Hello. I’m looking for some suggestions on how to deal with accessing a Lutron light bridge, Sonos, and pihole DNS through my pfSense VPN as well as suggestions on a redesign of the home network, if necessary.
I have a pfSense/Netgate SG-3100 firewall/router, Netgear MR60 Mesh wifi router w/satellite, Sonos Speakers, Caseta/Lutron Lights, a raspberry pi with access to my burglar alarm, another pi running pihole DNS, and a boatload of cameras. I also have a house that is built like a Faraday cage.
I have tried multiple Unify solutions but so far the only wifi solution that penetrates my walls from room to room is the Netgear Mesh Satellite system (kinda scary when you think about it). I’m also giving the next door neighbor wifi access through the Netgear “guest” network to keep her off my network and make a few bucks.
I have seen a lot of videos, Tom’s included, that suggest a separate IOT network. I currently have a single flat network that my IOT and home stuff are all on. My first problem was 15 various cameras that all wanted to phone home to China. I took care of that with a firewall rule as they are all accessed by Blueiris and do not need internet access.
My current problem is accessing the Caseta Lutron Light system bridge from my VPN. Since I have an inherent lack of trust of any organization that wants me to go through their “secure” servers into my own home light switch I blocked their device from internet access. Access is fine while at home with the mobile app but I’d really like to be able to VPN into the house while away, and control the lights.
Right now I can get into all of my devices (spotweb server, emby server, home webserver, burglar alarm webserver, blueiris server, etc.) from VPN except for Sonos and Lutron. I recently saw Tom’s video on Avahi and think this might be the solution to the Sonos and Lutron app issues but as I initially said I would also consider redesigning the network if necessary. And because I want to have my cake and eat it too, I want to use my pihole DNS server through my VPN.
Any and all solutions will be entertained. Is this all possible with the equipment that I have? Thanks!
GS