At the risk of quickly being in way over my head, I wonder if someone could help me figure out the smartest way to secure my environment.
I have 8 different locations connected via Wireguard. Each location has its own Internet access connection.
The locations have 7 different /24 networks (2 locations are connected with Cubes and share 192.168.20.0 – If it’s smarter, I can easily make location 8 192.168.25.0):
192.168.0.0
192.168.1.0
192.168.2.0
192.168.20.0
192.168.30.0
192.168.40.0
192.168.70.0
Management takes place 90% of the times from 192.168.2.0 and 192.168.0.0, 5% of the time from an iPhone using cellular data, and 5% of the time from one of the other locations.
Each location has wifi (mostly wifiwave2, but not all) for access to users that I trust as well as to strangers/guests.
The guests only need Internet access.
The trusted users should have greater access.
I run quite a few IoT devices at all locations, many of which need cloud access and access to the Home Assistant server at 192.168.0.103
I set up SSID “2point4” for the IoT (yes, 2.4ghz only); and SSID “Guest” for guests. (I also have other SSIDs for me and the trusted users.)
But, there is no VLAN or SSID-base-firewall set up. So, a guest on any network can see all the hosts/devices on all 7 networks.
I have tried to understand and implement VLANS but failed. I read the advised forum posts, watched videos, read other articles, and it’s just beyond me at the moment.
Is there an easier way to secure my environment?
What details, info and choices have a I left out that would help understand and advise?
Thank you.
