Thread: IOT Devices

    IOT Devices

    With the increasing number of IoT devices within the average house-hold how many of you are creating a DMZ on your WLAN? Radio Thermostats, door-bells and the like now have web-interfaces to allow remote management all using different security protocols. Has anyone successfully (and easily) set this up? I was thinking of plugging in a second wifi router to my DMZ port and then connecting my devices.

    This is an excellent comment. I never have thought about the protection I need in my own household. Not sure I know how to get there. Any thoughts?

    If we're talking about types of IoT devices found in the common home, assuming they're are configured properly and up-to-date, there shouldn't be a need to separate them from the primary network. This of course assumes the primary network itself is secure.

    OTOH if there is a potential for the primary network to be insecure, such as it being OPEN or the passphrase is known or can be easily determined, there are bigger concerns that should be addressed.

    But if there is a need to employ segregation involving IoT, I would recommend enabling the Guest AP feature on the wireless router. By enabling the Guest AP feature this creates a secondary network, i.e. a DMZ assuming the wireless router segments it from the primary network with no connectivity between the two.

    Afterward connecting the IoT devices to the Guest AP with segregation preventing an ability to connect to the primary network keeps things secure. Of course, in this scenario it might likewise be impossible for anything connected to the primary network to communicate to the devices on the secondary network, which means if/when you need to administer the devices you'll likely need to connect a system to the secondary network to allow for the changes to be made.

    Your name is funny haha! anyway lets move on. Nice explanation. I like how you have broken down the steps involved in the work.

