Jump to content

Recommended Posts

Posted

Hi all,

 

I wondered if you could give me your opinions on my home network setup. (Please see diagram below).

 

At the moment I have my router connected to the ISP's modem/router and have got ports 1-3 configured as my "Home" network. Port 4 is configured as a seperate isolated network which has a cat6 ethernet cable heading off upstairs to where the NVR is located in my new comms cabinet. This is the only cable that heads off to the up stairs and I can't get another one up there.

 

I have a Wifi AP connected to my "Home" network and this also has it's own "Guest" network switched on for Wif guests and Wifi IOT devices.

 

The problem I'm trying to solve is I would like to move my NAS up into the cabinet upstairs but the connection upstairs is only on the isolated network.

Even if I put a switch up there it would mean the NAS and NVR are talking to each other so not secure.

 

Can anyone offer a solution or idea I could implement to make things better?

 

 

network.png

 

 

 

Many thanks.

Posted

Devils advocate here, but do you need 1gig on the NVR/NAS? If not could always use a splitter and have it running at 2x 100mb instead, but obviously may not be a preference :p

 

But if you want the full speed, what's the reason the NVR is isolated? If it's only isolated away from the Internet in that sense, couldn't you have a switch upstairs and VLAN/isolate it that way? So it's still using the 1 cable downwards

 

Steve

  • Thanks 1
Posted

Could you set up the router with VLANS? Then you could trunk both the NVR and regular network VLANs upstairs, and have a switch break them out to the different devices (although this would probably require a more expensive switch upstairs).

Otherwise, either power line, trying to get the NAS on wifi (not my choice), or trying to get another cable up there. Maybe you could sacrifice the exsisting cable as a pull cord to get 2 new ones in?

  • Thanks 2
Posted (edited)
If additional cabling isn't an option how about Powerline adapters?

 

 

Hate the things. I know some people like them but I've never got on with them.

 

 

 

Devils advocate here, but do you need 1gig on the NVR/NAS? If not could always use a splitter and have it running at 2x 100mb instead, but obviously may not be a preference :p

 

Steve

 

 

Good idea for making use of one cable but I'd like to keep it a 1Gig if I can.

Reason to seperating the NVR is that it is a Hikvision NVR and I dont want any backdoors into my network.

 

 

 

 

Could you set up the router with VLANS?

 

 

I think I do have a spare VLAN aware switch so this could indeed be the only way of doing it I think.

 

 

Thankyou. :)

Edited by Sonic007
Posted
I've used quite a few flat ethernet cables, I know they can be a bit suspect and I don't use them for PoE. But apart from that I think vlans are probably the most sensible route and gives you more options in the future if you cannot run extra cables. Got a home network that would prob put some enterprise networks to shame, it is like I am permanently at work :ohwell:
  • Thanks 1
  • 3 months later...
Posted

Thought I'd update this thread:

Ended up going down the VLAN route. Picked up a ubiquiti Flex Switch Mini. Great little device.

Have got it adopted into my Unifi controller running on a laptop. Once configured with VLANS on each port I don't need the controller running.

VLANS configured on my Edge router.

All is good.

 

Eventually I will swap out the Edge router for a Dream Machine Pro.

Posted
I'd consider a pfsense FW compared to a DMP. You can get something like a Netgate/pfsense for around the same price yep they are a little more complex than a DMP (there are tons of YouTube videos) and you won't have it all in the same the Unifi management Eco system but they do offer things that the DMP does not. Jus a suggestion to compare :-) You can also build yourself Pfsense if you have suitable hardware.
  • Thanks 1
Posted (edited)

I have a virtual opnsense router and home with some tp link Omada AP’s runs great haven’t touched the config for months

 

Have a few vlans

 

Mgmt 192.168.10.xx

 

Servers - 10.10.xx.xx

 

VPN - 10.221.1.xx

 

CCTV - 10.129.xx.xx

Edited by Jcx500
  • Thanks 1
Posted

Interestingly, how many SSID's do you all have?

 

At the moment I only have my main network, Guest, and IOT but thinking of ditching Guest and having Children instead. Guests can go on to the IOT one instead.

Posted
At home, I only have 1. I did have a visitor wifi, but unless I was around guests would just get told the normal wifi login, so I gave up on it.
  • Thanks 1
Posted (edited)

I have 2 at the moment. I have one SSID that uses MPSK on Aruba and a Radius server where I can specify the vlan for a client to be on via their mac address, there is a default rule that catches anything else and can put them on another vlan with less access if necessary. I'm slowly moving devices onto the one SSID that uses MPSK then will only have that and possibly a testing one which I can enable only when testing.

 

I have an IoT network but I would not necessarily want guests on that, however all my smartphones/tablets are on it so they can easily get to Emby, etc. I don't get that many guests. Multiple firewall interfaces so keep everything separate.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...