NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
gdlgiii
Apr 09, 2017Tutor
Redesign home LAN for IoT
I am looking to redesign my current network for my home to accommodate these new IoT devices and want to maintain a secure way in isolating that traffic from my private LAN. Some of the IoT devices w...
- Apr 24, 2017
For the AP, I would recommend the WAC730. The WAC730 supports VLAN wherein you could assign a wireless network for the loT network as well as for the Private network that are broadcast at the same time. Also, the WAC730 supports PoE. Kindly check its data sheet here.
Here below is a network diagram that I recommend:
From the network diagram above, the ports connecting the Ubiquiti EdgeRouter Lite and the GS110TP on the 2nd floor will be configured as tagged ports so that it will become a trunk link. The same goes to the ports connecting the GS110TP on the 1st floor and the GS110TP at the 2nd floor. Tagging the ports is needed in order to identify which VLAN the packet belongs to.
The ports connecting the GS110TP on the 2nd floor to the RN104 and the WAC730 will be configured as tagged ports as well because both RN104 and WAC730 are VLAN-aware devices. However, the rest of the ports on the GS110TP (both on the 1st and 2nd floor) connected to the desktops and Arlo Base Stations will be set as untagged ports because the desktops and the Arlo Base Stations are not VLAN-aware devices.
Regards,
DaneA
NETGEAR Community Team
gdlgiii
Apr 23, 2017Tutor
If the r7000 does not support vlan, then what AP would? Or how can I set the switch port to possibly make the r7000 (when in AP mode) think it is connected to a standard port and connect with a static IP? Or would this need to be configured on the main router?
DaneA
Apr 24, 2017NETGEAR Employee Retired
For the AP, I would recommend the WAC730. The WAC730 supports VLAN wherein you could assign a wireless network for the loT network as well as for the Private network that are broadcast at the same time. Also, the WAC730 supports PoE. Kindly check its data sheet here.
Here below is a network diagram that I recommend:
From the network diagram above, the ports connecting the Ubiquiti EdgeRouter Lite and the GS110TP on the 2nd floor will be configured as tagged ports so that it will become a trunk link. The same goes to the ports connecting the GS110TP on the 1st floor and the GS110TP at the 2nd floor. Tagging the ports is needed in order to identify which VLAN the packet belongs to.
The ports connecting the GS110TP on the 2nd floor to the RN104 and the WAC730 will be configured as tagged ports as well because both RN104 and WAC730 are VLAN-aware devices. However, the rest of the ports on the GS110TP (both on the 1st and 2nd floor) connected to the desktops and Arlo Base Stations will be set as untagged ports because the desktops and the Arlo Base Stations are not VLAN-aware devices.
Regards,
DaneA
NETGEAR Community Team
- gdlgiiiApr 26, 2017Tutor
This is very very good information here. As long as devices on both network are not "aware" of each other, then I think this is the perfect solution. Thank you for the product suggestion on the WAC730 AP that can handle multiple VLANS for wireless devices.
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!