this post was submitted on 15 Aug 2023
35 points (97.3% liked)

Selfhosted

40728 readers
357 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
35
WiFi setup (lemmy.omat.nl)
submitted 1 year ago* (last edited 1 year ago) by toma@lemmy.omat.nl to c/selfhosted@lemmy.world
 

Hi,

I sometimes hear/read people putting their tv and other devices on a guest Wifi or even on a separate VLAN. Most guest WiFi's also have client isolation. I can understand that desire but I'm always wondering how that works in real life.

If you have a TV on a guest Wifi, how can you still cast things to it, as I assume your phone is on a different Wifi.

If you put your heating a different VLAN, how can you control the heating from your server that's on a different VLAN?

What's your setup in this regard. Is it worth to split? And what do you split and what not?

top 8 comments
sorted by: hot top controversial new old
[–] Im_old@lemmy.world 9 points 1 year ago

You have to set up proper routing, so the two vlans (your mobile/pc wifi vlan and the tv vlan for example) can communicate. But you don't give Internet access to the tv/thermostat vlan, so they can't "call home" and send all kinds of tracking back home.

[–] chris@l.roofo.cc 5 points 1 year ago (1 children)

Doing these "find your device with magic and do stuff" things can be a bit troublesome across networks. Some is possible to set up but sometimes it just doesn't work. It is the tradeoff between security and comfort.

[–] knobbysideup@lemm.ee 1 points 1 year ago (1 children)

A 1:1 NAT to the other network usually solves it for me.

[–] chris@l.roofo.cc 1 points 1 year ago

What about mDNS?

[–] DrinkMonkey@lemmy.ca 3 points 1 year ago

You create inter vlan rules that allow connections from your main vlan to the other vlans, but only allow established and related traffic from the secondary vlans back to the main vlan.

I have a separate vlan for IoT and guests but punch holes for contact back to my HomePods(main vlan) for my Ecobee thermostat (IoT vlan) to contact so my kids can use Siri to get the weather in the mornings, and for guests to use the printer, that sort of thing.

[–] youngerpants@lemmy.world 1 points 1 year ago

This is what Layer 3 is for. You need to open the relevant port between vlans (e.g. TCP 443 for https) on the firewall. I think its UDP 1900 but may vary by appliance.

I'd also allow multicast, ICMP (ping) and DNS between your vlans as a minimum depending on what they're used for.

[–] knobbysideup@lemm.ee 1 points 1 year ago

routing. On wireless, however, some devices are really stupid and can only talk to things on their own subnet. To address that, I use NAT on the IoT vlan to the real device on the private side.

[–] Decronym@lemmy.decronym.xyz 0 points 1 year ago* (last edited 1 year ago)

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
DNS Domain Name Service/System
IP Internet Protocol
IoT Internet of Things for device controllers
TCP Transmission Control Protocol, most often over IP
UDP User Datagram Protocol, for real-time communications

4 acronyms in this thread; the most compressed thread commented on today has 20 acronyms.

[Thread #52 for this sub, first seen 16th Aug 2023, 10:35] [FAQ] [Full list] [Contact] [Source code]