Advanced Smart Home Security - VLANs and Firewalls

  Рет қаралды 68,294

Home Automation Guy

Home Automation Guy

2 жыл бұрын

Secure your smart home network and stop hackers by separating your smart IoT devices from your laptops and mobile phones using VLANs (Virtual Local Area Networks) and firewalls.
I show you smart home networking best practices which are recommended by computer security experts.
Links:
Beginners Guide to Smart Home Security - • Smart Home Security fo...
The Hookup Guide to setting up IoT VLANs and Firewall Rules with UniFi - • Part 2 | Ultimate Home...
#ComputerSecurity #HomeAutomation #SmartHome

Пікірлер: 64
@davidtritsch4532
@davidtritsch4532 2 жыл бұрын
This and the prior beginners guide you published are really important. Every person using home networks should watch and study both of these videos. I will be coming back to these two videos until my network is as protected as I can make it. Thanks again.
@HomeAutomationGuy
@HomeAutomationGuy 2 жыл бұрын
Glad it was helpful David!
@jdez0583
@jdez0583 Ай бұрын
This was exactly what I was looking for. I don't want to give Sonos and other companies access to the same network as my computers and phones. Thank you!
@HomeAutomationGuy
@HomeAutomationGuy Ай бұрын
Glad it was helpful!
@Poyo69
@Poyo69 11 ай бұрын
I soon have an exam about network security and such; this was a great resource! Thank you!
@jonnygiantrobot
@jonnygiantrobot Жыл бұрын
It seems you talk about things but not really how to do these things.
@DerekWalker55
@DerekWalker55 2 жыл бұрын
Thanks for the very informative video, this is definitely my next step in securing my network.
@AS-os3lj
@AS-os3lj 2 ай бұрын
Thanks for the video. I will implement VLANS soon.
@jessejohnson529
@jessejohnson529 6 күн бұрын
0:00 Intro, unsecure devices 0:49 Basics to smart home security (see the other video in the desc) 1:03 Advanced smart home security: trusted and untrusted segments 1:30 Basic home network vs Trusted:Untrusted 3:20 Example of subnetting trusted and untrusted VLANs (using different IP range classes) 4:03 Create a new untrusted network 4:42 The Firewall (ask yourself these next questions) 5:29 Which devices need internet access? 6:32 Which devices need specific access to another device, or a device in a different VLAN? 7:00 Any (definitely) untrusted devices that do not need to talk to some trusted devices? 7:31 Firewall Rules 9:00 Isolating untrusted devices from other untrusted devices using multiple VLANs with varying levels of "trust" 10:04 Zigbee vs WIFI devices (see the other video tagged in the outro) This video was very helpful to me just going over the basics of VLANing, and I never even considered using a different subnet class between trusted (private C range) and untrusted (private A and B ranges). And I have been VERY overthinking the firewall that sits "between" these devices and VLANs, but it really is just a list of rule that you fine tune with ordering and other features, depending on the FW ofc.
@BloodlyKill
@BloodlyKill 9 ай бұрын
Usually most routers have something called “Guest network”. You can enable this and use it as an IoT network. Not only does this segment the devices on the network from your main devices, but it also applies device isolation so that they can’t communicate between each other. I even use the guest network feature on my unifi router just for the device isolation feature that is included with this type of network.
@CarlosRuiz-nx3vm
@CarlosRuiz-nx3vm 2 жыл бұрын
I'm starting to set up my new unifi network, and this video has been a great help, thank you.
@HomeAutomationGuy
@HomeAutomationGuy 2 жыл бұрын
You're welcome! What Unifi equipment did you end up choosing?
@CarlosRuiz-nx3vm
@CarlosRuiz-nx3vm 2 жыл бұрын
@@HomeAutomationGuy 1 Dream Machine Professional, 3 UAP AC LR, 1 Switch 8 60W, up to now.
