Prosumer - what to buy - how difficult to setup?
4,000 sf house on two floors. 1.2Gb cable internet service. I've been using an Orbi 6 Pro that supports VLANs, but it is EOL. I want:
1) House network for phones, computers, printers, Apple TV, music server, etc.
2) IOT network for IOT! Devices get access to the internet, but not the House network. Ideally devices on the House network can directly contact and interact with IOT devices without going through the cloud, but IOT devices can't initiate contact to the House network.
3) Guest network. Isolated from everything with internet access.
What do I buy and how is it wired up? I do have one ethernet cable between floors.
I'm a reasonably knowledgeable s/w guy with a working knowledge of networks, but not a network administrator. I don't want to spend hours defining rules for flows between ports because I'm sure I won't get it right.
-
What you want is to build a segmented network. What you need is (I assume you have a big network), is Firewalla unit (Gold SE, Gold Plus, Gold Pro) and also the same number of AP7's as your old Orbi;
To configure firewalla correctly, you will have some type of security experience. I assume you are, since, you already segmenting networks.
See if you understand this https://help.firewalla.com/hc/en-us/articles/4408644783123-Network-Segmentation
Since everything is integrated, it shouldn't take much time to implement what you want.
-
Similar situation, so I thought I'd add on to this discussion. I am getting a Gold Plus and a Switch SE soon. I currently have a 2 Gig service and cable modem and 4 TP-Link Deco BE77s in a meshwifi network. I use one BE77 as a router and have Cat6a cable between the router and an unmanaged 8-port switch which then supplies Cat6a to BE77s as a wired backhaul.
When I replace the BE77 router + unmanaged switch with the Gold Plus + Switch SE can I increase my IoT and other network security without replacing the BE77s? They are fairly new additions to my system and I can't really justify replacing them with AP7s right now. -
Hi Ian Dickerson, as long as the critical devices you're hoping to segment are wired directly to the Gold Plus and/or the Switch SE, yes, it can definitely help, since you can use VqLAN and Device Isolation. Just note, Firewalla may be unable to manage local traffic between Wi-Fi devices connected to the BE77, unless the traffic travels through Firewalla.
-
Yes, of course! Firewalla can still manage traffic between different networks and to the Internet. But to get granular control over local traffic within the same network, devices would need to be connected to the AP7 or the Switch.
This is a great article on Network Segmentation that demonstrates how you can segment your network with Firewalla: https://help.firewalla.com/hc/en-us/articles/4408644783123-Network-Segmentation
-
My understanding is that the key concept is that the Firewalla system (router, switches, APs) can't control or monitor traffic that does not transit Firewalla h/w. If the traffic is processed entirely by a non-Firewalla component, like two devices on the same third party switch or AP, Firewalla doesn't see that traffic. The network will work, to the extent the third party equipment is properly configured, but it's security is dependent upon the third party equipment and the full value of the Firewalla system is not realized.
Please sign in to leave a comment.
Comments
13 comments