How to isolate IoT devices (or how to create and assign devices to VLAN)

How to isolate IoT devices (or how to create and assign devices to VLAN)

How to isolate IoT devices (or how to create and assign devices to VLAN)
How to isolate IoT devices (or how to create and assign devices to VLAN)
2024-01-10 13:08:33
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.3 Build 20231201 Rel.32918

Hi,

 

I do not know how to do what I want and specifically how to set up what I want with ER605. I also do not know about VLANs.

 

What I want is to prevent IoT devices from being able to do anything to other devices on internal network. For example, I have a Roborock vacuum cleaner and I don't want anyone to exploit it to be able to do something within my network. I also don't want Roborock knowing anything about my internal network. I can't simply block access of the vacuum cleaner to Internet or block specific ports since that completely disables the ability to control the robot remotely.

 

What I have is that vacuum cleaner and few other devices I want to isolate all connected to same 2.4 GHz wifi network on one wireless router. There are few other devices on same 2.4 GHz network that I do not want to isolate. Same wireless router also has 5 GHz wifi network. Same wireless router acts only as a switch, it has no DHCP, it is just connected to one of the ports on ER605.

 

How do I isolate those IoT devices connected to the wireless router from being able to do anything to all other devices on both wireless and wired networks, with ER605? Do I create VLANs? How do I do this? I appreciate any help. Thank you.

  0      
  0      
#1
Options
2 Reply
Re:How to isolate IoT devices (or how to create and assign devices to VLAN)
2024-01-11 01:28:05
Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options
Re:How to isolate IoT devices (or how to create and assign devices to VLAN)
2024-05-28 12:20:28

  @Clive_A Thank you for replying. I am still confused after reading those articles.

 

I have one wireless router for all of my wireless devices. That router is not a DHCP server, it only acts as an access point. From all of the wireless devices that connect to this one wireless access point (which is connected to one port on ER605), I only want 2 devices to be separate from all other devices on VLAN (or another way). I do not want those 2 devices from being able to see any other devices on the network, both wireless and other wired devices connected to ER605.

 

Can I do this with VLANs on ER605 or not? I understood that I cannot since VLAN can only be applied to the entire port and not individual devices on one port.

  0  
  0  
#3
Options