Need some help creating a KidZone
FWG in router mode which feeds a cisco switch. The house was prewired with cable so all of the network cables feed into this switch.
The home uses an eero mesh, several have haulbacks to the prewired cabling. I have no idea what wires feed what areas of the house so physical isolation seems out of the question.
Currently, every device connects to the SSID of the Eero mesh network.
On the FWG, kids devices are thrown into a target list/group.
On the FWG, can create a VLAN that basically uses all of the ports of the LAN1 trunk. The VLAN can then point to a pi-hole DNS server which i can use to further restrict the Kid group.(In theory?)
Question really is, how can i direct the devices in the Kid group to the VLAN? Ideally in the FWG i could just tag certain devices to get DHCP addresses from the VLAN vs the LAN1.
I'm not sure what I am trying to do is possible. At least I havent figured it out. Pls lmk if you have any pointers or advice.
-
Hi Daisy, thanks for getting in touch. Unfortunately, there's no way to force a device/device group to use a certain VLAN through the Firewalla app since VLANs are dynamic. Is your main concern that your kids' devices will get around your pi-hole server by disconnecting from your VLAN?
What kinds of controls do you want to enforce using your pi-hole server? -
Hi Daisy
I'm forcing my kids onto a specific VLAN via WiFi SSID. I see that you are using an eero and though I've heard of it I've never used one so I don't know if it can do what I am doing to accomplish this.
I actually just ditched a Netgear Orbi Mesh setup in favor of a 16 port Ubiquiti switch and some U6 access points to accomplish this very objective. With these APs I am able to configure up to 8 SSIDs and assign each SSID to a VLAN.
In my case, the kids devices connect to SSID "WIFI-K" and all the traffic is tagged with VLAN ID 6. In the Firewalla app I have a network associated with VLAN 6 that is just for the kids. When the kids or any of their friends connect to WIFI-K they are all pushed on to the kids VLAN that has the appropriate rules, policies, and filters for safe internet use by all kids who use the network.
You do need a WiFi router (or switch and access points) that supports multiple SSIDs and assigning those SSIDs to VLANs.
Please sign in to leave a comment.
Comments
2 comments