How a virtual LAN can better secure your home network – and the best way to get started

Follow ZDNET: Add us as a favorite resource on Google.
ZDNET’s key takeaways
- Virtual LANs allow you to isolate devices on your network.
- This step is important because some devices are less secure.
- Not all ISPs allow the creation of VLANs.
Consider this scenario: You have a local area network (LAN) at home. On that network, you have your desktops, laptops, tablets, phones, and IoT devices, such as thermostats, smart TVs, speakers, and more.
Your IoT devices can see other devices and vice versa. Even though IoT devices have much less security than your desktops and laptops, they are allowed to connect to the same network.
Also: The best VPN routers: Expert tested and reviewed
Then, one fateful day, an IoT device is hacked. The malware is injected into the device, and then spreads to your desktops and laptops. The next thing you know, the hacker has your bank account information and is stealing your money.
All this happened because an unsecured thermostat has access to your desktop PC.
But what if you could avoid that situation? You can, thanks to VLANs.
What is a VLAN?
A VLAN stands for a local virtual area network. Without getting too deep into the mud and mire of network terminology, a virtual LAN is like a second network within your LAN that is separate from the rest of your network. Your main LAN might have an address scheme like 192.168.1.x, and your VLAN might have an address scheme like 192.168.2.x.
The important thing about this setup is that, because of the addressing scheme, the VLAN cannot directly access the LAN. That classification is important because it separates the tools.
Let’s use our example above and name our networks LAN1 and LAN2 (LAN1 being the main LAN and LAN2 being the VLAN).
Also: What is MoCA 2.5? How this low-cost network can replace Wi-Fi and fix dead spots
On LAN1, you connect your desktops, laptops, tablets, and phones. In LAN2, you connect all your IoT devices. If an IoT device is stolen, since it is isolated on LAN2, the only devices it can access are those on the same LAN, meaning your desktops, laptops, tablets, and phones are safe (more on this isolation later).
You can take this approach a step further and create two VLANs — one for phones and tablets and one for IoT devices, so your network architecture is:
- LAN: Desktops and laptops (you can also add printers to this setup)
- VLAN1: Phones and tablets
- VLAN2: IoT devices
You can even configure a LAN to access everything on its network, and everything on VLAN1 and VLAN2, but VLAN1 and VLAN2 cannot access devices on the LAN. If you have the appropriate network hardware, you can also set up VLAN2 so that no devices can communicate with each other and only have access to the outside world (or wide area network, WAN). This step can be important because it can prevent one IoT device from causing problems with another.
Another option would be to create a third VLAN for your children’s devices. You can also create VLAN3, which includes additional parental controls that can limit the websites your children can access, but won’t affect devices on the main LAN.
Also: Slow home internet? Here are 3 things I always check first to regain fast Wi-Fi speeds
In fact, you can take this approach even further by creating a fourth VLAN for guests and a fifth for working from home (that network may be routed through a VPN).
As you can see, the number of VLANs you create increases the complexity. The important thing is to know the devices on your network and how to isolate them.
How to create VLANs
This is where things get complicated, as every router/modem/network switch is different. How you create a VLAN depends on your specific hardware.
Also: Sick of online ads and trackers? How do I block them from my entire home network
For example, my network provider (Spectrum) does not allow VLANs to be created with its hardware. In fact, most ISPs do not support VLANs in their hardware.
That leaves me with two options:
- Use a Linux distribution, such as OPNsense or IPFire, that can act as a router.
- Buy a third-party router.
Since the first option can get complicated for many people, I recommend buying a third-party router. Here are a few models that support VLANs:
If you don’t buy one of the routers above, make sure the router you choose supports VLANs. Using a third-party router allows you to set up multiple VLANs, but you’ll want to read the router documentation to learn how, as each router’s setup will be different.
If you’re lucky and your ISP router/modem supports VLANs (again, many don’t), chances are they will be preconfigured in the router/modem’s web UI for guest networks, mobile devices, streaming devices, etc.
A bonus reason to go with a third-party router (especially a wireless one) is that you can buy one with a wider range than the one you already have.
Naming your VLANs
Although I mentioned creating VLAN1, VLAN2, VLAN3, etc., you can instead create VLANs in a naming scheme, such as IoT, Mobile, Children, and Guest — but I recommend against it. The problem with that naming convention is that it makes everything too obvious. If a bad actor sneaks into your environment and sees a wireless VLAN called IoT (if it’s visible on the WAN), he can connect with an unsecured device and (if he has the skills) do bad things. Because of that risk, I recommend using VLAN names that obscure their purposes.
Are VLANs pointless?
No. As I have said many times, when a device is connected to a network, it is vulnerable. However, setting up VLANs is more secure than hitting everything on a single network.
However, there is a phenomenon called VLAN hopping, which allows an attacker to use poorly configured switch ports or VLAN tagging methods to jump from VLAN to primary LAN (or from VLAN to VLAN). By taking that approach, attackers can gain unauthorized access to any device on your network.
Also: The best secure browsers for privacy: Expert tested
Therefore, it is important to ensure that your VLANs are configured correctly (depending on the hardware used), that your router’s firmware is up-to-date, and that devices on all networks have both updated applications and software.
Although VLANs are not a perfect solution to security challenges, they are a good way to isolate computer hardware to prevent less secure devices, such as IoT devices, from accessing machines containing sensitive information.



