This is a SOHO/SMB focused question for the most part. I typically create a management network for devices like managed switches, APs, Power Devices, and other various widgets that are directly related to core network operations. I let them pull DCHP and then set a reservation out of the DHCP scope. I wish more devices were dhcp out of the box.... IoT devices do not go on this network. I also typically use this network for router management and allow it in via and input rule. Do you think this is a bad idea? If I an idiot for doing it this way please feel free let me know - I am OK with a good public shaming.
Would it make more sense to create a separate "router access" network, no DHCP and apply it to a physical port on the router for direct management? It would limit the "physical" security risk to the router itself VS other devices (thinking APs) scattered through the premises.
I suppose I could leave it open to the management network and limit one IP address that I could use for router management.
The "available from" in the IP service list could also be used, but I am not sure how this layers in with a firewall rule. I would think the firewall rules would supersede anything but maybe not. If they were in conflict that would be bad me thinks.
Thoughts?