This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG v18 IoT security setup and/or suggestion for best practices

I am looking to secure my internal network with the IoT devices.

Currently I have a home automation system that controls the IoT devices. There are 20+ devices. Each device has a static IP based on the MAC ID setup in XG.

Current Setup:

Modem <> Sophos XG v18 <> Switch <> WiFi via Unifi AP's.

                                                                  Network PC with VM (home automation) & Plex server (this PC is wired)

                                                                  NAS (wired)

                                                                  Have 5 security cameras (wired) 

My goal is to secure the wireless IoT devices as well as the security cameras.

I need the home automation (VM) to be able to contact the IoT devices. The NAS controls the security cameras so this also needs to have contact with the cameras.

I have seen some posts on setting up a WiFi for the IoT devices and creating some VLANs. I have also seen some posts on using the MAC IDs to do some policies/filtering. Looking for the easiest and best practice to secure.

Thanks



This thread was automatically locked due to age.
Parents
  • Hi,

    I use a seperate network for my IoT devices. Where possible limit their ports and sites they can contact. I also use clienteles access as a management with static IP addresses.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I am not very technical in the networking realm.

    Can you elaborate? Like all the IoT devices are on a private network including WiFi?

    What is clienteles access?

    Thanks

  • Hi James,

    clienteles access is setup in the authentication tab where you assign user name, IP address, email address ( issue dummy email addresses) and group. Now you can use the groups to control access to firewall rules. The clienteles access only works if you are using static IP address assignments.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi James,

    clienteles access is setup in the authentication tab where you assign user name, IP address, email address ( issue dummy email addresses) and group. Now you can use the groups to control access to firewall rules. The clienteles access only works if you are using static IP address assignments.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Children