@HomeAutomationGuy
@HomeAutomationGuy 2 жыл бұрын
Niiiice! That's a good selection! Good luck with the setup
@1eskip
@1eskip Жыл бұрын
Thanks voor de info. erg leuk filmpje. Ik wil pas begonnen met het vervangen van mijn bewegingssensors voor Smart producten. Ik had wel al 2 slimme tv's en een wasmachine, maar die heb ik zo lang mogelijk dom gehouden om de kat uit de boom te kijken. En inderdaad Het klopt allemaal wat je zegt. Het is zeer onaangenaam idee als de buren mee zitten te kijken terwijl ik naakt uit de douche stapt of met een partner ligt te cohabiteren. Maar na het instellen van alles kwam ik er pas achter dat ik er zonder internet echt niets aan heb. Ik gebruik al een aantal jaar alleen mijn mobiele internet. Dus ik sta nu in het donker mijn telefoon aan mijn Mikrotik router te koppelen om de verlichting aan te krijgen hahaha. Maar internet is onderweg en aangezien jij het al hebt opgebouwd hoop ik stiekem dat jij vast ergens een lijst van protocollen en poortnummers hebt gangbare domotica producten zodat ik die aan de uitsmijter kan geven Oftewel Firewall. Dan kan ik met mijn ouwe draytek router hier een apart netwerkje voor opzetten.
@user-rd9kb6ox1v
@user-rd9kb6ox1v 10 ай бұрын
Thanks for the info and very nice explanation!!!
@radul476
@radul476 Жыл бұрын
I haven't yet started to build my smart home, but I plan to do so in the near future as I want to move into a new house. Your channel is immensely supportive, as it makes some things look less daunting, as I have 0 experience with the smart home environment, but I have some basic programming skills. I'm also concerned about security, and even though Home Assistant is the more difficult route, as I understand, it's better to start on the correct path, and build my knowledge from there. So from what I understand from your video, if I install my HA on a raspberry pi 4, and add a zigbee sky connector to it, I must set it on the untrusted network on the VLAN, right? If I do it this way, can I then access the HA from my phone (which is on my trusted network)?
@SuppressWarning
@SuppressWarning 2 жыл бұрын
Love love this video!!
@wimnanoe5887
@wimnanoe5887 Жыл бұрын
Great Video thank you..
@timmark4190
@timmark4190 Жыл бұрын
Great video. Pls create a video with actual example with devices
@bubbl_media
@bubbl_media Жыл бұрын
Thank you so much for your Videos! Is there any video about your firewall rules? If not, have you planned one? Would be great!
@HomeAutomationGuy
@HomeAutomationGuy Жыл бұрын
It will be coming!
@hnzcz
@hnzcz 8 ай бұрын
If you have a Raspberry PI with a Home Assistant, I'd like to put it into the trusted network. But, can Home Assistant find later any new devices (using Bonjour eg. for HomeKit platform) automatically in both networks?
@Pouyou-13
@Pouyou-13 5 ай бұрын
Would appletv be under trusted since you may display iPad videos on tv?
@panoshountis1516
@panoshountis1516 Жыл бұрын
Great video, thank you! Just a clarification, if the router does not have enough ports to accommodate all wired devices, wouldn't a switch that supports VLAN's also be required?
@HomeAutomationGuy
@HomeAutomationGuy Жыл бұрын
Yes, each port you hard wire to will need to support vlans
@longbeach225
@longbeach225 Жыл бұрын
You would need to get a managed switch to support VLAN. Those general Netgear 8 port switches are unmanaged.
@panoshountis1516
@panoshountis1516 Жыл бұрын
@@longbeach225 I have an HP ProCurve 1810G-24 (J9450A)
@stephanc7192
@stephanc7192 5 ай бұрын
Good video
@laveauxbazile6755
@laveauxbazile6755 7 ай бұрын
i want to set up my home network, I need some help from you: I have a sonicfirewall TZ500, unifi security gateway and switch, how to wire them?
@nahtay72
@nahtay72 2 ай бұрын
I use a Deco router from TPLink that has an IoT network as well as a network. I segmented all my wireless IoT devices to that network but my Hue bridge is wired so is on my main. There are no separate VLANs however. Is this still secure?
@davidcollins4940
@davidcollins4940 8 ай бұрын
Learning a lot from your videos! Might be a silly question but if your smart devices are blocked from accessing the internet, does that mean you can't control/monitor them when away from home and not directly on the network? E.g. look at security cameras when away on holiday?
@HomeAutomationGuy
@HomeAutomationGuy 8 ай бұрын
I make sure that I have remote access to my Home Assistant platform when I'm away from my home, which lets me control my smart home and view my cameras. This means that I don't need direct access to every single device from the internet
@jamegrabham9992
@jamegrabham9992 2 жыл бұрын
Thanks for the info..very good video... I to use Unifi equipment....my question is, what VLAN should Homeassitant be on? The untrusted network along with all of the IOT devices? I am guessing that the cameras should be on the untrusted network as well (or a totally separate network)? Thanks in advance...
