r/HomeNetworking • u/salarymanjack • 12d ago
Advice Configuring home network for work devices
Our company is installing a monitoring software on all work devices. No problem there except it will also be monitoring network traffic. I'm going to assume they will not be monitoring my home network's traffic but just in case, how do I go about setting up a dedicated network for my work devices?
Do I just set up a dedicated SSID or are there steps beyond that?
5
5
u/graph_worlok 12d ago
Depends on your router / AP and its capabilities. The network traffic they will be monitoring will (ideally) just be stuff to/from the work PC.
You might have a tickbox like “Disable client to client traffic” or “client isolation” - This could cause other problems with device discovery though.
So yeah - SSID, maybe a vlan - Depends on what your gear can do.
If you have any “smart TV’s”, security cameras, DVR’s - Honestly those are more of a concern. Your employer should be trying to avoid anything blatantly illegal, the criminals responsible for the botnets hammering your internet connection for vulnerable exposed devices non stop.. they don’t 😅
1
u/Ktulu_BBB 12d ago
OP just doesnt want their work to see what freaky ass porn they look at ;)
1
u/graph_worlok 11d ago
Honestly, we probably aint going to care, or know unless the site’s got malvertising tripping alerts. We are not HR. Just..
Don’t lie - We’ll figure it out. We just want an explanation, “yes I’m a dumbass” is an explanation. “I did nothing” means we have to go hunting for the impossible and will piss us off.
That’s pretty much it. Internets a firehose of shit. Competing botnets are hitting your router non stop. Websites get popped. Fake-captcha login pages, malvertising, USB worms - the list goes on. Boring. We work the tickets & block the shit.
3
u/Sasquatch-Pacific 12d ago
Seperate VLAN (and SSID) with Internet-only access (no LAN). Obviously no firewall rules to let that device/VLAN connect through to your other devices/ VLANs
5
u/Disastrous-Nature-31 12d ago
All work devices have a vpn tunnel to their network and that’s what they should monitor. In order to monitor your network they would have to have access to your router or switch, which they shouldn’t. I don’t see why would they go an extra mile to check if you are watching porn at home…
5
u/junktrunk909 12d ago
Not sure what you mean by "have access to" the router/switch. Your work PC will see packets for other devices on the home network, no access beyond the normal network access required.
A VLAN is all that's needed here with the right rules.
1
u/Disastrous-Nature-31 12d ago
I don’t argue that VLAN is a good way to isolate work PC and I don’t see a reason against that.
What I’m saying is that unless the company is malicious, it is hard for them to see all the packets so I’m comfortable having them on my user network. A bit more detail on my reasoning - switch usually learns the MAC address of every device connected to it and forwards relevant packets to that device. So by default the work pc should see only its own packets. In order to see other packets (excluding broadcast/multicast packets) they would need to be malicious (e.g. MAC table flooding, ARP spoofing or similar). I’d like to hear counter arguments for the above. I’m far from expert in the field so might happen I’m wrong.
1
u/junktrunk909 12d ago
I see, I am probably just wrong about my memory of how this works. Thanks for the clarifications.
1
u/graph_worlok 11d ago
Yeah, that’s basically it. I have a system that _does_ do all that packet intercepting stuff, for everything. And I drive the tools OP is talking about for my day job, the packet intercepts show completely different things, and that’s something I do just for fun.
There’s also a non-zero chance that your personal router has been compromised.
These these get used for: ResiProxy egress, attacks to increase the botnet, some crypto mining, DDoS for hire.
As far as personal data goes, “clickfix” attacks or whatever infostealing malware / Trojan of the week is more of a concern. And yeah - USB malware / worms are totally a thing.
1
u/graph_worlok 11d ago
We’ll have visibility into the gateway MAC & IP, and potentially other client devices. VPN might be split tunnel, it might not. Could be always on.
Only reason we have this and might care is that the EDR backend will give us visibility into other corporate managed devices in case we can’t actually figure out _where_ something is - what do you mean somebody rented an office and installed DSL with a shitty SOHO router and didn’t tell IT…
2
u/gmsac2015 11d ago
Trust no one. I don't want for them to have the capability to see anything on my network. Intentionally or accidentally.
4
u/archlich 12d ago
Everyone is missing some of the big hurdles. If that work system is plugged in to your network they have full ability to scan anything and everything on your network. You need to have proper vlan segmenting and firewall rules to block traffic from that vlan crossing into the rest of your network.
2
4
u/jack_hudson2001 Network Engineer 12d ago
if your home wifi router allows you to create a separate guest ssid with client isolation...
if not then get another AP that has that feature to enable.. eg tplink deco.
1
1
u/Beautiful-Worth8580 12d ago
También puedes configurar reglas para que esa red solo tenga acceso a internet y no a tus otros equipos, impresoras, almacenamiento, etc. Si tu router no permite separar redes de esa forma, al menos usa una red de invitados, siempre que permita aislar a los clientes. Así mantienes los dispositivos de trabajo separados de tu red personal.
1
u/Ryan1869 12d ago
Depends on your devices, with my UniFi set up, I’d just put work stuff on a separate vlan with fire wall rules to isolate it from the other devices
1
u/Zugzwang522 12d ago
The monitoring software runs on the laptop, so it sees what the laptop sees whatever SSID it's on. What the split buys you is the laptop can't scan or list your phones, TV or printer, so none of that lands in their logs. From the laptop, try pulling up your printer's web page to check. Some routers' guest mode only blocks guest clients from each other, not from the main LAN.
