I want to improve the security of my Network and banish the IoT devices into a vlan. I am using a Fritzbox 4040 and i need help setting it up. I allready know that i need to edit the config file but not how and where. The goal is that the lan can still speak with the IoT Vlan but the Vlan cant access the Lan.
a VLAN is only used if you intend to carry guest traffic over ethernet. Like if you have a separate access point connected to your router. Otherwise, if you have just a single all-in-one router, you can have the guest wifi without a separate VLAN.
Thanks for the feedback dlakelan. I know that guide and can follow it without any problems. My goal is to force a Hue Bridge into a seperate Vlan and let Clients from LAN/Wifi still communicate with the bridge.
I cant use Luci. When i change something in Luci i loose the connection. Its a driver problem as far as i understand and i need to use the config files.
what you will need to do is create a new VLAN, say VLAN 3, put one of your ports into that VLAN untagged, put your CPU port into the same VLAN tagged. then create a new interface called iot using eth0.3 as the physical interface.
put the iot network into a different firewall zone. allow forwarding from lan to iot but not vice versa.
I am sorry but i really dont know what you need from me. The network config file?
And again, how do i do all this in the config file? To be honest i just dont understand the options from the Wiki. Good examples are missing.
I just need help creating the Vlan. The rest i know how do it.
Here is an example (from a different router, though) on how to create VLA's 11, 22, and 33 for eth1 (LAN ports). This gives me devices eth1.11, eth1.22, and eth1.33. The next step is to create an interface for each VLAN. The third step is to disable forwarding between interfaces.
Thats whats in the file right now (like i said the default). Thanks for the example @fantom-x but i still dont understand the config file. If i read for file right, Vlan 33 is Ports 2 and 6 but in your Screenshot its 5. Where is my misstake? Can somebody tell me the right config if i want a seperate Vlan on Port 4?