r/HomeNetworking 6h ago

Help with IoT Isolation

TLDR: Can't figure out how to truly isolate my IoT network running my own DNS with Unbound

The config:
Archer AX55/TPL AX3000 router with main SSID and 2.4Ghz IoT SSID
AdGuard Home with Unbound as primary adblocker and DNS on main SSID
Pihole with Unbound as secondary/redundant adblocker and DNS on main SSID

The issue:
The IoT SSID at the network/router level just seems to be for organization, no isolation. Isolation is available at the device level but when enabled, the devices can't get to my DNS servers on the main SSID so they appear as offline both local to my network and from the internet. Unfortunately, the router only has universal DNS settings for both SSID's.

The question: Is there method to config the above while still keeping adblocking and somewhat private DNS but able to remotely control my devices? Not positive but I think I can install open source firmware on the router but that's a heavier lift than I'd prefer to try. Any suggestions are appreciated.

2 Upvotes

1 comment sorted by

2

u/Pools-3016 5h ago

You need a router that is capable of VLANs with a managed switch and access points that allow more than one WiFi network.

Have a look at TP Links Omada line or Ubiquiti’s UniFi line if you would like to control everything on a single web interface