Smart Home devices on isolated sub-network without internet access - possible?

Hello,

I want to set up my smart home with various devices. Due to privacy and security concerns, I want to set up my Airport Extreme wifi network so that all smart home devices are on a wifi-sub-network that doesn't allow internet access, but I still want to be able to control the smart home devices from my iPhone/Mac which are on the main wifi network with internet access.


Question 1: Do Smart Home devices / HomeKit devices (just Lightbulbs and plugs) need internet access to function or is it enough to have them on a wifi network (without internet access)?


Question 2: Is it possible to have a wifi sub-network without internet access on my Airport Extreme where I can put all the smart home devices on and still be able to reach them from my iPhone/Mac which is on the main wifi network with internet access?


One solution I came up with is to use the "Timed Access Control" feature of the Airport Utility app and apply to each smart home device (via MAC-address) a rule with "no access" - for one device tested (non-HomeKit LED controller) this did not work as the device didn't show up at all after the rule was applied.


Another idea would be to use the guest network feature and put all the smart home devices on that network (though then they would have internet access).


Any help would be appreciated,

Thanks!

AirPort Extreme 802.11ac Gen1

Posted on Apr 4, 2019 12:37 AM

Reply

Similar questions

4 replies

Apr 4, 2019 12:01 PM in response to jjffjjss

In addition to Bob's comments, your network really requires a router and managed Ethernet switches that support VLANs. By contrast, the AirPort's guest network is a very simplistic VLAN with very little administrative control.


Isolating your IoT devices would also require that you can configure firewall rules on a router to prevent these devices from accessing your "main" network, but still allow access from the main network to the IoT devices for administration.


FWIW. I had networking requirements where I needed to isolate my media devices, game consoles, and IoT devices. I was easily able to do so by creating individual VLANs for each of these types of devices. In my case I replaced my Apple routers with networking gear from Ubiquiti. However, there are a number of other vendors out there that can work as well. It really depends on how comfortable you are with networking configurations beyond simple "plug and play."

Apr 4, 2019 6:39 AM in response to jjffjjss

Last question first.......Is it possible to have a wifi sub-network without internet access on my Airport Extreme where I can put all the smart home devices on and still be able to reach them from my iPhone/Mac which is on the main wifi network with internet access?


No. This might be possible with some really advanced port forwarding setups on a fully featured router, but not on the AirPorts.


Do Smart Home devices / HomeKit devices (just Lightbulbs and plugs) need internet access to function or is it enough to have them on a wifi network (without internet access)?


The answer will probably depend on which particular device that you are asking about. Check with the support folks for the devices that you are using.


The camera system here does not operate correctly when it does not have an Internet connection and devices are simply connected to the WiFi. Other devices may behave differently though depending on how the devices have been designed to operate.






Apr 5, 2019 7:00 AM in response to jjffjjss

Timed Access is there to control the specific times that you want a given WiFi device to be able to connect to the wireless network.


For example, you want to limit Junior and his iPhone to the times that he is allowed to connect to the WiFi network between the hours of 4 PM to 10 PM Sunday through Thursday and between 8 AM and 11 PM on Fridays and Saturdays. The iPhone will not be able to connect to the WiFi network at any other time.


So the only option would be to setup the AirPort Extreme with the Guest Network VLAN and put all the smart devices on there - then they would be somewhat isolated from my main network (though just rudimentary due to the AirPort Extreme's limited capabilities) and still have internet access and be reachable from my iPhone/Mac from the main wifi network, correct?


No, since you asked in your first post.........Is it possible to have a wifi sub-network without internet access on my Airport Extreme where I can put all the smart home devices on and still be able to reach them from my iPhone/Mac which is on the main wifi network with internet access?


Devices on the "main" WiFi network will not be able to access devices on the "guest" network and vice versa. The reason for this is that Apple has designed the guest network to allow guests to be able to connect to the Internet, but they will not able to "see" or "access" any of the devices on the main WiFi network. And WiFi devices on the "main" network will not be able to "see" devices on the guest network. Nature of the beast.


For example......your printer is on your "main" WiFi network and you have set up a "guest" networks for guests. Guests will be able to connect to the Internet, but they will not able to print while they are on the guest network because the printer will not even be visible to them.


As Tesserax and I have mentioned, you can likely do what you want with professional equipment and a pro like Tesserax to know how to set up everything.





Apr 5, 2019 3:10 AM in response to jjffjjss

I did some testing and it seems that "Timed Access" is not suitable for smart home devices since almost all of them need an internet connection (and not just wifi), even a very simplistic smart plug that I tested.


So the only option would be to setup the AirPort Extreme with the Guest Network VLAN and put all the smart devices on there - then they would be somewhat isolated from my main network (though just rudimentary due to the AirPort Extreme's limited capabilities) and still have internet access and be reachable from my iPhone/Mac from the main wifi network, correct?


I guess I will look into some more sophisticated routers with more VLAN and isolating capabilities.


Thank you for all the replies!




This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Smart Home devices on isolated sub-network without internet access - possible?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.