After reading the Cliff Notes and various posts I think I have decided on my network setup but just want to see if there is a reason not to go forward with my plan.
Right now my network consists of a Ubiquiti edgerouter X, a Unfi 24 port switch and 3 AC pro APs. I have three vlans setup: secure, guest and DMZ. The three vlans all have a wired and wireless component. They cannot communicate with each other but are all connected to the internet. Guest is obviously for guests and DMZ is for all my IOT gadgets like echo dots, Sonos, and my homeseer PC. Secure is for all of my family's devices that don't fit into one of the other 2 categories. Basically I have the three dumb routers setup but using vlans instead of three separate routers.
Now I'm looking to add a BI PC and a wired IP camera network. My plan is to add a fourth vlan for my IP camera network. It would be completely isolated from everything via my firewall rules The BI PC will have two NICs One would be connected to the IP camera vlan and the other would be connected to the DMZ vlan. I plan to setup a VPN server on my ER-X to allow remote access to the BI PC but before I go there I'd like to get my network setup ironed out. So does my setup sound reasonable or have I missed something?
Right now my network consists of a Ubiquiti edgerouter X, a Unfi 24 port switch and 3 AC pro APs. I have three vlans setup: secure, guest and DMZ. The three vlans all have a wired and wireless component. They cannot communicate with each other but are all connected to the internet. Guest is obviously for guests and DMZ is for all my IOT gadgets like echo dots, Sonos, and my homeseer PC. Secure is for all of my family's devices that don't fit into one of the other 2 categories. Basically I have the three dumb routers setup but using vlans instead of three separate routers.
Now I'm looking to add a BI PC and a wired IP camera network. My plan is to add a fourth vlan for my IP camera network. It would be completely isolated from everything via my firewall rules The BI PC will have two NICs One would be connected to the IP camera vlan and the other would be connected to the DMZ vlan. I plan to setup a VPN server on my ER-X to allow remote access to the BI PC but before I go there I'd like to get my network setup ironed out. So does my setup sound reasonable or have I missed something?