- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Orbi BRKE963 - How to set and manage firewall rules
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Orbi BRKE963 - How to set and manage firewall rules
Hi All,
I recently set up my Netgear Orbi system.
We have a pretty decent smarthome with all kinds of IoT devices and hence would like to make sure everything is properly secured. Could you guys help me with where I can manage the firewall settings?
For example, I would like to include rules like "the washer machine shouldn't be able to talk to internet, but it should be able to talk to the computer".
I can't seem to locate these kind of settings.
Kind regards
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Orbi BRKE963 - How to set and manage firewall rules
Netgear's Orbi routers do not include sophisticated firewall capabilities. There is an optional (subscription, i.e. "paid") feature called Armor that you might explore. (Having never enabled Armor - because it is "paid" - I have no idea what it can and cannot do.)
The base product has an Advanced feature called Block Services.which deals with the specific situation mentioned (allow LAN access but deny internet access to a specific device or devices).
It is probably relevant to point out that the Orbi product does not support VLANs, which are often used to separate devices into separate network subsets and control communication between them. The internal LAN is one IP subnet, which means an device can connect to any other device. (With the exception of the Guest WiFi network, which allows access only to the internet).
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Orbi BRKE963 - How to set and manage firewall rules
Hi CrimpOn,
Many thanks for your reply. A bit odd that such a high-end product doesn't have these features and even asks for an additional subscription.
That said - You mentioned VLAN's are not an option. However, there is a VLAN section available in the advanced settings? I was actually planning on using VLAN's to try and reach some of the security goals.
I also have some managed switches in the network for that purpose.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Re: Orbi BRKE963 - How to set and manage firewall rules
The VLAN feature of Orbi routers is (in my mind) a bit misleading. As the User Manual points out (on page 92)
https://www.downloads.netgear.com/files/GDC/RBKE963/RBRE960_RBSE960_UM_EN.pdfhttps://www.downloads.netgear.com/files/GDC/RBKE963/RBRE960_RBSE960_UM_EN.pdf
The intended use is to support IPTV for Internet Service Providers who require it. What happens is that a port defined this way does not employ the usual Network Address Translation (NAT).
The Orbi router LAN ports do not recognize VLAN tagging, which is an essential part of a VLAN implementation.
As to what features one should expect of a consumer WiFi router (even at this price point), that's far beyond me.
• What is the difference between WiFi 6 and WiFi 7?
• Yes! WiFi 7 is backwards compatible with other Wifi devices? Learn more