this post was submitted on 18 Nov 2023
7 points (100.0% liked)

Home Networking

11 readers
1 users here now

A community to help people learn, install, set up or troubleshoot their home network equipment and solutions.

Rules

founded 1 year ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] domanpanda@alien.top 2 points 11 months ago (2 children)

I want to separate my sons PC and wifi devices from default network.

Even though im familiar with neworking - subnetting with masks, DNS, DHCP, VPNs (wireguard, openvpn, zerotier) somehow VLANS and tagging has never clicked in my head.

I have classic problem and pretty classic setup - edgerouterX and unifi AP as wifi device. All devices are in the same LAN. What i want is:

  • my son's PC (cable) is separated from default network
  • some particular wifi devices are also in this network (separate SSID)
  • this network does not have access to default network ...
  • ... except some few things like in this example (wifi) printer - everybody should have access to it

Ive watched 3 videos about Vlans and have seen this tutorial. https://help.ui.com/hc/en-us/articles/115012700967-EdgeRouter-VLAN-Aware-Switch but it doesn't have double WIFI ssids.

So i still have questions.

  1. Should i remove my current LAN or should i just tag it with id: 1 (this is tag for default networks right?). I dont want to creat entirely new network as i have things assigned to my IPs (like subdomains but not only that)
  2. Should i tag eth1,eth2 and eth4 ports with tag id '1' or should i just set 'untag 1' for eth3?
  3. eth4 should be "trunking" port right. Should i just set both tags on it - would it be enough?
[โ€“] TiggerLAS@alien.top 1 points 11 months ago

I don't use the default VLAN (VLAN1) on my network; I have one port assigned to VLAN1 on my ER-X, which I can plug into for management access to the ER-X. Everything else is on its own VLAN.

I created a few VLANs on my ER-X, and then used simple firewall rules to deny or permit access from one VLAN to the next as needed.

So:

VLAN1 = Unused, assigned to 1 port on ER-X for management. Untagged.

VLAN2 = PCs, phones, etc.

VLAN3 = Smart TVs, other smart devices.

VLAN4 = Guest network.

With that said, your plan would also work.

Add VLAN2 for your kid's devices. Add your NAT rules for internet access. Add Firewall rules to prevent access between VLANs. Add Firewall rules to allow access from your kid's network to printer. Trunk port to your access point, as you indicated in your diagram. Separate SSID for your kid's WiFi stuff, tied to their VLAN. Access port for your kid's hard-wired devices.

load more comments (1 replies)