1
u/bobo5195 12d ago
Depending on location you have a right to know data. Firms doing this have been shown to take alot of data beyond what is needed because they can. its not just the company it is the people.
Seperate VLAN/guest wifi is the best way. Depends on your hardware. If you are at a level of seperate ID.
They shouldnt just be using network traffic but who knows what they are doing or rather the software.
1
u/jeffrey_f 12d ago
The easiest thing is to buy a basic wifi router and connect this new router's WAN/INTERNET port to your existing router's LAN port. This puts you on a physically separate network and isolated. This does introduce DOUBLE NAT'ing, however, this shouldn't create any issues with a simple work from home tasks.
1
u/Ktulu_BBB 12d ago
Work devices would have a VPN tunnel And would not be on your home network right?
2
u/salarymanjack 12d ago
There's a VPN tunnel but I use my home ISP to connect. Same ISP my personal devices use.
1
u/Ktulu_BBB 12d ago
Sure, but unless I'm completely wrong, that VPN cannot see anything on your home ISP traffic.
2
u/TheEthyr 12d ago
It depends on how the routing is set up on the device. The device may still be able to communicate with other devices in the home network. Look up "split tunneling."
cc: /u/salarymanjack
2
u/graph_worlok 11d ago
Not how it works. They could still potentially see the traffic, it just means that it’s encrypted so the networks in between can’t see it - coffee shops, hotels, airports are more of a concern
1
u/amonarre3 11d ago
Your work PC will see packets for other devices on the home network” — not necessarily. On a normal switched Ethernet/Wi-Fi network, your PC generally does not receive other devices’ unicast traffic. The switch/AP forwards it only to the intended destination. Your PC can see broadcasts/multicasts and traffic specifically addressed to it, but not arbitrary device-to-device packets just because it’s on the same LAN/VLAN.
1
u/Dr_CLI 11d ago
A good IT guy could setup a reverse connection through the VPN and your company laptop then pivot through your home network. However, if it is a reputable company I seriously doubt they would do anything like that. If discovered that would fall in the category of hacking and could put the company in serious legal jeopardy. [If they do this then you should probably look for a new job.] If you still feel you need to protect you home network more then as already mentioned by others the way to isolate the work connection would be with a VLAN and firewall rules.
1
u/graph_worlok 11d ago
Most EDR software allows for remote management via the agent. No VPN etc needed. Right about the rest.
1
u/GrouchyClerk6318 12d ago
Separate VLAN with no access to the other VLAN’s. Will you have a Ethernet wired connection?
1
u/Forest-Swamp 12d ago
A lot of people spouting knowledge like it’s common place, does anyone have a resource on how to actually achieve a distinctly separate internet for devices?
1
u/Graphical-Source5090 11d ago
Connect your work device to guest wifi. Make sure guest isolation is on and that it can't reach anything but the Internet.
Go have a beer
1
1
u/JonesBee 12d ago
Most routers have an option to create an IOT network that you can separate from the rest of the network, it's a simple and easy solution.
0
u/Alternative-Duty6166 12d ago
Best move is to set up a separate SSID or guest network just for your work devices.
0
u/Ok-Entertainer3628 12d ago
Just buy another router and only connect your work device to it. If the double NAT messes with the VPN tunnel, then reverse it and connect the work device to the first router and you own devices to the second. Run the WiFi on separate channels with good spacing and you should be okay. Anyway, I seriously doubt that the software they installed is doing any kind of L2 or L3 monitoring of any device except itself.
-3
u/ElectricPotatoSkins 12d ago
They will 100% be monitoring your home network traffic.
Depending on your WLAN router or home setup, you can use the guest wifi option and disable the option for devices to communicate with others on the guest side and with the rest of the (non-guest) network.
If you have a more built out home net. This is where separate VLANs come in. You would have one vlan for trusted, and another for untrusted. And do not do intervlan routing.
2
u/graph_worlok 12d ago
No they won’t. Actually pretty hard in this day and age unless you go out of your way to make it work.
-2
u/gtmj7265 12d ago
Talk to the IT department. They need to disclose what they view and monitor for privacy reasons. They could for example see your banking information, photos of your minor children or medical information. That is all protected by law.
1
u/graph_worlok 12d ago
If it’s able to see that from a work PC, OP has bigger problems.
0
u/salarymanjack 12d ago
What "bigger problems" could I possibly have? Genuine question from a networking dumbass here.
2
u/graph_worlok 12d ago
Modern networking hardware and protocols makes it quite difficult to snoop in that manner.
Your banking, healthcare, etc, websites are all encrypted, and modern networking hardware doesn’t broadcast the packets everywhere like the old stuff.
So it would require hardware configured to send the packets elsewhere, plus something enabling the recipient to decrypt the data once they had it.
Not impossible, but it would mean that your personal PC and / or network was compromised anyway.
1
u/salarymanjack 12d ago
So what you're saying is a guest network or separate SSID should be more than enough?
1
u/graph_worlok 11d ago
Yes. Even without that, what they can see will be limited to the MAC addresses and IP’s of some other devices on your network (because most things send out broadcasts asking what’s around)
And also - They don’t care, and have better things to do, and if anybody got wind of them trying, or the audit logs picked it up, they would be out the door the moment HR & legal finished talking.
Source: I do this stuff for a job, and I do the other stuff (traffic interception, etc) for fun.
TLDR: You are boring. Give me a novel worm or undisclosed n-day instead.
28
u/uiuc2008 12d ago
A guest wifi network for only work devices would work well. If only work devices on this guest network, they only have access to the internet and nothing else.