multiple SSIDs, but can you do true mash Wi-Fi with any line of their APs?

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator
                              last edited by Feb 22, 2017, 5:07 PM

                              They do have a new line of mesh stuff..

                              https://unifi-mesh.ubnt.com/

                              But to be honest, in a home setup why would you really want/need mesh.  I have 3 AP, a Pro, lite and LR models - can do dynamic vlans, can do min rssi, can do band steering.. Has all the features I could possible need in a such a setup for very reasonable cost.  And can do multiple vlans - if using dynamically assigned really almost no limit on the number.  If you doing ssid based vlans then you would have a limit of 4 per band.  I currently run 4 different vlans on my setup.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              16 out of 16
                              • First post
                                16/16
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                This community forum collects and processes your personal information.
                                consent.not_received