Creating a new home network- advice/help needed

Wombat

Getting the hang of it
Joined
Aug 5, 2018
Messages
55
Reaction score
49
Location
AU
Sorry for the essay. I’ve got my ip cams from Andy and tested in a number of places etc. I need to run my cat6 to each location and install.

My real challenge is to redo my home network from scratch. I need to set the network up properly, so I’m here to ask. I’ve done LOTS of reading and I must admit I know minimal on the subject of networking.

The gear I’ve got available for me to use for the work is (excluding ip cameras)
2 x ASUS RT-AC68U modem routers
1 x TP-LINK Deco M9 mesh router
1 x TP-LINK SG1024DE smart switch
1 x NETGEAR GS108PP poe+ 8 port switch
1 x DAHUA 5208 no poe NVR

I could never get the ASUS routers mesh to work consistently so I use the Deco M9 for my mesh wifi. My house is also wired with cat6. My internet is provided wirelessly.

My current setup isbbasic. House rooms is wired to 24 port switch. Switch connects to ASUS router. ASUS router has wifi turned off. Deco M9 is connected to ASUS in AP mode. I have ASUS DDNS operating and open VPN. I can access devices like my router from my phone via the open VPN app. That was an achievement for me. Feeling my way in the dark there. I’ve done all the disable P2P etc on my router.

I understand I need to keep my ip cameras off the internet and segregated from my home network. I would like if possible to use the dahua app to receive notifications. My 24 port switch is VLAN capable so I found out. I’d like to setup VLANs for something like Main, pc, cameras and IoT for tv’s etc. or something like that.

So for the basic setup from my readings:
Obviously, Internet to my router. Again, wifi off. My Deco M9 in AP mode connected to router. My 24 port smart switch plugged to router. The switch split into the various VLANs. The camera VLAN port is to be tagged. The poe switch plugs to the tagged port. The ip cameras to the poe. My printer would need to be accessible both wirelessly and by any pc plugged at home. Does the NVR also go on the camera vlan?

I believe I have some ip addresses to do in the vlan switch also and probably on my devices. My ip cams will all have static addresses outside of the router dhcp range so no conflicts. Remove the default gateway and apparently block the MAC address. I also read I can point my nvr to my routers up address for time updates.

I’m sure there’s heaps more to be told. My head is spinning and I’m treading water at the moment just thinking about it. I’d like to be able to just click my heels together 3 times and it’s done but that ain’t going to happen.

Am I on the right track or am I headed for derailment. All advice greatly appreciated. In my short time here I’ve learnt so much already but that’s just a drop in the bucket of your collective knowledge.

Have a happy and safe Easter everyone.
 

holiday

Pulling my weight
Joined
Sep 12, 2018
Messages
273
Reaction score
182
Location
Having a holiday
you just need to keep it simple. Untagged vlans are easier to deal with.
Maintain 2 separate network .
One for your home, one for your cameras.

since you are re-wiring your house, wire all the cameras to the POE switch.
If your NVR only have one lan port, it should be plugged to the POE switch, else it will never see any of your cameras.

If your NVR has two lan ports, the other get plugged to your home network.
 

Wombat

Getting the hang of it
Joined
Aug 5, 2018
Messages
55
Reaction score
49
Location
AU
I hear you @holiday about keeping it simple. I read somewhere that to join a switch to a switch the ports should be tagged but I’ll disregard that and leave unstaffed. The rewiring will be as you said running cable from cams to poe. Can I instead of plugging nvr to poe plug the nvr as I posted? It would be plugged to my main switch with ports eg 1and 2 allocated to the cam vlan. That way aren’t they still on the same network (group) still. I’m trying to keep all the poe ports for cams. My nvr is single port
 

holiday

Pulling my weight
Joined
Sep 12, 2018
Messages
273
Reaction score
182
Location
Having a holiday
so assume your main switch has 2 vlans , vlan1 for camera and vlan2 for home.

vlan1 = port 1 & Port 2
Vlan2 = the rest of the remaining ports.
These should be untagged.

Yes, you can plug in the nvr to port 1 and port 2 get plugged to your poe switch. It will be able to "see" your cameras.
 

Wombat

Getting the hang of it
Joined
Aug 5, 2018
Messages
55
Reaction score
49
Location
AU
Yes, you can plug in the nvr to port 1 and port 2 get plugged to your poe switch. It will be able to "see" your cameras.
That’s good to have that confirmed

Do the VLANs have static addresses and they are eg xxx.xxx.1.1 and 2.1 etc?
 

Mike A.

Known around here
Joined
May 6, 2017
Messages
3,828
Reaction score
6,387
Do the VLANs have static addresses and they are eg xxx.xxx.1.1 and 2.1 etc?
No. VLANs work at a different level vs IP addresses.

The managed switch itself would have an IP (obviously).

An unmanaged switch may also pass VLAN-tagged traffic but would not have an IP address assigned to it,
 
Top