Network and VLAN for IoT Devices: Why It's Worth Isolating Your Smart Home

Module 23 · Lesson 8

Network and VLAN for IoT Devices: Why It's Worth Isolating Your Smart Home

A hacked outdoor camera from Module 21, connected to the same network as the computer holding your documents and passwords, gives a potential intruder a direct bridge to the most valuable data in the house. This lesson covers a network architecture with separate VLANs for the smart home, firewall rules, and an mDNS bridge between segments.

Budget around 60 minutes. This is an advanced, optional topic: it needs a router or switch that supports VLANs. It isn't required for the rest of the course to work, but it meaningfully raises the security level of the whole install.

Why One Flat Network Is a Risk

By default, every device on a home Wi-Fi network sits in one shared space: the TV, a camera, a Zigbee outlet (through the coordinator), a phone, and a computer holding documents. If one of the cheap, less frequently updated IoT devices gets compromised, an attacker at that point can try to reach everything else on the same network. A VLAN (Virtual LAN) solves this by splitting one physical network into logically separated segments.

Recommended Architecture: Three Segments

SegmentWhat it contains
Main LAN (trusted)personal computers, household members' phones, network storage devices
HA LANthe Home Assistant server itself, isolated from both Main and IoT, with controlled access to both
IoT LANevery smart-home device: bulbs, outlets, sensors, cameras, hubs

The key firewall-rule principle: Home Assistant can initiate connections to IoT devices on its own (it has to control them) and to the internet (updates, cloud integrations), but devices on the IoT segment shouldn't be able to initiate connections to either the Main LAN or directly to the internet beyond the bare minimum they need.

The mDNS Reflector: A Bridge That's Easy to Forget

VLANs break mDNS device discovery
Home Assistant and many integrations rely on multicast DNS (mDNS) to automatically discover devices on the network, and mDNS, by design, doesn't cross VLAN boundaries. Without an extra mDNS reflector service (retransmitting mDNS packets between segments), automatic discovery of new Chromecast, HomeKit, or other integration devices will stop working once VLANs are in place.

Most prosumer-class networking platforms (UniFi, for example) have built-in mDNS reflector support as an option you turn on when setting up the network, with no need for an extra, separate server.

Is This Necessary for Everyone

VLANs for IoT are clearly an advanced, optional topic, requiring networking hardware that supports the feature (a typical ISP-provided router usually isn't enough) and about an hour of configuration on prosumer-class hardware. If you're just starting out with this course, the priority is backup and updates from Lessons 2 and 3: network segmentation is a natural next step for more advanced, security-conscious users.

A Guest Network Versus a VLAN: Not the Same Thing

Many home routers offer a simple guest network, isolating devices from the rest of the house, but usually in a far less flexible way than a full VLAN: a guest network typically blocks all traffic to the main network, with no way to set precise rules like Home Assistant can, IoT can't. A guest network works well for visitors' devices, but it won't replace deliberate segmentation for permanent smart-home devices that need to talk to Home Assistant.

Wi-Fi Versus Zigbee and Z-Wave: Different Levels of Network Risk

It's worth remembering that not every device from this course carries the same network risk: Zigbee and Z-Wave devices from Module 9 communicate through a dedicated coordinator, not directly over your Wi-Fi or Ethernet network, so VLAN segmentation doesn't directly apply to them. The network risk covered in this lesson mainly concerns devices that connect to Wi-Fi directly: cameras, plugs, Wi-Fi bulbs, the tablets from Module 14, and ESPHome devices from Module 10, which have their own IP address on your home network.

Remote Access and Segmentation: How These Two Topics Connect

Module 7 of this course taught secure remote access to Home Assistant, and the network segmentation from this lesson is a natural complement to that knowledge: even the best-secured remote access won't help if, once inside your home network (through a compromised password, say), an attacker has full access to everything. Segmentation limits the damage even in a scenario where the first line of defense fails: this is known as defense in depth, where no single safeguard is the only barrier.

A Sample Firewall Rule Set in Practice (Illustrative Notation)

# Sample firewall rule logic between VLANs
# (exact syntax depends on your hardware vendor, e.g. UniFi, OPNsense, MikroTik)

Rule 1: HA_LAN -> IoT_LAN   ALLOW (Home Assistant controls devices)
Rule 2: IoT_LAN -> HA_LAN   ALLOW only necessary ports (e.g. MQTT 1883)
Rule 3: IoT_LAN -> Main_LAN BLOCK (IoT devices can't see computers)
Rule 4: IoT_LAN -> Internet  ALLOW only trusted vendors (firmware updates)
Rule 5: Main_LAN -> HA_LAN   ALLOW (household members use the dashboard)

DNS and Local Ad Blocking Versus Network Segmentation

Network segmentation pairs well with a local DNS server blocking ads and telemetry (Pi-hole or AdGuard Home, for example), often run as an add-on alongside Home Assistant. It's worth making sure devices on the IoT segment also use this DNS server, otherwise part of the benefit of segmentation (control over where cheap devices from overseas actually connect) gets lost.

Where to Start if Segmentation Feels Like Too Much at Once

1. Start with a simpler step: a separate Wi-Fi network just for IoT devices, without the full VLAN and firewall setup.

2. Check your router's documentation for a ready-made IoT security profile, some newer devices have this built in.

3. If you have budget for new networking hardware, pick platforms with an active community and VLAN documentation for Home Assistant.

4. Roll out segmentation gradually, starting with the most sensitive devices (cameras, locks), not the whole network at once.

How to Test This Lesson

1. Check whether your router or switch supports VLAN configuration.

2. If it does, plan at least a basic split: a main network and a separate IoT network.

3. Check whether your networking platform has a built-in mDNS reflector option.

Common Mistakes

Rolling out VLANs without an mDNS reflector: automatic discovery of new devices stops working across segments

Rules too restrictive, blocking Home Assistant too: instead of just IoT devices, breaking the whole system's functionality

Treating this as the first priority: instead of backup and updates, which give a bigger benefit for less effort

Practical Task

☐ Assess whether your networking hardware supports VLAN configuration.

☐ If it does, plan the segmentation rollout as a separate project, not something rushed alongside other work.

☐ If you don't have the right hardware, note it down as a potential future direction.

Key Takeaways

One flat network is a risk: a compromised cheap IoT device can reach the rest of the house.

The recommended architecture is three segments: Main LAN, HA LAN, and IoT LAN with controlled firewall rules.

An mDNS reflector is necessary for automatic device discovery to work across VLANs.

What's Next

Next lesson: The HACS Ecosystem: How to Assess Whether a Custom Integration Is Safe. Network security is one dimension; the security of the code you install is another.

Finished this lesson?