136

Block devices from Internet but allow local LAN

tl;dr - The current 'Block device' feature blocks the device from joining the local network entirely. It would be very useful to have an additional type of blocking mode that allows full local LAN access, but prevents outbound Internet connections.

Use-case: The main one (for me) is mainly for the millions of IoT devices that people have in their homes. The grand majority of these are not designed with security in mind (default root passwords, lots of unnecessary calls to cloud services for various data reporting, inability to even change these settings, etc.). Lots of the botnets these days are actually composed of these types of devices. Being able to use them in home via bluetooth and wifi (say, a light switch controller, a vaccuum, a kitchen appliance) but blocking them from outbound internet connections would be very useful.

Description of feature:  It’s all about being able to allow a device to talk to the local network (for example 192.168.1.0/24) but then be blocked in any outbound, non-local-subnet connections (i.e. those that will hit the default route (192.168.1.1 in this example) and then be NAT’d by the eero to the public address). The current feature acts more like blocking a switch port… if you block a device, it can literally talk to nothing (including 192.168.1.0/24 in this example).

91 replies

null
    • eero Community Manager
    • Jeff_C
    • 5 yrs ago
    • Reported - view

    Hey  jsmith

    Thanks for taking the time to share this feedback with the community. I'm happy to share this with our team.

    In the meantime, if you haven't already, I'd also encourage taking a look at our eero Plus service. With built-in threat scanning, eero Plus can automatically block IoT devices from joining known botnets. For more information, visit https://eero.com/shop/eero-plus .

      • Bender
      • 2 yrs ago
      • Reported - view

      Jeff C. No update?  This feature was requested 2 years ago and still no consideration. 

      • dialogue
      • 2 yrs ago
      • Reported - view

      Jeff C. Any update?

      • dialogue
      • 2 yrs ago
      • Reported - view

      Jeff C. Are you saying that I should additionally pay for eero plus to keep my network secure? Nice, nice 👍 

      • dialogue
      • 2 yrs ago
      • Reported - view

      Jeff C. Moreover, can you guarantee that you have your list of known botnets includes 100% botnets in the world? Of course not, right? If so, why haven't you implemented such blocking for certain devices yet? How can you talk about security in terms of your secure subscription then? Looks like hypocrisy, isn't it? 

      • dialogue
      • 2 yrs ago
      • Reported - view

      cc: James Evan (eero support) Kora (eero Support)

      • dialogue
      • 2 yrs ago
      • Reported - view

      I'm using the eero system and pretty happy with the simplicity, etc., but would like to have an update about this certain functionality. I chose eero because Apple recommends you as one of two manufacturers for using with the home kit. But in the end, any connected hub I have, for instance, Philips hue is available not only for a local network. Which multiplies security aspect provided by Apple home kit by 0 😐

      • markles
      • 2 yrs ago
      • Reported - view

      Jeff C. Jeff and team, can someone offer info as to the status of this request. When I bought eero, I was stunned this functionality wasn't in place but was told it would be coming soon. That was 18 months ago. I can't keep using eero without the ability to restrict access to just my local network.

      • someyoungguy
      • 1 yr ago
      • Reported - view

      Jeff C. I would also like to see this feature. 

    • jsmith
    • 5 yrs ago
    • Reported - view

    Yup, I'm already an eero Plus user and love the features it provides :) While I do think that preventing access to known botnets with that service is great to have, there's always new endpoints popping up (common technique for attackers) that take some time to make it to the 'known-bad' block lists, often days or weeks unless an Internet-wide attack (massive DDoS or something) is underway. The other significant part of this request, aside from outgoing botnet traffic, is that there are a ton of devices that report all kinds of data back to cloud services that a user should be able to shut off for privacy reasons. Like for instance, many smart TVs allow you to mirror a mobile or laptop to the screen via wifi, which is a cool feature. However, almost all of them also connect to the Internet to send a *ton* of data about your usage habits (and even continuous audio samples in some cases!). In that case, this feature would allow blocking from Internet to preserve privacy while still letting you use the local features you want.

    The only other point I'd make is that many people have some wifi devices that have no business whatsoever connecting to the Internet (lights, switches, outlets, etc.) but do need local wifi to operate. It would be really convenient to just set this proposed feature and forget about trying to do something more complicated to monitor them for misbehavior (or more likely for most folks, ignore the risk until something bad happens).

    • pallazola
    • 5 yrs ago
    • Reported - view

    Yes! I need this! I have so many iot devices I would like to block from the internet. 

