Skip to content
DnsLister Forum

Where domain hunters compare notes

Looking for feedback on my Firewalla Gold Pro + AP7 topology — Is it time to move from Groups/VqLAN to proper VLANs?

I’m looking for a sanity check and some expert eyes on my current network topology. Everything is running smoothly, but I want to see if I can harden my security and optimize the setup further.

Current Hardware Setup:

  • Router: Firewalla Gold Pro
  • Access Points: 4x Firewalla AP7s
  • Switch: Unmanaged PoE Switch

Current Network Configuration:

How Traffic & Isolation Are Managed Today:

  • Devices joining the Guest and IoT SSIDs are automatically assigned to Firewalla Guest and IoT device groups.
  • Guest Network: Has VqLAN (Virtual Network/VLAN-like isolation via AP) enabled to isolate guest clients from each other and the rest of the LAN.
  • IoT Network: VqLAN is disabled because several IoT devices need local communication (e.g., Home Assistant on a Raspberry Pi, Philips Hue Bridge communicating with Apple TVs/iPhones for HomeKit).

While this is functional, I’m trying to gauge if I’ve hit the limit of what Device Groups and VqLAN can cleanly do, and whether I should migrate to full 802.1Q VLANs.

A few specific questions for the group:

  1. VLANs vs. Groups/VqLAN: Given that I have a Gold Pro and AP7s, should I drop the single /22 subnet setup and build true VLANs (e.g., Main, Guest, IoT)?
  2. Impact of the Unmanaged Switch: Since my PoE switch is unmanaged, it won't tag or process 802.1Q VLAN tags natively. If I create tagged VLANs on the FWGP and pass them through an unmanaged switch to the AP7s (which map SSIDs to VLAN IDs), will the switch trunk/pass those tagged frames reliably, or is upgrading to a managed switch a hard prerequisite here?
  3. IoT Isolation vs. Inter-Device Communication: If I enable VqLAN or put IoT on its own isolated VLAN, what is the best practice for handling required local traffic (like Home Assistant or HomeKit/mDNS across segments) without breaking local control or exposing the entire main LAN?
  4. General Optimization: Any other Firewalla-specific features or firewall rules I should leverage to harden this setup further?

Appreciate any insights, recommendations, or lessons learned from similar Firewalla setups!

https://www.reddit.com/gallery/1w9vg4y

Source: r/firewalla · by /u/YankeesIT

Leave a Reply

Your email address will not be published. Required fields are marked *