Prosumer - what to buy - how difficult to setup?

Comments

13 comments

  • Avatar
    Firewalla

    What you want is to build a segmented network. What you need is (I assume you have a big network), is Firewalla unit (Gold SE, Gold Plus, Gold Pro) and also the same number of AP7's as your old Orbi;

    To configure firewalla correctly, you will have some type of security experience. I assume you are, since, you already segmenting networks. 

    See if you understand this https://help.firewalla.com/hc/en-us/articles/4408644783123-Network-Segmentation

    And also this https://help.firewalla.com/hc/en-us/articles/36325500638739-A-Secure-and-Better-Network-with-Firewalla-Part-4-Zero-Trust-Network-Architecture

    Since everything is integrated, it shouldn't take much time to implement what you want. 

    0
    Comment actions Permalink
  • Avatar
    Boatguy

    I read the segmentation document. My understanding is that all the segmentation is in the switch, the APs are not smart enough to process VLAN tags. Each VLAN needs its own set of APs.

     
    Is that correct?
    0
    Comment actions Permalink
  • Avatar
    Firewalla

    There are two types of segmentation.

    1. VLAN, this is part on the switch and AP7. (Firewalla AP7 can easily do VLAN)

    2. VqLAN, different technology, but works only with AP7 and firewalla switch

    You can have one set of AP, and each AP has different VLAN's on them. 

    0
    Comment actions Permalink
  • Avatar
    Ian Dickerson

    Similar situation, so I thought I'd add on to this discussion. I am getting a Gold Plus and a Switch SE soon. I currently have a 2 Gig service and cable modem and 4 TP-Link Deco BE77s in a meshwifi network. I use one BE77 as a router and have Cat6a cable between the router and an unmanaged 8-port switch which then supplies Cat6a to BE77s as a wired backhaul.

    When I replace the BE77 router + unmanaged switch with the Gold Plus + Switch SE can I increase my IoT and other network security without replacing the BE77s? They are fairly new additions to my system and I can't really justify replacing them with AP7s right now. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Hi Ian Dickerson, as long as the critical devices you're hoping to segment are wired directly to the Gold Plus and/or the Switch SE, yes, it can definitely help, since you can use VqLAN and Device Isolation. Just note, Firewalla may be unable to manage local traffic between Wi-Fi devices connected to the BE77, unless the traffic travels through Firewalla. 

    0
    Comment actions Permalink
  • Avatar
    Ian Dickerson

    Can I assign rules or ID in Firewalla to Wifi devices that connect to the BE77? For example, as long as IoT devices are in their own isolated network can I exclude them from communicating with computers or phones on a separate VLAN?

     

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Yes, of course! Firewalla can still manage traffic between different networks and to the Internet. But to get granular control over local traffic within the same network, devices would need to be connected to the AP7 or the Switch. 

    This is a great article on Network Segmentation that demonstrates how you can segment your network with Firewalla: https://help.firewalla.com/hc/en-us/articles/4408644783123-Network-Segmentation

    0
    Comment actions Permalink
  • Avatar
    Ian Dickerson

    Thank you, that was quite a helpful link.

    0
    Comment actions Permalink
  • Avatar
    Ian Dickerson

    My BE77s can make separate networks for IoT and for regular users. Can I integrate the BE77 IoT network into a Firewalla VLAN to isolate devices, or would I set the BE77 to make a single LAN and control all from Firewalla?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    I assume this is a TPLink router? if it is, you need to make sure it works as a bridge mode first, then VLAN can be used in that mode. Then it should be pretty simple, all you need is to create the VLAN inside firewalla to match to TPLink router's VLAN

    0
    Comment actions Permalink
  • Avatar
    Ian Dickerson

    Yes, I have not yet received my Gold Plus. In my current setup the TP-Link Deco BE77 is set up as Router. Once I have the Firewalla Gold installed I think if I flip the Decos to Access Point mode they will be in bridge mode.

    0
    Comment actions Permalink
  • Avatar
    Boatguy

    My understanding is that the key concept is that the Firewalla system (router, switches, APs) can't control or monitor traffic that does not transit Firewalla h/w. If the traffic is processed entirely by a non-Firewalla component, like two devices on the same third party switch or AP, Firewalla doesn't see that traffic. The network will work, to the extent the third party equipment is properly configured, but it's security is dependent upon the third party equipment and the full value of the Firewalla system is not realized.

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Yes, your understanding is correct, Boatguy. Very nicely put. 

    0
    Comment actions Permalink

Please sign in to leave a comment.