HOME VLAN cannot access IOT VLAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

HOME VLAN cannot access IOT VLAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
HOME VLAN cannot access IOT VLAN
HOME VLAN cannot access IOT VLAN
2021-05-24 16:49:36
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.0.1 Build 20210113 Rel.35074

I'm a little bit stuck what I'm trying to do is put all my IOT devices into the IOT VLAN through a separate WIFI network and dedicated ports on my switch: TL-SG2008P v1.0 but I can't seem to figure out what I should configure to make this relatively simple setup work:



The only way I can make it work right now is by explicitily allowing IOT to access HOME but that's not what I want I only want HOME to access IOT and IOT to be able to reply back to HOME after HOME initialized the request. Say for Google Chromecast with Google TV or a Phillips HUE bridge. 
 



My end goals for this is to achieve a setup like: https://robpickering.com/ubiquiti-configure-micro-segmentation-for-iot-devices/

  0      
  0      
#1
Options
6 Reply
Re:HOME VLAN cannot access IOT VLAN
2021-05-24 18:39:45

@SchippieNL 

 

Your vlans are on different subnets? You appear to have it configured correctly, assuming you blocked the IoT from Home.  Typically your permit ACL allowing Home to contact IoT would allow the IoT to respond. If not you would need another permit ACL to allow specific IoT devices, on specific ports, to address specific devices on the Home vlan. 

 

Also chromecast and apple devices use mDNS to locate and communicate with other like devices on the network.  If the devices are on different subnets (Home-IoT) the mDNS broadcast will not repeat on the other subnets. This requires MDNS relay/repeater which is not currently available on the Omada routers. 

  1  
  1  
#2
Options
Re:HOME VLAN cannot access IOT VLAN
2021-05-25 18:11:22

@1207 yeah I've got mine configured on different VLAN's what would you suggest I'd do? Just wait for a future update that fixes it or re-configure all the subnets to make this work? And if so how would you advice I'd configure it?

  0  
  0  
#3
Options
Re:HOME VLAN cannot access IOT VLAN
2021-05-25 19:29:27

@SchippieNL 

 

 

You can either put all the devices on the same vlan (or allow access) for now and wait for TP-link to implement a mDNS repeater/reflector on the ER605, or run Avahi on a NAS or other server.

 

"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite." It is a light weight application that runs on Linux platforms and only requires one ethernet connection to the network.

 

TP-link is updating the router firmware by the end of this month, but there is no indication it will include mDNS.

 

 

  1  
  1  
#4
Options
Re:HOME VLAN cannot access IOT VLAN
2021-05-27 18:58:12
This should help https://www.youtube.com/watch?v=7i17jvrIjD0
  1  
  1  
#5
Options
Re:HOME VLAN cannot access IOT VLAN
2021-05-27 19:09:00

@KLX 

 

This video just shows basic configuration and does not address mDNS issues with apple and chromecast devices, but it is a good video.

  1  
  1  
#6
Options
Re:HOME VLAN cannot access IOT VLAN
2021-05-27 19:37:31

@KLX most of my configuration comes from this video. Sadly the problems with IOT devices remain. 

  1  
  1  
#7
Options