Putting smart devices on a separate network
Updated
A guest or IoT network keeps cheap cameras, TVs and gadgets away from your computers, but it can break local control. Here is when to split, how, and which devices to leave on the main network.
As an Amazon Associate we earn from qualifying purchases. Links to Amazon on this page are affiliate links: buying through them costs you nothing extra.
Why separate at all
Every connected device is a small computer that may get few security updates. The FTC calls your router “the key to privacy in the Internet-of-Things world” and advises changing default settings, enabling encryption and checking for updates. A separate network adds a second layer: if a cheap camera or a smart TV is compromised, it cannot reach the laptop that holds your documents. The FTC notes that a guest network also means fewer people have your main Wi-Fi password and that malware on a guest’s device stays off your main network. NIST has published a baseline of recommended cybersecurity features for consumer IoT products (NIST IR 8425) and the U.S. Cyber Trust Mark labeling effort builds on it, but many devices in your home do not carry such a label, so separating them is a sensible default.
Network separation does not replace the basics: a unique router admin password, current firmware, WPA3 Personal or WPA2 Personal encryption, and removing devices you no longer use. The FCC likewise tells users to change the router’s default administrative password.
Three ways to separate
| Method | What it does | Effort | Main catch |
|---|---|---|---|
| Guest network | Second Wi-Fi name and password, usually isolated from the main network | Low: a toggle in the router | Isolation often blocks local control; some routers also limit speed or hours |
| IoT or “smart home” network (some routers and mesh systems) | A second network meant for devices, often with rules that still let your phone reach them | Low to medium | Not every router offers it; settings vary |
| VLAN with firewall rules | A separate network segment you control with rules about who may talk to whom | High: needs a router or firewall that supports VLANs and managed access points | Local discovery needs extra setup (see below) |
The catch: local discovery and control
Many smart home products find each other through multicast DNS (mDNS, also called Bonjour): a device announces itself and your phone listens. These announcements normally do not cross from one network to another. When you put cameras, TV and speakers on a different network from your phone, things like AirPlay, Chromecast casting, printer discovery and Matter commissioning may stop working, even though both devices have internet. Matter runs on Wi-Fi and Thread and is built for local control; in practice the controller, the phone doing the pairing and the device generally need to be on the same local network. Thread border routers also need to be on the same network as your Matter controller. See Thread border router: what it is and Matter multi-admin.
That is why the right split is usually by device type, not “everything on IoT”.
What to put where
| Device type | Where it usually goes | Why |
|---|---|---|
| Phones, laptops, NAS, work devices | Main network | Trusted devices that hold your data |
| Hubs, Matter controllers, Thread border routers, Home Assistant | Main network (or the same network as the devices they control) | They need local discovery and many open connections |
| Cloud-only cameras, doorbells, robot vacuums, smart TVs | Guest or IoT network | They need only the internet; limits harm if one is compromised |
| Smart plugs, bulbs and sensors that work through a cloud app | Guest or IoT network, if the app still works from there | Test one first |
| Speakers and displays that cast, AirPlay or take part in Matter | Main network | Discovery across networks often fails |
| Guests’ devices | Guest network | Keeps your devices private |
If you use Home Assistant or another local controller, put the controller and the devices it controls on one network, and give only the ones that need no local control a separate network.
Set up a guest or IoT network in six steps
- Log in to your router or mesh app and find Guest network or IoT network.
- Give it a different name and a strong password. Avoid names that reveal your name, address or router brand, as the FTC advises.
- Choose WPA3 Personal or WPA2 Personal. If devices will not join, use mixed mode, as in our connection troubleshooting guide.
- Make sure 2.4 GHz is on for the new network.
- Move one device at a time: reset it, pair it on the new network and test every feature (remote access, notifications, voice control, automations).
- If something breaks, check whether the router has a setting to allow your main network to reach the IoT network (some call it “allow access to local network”), or move that device back.
If you go further with VLANs
A VLAN setup needs a router or firewall that supports it, plus access points that can carry several networks. Plan firewall rules that let your phone and hub start connections to the IoT network, but not the other way round. To keep discovery working you will probably need an mDNS repeater or reflector (the feature name varies) and, for some devices, multicast settings such as IGMP snooping. Thread and Matter add IPv6 requirements. This is a good project for a home lab, but it is more than most households need; and a misconfigured rule can cut off every device at once, so keep a note of the original settings. If you rent, check what the landlord’s or building’s network allows before changing anything.
Common mistakes
- Moving the hub and the devices to different networks.
- Turning on client isolation for a network where your phone needs to reach devices.
- Believing that a separate network fixes a device with no security updates. It limits damage, but replace devices that are no longer supported.
- Forgetting to update the Wi-Fi password in each device when you rename or move a network. Devices that go offline after a change are covered in how many devices your router can handle.
Shop by need
Most households that want a simple split
What to look for: router or mesh with a guest or IoT network option, WPA2/WPA3 mixed mode, an option to allow access to the local network, automatic updates
Typical price: $80–$300
See options on AmazonEnthusiast who wants a VLAN
What to look for: router or firewall with VLAN and mDNS reflector support, managed access points that carry multiple SSIDs, PoE switch
Typical price: $150–$500
See options on AmazonFrequently asked questions
Should smart home devices be on a guest network?
Cloud-only devices such as cameras, TVs and robot vacuums usually can. Devices that rely on local control, such as Matter, AirPlay and Chromecast, often need to share a network with the phone or hub that controls them, so test one device first.
Why does casting stop working on a separate network?
Casting and AirPlay use local discovery (multicast DNS) that does not cross between networks, and a guest network may block devices from talking to each other. Put the phone and the cast device on the same network.
Do I need a VLAN for smart home security?
No. A guest or IoT network gives most of the benefit with little work. A VLAN adds control, but it needs compatible equipment and careful rules.
Does Matter work across different networks?
Matter is built for local control, and in practice the controller, the phone doing the pairing and the device generally need to be on the same local network. Keep Matter devices and controllers together.