6
Votes

IoT network isolation / segmentation / separation from main network.

 
6
Votes

IoT network isolation / segmentation / separation from main network.

IoT network isolation / segmentation / separation from main network.
IoT network isolation / segmentation / separation from main network.
2025-07-10 10:54:06
Model: Deco X50  
Hardware Version: V1
Firmware Version:

It would make great sense to offer a dedicated and segmented IoT network option and allow Wired connections to the chosen network, set by device, whether that be Main, Wired or IoT so you could manage true segmentation.

 

Please make these features available for the Deco ecosystem.

 

Thanks

#1
Options
11 Reply
Re:IoT network isolation / segmentation / separation from main network.
2025-07-11 06:28:02

  @OverMyDadBody 

Hi, nice to see you again.

Do you wish to have a separate IOT network to reduce the peer 2.4GHz interference from the main network?

 

The engineers initially thought that most smart devices are controlled by the individual App installed on the mobile phone. While the mobile phone is often on the main network. To maintain a proper connection between the mobile phone and smart home devices during configuration and further management, there should be no separation between these two networks.

 

Wait for your reply.

Best regards.

#2
Options
Re:IoT network isolation / segmentation / separation from main network.
2025-07-11 07:12:12

  @David-TP 

 

Thanks for your prompt response 

 

Well the original idea of the engineers are outdated today. Now almost all IoT devices are controlled via the manufacturer's infrastructure so the need for optional isolation features are very high. If anyone browses information security news regularly can see that IoT is a potential backdoor, zombie host, network surveillance candidate. 

 

To mitigate this TP-LINK has to give granular control over detailed  and various security settings to router owners. 

 

Failing this would eventually fall back on the company, but pioneering this would improve reputation and usability.

 

So answering your question: yes we need to be able to switch the IoT network isolated optionally,  or, even better, to switch per device isolation individually in main, Guest, or IoT network.

 

#3
Options
Re:IoT network isolation / segmentation / separation from main network.
2 weeks ago

  @David-TP You are correct when stating that most IoT devices have their own app, but the devices in 99% of the cases are communicating with the servers of the manufacturers in the cloud. It has nothing to do with the local network. As long as the device can reach the internet, there will be no problem in isolating the IoT from Guest/Main Network. PLEASE PLEASE PLEASE implement this!

#4
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago

 

David-TP wrote

The engineers initially thought that most smart devices are controlled by the individual App installed on the mobile phone. While the mobile phone is often on the main network. To maintain a proper connection between the mobile phone and smart home devices during configuration and further management, there should be no separation between these two networks.

 

@David-TP my experience is that there are two use cases here:

  1. The scenario you've described, where uses are regularly using their phone to control smart devices
  2. A full home automation setup (using Home Assistant / Hubitat / etc.), where smart devices are automated and/or controlled by a separate dashboard exposed on the open internet

 

In case (1), I agree that mobile phones would need to be able to communicate with the IoT network. This is probably insecure, but convenient. In case (2), they don't need to communicate on a regular basis, and the preference would be for network security.

 

I fall under under case (2) -- I have a number of IoT devices connected to Hubitat, and I use ActionTiles to control them from my phone. If I need to connect directly to configure an IoT device, I manually connect my phone or PC to my IoT network, make the changes, and then switch back. Today, I use a TP-Link Omada switch and a second router to provide isolation for my IoT network, but it would be wonderful to ditch the second router and gain the mesh network benefits of my Deco for my IoT network.

 

Since there are two distinct use cases, perhaps it would be possible to make this configurable? Make the default behavior of the IoT network the same as it is today, but allow users to toggle an option for IoT network isolation?

#5
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago

Oh, now I'm seeing the point of those who posted above me -- I think they're right that in many cases, apps controlling IoT devices are using the manufacturer's infrastructure to communicate, and thus communicate over the open internet. I can still see the value of use case (1) in some instances, such as connecting to an Echo device. It still makes sense to me to make IoT network isolation configurable so that it can be enabled or disabled.

#6
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago

  @JeffRosenberg 

Hi, thanks for the feedback.

Apart from the "IOT Network", there is another feature called "Device Isolation" which can be enabled for individual devices.

I think enabling "Device Isolation" would be a better option than isolating the IOT Network.

How to set up Device Isolation on a TP-Link Router/Deco

Best regards. 

 

#7
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago - last edited a week ago

  @David-TP

 

David, 

 

That is not uniformly available on all Deco systems 

 

For example my X50 has  no such option.

 

 

See my screenshots attached.

 

Setting missing Missing option 

 

 

 

 

 

 

 

 

Regards

 

Viktor 

 

 

#8
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago

  @OverMyDadBody 

Hi, apart from Deco X50_v1_1.6.7, would there be other Deco models in the Mesh network?

Best regards.

#9
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago

  @David-TP 

 

Yes the main is an X50 and the satellites are X20 (hw v1.2)

#10
Options
Re:IoT network isolation / segmentation / separation from main network.
a week ago

  @OverMyDadBody 

Hi, thanks for the quick reply.

Could you please do me a favor to check if there is "Device Isolation" under the client settings, such as:

Or you can temporarily remove the satellite Deco X20 from the APP to see whether "Device Isolation" would show up.

I think it is very likely that this feature needs the support of all Deco units in the Mesh network.

Wait for your reply.

Best regards.

 

 

#11
Options