Hi all, I have been considering upgrading the home network primarily as it pertains to security. With the implementation of many IoT devices which will continue to increase, I see this as my primary threat. I took a stab at implementing VLANs last year but could not make it work but now would like to figure it out. I would also like to use my existing router as the path to the internet but move all routing functions onto a new Layer 3 Switch. Here are my Objectives:
Here is the general plan:
RV340
SG350X-26P
SG250X-48
SG200-08
VLAN 10 “Server”
Server
Brother MFC-9340CDW
VLAN 20 “Office”
Main PC
Work PC
Mitel 5330 IP Phone
Personal Laptop (Wired & Wireless)
Golf Sim PC
Alarm Monitoring (wired)
Ring Video Monitoring (Wireless)
DogWatch Invisible Fence (wired)
Sprinkler System (Wireless)
VLAN 30 “Home”
Kids Laptops (Wireless)
iPhones, iPads
Xbox One
VLAN 50 “IoT”
Sonos (10 Zones all wired)
Light Switches
HVAC Control (Lennox wireless)
Hot tub
Alexa Devices
Smart TVs
Amazon Firesticks
AV Devices
Guest VLAN
Visiting Wireless Devices
Initial Questions:
- Decrease security exposure of IoT Devices through use of VLANs
- Segregate Kids activities from other devices
- Maintain Control over IoT (Sonos, Light Switches, Hot Tub, Thermostat, etc.) via Main PC and iPhone. Maintain Ring Monitoring on Alexa and iPhone (Parents) on the same systems
- Maintain ability to Share Central Printer/Scanner (Brother MFC-9340CDW) throughout the house permanent users
- Have separate Guest Network which can access Internet, but not any other network device
- Ensure connectivity to planned Synology Server
- KISS – Keep it Simple Sxxxxxx - if this is possible
- Maximize performance of key pieces of equipment – prevent bottlenecks
- Groundwork for Expanding wired and wireless network
- 1Gpbs ISP service with Modem (Bridged)
- RV340 Router with Security License
- SG350X-26P Switch
- SG250-48 Switch
- SG200-08 Switch
- WAP-571 (x3) setup in Cluster (may add one additional in Garage)
Here is the general plan:
- Use New SG350X-26P Switch for all Layer 3 routing (take the task off RV340)
- Use New SG350X-26P Switch to power WAP-571 devices
- Connect Server to SG350X Switch via LAG or XG Ports
- Use SG250X Switch to connect bulk of wired connections (currently 30+)
- Use SG-200-08 Switch to distribute wired connections in Family room (Golf Sim PC, AV Receiver, Xbox, Blu-ray Player
- Use Management VLAN 1 if/as required – See this in several posts – unsure why it is required..
- Server on it’s own VLAN with Printer
- Total of 5 VLANs + Guest as follows:
RV340
SG350X-26P
SG250X-48
SG200-08
VLAN 10 “Server”
Server
Brother MFC-9340CDW
VLAN 20 “Office”
Main PC
Work PC
Mitel 5330 IP Phone
Personal Laptop (Wired & Wireless)
Golf Sim PC
Alarm Monitoring (wired)
Ring Video Monitoring (Wireless)
DogWatch Invisible Fence (wired)
Sprinkler System (Wireless)
VLAN 30 “Home”
Kids Laptops (Wireless)
iPhones, iPads
Xbox One
VLAN 50 “IoT”
Sonos (10 Zones all wired)
Light Switches
HVAC Control (Lennox wireless)
Hot tub
Alexa Devices
Smart TVs
Amazon Firesticks
AV Devices
Guest VLAN
Visiting Wireless Devices
Initial Questions:
- Am I completely off base - making my life too difficult?
- Which devices need static IPs?
- Can I mix wired and wireless devices in the same VLAN?
- DHCP should be off on the WAP Cluster I assume?
- DHCP should be on the Layer 3 switch?
- Any benefit to using the 10GB (XG) ports available on the 350X and 250X switches? I will be using a server with 10Gbps connectivity
- Any benefit from using the static LAG capability on RV340?
- How Many VLANs do I need / Should I be considering?
- Should I be using the same SSID on my WAP Cluster for 2.4GHz and 5GHz signals?