140

Block devices from Internet but allow local LAN

tl;dr - The current 'Block device' feature blocks the device from joining the local network entirely. It would be very useful to have an additional type of blocking mode that allows full local LAN access, but prevents outbound Internet connections.

Use-case: The main one (for me) is mainly for the millions of IoT devices that people have in their homes. The grand majority of these are not designed with security in mind (default root passwords, lots of unnecessary calls to cloud services for various data reporting, inability to even change these settings, etc.). Lots of the botnets these days are actually composed of these types of devices. Being able to use them in home via bluetooth and wifi (say, a light switch controller, a vaccuum, a kitchen appliance) but blocking them from outbound internet connections would be very useful.

Description of feature:  It’s all about being able to allow a device to talk to the local network (for example 192.168.1.0/24) but then be blocked in any outbound, non-local-subnet connections (i.e. those that will hit the default route (192.168.1.1 in this example) and then be NAT’d by the eero to the public address). The current feature acts more like blocking a switch port… if you block a device, it can literally talk to nothing (including 192.168.1.0/24 in this example).

92 replies

null
    • kwackhog
    • 4 yrs ago
    • Reported - view

    I recently replaced my dated wireless router and was disappointed to see that eero does not have such a basic feature. I have a workaround in place (yes it's that important), but would like to see the ability to block external access to the Internet in eero.

    • bretep
    • 4 yrs ago
    • Reported - view

    I agree, this should be a standard feature. Local network only for certain devices.

    • Jord
    • 4 yrs ago
    • Reported - view

    I just got my eero pack and while I love it so far, i'm really missing this feature. On my old ISP-provided router I used it to isolate IP cameras and various IoT devices and it would be great to be able to do it with my Eeros too. Also, Eero Plus doesn't seem to be available in europe, which makes this feature even more important. Thanks!

      • bretep
      • 4 yrs ago
      • Reported - view

      Jord I ended up getting a firewalla https://firewalla.com/ you can also build it for “free” you just need a raspberrypi. I have symmetric gigabit internet and the blue works great! 
       

      if you want to build it yourself here is where to get the software they run on the tiny raspberry pi they are selling. https://github.com/firewalla/firewalla

      • txgunlover
      • 4 yrs ago
      • Reported - view

      bretep Just remember, it uses ARP poisoning just like the Disney Circle...

      • bretep
      • 4 yrs ago
      • Reported - view

      txgunlover txgunlover yes it does. And it works well. There are traditional inline firewalls you can buy  which are complicated (for consumers) to setup. However I’d prefer to recommend something more consumer friendly, like the firewalla.

       

      ARP poising is bad IF it’s an untrusted device poising maliciously.
       

      All the binaries running on this firewalla device are 100% open source. I’ve read the code to see what they are doing, I’ve also linked to the repository and I may even contribute to it. I trust it. 

      If you have a reason you don’t like how it works other than the word “poisoning” seeming to be a bad word, I’d love to hear why you think it’s bad. 
       

      I think providing a reliable way for consumers to protect their home at little to no cost and allowing them root access to the device and source code is a very good thing. 
       

      This is not an untrusted device, like a camera you buy from China running a binary you don’t trust, can’t read and they’re creating a reverse connection back to you. 
       

      Ideally Eero would offer their firewall at no cost. These erro devices pack enough resources to handle such rules.   

      • txgunlover
      • 4 yrs ago
      • Reported - view

      bretep Recommend you read the head dev's take on ARP poisoning.  You're not taking overhead into account, and the loss of performance, while small to some, is significant to others.

      • bretep
      • 4 yrs ago
      • Reported - view

      txgunlover as a network and software engineer there is not a significant / noticeable performance issue to. Abuse any concern for any home user or gamer.  If you are running real-time bidding systems or something that is extremely sensitive to latency, than you should probably not host that out of your home or small business, focus on datacenters and buy the equipment that serves your needs. 
       

      I could install the routers/switches I make in my home (well I do, but not for my home network) but it’s over kill and I don’t want to play technical support  for home.   

      • txgunlover
      • 4 yrs ago
      • Reported - view

      bretep Having been the same for 22 years for for a fortune 100 company, and early CCIE, I respectfully disagree and assure you there is a noticeable performance impact due to ARP poisoning.  A gamer can very well experience this perceived lag.  The smaller the network, the less the impact, but as many home networks approach 100+ devices, it becomes a latency factor.

    • chanomie
    • 4 yrs ago
    • Reported - view

    This would be a great feature for my smart HomeKit TVs. I want to use HomeKit with them, but concerned about what data they send out.

