How I split my home network into VLANs
Main, IoT and Kids: what each network is for, how I locked down who can talk to what, and why I didn't open a single port to get at it from outside.
For years everything in our house sat on one network. Laptops, phones, the TV, smart plugs, the kids' tablets, all of it. It worked, but it meant a £10 smart plug from a company I'd never heard of could, in theory, see my laptop. That started to bother me, so when I moved over to UniFi I split the network up properly.
This post covers how I first set it up: how it's laid out, what each network is for, and how I locked down who could talk to what. I've changed a fair bit since, especially the firewall, and I'll cover that in a follow-up.
The kit
- BroadbandVodafone full fibre
- GatewayUniFi Cloud Gateway Max (UCG Max)
- SwitchUniFi USW-Lite-8-PoE
- Wi-FiUniFi U6+
- DNSPi-hole (added later, it gets its own post)
- AutomationHome Assistant
- Remote accessTailscale
The layout
| Network | VLAN | Subnet | What's on it |
|---|---|---|---|
| Default | 1 | 192.168.1.0/24 | UniFi kit only (management) |
| IoT | 10 | 10.92.10.0/24 | Smart devices, Home Assistant, Raspberry Pis |
| Kids | 20 | 10.92.20.0/24 | The kids' devices |
| Main | 30 | 10.92.30.0/24 | My wife's devices and mine |
The third number of each subnet matches the VLAN ID. If I see a
10.92.20.x address in a log, I know straight away it's
something on the Kids network. It's a small thing, but it saves a lot of
looking things up.
Start by blocking everything
In UniFi's network settings I set the default security posture to Block All. Nothing could cross from one network to another unless I'd written a rule allowing it.
I'd recommend starting this way. It's much easier to open up the handful of things you actually need than to try to close every gap afterwards.
The other networks could only reach the gateway for DHCP (port 67) and DNS (port 53). They could get an address and look things up, and that was it. They couldn't get anywhere near the UniFi management page.
Main
This is our network: my wife's phone, and my phone, iPad and laptop. It's the most trusted of the four, and it was the only one allowed to reach the management network.
I narrowed that down further. It wasn't the whole of Main that could reach management, just my laptop. The laptop has a fixed IP address, and the firewall rule only allowed that one address through.
To be honest about it, this wasn't bulletproof. Anyone on Main who set their device to the same IP could have got past the rule. But they'd still have needed to be on Main in the first place, and then get past the UniFi login. For a home network, it was a big improvement on everything being able to see everything.
IoT
The IoT network is for anything smart: smart plugs and a few other bits and pieces. These are the devices I trust least. They're cheap, they rarely get updates, and a lot of them want to phone home to servers abroad.
Home Assistant lives here too, running on a Raspberry Pi 5 (8GB). So does a touchscreen in the kitchen, which runs a couple of local services for the family and a simple Home Assistant dashboard. That one deserves a post of its own. Putting Home Assistant on the same network as the devices it controls means it can talk to them directly, without me having to open holes in the firewall for every device.
The catch was that I still needed to get at Home Assistant and the Pis. Rather than open up the whole of Main, I added a single firewall rule: my laptop could reach Home Assistant and the Pis, and nothing else on Main could.
For everything else, I use Tailscale. I set it up on Home Assistant first, then later added it to one of my Raspberry Pi 5s, which is wired in over Ethernet. That gives me a second way in if Home Assistant is ever down, which is exactly when I'd most want to get at things. Between the two, I can reach home from my phone wherever I am, without opening a single port on my router.
Kids
The kids have their own network, and it does two jobs.
Filtering. DNS on the Kids network went to OpenDNS FamilyShield, which blocks adult content before it ever loads. It's not perfect, but it catches the obvious stuff without me maintaining any blocklists.
Bedtime. The kids' Wi-Fi only broadcasts between 7am and 8pm. After eight, the network simply isn't there. There's no arguing with a router, and it's done more for bedtimes than any number of "five more minutes" conversations.
At the time, that was as far as I went. Nothing stopped a device from simply using a different DNS server, so a curious kid with a settings menu could have got round the filter. I tightened that up later when I brought Pi-hole in, which is the next post.
What went wrong
Nothing dramatic broke. The real problem was quieter than that: I never properly knew whether my firewall rules worked.
Not long after setting up the VLANs, I installed Tailscale. Tailscale goes around the UniFi firewall rather than through it, so once it was running I was reaching everything that way instead. It worked brilliantly, but it meant I never actually tested the rules I'd spent all that time writing. I'd built a wall and then started using a door that went round it.
I've since rebuilt my firewall setup from scratch. I'd like to show you the before and after, but I didn't keep screenshots of the original rules, so I can't show them and I can't go back and test them either.
If I did it again, I'd:
- Screenshot every rule before changing it. It takes seconds, and it's the only record you'll have of what you had.
- Test each rule from the network it's meant to block. Turn Tailscale off on your phone, join the Kids Wi-Fi, and try to open the UniFi page or reach your laptop. If it loads, the rule isn't doing its job.
- Test before adding anything that goes round the firewall. Once Tailscale or a VPN is in the mix, it's much harder to tell what's actually stopping or allowing traffic.
What's next
Vodafone gave me a static public IP when I asked for one, and honestly I haven't needed it. Tailscale already covers getting at things from outside the house, and it does that without me opening any ports. I'll keep the static IP for if I ever want to host something publicly. Before that, the next post covers bringing Pi-hole into the network, and what my firewall looks like now.
If you've set up something similar, or think I've done something daft, I'd like to hear about it: [email protected]