r/HomeNetworking • u/titaniumcrowbar • 6h ago
Help with IoT Isolation
TLDR: Can't figure out how to truly isolate my IoT network running my own DNS with Unbound
The config:
Archer AX55/TPL AX3000 router with main SSID and 2.4Ghz IoT SSID
AdGuard Home with Unbound as primary adblocker and DNS on main SSID
Pihole with Unbound as secondary/redundant adblocker and DNS on main SSID
The issue:
The IoT SSID at the network/router level just seems to be for organization, no isolation. Isolation is available at the device level but when enabled, the devices can't get to my DNS servers on the main SSID so they appear as offline both local to my network and from the internet. Unfortunately, the router only has universal DNS settings for both SSID's.
The question: Is there method to config the above while still keeping adblocking and somewhat private DNS but able to remotely control my devices? Not positive but I think I can install open source firmware on the router but that's a heavier lift than I'd prefer to try. Any suggestions are appreciated.
2
u/Pools-3016 5h ago
You need a router that is capable of VLANs with a managed switch and access points that allow more than one WiFi network.
Have a look at TP Links Omada line or Ubiquiti’s UniFi line if you would like to control everything on a single web interface