@HomeAutomationGuy
@HomeAutomationGuy 2 жыл бұрын
That is a very good question Jame, and that is entirely up to you and your own personal threat models. I personally keep my Home Assistant on my trusted network and try to keep it as secure as possible with regularly applying updates, using strong passwords and two factor authentication etc. I then allow certain devices from the IOT network to talk to ONLY the Home Assistant IP address on specific ports and protocols. Cameras should be on the untrusted network only. I have local security cameras (Which are also Unifi) and they save their footage to a local Unifi Cloud Key service. My cameras are actually on their own VLAN which is firewalled off so they can only talk to the Cloud Key and Home Assistant IP addresses - they are denied access to and from the internet, the trusted network and the untrusted network.
@jamegrabham9992
@jamegrabham9992 2 жыл бұрын
@@HomeAutomationGuy Thanks for the reply...my cameras are all Reolink, and the POE is thru a unified switch... the footage is saved currently to a QNAP Nas but I access "remote" streaming thru the Reolink app...if I lock the cameras down as you have, I don't think that I would be able to access them remotely unless thru HA? I will have to give this some thought? Any suggestions would be appreciated...thanks again...:)
@HomeAutomationGuy
@HomeAutomationGuy 2 жыл бұрын
@@jamegrabham9992 I'd probably set up a VPN to remotely access my home network when I'm away, then the Reolink App should be able to access the cameras "locally" the same way as it does when you're at home
@jonnygiantrobot
@jonnygiantrobot Жыл бұрын
Dont you also have to configure ports also?
@mycosys
@mycosys Жыл бұрын
Is there a particular advantage to VLANs over actually physically separate networks? Best plan i can figure atm wiith what i have is run HASS on proxmox so i can use one network interface for IoT and a separate one for internet. Either that or a separate machine for a firewall.
@TheDisturbed0ne1
@TheDisturbed0ne1 Жыл бұрын
Easier to set up and maintain. Imo not really worth the headache to split them physically for what would be a very minor security benefit, especially if you have a large house/premise you want to cover with ethernet and WiFi.
@PoetofHateSpeech
@PoetofHateSpeech 10 ай бұрын
Easier to set-up, less overhead etc.
@area51xi
@area51xi 5 ай бұрын
Which cameras do you use?
@HomeAutomationGuy
@HomeAutomationGuy 5 ай бұрын
Unifi
@lindamora7
@lindamora7 Жыл бұрын
hello, is there any chance that you would be so kind to assist me with setting my network up? I had a few other questions. I do have a dream machine,
@FE59FE59
@FE59FE59 Жыл бұрын
Hi, First of all, have you tried to google your request? This answers a lot of questions. Do you still have a question that you can't seem to find on Google?
@richardefriend
@richardefriend 2 жыл бұрын
I have over 80 connected devices in my 'smart home''. Your one device at a time reconfiguring shouldn't take much more than a week's time to finish--but in the end, EVERY device needs to get through to the internet for firmware updates, and possibly much more. And every device needs to connect to my 'trusted' smart phones (many of which are just used as convenient remote controls or for quick internet access, with at least one per room) and computers. As such, I can't see how your suggestions would accomplish much in terms of added security for my setup.
@benoitgaussein5621
@benoitgaussein5621 Жыл бұрын
Your smart devices doesn't need to be connected TO your trusted phone. But they need to be accessed FROM your smartphone. Here is the difference
@asmongoldbald
@asmongoldbald Жыл бұрын
where does a chromecast sit... it has to be on same network as phone to work
@nahtay72
@nahtay72 2 ай бұрын
You can but a wired adapter and wire it in so you don't have to expose it on wifi.
@sam5992
@sam5992 Жыл бұрын
My LIFX light bulbs don't have full functionality without internet access. I cannot "favorite" lights without it. It's frustrating and stupid, but that's what it is. Also, I don't think I can control the bulbs through their app without internet access or if they're on a vlan. I can control them via Home Assistant, but the functionality is stunted, and the UI on the app, despite how bad it is, is way better than the UI on Home Assistant.
