Comments

11 comments

  • Avatar
    Firewalla

    May I know which part is not working? is it the discovery part or the controlling part? Is your network a single flat network? or across VLAN? do you have multiple SSIDS and devices are distributed across them?

    0
    Comment actions Permalink
  • Avatar
    rawb

    It was VQLAN. What’s the best practices for using the WAP to segment iot traffic?

    2
    Comment actions Permalink
  • Avatar
    Firewalla

    Make sense, VqLAN will block things off

    Hopefully, during beta, some of our customers can share their experience with VqLAN, but in general, VqLAN is a simpler (much simpler) version of VLAN. So many things that work with VLAN, should also work with VqLAN at a smaller scale and within your WiFi

    1
    Comment actions Permalink
  • Avatar
    Mr Robinson

    I'd like to see real world examples of how people are using in their homes.  Even the examples I see like segment iot devices... well then my phone can't talk to the iot devices so that sucks.  Outside of a guest vqlan I'm having a harder time in home use thinking of great use case that won't be more trouble than its worth.  I like the feature and idea of it, just hard time thinking of how useful it'll be in reality.

    2
    Comment actions Permalink
  • Avatar
    rawb

    Firewalla makes a good point though, with VLAN comes a lot of additional config on switches and such. vqlan makes it easy to segment stuff for the everyday person. I just completely forgot I turned it on to test it and didn't turn it back off LOL.

    1
    Comment actions Permalink
  • Avatar
    Steven

    I would hope that Firewalla being not only targeted to tech savvy individuals, but consumers, there would be some templates that could be added in the future.  Here are some examples;

    1.  IOT device only need certain ports and URLs out to the WAN to properly communicate and work.
    2.  Apple HomeKit or Samsung devices need to not only connect to the internet but also to devices that might be segregated into multiple VLANs internally.

    If there was a way to have official templates that we could easily apply to the Firewalla eco system that would allow the communication to work based on manufacture and device type. These tempates would already have ports / urls pre-defined. I would imagine that this would be a community driven templates (feedback based on testing) that would help build the tempate requirements and Firewalla would add / update them to future releases.  

    This feature is useful because Firewalla does overtime block communications and now with the introduction of Zero Trust, having to troubleshoot each device is challenging and will make individuals just stop using the firewall portion of the product if it is too complicated.

    2
    Comment actions Permalink
  • Avatar
    Andy

    With HomeKit, you have to allow communication with the home hub, which include Apple TV and HomePod. With latest updates you can allow the hubs to communicate with the group in a vqlan.

    0
    Comment actions Permalink
  • Avatar
    Steven

    Understand and agree with you @Andy, but we all would benefit as a community with some sort of templates so that we don't have segregate and group within a vqlan, and then potentially open up ports if we need communicate between other vqlans. The strength of Firewalla is the ease of use.

    1
    Comment actions Permalink
  • Avatar
    atif.ahmad

    What an excellent point @Steven  @firewalla. Templates are what we need 100%. I was thinking exactly that how do I segregate iot network HomeKit devices knowing well that they need internal connection to hubs which for examples are Apple TV iPads ets and on the other hand need internet connection and at same time we need safety.

    1
    Comment actions Permalink
  • Avatar
    atif.ahmad

    Adding. - a use case. HomeKit lock in iot vqlan and hub Apple TV in media and ipad in user vqlans

    1
    Comment actions Permalink
  • Avatar
    Steven

    I get the example in which we would want to put all of the Apple Homekit devices in one vlan / VqLAN. The hope and desire to accomplish this in creating a vlan and attaching a template called Apple HomeKit which would have all of the network protocols (ports / IP address) for those devices from a least privileged access Zero Trust perspective to access resources on the lan / wan.

    We do also need to consider if you have a device (iPhone) that cannot be pinned a certain vlan as it needs to access resources in other vlans, we could tag the iPhone with multiple templates and in return the iPhone would have access to all of those vlans and the resources.  

    This would be a nesting concepts of tagging vlans and applying rules based on a template concept.

    2
    Comment actions Permalink

Please sign in to leave a comment.