Fine. Your decision to make.
So at least for me my original question to the OP remains. what’s the point? (Your goal end game rational or logical reason for your decision to implement VLANs with in your network?
Many folks have mentioned the thought process they had for doing such an implementation but without really understanding what you want to accomplish and the problem you’re trying to solve. it becomes difficult to really give the “good, experienced advice” What has been provided as guidance is just the basic here is what I did and why replies.
There are lots of valid reasons for using VLANS a few have been touched on by other posters and a few that make assumptions on what having a VLAN may protect your network from.
The key understanding is ingress and egress both must be managed some protocols are far “chattier” then others and some services offer a riskier potential when allowed to define configurations on the basis of what a vendor may or may not have included in the firmware. (UPNP is a perfect concern for that) Perhaps Isolation with regard to iSCSI NAS storage and insuring it does not saturate your network implementing DCB and QOS is also a very good reason for using a VLAN as well. But the most important thing to consider is intra-VLAN routing and what exactly you will or will not allow. using VLANs to have as an example a separate DHCP server assigning reserved IP addresses to a subnet that you have defined to only exist on that tagged VLAN and perhaps use a blackhole gateway to stop any devices from listening outside of the isolated VLAN but still have a way to "enable the external access in a controlled manner for updates or other temporary needs without having to reconfigure your entire subnet or gateway.
It is also a good idea to be mindful many IOT devices initiate the connection (ET phone home behaviors) out to the “interweb” and open a UDP path back as part of establishing that connection to the “cloud server” and most basic firewalls only address incoming connections not outgoing and many devices exit on 443 and then “negotiate a UDP link to the cloud portal”.
I am by no means saying don’t use VLAN’s I actually have I think somewhere in the vicinity of 20 VLAN’s defined within my network (lot of work when you want to add something or test a device and cannot recall what the port you plugged into is configured for
) or forget you last had that port setup up for all tagged and in trunking mode and you spend a few annoying minutes thinking about why the heck this device won’t pull a IP! That happens a lot more now days since I have gotten older too.
Oh, yea I also changed my default VLAN to not be 1 and do not use it at all I have management ports that are on a separate internal switch with no gateway and no path to the outside world that allows all of my switch management and there is no reason at least for me to ever need to configure my network devices from outside my location. As for the hardware I use a pair of cisco NEXUS 5548’s with layer 3 daughter cards and also everything runs on glass (fiber and SFP’s) and I have multiple racks of dell md3620 SAN storage arrays with 490 TB of SAS SSD’s I also have cisco catalyst 3560X that provide my POE for any copper driven devices security cameras wireless access points are powered by. This enterprise grade hardware is cheap to buy but expensive to run however it does any configurations needed like changing the default VLAN and still isolate and not use VLAN 1 pretty much at all except for CDP traffic. All of my other network traffic is on the other VLAN’s including my DMZ and also my VPN web servers are only thing that sees outside world and only on https port and many different subnets for work and play are all trunked on a fiber run between the workshop and the house. As for a firewall I took some old F5 IP 4000 series wiped then installed a SSD and installed BSD i.e. PFSense and configured up HAProxy (sorry Rich yep still on it) I keep saying I will switch over to Opensense but never got around to doing it.
As you can see without knowing what your reason for this implementation it remains a simple question of
What the point?
I think the point has become relatively clear during the conversation, it is to have layer 3 separation for whatever reason. It can be “security”, for organization, but basically it’s just a way to divide an interconnected physical network infrastructure into multiple virtual ones. It’s useless without a router/firewall that can implement whatever “rules” you want to apply to the different networks.
If you have no need to segment your network, I would just leave it be. If you need to segment the network for one reason or another, and have equipment that supports VLAN tagging, it’s much more convenient than physically building separate networks (and often cheaper, depending on what equipment you already have).
I couldn’t live with the amount of nagging and restrictions in pfSense and switched over years ago. How can you manage to still run pfSense? Are you simply staying at an old version? I would think that by now, they have made it practically unusable if you’re not paying them..?
No, I do not see where the OP ever actually clarified why he was implementing VLAN’s
other then to “play around” nor has he stated what he really hopes to accomplish.
To me, this indicated that it was primarily about security, having different levels of “trusted” devices on separate networks, so that whatever BS manufacturers do with their firmware updates, they don’t get full access to your LAN:
- ‘trusted’ devices (laptops, phones)
- IoT devices (Shelly, printer and whatnot)
- ‘local’ devices (ESP32 etc.)
- ‘guest’ devices (for guests, obviously)
well ok but VLAN’s alone do not offer security that is a false narrative many folks fall to fully understand.
Yes, VLANs only offer separation. But it enables giving those networks different access.
Right the security comes from managing ingress and egress rules along with routing tables plus all the other wonderful firewall rules it takes to keep a network secure plus good user hygiene (habits)
nope they still have a community version that stays current semiannual updates. No nagging again I am not running on their hardware I use a couple old F5 series 4000 I wiped and reloaded I just never got around to building an installer for them using Opensense so I never swapped over. I do not have any issues, and I ignore the Netgate forum noise just read release notes and test my upgrades and apply the patches or upgrades after I have made sure it does not break things.
I didn’t run on their hardware either, but there was nagging and warnings about what was going to stop working unless you paid. I don’t remember the exact details, it’s probably 5+ years ago now, but I already felt that I had “stayed too long” when I finally made the switch.
