New Firewalla Gold SE install -- Sanity Check

Comments

1 comment

  • Avatar
    Firewalla Team

    @Jon, it sounds like you want to isolate the primary network from accessing the other two networks but access it from the IoT network. It's easy to do with two rules.
    1. Block local traffic from & to all local networks, applied to the primary network
    2. Allow local traffic from the IoT network, applied to the primary network

    In the future, the group can help if you want to give exceptions or higher-level protection to any devices. The keys are 'block' as the baseline and 'allow 'as the exception. 

    1. The priority of different levels is Device > Group > Network > Global
    2. At the same level, allow rules take precedence over block rules.


    Additionally, I would suggest introducing another cheap AP for those WiFi-only IoT devices in IoT network. Make IoT network for IoT and WiFi network for personal device only. iCloud encryption, like iCloud private relay, can't really restrict local access but hides things from being seen by your Gold SE. Firewalla protection won't fully work on those Apple devices.

    0
    Comment actions Permalink

Please sign in to leave a comment.