Flat home networks treat a smart plug and a payroll laptop as equals — attackers love that architecture.

Hybrid work, game consoles, doorbells and school tablets now share one Canadian ISP connection. Segmentation sounds enterprise-y; in practice it can be as simple as a guest SSID plus an IoT network on a modern mesh kit. This guide walks through realistic setups without requiring a rack full of switches.

Why segmentation matters at home

IoT devices update slowly and rarely get the scrutiny of phones. If a camera is compromised, you want it blocked from probing the laptop that holds CRA filings and client files. Kids' devices benefit from filtered DNS without forcing the same rules onto a home office machine.

Tiered model that fits most households

  • Trusted LAN: work laptops, desktops, phones of adults, NAS.
  • IoT / smart home: bulbs, plugs, cameras, speakers, TVs.
  • Guest: visitors, contractors, temporary devices.
  • Optional kids: school tablets with stricter DNS and schedules.

Many consumer meshes expose « guest » and « IoT » toggles without calling them VLANs. Use them. Enthusiasts on Ubiquiti or OpenWrt can do formal VLANs — only if you will maintain them.

ISP gateway limitations

Stock Bell, Rogers and Telus gateways vary wildly in guest Wi-Fi quality. If segmentation options are weak, put the ISP box in bridge mode and buy a router/mesh that supports multiple SSIDs with client isolation. That single upgrade often unlocks the whole strategy.

Firewall rules without the headache

Default goals: IoT can reach the internet for updates but cannot initiate connections to Trusted LAN. Trusted LAN can reach IoT when you need to cast or administer devices. Guests cannot see either. Cameras that require local viewing may need a carefully allowed path — document exceptions.

Avoid UPnP on the trusted edge. Disable remote admin from WAN. Prefer mDNS reflection features only when casting breaks without them.

Work-from-home specifics

Employers increasingly require disk encryption and MDM; they also assume your home LAN is hostile. Segmentation helps you meet that assumption. Prefer ethernet to the desk for video calls. If you use a corporate VPN, keep personal torrents and shady IoT off the same broadcast domain as the work device.

Rollout plan for a weekend

  1. Inventory devices and write target network beside each.
  2. Create SSIDs with clear names (Home-Trusted, Home-IoT, Home-Guest).
  3. Move IoT devices one room at a time; re-pair what breaks.
  4. Test casting, printers and smart speakers — fix exceptions deliberately.
  5. Screenshot final settings into your password manager notes.
Segmentation is not paranoia — it is blast-radius control for a house full of gadgets that will never all be patched on the same day.