Jump to content
TomLeitner

iptables configuration.

Recommended Posts

TomLeitner

Hi,

 

For security reasons, I've put all my IOT devices on a separate Wifi (separate SSID, VLAN and Subnet). There's a pfsense router between my main network and the IOT network.

The Domotz agent runs on Debian Stretch on a box sitting in my main network. Now in order to allow the IOT subnet to be Domotz scanned and monitored, I've created a second VLAN interface on the Domotz machine which is connected to the IOT VLAN. While this works great, securitywise this is not the best solution because the Domotz Box could be used to break from the IOT Subnet into my main subnet.

 

So my idea is to use iptables to filter traffic on the VLAN interface of the Domotz machine. 

 

Question: How do I do that? What traffic do I need to allow through for basic device scanning and presence detection?

 

Thanks // Tom

 

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...