
Block devices from Internet but allow local LAN
tl;dr - The current 'Block device' feature blocks the device from joining the local network entirely. It would be very useful to have an additional type of blocking mode that allows full local LAN access, but prevents outbound Internet connections.
Use-case: The main one (for me) is mainly for the millions of IoT devices that people have in their homes. The grand majority of these are not designed with security in mind (default root passwords, lots of unnecessary calls to cloud services for various data reporting, inability to even change these settings, etc.). Lots of the botnets these days are actually composed of these types of devices. Being able to use them in home via bluetooth and wifi (say, a light switch controller, a vaccuum, a kitchen appliance) but blocking them from outbound internet connections would be very useful.
Description of feature: It’s all about being able to allow a device to talk to the local network (for example 192.168.1.0/24) but then be blocked in any outbound, non-local-subnet connections (i.e. those that will hit the default route (192.168.1.1 in this example) and then be NAT’d by the eero to the public address). The current feature acts more like blocking a switch port… if you block a device, it can literally talk to nothing (including 192.168.1.0/24 in this example).
-
know this is an old request - but thought I'd add a use case in hopes that it gets bumped up
. We have two different NAS drives for our house. One is for media and the other is a RAID for backups of our personal data. The media one isn't touched much and doesn't need outside access. from a security perspective would like to just have it locked down so I don't have to muck with it with every little security update.
On the RAID - I absolutely want to make sure that the RAID is not accessible external to our local network as it comes with all sorts of pre-installed software for FTP and SMTP servers. I've turned those off I believe at the device but it would be brilliant if I could just shut off all Internet access for that device but still let it work on our network. I occasionally will want to turn it back on in controlled situations so having a easy 'switch' in the Eero software would be really valuable. -
Hi,
I think you should try the dmoat home network security device. this device provides security to your home router and builds a security firewall.
-
By and large I'm satisfied with eero, but this is not the first time I've needed a feature and been quite surprised that eero doesn't have it. This is practically table-stakes. Depressingly, I wonder if this is intentionally withheld to make eero Plus seem more valuable as a service.
After all, the promise of a maintained blacklist of botnets would theoretically justify ongoing payment. But the much simpler solution — whitelisting to local devices only — is easy, and would possibly mean that fewer people would need to pay for eero Plus.
The absence of these sorts of features makes me highly unlikely to invest any further in my eero setup and more likely to jump to Ubiquiti — or anyone else who'll just sell me WiFi equipment without entangling me in a quirky business model.
-
I have this same concern! Western Digital (WD) just announced an issue with some of their drives where remote wipes are occurring and recommended that users remove Internet access. My model is not mentioned as being affected but I would like to remove that access as a precaution; however, WD does not have an option to disable cloud services on My Cloud Home or My Cloud Home Duo (doh!) and eero does not seem to have a way to block only outbound Internet access (doh!). I cannot disconnect the NAS from ethernet or I lose local network access which defeats the purpose of the drive (Time Machine backups, media server, etc.). Finally, I am paying for eero Secure but even those controls are not adequate. You have to block by site so now I will have to use Little Snitch and other tools to try to figure out where the drive is connecting to then block by URL (not impossible but a HUGE pain).
-
I ended up buying a firewall and putting eero in bridge mode to secure my network and make this request possible. I also advise many people to do this and to not subscribe to the built in security features of eero. Unfortunately something as simple as this feature request not being implemented and is a basic feature of any firewall is costing eero business. The firewall I am using is the firewalla gold. https://firewalla.com/