• How do I go about setting up a network that is firewalled from the internet, other than through a gateway server?

    I have a number of IOT things (heating, lights, file server etc...) but don't want them all facing the wide world - Instead, I want to have a single portal (Homeassistant in this case) that I can forward to the internet at large.

    My router is an Ubiquiti Edge router, with a Toughswitch (soon to be two) on the back of that.

    I feel I'm missing something obvious, but can't figure it out.`

  • As long as you don't leave any obvious ports open, it should be fine, no?

  • how are you finding the Router and Toughswitch, gonna buy them, but still require a bit of forum pep talk to make sure I'm not making a mistake?

    Easy enough to set up? Any issues with usage?

  • My feeling would be that you'd make use of the Edge Router's capability to run two distinct networks on two of its ports and only have one of those connected to the internet and the other just local. Don't know about the technicalities though.

    @cornelius_blackfoot It's more complicated than a bog-standard consumer router. For instance by default it is set up not to connect to the internet so you have to change that (and know to change that more to the point).

    Some stuff is nice and straight-forward, assigning static IP addresses, port-forwarding, etc which can be done through the GUI. Other stuff (trying to set up one port to be a separate network that is routed through a VPN for instance) involves some obscure command line interface that appears to have minimal documentation (I gave up trying to use that pretty quickly).

    Very stable though, I went on mine to update the firmware and saw that it had been running continuously for 6 months (no reboots) with no issues.

About