Comment Re:IoT SSID (Score 3, Informative) 33
Despite having OpnSense as my router and a managed switch, for some reason I never considered separating things on my local LAN subnet until I was working on a remote backup PBS server I was going to put in my daughter's home and wanted it to by default VPN into my home, but I didn't want it to end up on my home subnet. Out came a separate subnet for a DMZ with no access to anything except me being able to access it. Once I did that, I ended up setting a guest WiFi VLAN, a second VPN subnet for remote access instead of SSH, and a separate VLAN for stuff like Roku which don't do anything but access the internet.
To be honest, doing the whole thing was somewhat easier than I thought, but nowhere near what a casual, non-technical user would be able to do. The problem is that without an actual VLAN implementation, a "guest" SSID is not ironclad. It just takes more equipment and more know-how to separate things for casual users.