Post #3563290
2026-07-03 18:41 UTC
Replies (4)
-
@zrail@hachyderm.io 2026-07-03 18:51
@badnetmask@hachyderm.io @homelab@fedigroups.social there's a thing that goes by many names (ex: "micro segmentation") but the gist is literally that: an automatically provisioned VLAN per client with automatic routing rules. Usually a big iron enterprise thing but there's an open source wifi router project out there whose name I can't remember.
-
@paul_ipv6@infosec.exchange 2026-07-03 18:49
@badnetmask@hachyderm.io @homelab@fedigroups.social it's really out of control. i'm almost at the stage of setting up a per device vlan with a filtering DNS/router per vlan that only lets them phone home to the real vendor of the device and they can't talk to each other or to other devices on the internet, just to keep them from leaking PII or being a bot in a botnet. there's no way any normal person should need to do that...
-
@marbletravis@mastodon.world 2026-07-03 18:48
@badnetmask@hachyderm.io @homelab@fedigroups.social I feel the same way
-
@fullywoolly@mastodon.social 2026-07-03 19:04
@badnetmask@hachyderm.io @homelab@fedigroups.social I know you're not asking for technical advice but my plan was to have one IoT VLAN that could talk to my HA server but nothing else. And for wifi connected stuff serve a dedicated SSID that is quarantined to the same vlan. All just an idea floating in my brain though. Kinda curious what other people are doing. Openwrt btw.