My network has grown organically over the years from a single computer on a 9600 baud modem(remember those?) to over 25 devices. Having my card info stolen at Best Buy made me start thinking about my network security. I have a Netgear WRT1200AC that gives good coverage, but it only allows the one common local network, a guest network, and a DMZ. I can't put the IOT devices on the guest network because they are "helping" me by providing a web page logon rather than a WPA2/PSK preconfiguration.
My current configuration is cable modem-->WRT1200AC-->LAN with all devices on the lan. I can segregate my devices into two categories secure(printers, PCs) and insecure. The insecure category can include IOT stuff (cameras, phones, tablets, music streaming, TV streaming, mill DRO, etc.) as none of them need to access local resources. Steve Gibson recommends a three router option (https://www.grc.com/sn/sn-545.pdf, start on page 21) which seems to make sense. I'd missed the MAC snooping issues he mentions when I was considering my options.
What are other folks doing?
My current configuration is cable modem-->WRT1200AC-->LAN with all devices on the lan. I can segregate my devices into two categories secure(printers, PCs) and insecure. The insecure category can include IOT stuff (cameras, phones, tablets, music streaming, TV streaming, mill DRO, etc.) as none of them need to access local resources. Steve Gibson recommends a three router option (https://www.grc.com/sn/sn-545.pdf, start on page 21) which seems to make sense. I'd missed the MAC snooping issues he mentions when I was considering my options.
What are other folks doing?
Comment