Tech • AI • Robotics • Game

VIDEO
ENFR

Stop Putting Everything on One Network!!

5/10
AINetworkChuckOctober 5, 2026 at 07:10 PM21:43
Audio player
0:00 / 0:00

TL;DR

Segmenting home devices into separate VLANs with a firewall and managed switch can sharply reduce the risk that vulnerable IoT gear will reach family computers, phones, or work devices.

KEY POINTS

Why one home network is risky

Many households still place laptops, phones, cameras, smart locks, light bulbs, TVs, and appliances on a single network. That creates a broad attack surface: one poorly secured IoT device can become an entry point for malware, spying, or botnet activity. Isolating those devices limits how far an attacker can move after a compromise.

Basic fix: separate networks

Security specialists commonly recommend putting IoT devices on their own network, or at minimum on a guest network. The goal is containment: if a smart camera or switch is taken over, it should not be able to talk directly to personal or work devices. That can be done with multiple physical networks, but also with VLANs, which create separate virtual networks over the same hardware.

How VLANs work

A VLAN, or virtual LAN, lets a router or firewall carve one physical interface into multiple logical networks. In the setup demonstrated, a new VLAN was created on an OPNsense firewall, showing how one port can carry traffic for several networks at once. That approach avoids buying a separate router for every network segment.

Why the switch matters

Not every Ethernet switch can handle VLANs. An unmanaged switch simply passes traffic, while a managed switch can assign ports to specific VLANs and tag traffic on uplink ports. In this case, a QNAP managed-lite switch was used, with some ports configured as untagged access ports for one network and the uplink configured as a tagged trunk carrying multiple VLANs.

A VLAN alone is not enough

Creating the VLAN did not immediately produce a usable network. The firewall also needed a VLAN interface, an IP address, DHCP service, and firewall policy. Until those pieces were added, connected devices only received APIPA self-assigned addresses, a sign that no DHCP server was answering.

The configuration that finally worked

On OPNsense, the new VLAN was assigned its own interface and given an address of 172.16.14.3 on a 172.16.14.0/24 network. A DHCP pool of 172.16.14.100 to 172.16.14.200 was then created. The critical troubleshooting step was enabling DHCP listening on the new interface; once that was done, devices immediately received valid addresses, confirming both the firewall and the switch were set correctly.

Firewall rules enforce isolation

The firewall’s default-deny posture blocked traffic until explicit rules were added. One network was given broad access for work use, while the IoT network was treated differently: rules allowed internet access but blocked connections to private internal networks grouped in an alias. A ping test confirmed the IoT segment could no longer reach the main household networks.

Result: containment, not invisibility

Segmenting devices does not make vulnerable hardware safe by itself, but it limits blast radius. Smart home devices plugged into the same switch can still be prevented from reaching laptops or family phones because traffic between different VLANs must pass through the firewall. If the firewall denies that path, lateral movement is stopped.

A wider warning on stolen credentials

Network segmentation solves only part of the problem. If a laptop is already infected with an infostealer, accounts can still be compromised off-network. Figures cited from Flare described monitoring of more than 150 million stealer logs, 127,000 Telegram channels, and 18 million dark-web forum posts over three months, with a claim that 54% of ransomware victims had data exposed in infostealer logs before the attack.

What remains unfinished

Wired segmentation was completed, but wireless access still needed to be integrated so Wi-Fi devices could join the proper VLANs. An AI agent running on a Raspberry Pi was also connected to the firewall and switch for future automation, suggesting a path toward easier home-lab management once the core network design is in place.

CONCLUSION

For home users surrounded by connected gadgets, the most practical security upgrade may be simple segmentation. A firewall, a VLAN-capable switch, and strict rules can turn one flat, risky network into separate zones that contain compromise instead of letting it spread.

Ask a question

More from AI