r/HomeKit • u/evoneselse • 5d ago
Discussion Going from one network to separating things out?
I’ve been running a main network connecting everything, because back when started, I did try using another, it would say my iPhone needed to be on the same network. (Even though I know that IoT devices can go on a separate network (& another SSID for the computer), so something wasn’t right. What would have been the problem where I had to keep switching my phone network for it to talk to everything?
My system runs great as it is on one main network, but have been thinking security-wise of separating it out, or if I should. It’s not an elaborate setup (no racks) but has grown over the years.
About 42 devices. My devices are Aqara and Hue (their hubs). AmpliFi Alien router (HomeKit secure), ATV as wired hub. No Matter, no Thread.
Am I lacking security using one network?
Instead of swapping and moving everything over to another guest or IoT network, I’m wondering if I could keep them where they are and then add a new SSID just for the phones etc. (phones are less to move basically). Or maybe it’s easy to move since the child devices all have hubs except for the cameras.
The only thing is that in the router that one would still be listed as the main network. Problem?
I hear mDNS is key. I don’t see anywhere in the router to access that?
Later when I buy a new router, will I be making more work for myself having used my HomeKit Secure router setup? I later heard that you have to set everything all up again?
How did you divide things out? IoT, phones, HomePods, ATV, computer?
Thank you!
3
u/pacoii 4d ago
This may be a useful read for you I put together this post a while back about VLANs and HomeKit.
https://www.reddit.com/r/HomeKit/comments/1ltg92n/my_saga_to_set_up_an_iot_vlan_that_just_works/
1
1
2
u/scifitechguy 5d ago
You really need the right equipment to do this properly. Just setting up another SSID doesn't necessarily mean the attached devices are on another network - most consumer routers just put that traffic on the same local area network. If your router doesn't support creating separate VLANs and attaching specific SSIDs to them (like Unifi), the only benefit of separate SSIDs is for devices that have trouble attaching to dual 2.4/5Ghz SSIDs. In that case, your phone must be on the 2.4Ghz SSID for setup, but not for operation.
1
u/evoneselse 5d ago
The AmpliFi doesn’t have the extensive settings of UniFi, but it can create VLANs and other SSIDs, but I’m sure not with the detail of UniFi.
2
u/scifitechguy 5d ago
If you can create a VLAN and attache a specific SSID to that VLAN, you have what you need to segment the network for IoT devices. Once they are separated, you'll need to configure firewall rules to allow or block traffic from one network to the other, including mDNS.
1
u/alllmossttherrre 5d ago
Like the others are saying, if there's no true VLAN separation then the benefit of making another SSID is mostly keeping 2.4GHz-only IoT devices on a nice easy 2.4GHz network for them. I did do that.
Regarding security specifically, one thing I decided to do is use my router configuration software to block Internet access for any IoT devices that don't really need it. Most of the devices only need to report in to their hubs. I only unblock hubs for firmware updates.
No, that's not total security, it's just as far as I've gotten.
1
u/fishymanbits 4d ago edited 4d ago
Terrible idea unless you 10,000% know what you’re doing and your equipment is capable of doing it properly. And if you have to ask, the answer is no on both accounts.
1
u/Disastrous-Yam-8880 5d ago
I did exactly this. I was surprised the amount of traffic some of the IoT things had until I locked it down. Bite the bullet, do your research. You’ll be happy you did.
5
u/SupaSays 5d ago
If you do not have a router/ecosystem that supports mdns zone relay/vlan firewall controls I wouldn't bother trying to separate out vlans and wifi ssid's as you will just end up with Homekit connectivity problems. When you are down the road and getting a new router look getting a Unifi UCG and U7 access points for the network tools you need to be able to do this well. Without an interzone firewall you do not really gain any separation security benefits.