sandiegoboy
Occasional Visitor
My Setup - looking for some advice on configuration and best practices. Apologize for long post and my obvious lack of knowledge
I started reading that maybe I should leverage/enforce the guest network feature. Some comments that some folks leverate then for IOT as well
- AiMesh
- I have an ASUS RT-AX86U (regular not the pro) on latest stock asus firmware. This is the main node
- I have aimesh node ASUS RT-AX58U
- I have aimesh node ASUS RT-AC68U
- Networking
- FiberOptic Terminal connected to AX86U directly
- AX86U connects to a GS108Ev3 - 8-Port Gigabit Ethernet Smart Managed Plus Switch
- Switch settings are 100% default.
- VLAN port based = Disabled
- 802.1Q is disabled
- Switch settings are 100% default.
- RT-AX58U, AC68U, some other wired devices connected to this Switch via ethernet
- Devices
- Personal Devices
- I have several laptops via wifi and also ETH. Also several smartphones
- I have a Windows 10 homeserver as well via ETH. This is properly secured
- Smart/IOT Devices on ETH
- Smartthings Hub via ETH (only option)
- 2 Brother printers via ETH (only option)
- Obi200 voip box via ETH (only option)
- One laptop in enterntainment center normally unlocked - via ETH (could be WiFi)
- Smart/IOT Devices Wifi
- Aqara Hub
- Meross Switch, MyQ garage door, Wyze doorbell and cameras
- nVidia Shield, Onn media player, MiBox media player, Smart TV
- Sonos Speakers
- Personal Devices
I started reading that maybe I should leverage/enforce the guest network feature. Some comments that some folks leverate then for IOT as well
- Guest-1 at 2G and Guest-1 at 5G are suported via vlan and get IP on 192.168.101.x and 192.168.102.x range
- Guest-2 anf Guest-3 are supported via Firewall rules and get IP on "regular" 192.168.1.x and 192.168.1.x range
- I am not clear whether I should leverage only Guest-1 or only Guest-2 / 3 or combined ? Sounds like Guest-1 is more secured but I am not sure if I should split guests visiting with my own IOT devices ? And which goes where ?
- I am questioning now my configuration AiMesh with ethernet backhaul through the switch since I have more than one VLAN? The switch (not configured for 2 VLANs) is between ai mesh nodes which support 2 VLANs
- I moved two of the media players to the guest network-1 and they seem to work fine even although the switch does not have any configuration other than default. Is this expected ? I had the sense that the devices were a tad slower than normal to start a youtube video for example
- How to deal with some of the ETH connected smart devices I rather move out of the network. The WiFi connected smart devices can move to one of the guest networks
- Some need to stay (printers/scanner) since they need direct access from PC
- Some can move to WiFi and deal with them via Guest network
- Some best to move to other VLAN via settings on Netgear Switch - port based ??
- Unfortunately one of those (Shared open PC) is connected via ETH to the AC68U and not to the switch. Worst case maybe can force this to WiFi