Block devices from Internet but allow local LAN
tl;dr - The current 'Block device' feature blocks the device from joining the local network entirely. It would be very useful to have an additional type of blocking mode that allows full local LAN access, but prevents outbound Internet connections.
Use-case: The main one (for me) is mainly for the millions of IoT devices that people have in their homes. The grand majority of these are not designed with security in mind (default root passwords, lots of unnecessary calls to cloud services for various data reporting, inability to even change these settings, etc.). Lots of the botnets these days are actually composed of these types of devices. Being able to use them in home via bluetooth and wifi (say, a light switch controller, a vaccuum, a kitchen appliance) but blocking them from outbound internet connections would be very useful.
Description of feature: It’s all about being able to allow a device to talk to the local network (for example 192.168.1.0/24) but then be blocked in any outbound, non-local-subnet connections (i.e. those that will hit the default route (192.168.1.1 in this example) and then be NAT’d by the eero to the public address). The current feature acts more like blocking a switch port… if you block a device, it can literally talk to nothing (including 192.168.1.0/24 in this example).
91 replies
-
I recently replaced my dated wireless router and was disappointed to see that eero does not have such a basic feature. I have a workaround in place (yes it's that important), but would like to see the ability to block external access to the Internet in eero.
-
I agree, this should be a standard feature. Local network only for certain devices.
-
I just got my eero pack and while I love it so far, i'm really missing this feature. On my old ISP-provided router I used it to isolate IP cameras and various IoT devices and it would be great to be able to do it with my Eeros too. Also, Eero Plus doesn't seem to be available in europe, which makes this feature even more important. Thanks!
-
This would be a great feature for my smart HomeKit TVs. I want to use HomeKit with them, but concerned about what data they send out.
I also noticed that this feature is listed in Apple’s “HomeKit Router MFI”, so if Eero goes on to support the HomeKit Router spec, this would be a part of it.
-
Brand new eero pro user! Loving this setup so far. Count me in on wlan only blocking. I'm going to have to get creative to work around this in the meantime.
-
This is a very basic security feature. It's an unacceptable gap.
-
I would also like to see this feature for the reasons listed by others above. I don’t want to trust iot devices.
-
Hello, is there any update on this? HomeKit router was nice but only a small percentage of my iot devices are HomeKit compatible, and I would like to have the same level of control for all the others. Thanks!
-
Any update on this wlan-only blocking? Not sure if this example was already mentioned- I have a baby monitor which requires the home WiFi network to communicate between the cameras and the parent unit (I’ve tried several high-rated non-WiFi models but none have sufficient signal strength for my needs, hence the WiFi model). I have no desire to use the phone app, so I’d love to be able to “unplug” it from the internet while still running the system locally.
-
Since this is a pain for me still not adressed, and together with other issue I was not aware until I actually setup the connection (lack of PPPoE), the simplest solution is to use another router :/
My setup has the modem plugged into a tp-link router, and the Eero network is in bridge mode.
On the tp-link I can do the PPPoE auth and use the parent control feature to limit internet access of specific devices.It's very sad that even with premium priced routers I need another a third party to get all the basic features one would expect.
-
Yes, please! I would love to be able to limit devices to local area only, and not give online access.
-
I have a NAS that I would like to block from accessing or being accessed from the internet. I would like for it to only be accessed from computers on the local network.
-
Yes, this is a real issue for me. There are times when I need the kids to not have internet, but they need local access to print out school work, stream music from our media server, and work the freakin' IP light bulbs.
-
This would be an excellent feature on eero. Please add as a standard feature (I.e. don’t add as a subscription feature)
-
know this is an old request - but thought I'd add a use case in hopes that it gets bumped up
. We have two different NAS drives for our house. One is for media and the other is a RAID for backups of our personal data. The media one isn't touched much and doesn't need outside access. from a security perspective would like to just have it locked down so I don't have to muck with it with every little security update.
On the RAID - I absolutely want to make sure that the RAID is not accessible external to our local network as it comes with all sorts of pre-installed software for FTP and SMTP servers. I've turned those off I believe at the device but it would be brilliant if I could just shut off all Internet access for that device but still let it work on our network. I occasionally will want to turn it back on in controlled situations so having a easy 'switch' in the Eero software would be really valuable.
Content aside
- Status Under Consideration
-
136
Votes
- 10 days agoLast active
- 91Replies
- 3503Views
-
76
Following