on 05-03-2022 17:22
Hi
This my first post here so please excuse my ignorance.
For the moment I've left my LAN on the default IP of 192.168.0.0 with the HUB 3 at 192.168.0.1
Thanks to some very helpful posts here (I'd have been lost without them) I've managed to configure the fourth LAN port on my HUB 3 as a DMZ port by creating a DHCP range and reserving the DMZ port IP address.
However, the DMZ configuration screens seem to automatically force the same IP range for the DMZ network as the rest of the network i.e. 192.168.0.0 which seems odd and unhelpful.
I would have thought it to be usual to have a different range for the DMZ network and indeed I require the DMZ subnet to be on a completely different IP range e.g. 172.16.2.0
Reason: I have a number of IP cameras which I need to keep well away from my LAN trading computers and I also wish to use MAC address filtering, which I've yet to master on the HUB 3.
Now if, for some strange reason, a solution to the above isn't possible, I'm wondering if I should put the cameras on a Guest network, always assuming the Guest network will be on a different IP range.
Any help with my dilemma would be very much appreciated
Thanks in advance
on 05-03-2022 17:38
on 05-03-2022 18:19
Thanks Alessandro for your prompt response but I'm afraid that >£1,000 seems rather overkill and is a bit out of my price range
ZyXEL ZyWALL VPN300 Network Security/Firewall | Ingress.co.uk
I've used Zyxel products in the past and found them to be useful with helpful support
Going back a few years the old Zywall 5 was a very handy gadget
However surely there must be internal firewalls with proper DMZ for significantly less than that ??
05-03-2022 19:00 - edited 05-03-2022 19:10
Sure you could go with a USG60W by Zyxel but you will not get 1Gb TCP speed out of it more like 400Mb
or you can go Ubiquiti
or you can get a Managed switch and do ACL rules to have the DMZ IP not have access to your rest of the IPs in subnet.
on 05-03-2022 19:04
I use Ubiquiti kit and it’s easy to separate devices into VLANs according to their type, I have management, IoT and Cameras VLANs.
on 05-03-2022 19:18
Thanks I'll do some more investigation and have a think.
As a temporary measure I currently have both 2.4GHz & 5GHz Wifi disabled on the HUB 3 and just connect a single HUB 3 LAN port to one of the WAN ports on an old Netgear FVS336G firewall with DMZ configured on a different subnet, but it's very unreliable.
This configuration intermittently blocks IMAP & SMTP and also occasionally ignores the MAC address filtering database which is unhelpful to say the least.
Perhaps a better replacement for the Netgear firewall might be a solution.