Put smart TVs and cameras on a separate VLAN or isolated IoT/guest SSID so a compromised gadget cannot freely scan laptops and NAS on your main LAN. You need a router or firewall that supports VLANs/guest isolation (or a mesh vendor’s “IoT network” feature). This how-to is LAN segmentation—not Android Private DNS, not WPA3 alone, and not ISP phishing.

1. What you need

  • Router/firewall/AP firmware with VLAN, “guest network,” or “IoT network” controls (prosumer and many mesh systems).
  • Ability to set a second SSID or wired VLAN membership for TVs/cameras.
  • Optional: firewall rules blocking IoT → LAN while allowing IoT → internet (and limited LAN → IoT if you use a viewing app).

Exact menus differ by vendor—use the vendor manual for click-by-click paths; the pattern below is portable.

Convenience casting is why many homes skip isolation. If a cheap camera is wormed, flat LANs hand attackers a path to file shares—segment first, then open only the ports you prove you need.

2. VLAN vs Private DNS vs WPA3

ControlPrimary jobNot a substitute for
IoT VLAN / guest SSIDIsolate device groups on LANDNS-over-TLS on phones
Private DNSEncrypt DNS on one Android deviceStopping camera↔laptop LAN worms
WPA3Strong Wi-Fi handshakeSeparating trusted vs untrusted devices once joined

3. Steps: segment TVs and cameras

  1. Update the router/AP firmware from the official vendor source.
  2. Create a new IoT / Guest network or VLAN ID (example pattern: VLAN 20 named `iot`).
  3. Assign a dedicated SSID (e.g., `Home-IoT`) to that VLAN; use strong WPA2/WPA3 settings appropriate for those clients.
  4. Enable client/AP isolation on that SSID if you do not need camera-to-camera chatter.
  5. Firewall defaults to prefer: IoT may reach the internet; IoT may not initiate connections to your main LAN; your phone on main LAN may reach cameras only on required ports if the app needs it—or use the vendor cloud (understand the privacy tradeoff).
  6. Move smart TVs and cameras onto `Home-IoT` (forget the old SSID on each device).
  7. Keep PCs, phones, and NAS on the main LAN/SSID.
  8. Test: phone on main LAN still streams the camera app if that is required; a TV on IoT should not see your NAS shares.
  9. Document the VLAN ID and SSID in your household notes.
  10. Recheck IoT update support so segmented devices still get patches.

4. If your ISP gateway cannot VLAN

  1. Add your own router behind the ISP modem in true router mode (avoid double-NAT surprises—follow vendor guidance).
  2. Or use the gateway’s Guest Wi-Fi as a lighter isolation layer when full VLANs are unavailable.
  3. Still change router admin credentials and keep endpoints patched with Norton or Bitdefender (TotalAV, McAfee, Avast on-site).

FAQ

Will casting from phone to TV break?

Sometimes. You may need mDNS/reflection rules or keep the phone on a network that can reach the TV. Prefer vendor-documented cast ports over “allow all.”

Is guest Wi-Fi good enough?

Guest isolation is a practical middle ground when VLANs are unavailable. True VLANs give cleaner wired + wireless policy.

Does this stop ISP bill phishing?

No. Phishing is an account problem—see the ISP phishing guide.

Do cameras still need passwords?

Yes. Segmentation limits blast radius; unique camera passwords and updates remain mandatory.

Avoiding how to segment smart TVs and cameras on a separate VLAN does not require paid antivirus. Careful habits and official support paths are a valid buy-nothing stack. If you want multi-device paid protection later, use only these on-site paid links: TotalAV (paid link), Norton (paid link), Bitdefender (paid link), McAfee (paid link), Avast (paid link).