<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Home network segmentation | Is it overkill or necessary]]></title><description><![CDATA[<p dir="auto">I have asked about the same subject on another forum (not pfSense) but I'd like more input before I make my mind.</p>
<p dir="auto">So I am a home user with my girlfriend and her kid.  I have been reading on how to protect my home network from ransomware and sure, I'd like to limit this possibility as much as possible.</p>
<p dir="auto">If one is googling for network protection and VLAN, sure he will get a lot of documentation of how it is absolutely necessary.  But as I am not a networking expert, I just can't be sure wether it is or not.</p>
<p dir="auto"><strong>Actual setup and possible configuration</strong><br />
So here is a picture of my actual network in which all hosts are in the same subnet 10.0.0.0/24.</p>
<p dir="auto">The grey shaded area represent physical rooms while the colored shaded area represent segmentation I should go with if I were to follow what I gathered on the subject.</p>
<p dir="auto">Any thoughs on that will be much appreciated.</p>
<p dir="auto">Thanks.</p>
<p dir="auto">[EDIT]<br />
My question <strong>is not</strong> how to segment this.</p>
<p dir="auto">It is : is it overkill or is it really useful.  And if it's overkill, what would be a more sensible config.</p>
<p dir="auto"><img src="/assets/uploads/files/1633287337777-a386991e-c464-4b5b-8fe6-aecd5d79c8e2-image.png" alt="a386991e-c464-4b5b-8fe6-aecd5d79c8e2-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/166961/home-network-segmentation-is-it-overkill-or-necessary</link><generator>RSS for Node</generator><lastBuildDate>Fri, 12 Jun 2026 15:12:11 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/166961.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 03 Oct 2021 18:56:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Home network segmentation | Is it overkill or necessary on Sun, 03 Oct 2021 20:47:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ninthwave">@<bdi>ninthwave</bdi></a></p>
<p dir="auto">One very important thing, don't let them run as Admin!!!  Most people get a Windows computer and run as Admin, which leaves the computer wide open for malware.  Run as a user and only use the Admin account when necessary.  This is the way things are normally done in the Linux/Unix world.</p>
]]></description><link>https://forum.netgate.com/post/1004230</link><guid isPermaLink="true">https://forum.netgate.com/post/1004230</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Sun, 03 Oct 2021 20:47:23 GMT</pubDate></item><item><title><![CDATA[Reply to Home network segmentation | Is it overkill or necessary on Sun, 03 Oct 2021 19:21:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bingo600">@<bdi>bingo600</bdi></a> said in <a href="/post/1004221">Home network segmentation | Is it overkill or necessary</a>:</p>
<blockquote>
<p dir="auto">Why do you specify adult &amp; kid in the same vlans ?</p>
</blockquote>
<p dir="auto">There is only one PC for adult and one PC for the kid.</p>
<p dir="auto">I would believe I present as much risk as the kid since it is not impossible that I click an attachment in an email.  But I am not sure.</p>
<p dir="auto">And a single firewall rule can keep the kid from accessing the router.</p>
]]></description><link>https://forum.netgate.com/post/1004224</link><guid isPermaLink="true">https://forum.netgate.com/post/1004224</guid><dc:creator><![CDATA[NinthWave]]></dc:creator><pubDate>Sun, 03 Oct 2021 19:21:57 GMT</pubDate></item><item><title><![CDATA[Reply to Home network segmentation | Is it overkill or necessary on Sun, 03 Oct 2021 19:14:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ninthwave">@<bdi>ninthwave</bdi></a><br />
This looks a bit like my setup <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f600.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--grinning" style="height:23px;width:auto;vertical-align:middle" title=":grinning:" alt="😀" /></p>
<p dir="auto">Why do you specify adult &amp; kid in the same vlans ?<br />
It would prob be easier to have kids in one vlan &amp; adults in another , then it's easy(ier) to filter kids.</p>
<p dir="auto">I ended up putting the WiFi printer in the "Phone Vlan" , and denying it access to the Inet. This was due to the Wife wanting to print from her phone <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f915.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--face_with_head_bandage" style="height:23px;width:auto;vertical-align:middle" title=":face_with_head_bandage:" alt="🤕" /> , and the phone would not see the printer on another vlan. And PC's etc have no issue seeing the printer on the "phone vlan"</p>
<p dir="auto">/bingo</p>
]]></description><link>https://forum.netgate.com/post/1004221</link><guid isPermaLink="true">https://forum.netgate.com/post/1004221</guid><dc:creator><![CDATA[bingo600]]></dc:creator><pubDate>Sun, 03 Oct 2021 19:14:52 GMT</pubDate></item></channel></rss>