NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
JmsWhitlow
Nov 28, 2025Aspirant
Router Recommendations
I am hopeful that a knowledgeable someone can save me some research time in selecting a new router. I have a few must haves and a few nice to haves: Must Haves: VLAN support with wireless for e...
StephenB
Dec 31, 2025Guru - Experienced User
JmsWhitlow wrote:This allow me to keep my IoT devices separated from my primary VLAN. It also allows me to keep my guest network separate from both my primary and IoT VLANs.
Is the goal here just to have
- a main wifi network
- an IoT network (distinct, but can reach the main network and vice-versa)
- a Guest Network (isolated)
You can get this with WiFi 7 Orbi products, but the technology used is not VLAN.
JmsWhitlow
Dec 31, 2025Aspirant
StephenB wrote:an IoT network (distinct, but can reach the main network and vice-versa)
I wish to keep IoT devices completely isolated from my primary network.
All of the things in my Must Have list are easily accomplished with many non-mesh routers using custom firmware. That is exactly what I am doing currently. I use Fresh Tomato. However, my router is quite old and only offers 100 Mbps speeds. It is quite overdue for an upgrade! I was hoping to setup a mesh network, but it appears that I will have to basically repeat what I previously did, but with a newer non-mesh router. I think I am going to have to buy a modern non-mesh router and flash it with custom firmware like Fresh Tomato or OpenWRT.
With Fresh Tomato I can create multiple VLANs. I can assign specific port(s) to a specific VLAN. I can also have WiFi for each VLAN. It works quite well and keeps things isolated. I was hoping (not actually expecting) that there might be a mesh system that either offered these features with built-in firmware or could be flashed to do so.
Since many IoT devices do not have good security or anti-malware and can go for long periods of time without updates, it seems dangerous (in my opinion) to keep them on the primary LAN.