Hi,
I've been doing a lot of reading on this but I cant seem to establish which method to use to achieve my desired goal, which is to isolate all of my IoT devices on their own subnet which will not have access to my PC's, NAS etc., hopefully someone here can point me in the right direction. My setup is as follows:
3 TP-Link EAP225's as my WiFi AP's, currently one SSID for both 2.4GHz and 5 GHz frequencies with smart-switching between the two which is handled by the Omada management software. All wireless devices use these via the one SSID.
1 Dlink smart-switch which supports 802.1Q VLANs, the AP's are directly wired into this switch as are all the smaller 8-port switches located throughout the house to provide hard-wired connectivity
1 hAP ac2 as the main router which sits between the switch and the ISP hub which is in bridge mode. I could easily re-wire so that the AP's are directly plugged into this instead of the main switch.
I currently have multiple devices accessing the internet through WiFi, some I'd like to isolate and some that should have access to internal resources.
What I'd like to accomplish is to isolate the multiple smart devices we have from our "internal" traffic so that they would only be able to access the internet. Because they are mixed in with our other devices via our single WiFi SSID, I was thinking VLAN's would be the way to go, but would that be a MAC-based VLAN since there are no individual ports dedicated to just the IoT devices? It there another way to accomplish this without completely re-doing my home setup? I was thinking I could accomplish this all through the RouterOS on the hap as it performs all internal routing, but if there's a better way to accomplish this with the devices I have I'm happy to hear about it.
Thanks!