    I also noticed that this feature is listed in Apple’s “HomeKit Router MFI”, so if Eero goes on to support the HomeKit Router spec, this would be a part of it. 

      • Drew
      • 3 yrs ago
      • Reported - view

      chanomie Thanks for your patience! As of today, eero now fully supports HomeKit integration. Please make sure your app is updated to version 3.3.1 to use the new feature. You'll need to be at home on your eero WiFi in order to add HomeKit devices. If you run into any questions or concerns, please reach out to support at 877-659-2347 or email support@eero.com

      • Infinitypgh
      • 3 yrs ago
      • Reported - view

      Drew Any update on the main issue in this thread?  We all would like to see LAN access with internet blocking become available in the near future.

      • chanomie
      • 3 yrs ago
      • Reported - view

      Drew I'm SUPER excited to have HomeKit Router Support for Eero, and while this does address this feature request for HomeKit devices, it sadly doesn't address it for non-HomeKit devices.

      Like I have older SamsungTV's that I would love to give local intranet access, but block from sending TV viewing data back to Samsung.  Since they are older devices, they don't have HomeKit support and this feature doesn't work for them.

    • usernamebryan
    • 3 yrs ago
    • Reported - view

    Brand new eero pro user! Loving this setup so far. Count me in on wlan only blocking. I'm going to have to get creative to work around this in the meantime.

    • sleepercar
    • 3 yrs ago
    • Reported - view

    This is a very basic security feature. It's an unacceptable gap.

    • oliisaac
    • 3 yrs ago
    • Reported - view

    I would also like to see this feature for the reasons listed by others above. I don’t want to trust iot devices.

    • Jord
    • 3 yrs ago
    • Reported - view

    Hello, is there any update on this? HomeKit router was nice but only a small percentage of my iot devices are HomeKit compatible, and I would like to have the same level of control for all the others. Thanks!

    • Mattyshan
    • 3 yrs ago
    • Reported - view

    Any update on this wlan-only blocking? Not sure if this example was already mentioned- I have a baby monitor which requires the home WiFi network to communicate between the cameras and the parent unit (I’ve tried several high-rated non-WiFi models but none have sufficient signal strength for my needs, hence the WiFi model). I have no desire to use the phone app, so I’d love to be able to “unplug” it from the internet while still running the system locally. 

    • Leo
    • 3 yrs ago
    • Reported - view

    Since this is a pain for me still not adressed, and together with other issue I was not aware until I actually setup the connection (lack of PPPoE), the simplest solution is to use another router :/
    My setup has the modem plugged into a tp-link router, and the Eero network is in bridge mode.
    On the tp-link I can do the PPPoE auth and use the parent control feature to limit internet access of specific devices.

    It's very sad that even with premium priced routers I need another a third party to get all the basic features one would expect.

    • resubleu
    • 3 yrs ago
    • Reported - view

    Yes, please! I would love to be able to limit devices to local area only, and not give online access.

    • resubleu
    • 3 yrs ago
    • Reported - view

    I have a NAS that I would like to block from accessing or being accessed from the internet. I would like for it to only be accessed from computers on the local network.

    • Mark.7
    • 3 yrs ago
    • Reported - view

    Yes, this is a real issue for me. There are times when I need the kids to not have internet, but they need local access to print out school work, stream music from our media server, and work the freakin' IP light bulbs.

      • nibrwr
      • 3 yrs ago
      • Reported - view

      +1. Would like to limit Internet access but allow LAN Plex/Time Machine access

    • Badgiec
    • 3 yrs ago
    • Reported - view

    This would be an excellent feature on eero. Please add as a standard feature (I.e. don’t add as a subscription feature)

    • drlansing
    • 3 yrs ago
    • Reported - view

     know this is an old request - but thought I'd add a use case in hopes that it gets bumped up

    .  We have two different NAS drives for our house.  One is for media and the other is a RAID for backups of our personal data.  The media one isn't touched much and doesn't need outside access. from a security perspective would like to just have it locked down so I don't have to muck with it with every little security update.

    On the RAID - I absolutely  want to make sure that the RAID is not accessible external to our local network as it comes with all sorts of pre-installed software for FTP and SMTP servers.  I've turned those off I believe at the device but it would be brilliant if I could just shut off all Internet access for that device but still let it work on our network.  I occasionally will want to turn it back on in controlled situations so having a easy 'switch' in the Eero software would be really valuable.

Content aside

  • Status Under Consideration
  • 140 Votes
  • 2 wk agoLast active
  • 92Replies
  • 3841Views
  • 79 Following