DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Buying advice: Protection from IOT malware

  • rustleg
  • Topic Author
  • User
  • User
More
17 Jan 2017 17:16 #1 by rustleg
I want to connect a "smart" TV to the internet without it having any access to the rest of the LAN. Would the Vigor 2860ac do this? And does it have to be a wireless connection? I can use either a wired or wireless connection for this TV.

More background information: I recently purchased a Vigor 2860ac for my club which intends to offer member wifi because I understand it is capable of individual wireless client isolation so that each client cannot interact with any other. I was thinking of buying one for my own personal use for this isolation feature even though it is significantly more expensive than most other routers. Perhaps there are cheaper routers which do this but I also want something I can depend on and these units seem to have a good reputation. At the moment I am using a Virgin cable modem/router used for home PCs and phones, and I am about to purchase a new "smart" TV. I am concerned about reports that consumer Internet of Things equipment is often poorly secured and attaching it to a LAN can allow access to the rest of the LAN by malware exploiting weaknesses.

Any useful comments would be appreciated.

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
17 Jan 2017 17:44 #2 by hornbyp
Completely isolating the smart tv is relatively easy to do - either via Wifi or wired.

However, you may actually want *some* access to this TV from your LAN - which is where it gets more complicated.

The sort of things I'm thinking of are: Smart Phone Remote Control App., DLNA media access to your PC, Screen Mirroring from laptops.

The Vigor does not have simple, consumer-focused firewall rules to facilitate this - you need to work out what is required, and write your own.

Please Log in or Create an account to join the conversation.

  • rustleg
  • Topic Author
  • User
  • User
More
17 Jan 2017 19:50 #3 by rustleg
Thanks for confirming that complete isolation is possible either wired or wireless.

I am not interested in any of the 3 things you mentioned, at least I don't think so. I don't actually want the smart facilities of the TV but you can't buy one nowadays without it. I just want to watch sport and wildlife documentaries in 4K from the Virgin box.

I'm not sure if I even need to connect the TV to the internet. Perhaps it could be needed if there is a necessary firmware update if that's the way they are delivered. I presume it still works without problems if you don't connect it because otherwise they would be useless where internet is not available. Of course I could change my mind in the future if there is some benefit I currently don't know about. Maybe smartphone access might be useful for some reason but I appreciate the point about this part being more difficult to set up in terms of keeping it isolated.

Please Log in or Create an account to join the conversation.

More
18 Jan 2017 10:58 #4 by aweaton

rustleg wrote: Thanks for confirming that complete isolation is possible either wired or wireless.

I am not interested in any of the 3 things you mentioned, at least I don't think so. I don't actually want the smart facilities of the TV but you can't buy one nowadays without it. I just want to watch sport and wildlife documentaries in 4K from the Virgin box.

I'm not sure if I even need to connect the TV to the internet. Perhaps it could be needed if there is a necessary firmware update if that's the way they are delivered. I presume it still works without problems if you don't connect it because otherwise they would be useless where internet is not available. Of course I could change my mind in the future if there is some benefit I currently don't know about. Maybe smartphone access might be useful for some reason but I appreciate the point about this part being more difficult to set up in terms of keeping it isolated.


If you're not using the smart functions of it then there's little point of connecting it to your LAN. Remember firmware updates can usually be done using a USB stick too.

Please Log in or Create an account to join the conversation.