I am a cybersecurity engineer and it is a good security practices to place internet of things devices (e.g., Roku USB stick) on a separate network. Thus I plan to place it on my wireless "Guest" network. However, I still want to access it from a my iPhone which will be on the main wireless network in my home. Thus, how should I configure a router to allow this? e.g., what ports do I need to open/forward? Thank you!
That's funny.
Please clarify why this is funny. The idea is to segregate internet of things devices, like the Roku, on its own network as they are often compromised by attackers (e.g., automated attacks). Thus you open only a specific port(s) to allow traffic IN to the separate Guest network, and thus the Roku (or any internet of things device) cannot initiate communications with anything on my main (non-guest) network. Thank you.
I’m guessing you’re running something like pfSense, DD-WRT or OpenWrt? If so, you’d probably have much more luck asking about this at one of their respective forums.
Maybe you could put them on the same network, turn on client isolation, but maybe define ways in which some clients can communicate with others??? Just thinking out loud.
Even funnier, kid.
EDIT: 1) Use a second router with a VPN server for IOT. Access it via a VPN client on the phone from any other network. It's gonna be laggy.
or: 2) Use a guest network on your router for IOT, and access it from your phone by switching wi-fi networks.