I’m not crazy about how OPNsense goes about business either, too much breaking, updates, changes to UI etc. for me. But, except for some annoyance, it does its job.
For me there are two points, the first is security. Granted, as justanoldman’s post pointed out what I’ve done to secure my network is trivial. Some people secure their house using deadbolts, bars on the windows, contact alarms, glass break sensors, camera systems, etc. in order to improve their security. But if someone really wants to break into their house none of that will stop them. What that security can do is possibly persuade a burglar to go to someone else’s (less protected) house. In the same way implementing VLANs and firewall rules won’t provide absolute protection of a network, but it may encourage someone to look somewhere else.
The second point for me is that I enjoy it. I retired not too long ago and I didn’t want to become the guy that spends his days in a recliner watching Gunsmoke reruns. Learning networking and home automation has been both challenging and rewarding for me. Its my hobby.
Yea I recall all that nonsense for me nothing I used stopped working so I just kept updating and using it.
absolutely if a bad guy wants to get in they will find a way but if the bad guy has a choice of walking through an open front door at the neighbors house versus breaking a window and possible cutting himself and then suing the me for having too sharp of broken glass in most cases he will choose the open door.(I hope) and isn’t nothing wrong with gunsmoke reruns either but yea doing things and learning is what keeps your mind sharp and young at heart and body fit for sure.
Indeed. As for ‘hackers’ trying to break into my system, I understand I’m not a big corporation, so the actual need for heavy security is limited, and the hardware (and setup) I have will make ‘excellent security’ difficult/impossible to achieve.
But my hardware (UniFi Dream Router) does offer some capabilities, and I’m interested in learning more about it.
What I understand from this discussion so far, is that in theory, openHAB should be able to live in some ‘server VLAN’, but that the reality is that that leads to communication (or at least discovery) problems.
Discovery problems are a given, other communications problems mostly binding dependent if you place OH on a separate VLAN. I’d say that unless you have “extreme needs”, forget about that. What should work much better (but still have some potential challenges), is if your OH NIC can handle VLAN tagging itself, so that you can let the switch forward more than one VLAN ID to the OH server, and the OH server can then have one “virtual NIC” per VLAN in participates in, also called multi-homes. There might still be some challenges based on binding limitations, but the basics will work, including discovery.
I don’t know if you saw openHAB with reverse proxy using OPNsense and HAProxy. The HAProxy configs themselves should be translatable to what ever pfsense presents through it’s UI or you could resort to manually configuring the haproxy config. It’s the overall flow that will be the same though which should work for almost any reverse proxy setup.
I will say that when I migrated to opnsense from pfsense it was way less work than I expected (took about two hours to complete and test everything). But clearly I have a much simpler network than you so YMMV.
Just to pivot off this a little bit. What are some things besides VLANS that do address security concerns?
| Technique | Why |
|---|---|
| No exposed ports, only access to the LAN is via a local connection or VPN | Reduces bots and script kiddies from probing and attacking your LAN from the Internet. |
| DMZ | Isolates your hosts/services that must be exposed to the Internet to reduce the “blast radius” of a successfull attack. |
| Geo blocking | Simply reject connections from regions of the world unlikely to have a legitimate reason to connect to your services |
| fail2ban | create firewall rules to block connects from IPs that fail authentication too many times. |
| CrowdSec | Automatically create firewall rules to block known and active attacks. |
| DNS Filtering (e.g. PiHole) | Include blocks for tracking and malicious domains (mainly protects outbound traffic). |
| IP Filtering | Kind of like the DNS filtering but use lists of IPs instead of domain names and work at the firewall level instead of DNS level. Geo blocking is a subset of this. |
| Block devices that don’t need to access the Internet from accessing the internet through firewall rules. | Prevents untrusted devices from phoning home. |
| Snort/etc. | Monitor LAN traffic for signs of attack. In my experience the juice isn’t worth the squeeze on a home LAN but YMMV. |
| VLANS | Prevents untrusted devices from gaining latteral movement to other more valuable devices on your LAN. |
This is not an exhaustive list and as with any complicated system, some degree of design needs to be applied. And pretty much all of these comes with a maintenance long tail and requires some degree of continuous monitoring.
I’d say almost equally important, from updating themselves, removing existing functionality.
If you just segment your network into different “trust zones” and set up a basic set of rules for “cross zone access”, it doesn’t necessarily come with a lot of maintenance or monitoring needs. If you want to “stay on top of everything” and guard against the unexpected, you must both monitor and analyze a lot, but I think that’s normally out of scope for a home network.
I tend to prefer to stay away from anything that relies on external services, heuristics analysis, geoblocking etc. It’s just not worth it. Block everything incoming, and if there’s something you can’t block, make sure to log that traffic and analyze it from time to time to see what’s going on. Only open the ports you absolutely must, and use non-standard ports if possible, to avoid probing scans.
Except when you add stuff.
But my statement addresses specifically those things I listed in the table.
Not worth it to you. And that’s fine. But that also comes with opportunity costs. It is worth it to many. So because it’s not worth it to you we shouldn’t discuss them?
I didn’t say so. I said that I prefer to stay away from them, because I don’t think it’s worth it. If everything is blocked already for example, what is the point of banning an IP?
And if you can’t block everything? Just give up?