Soldato
- Joined
- 8 Jan 2003
- Posts
- 3,814
- Location
- Scotland
Personally I have split my IoT devices onto a separate VLAN from anything important and it is not a lot of work to do so.
Given I had quite a few things like wifi enabled bulbs I created a new SSID for non-IoT devices and then assigned the old one to a separate VLAN via the Ubiquiti controller (seemed the easiest way to do that as it meant that the IoT devices did not need to be reconfigured as they were just using the same SSID as before as far as they were concerned and its a lot easier to reconfigure normal devices). Add any wired IoT devices to the new VLAN at the switch port level (e.g. Hive Hub).
Create firewall groups for the address ranges of each VLAN and then create a firewall rule on the Controller which blocks devices on the IoT VLAN from instigating connections to the "main" network. This means that devices on the "main" network can access the IoT network for management and then devices can then respond but IoT devices cannot communicate on their own to the "main" network.
Took maybe 30 minutes including Googling to find out how to do it.
Pretty much the same as what I've done. Only thing that was a faff was Sonos but once I had mDNS and IGMP Proxy setup and the required firewall ports open, it worked fine. Can control my Sonos from a different wireless network/VLAN.