Coder Social home page Coder Social logo

Define Subnet(s) for Scanning to increase IT Security (IoT devices should be in firewalled seperated subnet) about iobroker.broadlink2 HOT 4 CLOSED

iobroker-community-adapters avatar iobroker-community-adapters commented on June 19, 2024
Define Subnet(s) for Scanning to increase IT Security (IoT devices should be in firewalled seperated subnet)

from iobroker.broadlink2.

Comments (4)

frankjoke avatar frankjoke commented on June 19, 2024

I will keep an eye on it how to change subnet when I work on some other changes to broadlink2 and radar adapters.

from iobroker.broadlink2.

at24106 avatar at24106 commented on June 19, 2024

Thanks a lot!

from iobroker.broadlink2.

frankjoke avatar frankjoke commented on June 19, 2024

By the way, I tested a bit on my networks and there is one outcome: The device which manages the broadlink devices need to be on same submet than the devices themself.

For that I found two prossibilities on my FritzBox with one of my test-raspi's:
I put the wireless broadlink devices to Guest network and have one Raspi which is connected to normal network via Lan and to Guest network on wireless.

If you run there broadlink2 you will get devices on the guest network and on the normal network.

You can make guest network to handle no UDP traffic in which way you can prevent the devices talking to their servers in China.

In any case, I can program broadlink only to use certain interfaces, which need to be wireless or wired IPv4 networks. so however you want to generate the Virtuallö network make sure that the iobroker instance where broadlink2 runs on is also included.

p.s.: Made myself my own router with an old raspi and a USB lan-adapter as well an USB-Wlan-Stick (Theis Raspi did not have wlan).

I can now test (and capture network with wireshark) in my specific environment and no data goes out to normal network.

from iobroker.broadlink2.

at24106 avatar at24106 commented on June 19, 2024

Hello frankjoke,

thanks for your comprehensive solution description - and yes this is a valid solution. I thought it might be routeable ... which would allow to keep iobroker in DMZ ... and open only a firewall hole for this port which is then in another subnet <DMZ ... with iobroker> <firewall with pinhole for udp/port to iobroker ip> . For that it approach it requires to define another subnet to scan (instead of the local one which is used now).

Again, thanks for trying.

Best wishes, Rainer

from iobroker.broadlink2.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.