@Simpletoneasy
@Simpletoneasy Жыл бұрын
Check the above name on instagram he is the man for the job 👆👆👆
@Simpletoneasy
@Simpletoneasy Жыл бұрын
Check the above name on instagram he is the man for the job 👆👆👆
@johnbutt5156
@johnbutt5156 7 ай бұрын
I like Omada by TP Link cause they're cheaper, provide about the same functionality and have more products
@jdb6284
@jdb6284 Жыл бұрын
Seems my GT AX11000 router doesnt support vlan, that's a bummer... ;(
@PoetofHateSpeech
@PoetofHateSpeech 10 ай бұрын
Just found out that your router isn't supported by openwrt unfortunately...... But all hope isn't lost, a search discovered asus merlin. I've never used it, but it's another firmware and I believe VLANS are possible with it
@PoetofHateSpeech
@PoetofHateSpeech 10 ай бұрын
Do a google search for this "AsusWRT-Merlin VLANs for ethernet and WIFI"
@badsomething
@badsomething Жыл бұрын
looks like you're allowing some IOT devices full access to your LAN, poking holes and allowing a path to your critical devices.
@HomeAutomationGuy
@HomeAutomationGuy Жыл бұрын
I give some IOT devices access to some devices on my LAN (Like my home automation system, DNS, etc). Most of these are restricted to certain ports too
@NedumEze
@NedumEze Жыл бұрын
Seeing that most IP Cameras in the market today are of Chinese origin, and the great concern about pervasive Chinese spying, can we use the Chinese Cameras and prevent them from communicating with Chinese Servers?
@drk_blood
@drk_blood Жыл бұрын
As long as you stay away from Eufy 😂
@jonnygiantrobot
@jonnygiantrobot Жыл бұрын
Its just kind of "be aware of" kind of videos then?
@PoetofHateSpeech
@PoetofHateSpeech 10 ай бұрын
Openwrt will make many routers be able to use VLANS, etc. There is no need to spend the crazy amounts ubiquiti charges. To people out there who can't afford or justify spending thousands on networking equipment for your home but want similar functions, there's some cheap TP-link switches that do VLANs and openwrt for your router. On the firewall side, either a cheap second-hand laptop for pfsense or a raspberry pi. There's also heaps of second-hand cisco equipment on eBay... In case you didn't know, cisco is the top dog in the networking world. Creators need to stop pushing these super expensive solutions.
@ethanwasme4307
@ethanwasme4307 Жыл бұрын
although funny at the time, tiktok probably can do this as well like those old farts were saying 😂
@jjovanw
@jjovanw Жыл бұрын
Nice work, however the connections between devices and the firewall in your diagrams are too abstract and imply hard wired connections. Since most untrusted devices are wireless you should have illustrated it that way so noobs understand how the firewall is used to separate trusted network from the wireless untrusted network. You made an assumption that noobs know the difference between a router and firewall or that they can be one in the same.
Smart Home Protocols Explained
18:25
Home Automation Guy
Рет қаралды 137 М.
Home Lab Network Security! - vlans, firewall, micro-segmentation
18:29
VirtualizationHowto
Рет қаралды 42 М.
¡Puaj! No comas piruleta sucia, usa un gadget 😱 #herramienta
00:30
JOON Spanish
Рет қаралды 22 МЛН
ХОТЯ БЫ КИНОДА 2 - официальный фильм
1:35:34
ХОТЯ БЫ В КИНО
Рет қаралды 2,5 МЛН
狼来了的故事你们听过吗?#天使 #小丑 #超人不会飞
00:42
超人不会飞
Рет қаралды 58 МЛН
Securing Your IoT Devices
13:55
IBM Technology
Рет қаралды 23 М.
I Tried Building the PERFECT Smart Home: What I Learned (Mistakes Included)
14:51
Smart Home Security for beginners - How to not get hacked
10:58
Home Automation Guy
Рет қаралды 25 М.
The Best Home Security Device Money Can Buy
18:33
Legends of IT
Рет қаралды 48 М.
Secure IoT Network Configuration
34:30
Crosstalk Solutions
Рет қаралды 406 М.
Network Virtual LANs (VLANs), Explained Simply (VLANs, Part 1)
28:38
Doug Johnson Productions
Рет қаралды 125 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,1 МЛН
IoT Hacking - Netgear AC1750 NightHawk - UART Root Shell
41:23
Matt Brown
Рет қаралды 17 М.
Венозные Руки 🤯
0:25
MovieLuvsky
Рет қаралды 5 МЛН
1🥺🎉 #thankyou
0:29
はじめしゃちょー(hajime)
Рет қаралды 77 МЛН