Bridge and AP Connected to Gold
Hello,
Can someone please comment on whether this is an optimized setup for my Gold in my home environment.
Main Setup
- Firewalla Gold is setup in router mode connected to Xfinity modem (Port 4)
- Linksys wireless router is setup in Bridge mode (Port 3)
- In this setup and in this Main LAN environment in Gold, I connect personal laptops, tablets, and other devices wirelessly to leverage the new Linksys WiFi 6 features
Secondary Setup
- I repurposed my old Netgear wireless router and set it up in AP mode (Port 2)
- In this setup and in this IOT Network, I connect all IOT devices, locks, thermostat, vacuum, etc.
- I created a Rule to block traffic to all local networks
- I have other wireless extenders connecting to this AP
Third Setup
- I connected a non-wireless switch to Port 1 of Gold
- This is Mixed LAN environment where a small handful of devices are hard wired to switch, XBOX, FireTV, etc.
- I created a Rule to block traffic to all local networks
- I'm not too concerned about this setup
Questions
- In my environment is it ok to have bridge and AP wireless setups connected to Gold?
- In the Secondary setup would Bridge mode be better/faster than in AP mode if it is only supporting IOT devices? The differences between Bridge and AP is very confusing.
- Could or should I disconnect AP from the Gold and move it to another place in the house? Does AP work wirelessly or does it have to be connected to Gold for AP to work?
- In the Main LAN I did not create a Rule to block traffic to all local networks. Should I?
- Everything is working as expected but is there something I need to consider in this environment?
Thanks for your feedback.
-
I would defer to the firewalla people to confirm but...
- the firewalla appliance does not provide hardware switching, everything is in software, as such you might want to avoid using it for switching purpose as much as possible... so...
- what you are doing is ok (it just uses some cpu) and a bit complicated to setup and maintain...
- you might want to consider enabling the VLAN features (there is an example in their knowledge base) which should simplify your setup a bit.
- even better, you might want to buy a switch on eBay which supports VLAN and offload the switching/VLAN completely off the firewalla and let it focus on the internet firewalling/access only. in this case, the firewalla is connected to the modem port4 and the switch port1 which is configured as your internet access VLAN.
-
Thank you, I appreciate the input! Yeah I can see how the maintaining part will/may be cumbersome. Just hoping to set it and forget it once I'm all done. I read up on the VLAN configuration articles, here, but I'm not that technical and don't have any hardware that supports that, so I might have to search for something that supports that if my current setup is not 'optimized' for the Gold.
Please sign in to leave a comment.
Comments
2 comments