This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG v18 IoT security setup and/or suggestion for best practices

I am looking to secure my internal network with the IoT devices.

Currently I have a home automation system that controls the IoT devices. There are 20+ devices. Each device has a static IP based on the MAC ID setup in XG.

Current Setup:

Modem <> Sophos XG v18 <> Switch <> WiFi via Unifi AP's.

                                                                  Network PC with VM (home automation) & Plex server (this PC is wired)

                                                                  NAS (wired)

                                                                  Have 5 security cameras (wired) 

My goal is to secure the wireless IoT devices as well as the security cameras.

I need the home automation (VM) to be able to contact the IoT devices. The NAS controls the security cameras so this also needs to have contact with the cameras.

I have seen some posts on setting up a WiFi for the IoT devices and creating some VLANs. I have also seen some posts on using the MAC IDs to do some policies/filtering. Looking for the easiest and best practice to secure.

Thanks



This thread was automatically locked due to age.
Parents
  • I am struggling getting my wireless network going for the IoT devices.

    I setup a new network in UniFi.

    I then created my IoT wifi.

    Created a VLAN.

    Created a DHCP.

    I have firewall rules for the IoT VLAN.

    I currently can not get an IP address from my DHCP range on my wifi network. I get an error stating there is no internet and the IP address is a random one. Notr in any of my IP ranges.

    What did I setup or miss?

  • Sorry for the typo. Can someone help point out what I missed or setup incorrectly?

  • Looks like you have assigned the VLAN as a sub interface on the Sophos via a VLAN tag, what have you done re the switch side, on unifi VLANs are controlled via profiles (what a crap name).  Why they didn't stick to Untagged/tagged / native/tagged concepts etc. I don't know. 

    Default on Unifi if I recall is ALL for profiles, so if Unifi is correct I'd expect a native VLAN of 1 and a tagged VLAN of 10.  Again I hate the fact that in Unifi you can't change the default VLAN. 

    DHCP requests shouldn't need to pass through the firewall if it's for the same subnet.  Have you tried with a wired device and set the interface on the Unifi switch to a profile of IOT (I.e. made the IOT the native VLAN for that port?

  • I have done nothing with my switches.

  • What kind of switch do you have? Based on your screenshots, I’m assuming you don’t have a Unifi managed switch (reference USW Required).

    ---

    Sophos XG guides for home users: https://shred086.wordpress.com/

Reply Children