October 8, 2026

VLANs at home: what I split up and why

networkinghomelab3 min read

Why segment a home network at all

For a long time my home network was one flat segment: laptops, phones, light bulbs, a couple of self-hosted services, guests’ phones, all talking to each other freely. That’s convenient right up until one cheap IoT device with bad firmware can see everything else on the network. I split things into four VLANs: trusted, IoT, DMZ, and guest.

Trusted

This is the segment for devices I actually manage and trust: my own laptops, desktops, and the core homelab hosts. It has the most access to everything else, because it’s the segment where I’m the one typing.

IoT

Smart bulbs, plugs, and ESP32-based sensors live here, fully separate from anything with real access. The honest reason is that a lot of consumer IoT firmware is not something I’d trust to resist a compromise attempt, and I’d rather a bad bulb be stuck talking to nothing than sitting on the same segment as my NAS. IoT devices get just enough outbound access to do their job and nothing else.

DMZ

Anything that needs to be reachable from the public internet — a self-hosted service with an actual external user — sits in its own DMZ segment, isolated from both trusted and IoT. If that service gets compromised, the blast radius stops at the DMZ’s firewall rules instead of spreading to the rest of the house.

Guest

Visitors’ phones and laptops get a guest network with internet access and nothing else. No path to IoT, no path to trusted, no path to the DMZ. It’s the same principle as IoT isolation, just for people instead of devices.

The gotcha: mDNS doesn’t cross VLANs

The first thing that broke the moment I turned this on: mDNS-based discovery (the thing that lets you find a device by a friendly .local name, or lets a smart speaker “just find” a bulb) doesn’t cross VLAN boundaries by default. It’s a multicast, link-local protocol — it was never designed to hop between segments, and most routers won’t forward it even if you ask nicely.

Practically, that means a device on the trusted VLAN can’t discover something sitting on the IoT VLAN by name the way it could on a flat network. The fix isn’t to bridge mDNS across VLANs — that undoes the whole point of segmenting — it’s to add things by IP address directly, and open only the specific ports that integration actually needs between the two segments:

# Firewall rule, trusted -> IoT, narrowly scoped
allow  trusted_net  ->  iot_net  tcp/8123   # Home Assistant API only
deny   trusted_net  ->  iot_net  any        # everything else stays closed

That one rule took me longer to find than I’d like to admit, because the symptom — “device just isn’t showing up” — looks identical to a dozen other unrelated problems. Once I understood that mDNS simply doesn’t travel between VLANs, the fix was two minutes: swap discovery for a static IP and a narrow firewall rule, and move on.

Where it landed

Four segments, each with only the access it actually needs, and a short list of explicit firewall rules instead of implicit trust. It’s a little more friction day to day — nothing auto-discovers across boundaries anymore — but that friction is the entire point.

Enjoyed this

Here's what I'm building with it.

See projects →