Practical Home Tech

Network · September 2026

How I split my home network into VLANs

Main, IoT and Kids: what each network is for, how I locked down who can talk to what, and why I didn't open a single port to get at it from outside.

For years everything in our house sat on one network. Laptops, phones, the TV, smart plugs, the kids' tablets, all of it. It worked, but it meant a £10 smart plug from a company I'd never heard of could, in theory, see my laptop. That started to bother me, so when I moved over to UniFi I split the network up properly.

This post covers how I first set it up: how it's laid out, what each network is for, and how I locked down who could talk to what. I've changed a fair bit since, especially the firewall, and I'll cover that in a follow-up.

The kit

The layout

NetworkVLANSubnetWhat's on it
Default1192.168.1.0/24UniFi kit only (management)
IoT1010.92.10.0/24Smart devices, Home Assistant, Raspberry Pis
Kids2010.92.20.0/24The kids' devices
Main3010.92.30.0/24My wife's devices and mine

The third number of each subnet matches the VLAN ID. If I see a 10.92.20.x address in a log, I know straight away it's something on the Kids network. It's a small thing, but it saves a lot of looking things up.

Start by blocking everything

In UniFi's network settings I set the default security posture to Block All. Nothing could cross from one network to another unless I'd written a rule allowing it.

I'd recommend starting this way. It's much easier to open up the handful of things you actually need than to try to close every gap afterwards.

The other networks could only reach the gateway for DHCP (port 67) and DNS (port 53). They could get an address and look things up, and that was it. They couldn't get anywhere near the UniFi management page.

Main

This is our network: my wife's phone, and my phone, iPad and laptop. It's the most trusted of the four, and it was the only one allowed to reach the management network.

I narrowed that down further. It wasn't the whole of Main that could reach management, just my laptop. The laptop has a fixed IP address, and the firewall rule only allowed that one address through.

To be honest about it, this wasn't bulletproof. Anyone on Main who set their device to the same IP could have got past the rule. But they'd still have needed to be on Main in the first place, and then get past the UniFi login. For a home network, it was a big improvement on everything being able to see everything.

IoT

The IoT network is for anything smart: smart plugs and a few other bits and pieces. These are the devices I trust least. They're cheap, they rarely get updates, and a lot of them want to phone home to servers abroad.

Home Assistant lives here too, running on a Raspberry Pi 5 (8GB). So does a touchscreen in the kitchen, which runs a couple of local services for the family and a simple Home Assistant dashboard. That one deserves a post of its own. Putting Home Assistant on the same network as the devices it controls means it can talk to them directly, without me having to open holes in the firewall for every device.

The catch was that I still needed to get at Home Assistant and the Pis. Rather than open up the whole of Main, I added a single firewall rule: my laptop could reach Home Assistant and the Pis, and nothing else on Main could.

For everything else, I use Tailscale. I set it up on Home Assistant first, then later added it to one of my Raspberry Pi 5s, which is wired in over Ethernet. That gives me a second way in if Home Assistant is ever down, which is exactly when I'd most want to get at things. Between the two, I can reach home from my phone wherever I am, without opening a single port on my router.

Kids

The kids have their own network, and it does two jobs.

Filtering. DNS on the Kids network went to OpenDNS FamilyShield, which blocks adult content before it ever loads. It's not perfect, but it catches the obvious stuff without me maintaining any blocklists.

Bedtime. The kids' Wi-Fi only broadcasts between 7am and 8pm. After eight, the network simply isn't there. There's no arguing with a router, and it's done more for bedtimes than any number of "five more minutes" conversations.

At the time, that was as far as I went. Nothing stopped a device from simply using a different DNS server, so a curious kid with a settings menu could have got round the filter. I tightened that up later when I brought Pi-hole in, which is the next post.

What went wrong

Nothing dramatic broke. The real problem was quieter than that: I never properly knew whether my firewall rules worked.

Not long after setting up the VLANs, I installed Tailscale. Tailscale goes around the UniFi firewall rather than through it, so once it was running I was reaching everything that way instead. It worked brilliantly, but it meant I never actually tested the rules I'd spent all that time writing. I'd built a wall and then started using a door that went round it.

I've since rebuilt my firewall setup from scratch. I'd like to show you the before and after, but I didn't keep screenshots of the original rules, so I can't show them and I can't go back and test them either.

If I did it again, I'd:

What's next

Vodafone gave me a static public IP when I asked for one, and honestly I haven't needed it. Tailscale already covers getting at things from outside the house, and it does that without me opening any ports. I'll keep the static IP for if I ever want to host something publicly. Before that, the next post covers bringing Pi-hole into the network, and what my firewall looks like now.

If you've set up something similar, or think I've done something daft, I'd like to hear about it: [email protected]