Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Best way to separate IOTs from main LAN?

    Scheduled Pinned Locked Moved General pfSense Questions
    24 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bthovenB
      bthoven @bthoven
      last edited by bthoven

      @bthoven said in Best way to separate IOTs from main LAN?:

      Thanks. I add IOT to Network Interface, press save, and it is now running.................same symptom as when I selected ALL........still waiting..............

      Hi,
      I solved this problem by stopping the DNS Resolver first, then additionally chose IOT interface and save. Then it registered the new setting and the resolver restarted itself.

      Thanks Steve and John for your help.

      ps. Strange, now Snort blocked Netgate forum ip 208.123.73.199. I had to remove it from the block list. :)
      642fd65e-cd2f-4441-a224-8a5938a45a6f-image.png

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Have you just installed Snort, if you have I'd advise not putting it into block mode and baseline what it doesn't like.

        FYI here are the rules I've disabled:-

        Screenshot 2019-08-08 at 09.45.17.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • bthovenB
          bthoven
          last edited by bthoven

          I monitored Snort for a week before enabling block mode.

          Could you explain why you disabled those rules? One by one rule explanation would be great.

          Thanks

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            Most of the ET Policy ones are related to my IOT network, I should really tighten up $home_net now I'm running Snort on the parent interface.

            The SIP stuff is related to a VOIP phone sat on my network.

            The rest was just normal day to day traffic.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.