    • guatedude
    • 4 yrs ago
    • Reported - view

    I too want this, I have a Robovac that sends statistics to Xiaomi, without really consenting

    • shill
    • 4 yrs ago
    • Reported - view

    YES! Need to keep my Harmony Hub from updating firmware and nuking all the local API calls I enjoy, but if I block it totally, it doesn't function at all.

    • Msargent
    • 4 yrs ago
    • Reported - view

    Any more on this?

    I too would like to see this capability. I too already have eero Plus.

    And rather than assume that eero Plus is going to automagically block my iOT devices from calling home to China or wherever else with whatever data they can mine from my systems, I want the capability to actively control outbound data connections.

    Hopefully this is being worked.

    • Jonathan.1
    • 4 yrs ago
    • Reported - view

    Another +1 for this. I could really use this for my TV. I need LAN access for AirPlay, but I don't want the TV reporting my viewing back to Vizio/LG/Samsung/etc.

    • Ken
    • 4 yrs ago
    • Reported - view

    I found this page googling for whether this is a feature. Count me in!!

     

    I’m guessing 2019 is the year the lid gets blown of how much spying IoT devices are doing. I would like to pay eero and Apple to protect me from that. 

      • Msargent
      • 4 yrs ago
      • Reported - view

      Ken This is one of the reasons I only do Apple HomeKit gear. Unlike Amazon and Google, who freely acknowledge you (your information) are being sold. With Apple at least they claim your information is not being sold.

      • Fan of tinkering with new hardware. Canadian dude.
      • cotedan87
      • 4 yrs ago
      • Reported - view

      Msargent Agreed. I've noticed that Apple appears much less in the outward scans carried out by eero Plus. Google, on the other hand, calls out a lot !

    • nightkid
    • 4 yrs ago
    • Reported - view

    +1 for this feature. Just recently got into smart home devices and this is a serious concern for Chinese made devices... Please get this feature into Eero!

    • brianjmarshall
    • 4 yrs ago
    • Reported - view

    To be clear, this needs to be a feature of Eero the device, not Eero plus.

    • cherroneous
    • 4 yrs ago
    • Reported - view

    I have a Brother WiFi enabled printer and it consistently shows up in the my Eero Home screen top devices by usage. This thing gets used max twice per week. My understanding is that the usage ranking is for internet egress/ingress, not local network activity. What is getting sent out?! This feature would let me lock this sucker down.

      • Fan of tinkering with new hardware. Canadian dude.
      • cotedan87
      • 4 yrs ago
      • Reported - view

      cherroneous I don't have a Brother printer, but I've got about 45 devices of all kinds, and even my Roomba vacuums call home once in a while. All part of the iOT world I guess.  Most traffic scans are obviously from my desktop, laptop and iPads etc, but even Google Home that has been muted calls home regularly. The Nest Outdoor cams are at the bottom of the traffic list. 

      Glad to have eero Plus scanning the outward traffic DNS for bad players. Peace of mind for me and my 45 "can't-do-without" devices.

      • Mike_Bianco
      • 2 yrs ago
      • Reported - view

      cherroneous I just installed a new Eero 6 and I also have a Brother printer. Looking at the usage, the other day, the printer uploaded 26 GB!  That is scary as heck. I also really want to lock this printer down. I print maybe 1-2 pages a week. I've paused the printer for now and will un-pause it when I want to print something.

    • jsmith
    • 4 yrs ago
    • Reported - view

    It's been damn near a year and we can't figure this out yet? I'm sure I'm over-simplifying, but this can't be that hard (managing a single ACL term per device? that's stupid easy on any network hardware or embedded system). Sadly, I guess I'll have to vote with money and cancel my eero plus subscription and rip out the gear (or relegate the gear to a 'dumb' wifi mesh, which sucks because it can be had for far cheaper). Disappointing, I had been recommending eero, but that's long been over now (and I actively tell folks to avoid). Shame, you guys almost had a good home network solution.

    • Infinitypgh
    • 4 yrs ago
    • Reported - view

    Eero please bump the priority on this. Everything about eero is great. Except this.  Just because a device is phoning home to a white listed server doesn’t mean that server is fully secure and won’t result in data being compromised that could have easily been prevented by simply not allowing said device to have access to the web. Iot device overload is one of the reasons I switched to Eero and I feel like I’m way less secure than I was with my junk router. 

Content aside

  • Status Under Consideration
  • 136 Votes
  • 4 days agoLast active
  • 91Replies
  • 3475Views
  • 76 Following