Comments

42 comments

  • Avatar
    Mike999

    No need for a second IP from your ISP. All traffic from both your internal networks can be routed out one external IP.
    What I would suggest is start with the gear you have, get it working, and then build from there. If things work and you’re still receiving security updates for all your APs, why change?
    I switched from Asus to UniFi for their VLAN support and so that I could break my network into 3 segments: IOT, Home, and Work. I completely segregated the Work network from the rest (disabled the mDNS, etc) because work machines have monitoring software on them. I did not want to buy multiple APs (a pile of 2x3=6 routers around the house was kiboshed) means one set of 2 AP for each of the three networks, did not want to hard wire that many APs, and wanted to use PoE to provide UPS power consistently to the entire network in the event of a power outage.
    VLANs do add a level of complexity, both config and troubleshooting. You have to be comfortable with that.
    Firewalla Gold is dead easy to config and still super powerful. It’s a solid choice. You might want to draw out your network (even by hand) before you start so have a plan.
    Hope that helps.

    1
    Comment actions Permalink
  • Avatar
    Michael Johnson

    Mike999,

    That helps more than you know, truly thank you for your time you are for real the best! I have begun drawing out my current network topology and how I think it should look.

    I’ve decided I will keep my eeros for now and get the Firewalla gold to run in router mode for me and then consider using my old eero pro for IoT segmentation.

    Within the Firewalla itself is it pretty easy to just setup a segmented network for IoT devices or would I need to setup a separate network with another router?

    0
    Comment actions Permalink
  • Avatar
    Mike999

    Separate router, meaning a second firewalla? If so, nope all in one, it can do it all from separate ports. When you have your napkin diagram done, scan and post. Happy to look at it and comment.

    0
    Comment actions Permalink
  • Avatar
    Michael Johnson

    Mike999,

    Not a separate firewalla - just a second router plugged into my FWG but I’m realizing it may have to be something other than eero for me to control it.

    Here’s a link to my napkin drawing
    https://i.imgur.com/bCFqOnY.png

    0
    Comment actions Permalink
  • Avatar
    Mike999

    That looks like an accurate depiction of what we discussed. I’d add your subnet IPs to the diagram so you keep them straight. Like:
    192.168.1.x/24 - Home
    192.168.2.x/24 - IOT
    24 meaning a mask of 255.255.255.0, nothing strange in terms of masking.
    You can pick different number instead of .1.x or .2.x. Could be .10.x and .20.x for example. I correlated the VLAN number with the IP subnet. Helps keep things straight and easy.

    0
    Comment actions Permalink
  • Avatar
    Michael Johnson

    You are truly a saint Mike999.
    Thank you my friend!

    I will be sure to add my IPs to keep them straight. All I’m going to change is adding a cheap TP Link router for the IoT network.

    0
    Comment actions Permalink
  • Avatar
    Michael Johnson

    Mike999,

    Last question I swear - is there an easy way to segment networks using the FWG and not having a second router? As in can I just create a secure guest network on the FWG for my IoT devices? Thanks again.

    1
    Comment actions Permalink
  • Avatar
    Stretch

    Yes , it's what I do.

    You create a second DHCP on one of the unused WAN ports, put your guest WAP to it, then create a FW rule that says can not talk with other segments and only the internet.

    This link you want to review.

    https://help.firewalla.com/hc/en-us/articles/360046231493-Firewalla-Tutorial-Network-Segmentation-Example-with-VLAN

    1
    Comment actions Permalink
  • Avatar
    Michael Johnson

    Stretch,

    Thank you very much this makes my life much easier. Appreciate the precise feedback and the link.

    1
    Comment actions Permalink
  • Avatar
    Robert Bell

    I will reiterate the comment about Orbi. I'm dealing with it now, its a nightmare. $1500 and its Junk. Support will string you along until you are past the 30 day return window. That seems to be their only objective. When it works its really amazing speed and range but, even in AP mode, it just randomly crashes and you will spend hours trying to get the nodes to sync back up. 

    0
    Comment actions Permalink
  • Avatar
    Mike999

    Ubiquiti APs all the way!! Returned my Orbis and have never looked back.

    0
    Comment actions Permalink
  • Avatar
    Robert Bell

    I had a bad experience with Ubi but may be willing to go back. What’s the current recommendation? I need table top APs

    0
    Comment actions Permalink

Please sign in to leave a comment.