david-bann
Active Member
- Joined
- Aug 11, 2008
- Messages
- 31
- Reaction score
- 8
Hey everyone,
I have recently upgraded my home network and want to secure it now but need guidance please. I’m not afraid to get my hands dirty but I am by no means an expert in networking. I understand basic concepts such as VLAN’s, subnets, ports, etc, but still have a long way to go in my overall understanding of network security and “best practices”.
This is my current hardware setup:

This is what I think I need to set up on the UCG:
Questions:
Many thanks
David
I have recently upgraded my home network and want to secure it now but need guidance please. I’m not afraid to get my hands dirty but I am by no means an expert in networking. I understand basic concepts such as VLAN’s, subnets, ports, etc, but still have a long way to go in my overall understanding of network security and “best practices”.
This is my current hardware setup:
- Ubiquity UCG-Ultra
- Unifi access points
- Reyee POE Managed switches
- Dahua IP NVR and cameras
- IOT devices
- Intel NUC running Home Assistant

This is what I think I need to set up on the UCG:
| Network | VLAN ID | WLAN | Notes |
| Default | 1 | Family | To be used for family member devices like mobile, iPads, laptops, printer, etc. |
| CCTV | 2 | n/a | For our CCTV cameras, to isolate from other networks. For now I only have wired cameras but might add wireless later, in which case I will create a new WLAN for that linked to the Camera network. |
| Guest | 3 | Guest | We run a single unit B&B and want them isolated from our other networks. |
| IOT | 4 | Smart Devices | For all the IOT devices such as light switches, globes, breakers, Google Nest speakers, etc. |
Questions:
- Any suggested changes to my approach above? i.e. any potential problems, risks or better ways?
- Should my Home Assistant server be on the IOT network, along with all other IOT devices?
- Since I am not using Ubiquity managed switches, but rather Reyee managed switches, how do I handle the VLAN’s? I mean, do I create the VLAN’s on the UCG and mirror the same VLAN ID’s on the Reyee switches? Will that pass through correctly if I do that?
- I’m not experienced with VLAN config, so some guidance on how to configure the Reyee VLAN’s would be appreciated – i.e. do I set the port connected to the UCG as an access or trunk port, and do I set to tag packets or not? Then same question for ports to AP’s, to TV,s, Home Assistant server, other switch, etc.
- I will obviously need to set up firewall rules to control which networks have access to what. Unifi now manages that through Zones. Would also appreciate some guidance on what types of rules I need to create.
Many thanks
David
