October 8, 2026
VLANs at home: what I split up and why
Why segment a home network at all
For a long time my home network was one flat segment: laptops, phones, light bulbs, a couple of self-hosted services, guests’ phones, all talking to each other freely. That’s convenient right up until one cheap IoT device with bad firmware can see everything else on the network. I split things into four VLANs: trusted, IoT, DMZ, and guest.
Trusted
This is the segment for devices I actually manage and trust: my own laptops, desktops, and the core homelab hosts. It has the most access to everything else, because it’s the segment where I’m the one typing.
IoT
Smart bulbs, plugs, and ESP32-based sensors live here, fully separate from anything with real access. The honest reason is that a lot of consumer IoT firmware is not something I’d trust to resist a compromise attempt, and I’d rather a bad bulb be stuck talking to nothing than sitting on the same segment as my NAS. IoT devices get just enough outbound access to do their job and nothing else.
DMZ
Anything that needs to be reachable from the public internet — a self-hosted service with an actual external user — sits in its own DMZ segment, isolated from both trusted and IoT. If that service gets compromised, the blast radius stops at the DMZ’s firewall rules instead of spreading to the rest of the house.
Guest
Visitors’ phones and laptops get a guest network with internet access and nothing else. No path to IoT, no path to trusted, no path to the DMZ. It’s the same principle as IoT isolation, just for people instead of devices.
The gotcha: mDNS doesn’t cross VLANs
The first thing that broke the moment I turned this on: mDNS-based discovery (the thing that lets you find a device by a friendly .local name, or lets a smart speaker “just find” a bulb) doesn’t cross VLAN boundaries by default. It’s a multicast, link-local protocol — it was never designed to hop between segments, and most routers won’t forward it even if you ask nicely.
Practically, that means a device on the trusted VLAN can’t discover something sitting on the IoT VLAN by name the way it could on a flat network. The fix isn’t to bridge mDNS across VLANs — that undoes the whole point of segmenting — it’s to add things by IP address directly, and open only the specific ports that integration actually needs between the two segments:
# Firewall rule, trusted -> IoT, narrowly scoped
allow trusted_net -> iot_net tcp/8123 # Home Assistant API only
deny trusted_net -> iot_net any # everything else stays closed
That one rule took me longer to find than I’d like to admit, because the symptom — “device just isn’t showing up” — looks identical to a dozen other unrelated problems. Once I understood that mDNS simply doesn’t travel between VLANs, the fix was two minutes: swap discovery for a static IP and a narrow firewall rule, and move on.
Where it landed
Four segments, each with only the access it actually needs, and a short list of explicit firewall rules instead of implicit trust. It’s a little more friction day to day — nothing auto-discovers across boundaries anymore — but that friction is the entire point.
Enjoyed this
Here's what I'm building with it.
See projects →