Create an IoT VLAN with its own SSID and DHCP range, denying lateral traffic to personal laptops and phones. Permit only your hub’s IP to reach specific devices, and reflect mDNS thoughtfully using Avahi or router features. This lets discovery function without gifting blanket access. Over time, you can refine policies per device class, limiting cameras differently from lamps. Segmentation prevents a single compromised plug from becoming a backstage pass to everything else you value on the home network.
Run your own DNS and DHCP so everything has predictable names, then sinkhole telemetry domains. Tools like AdGuard Home or Pi‑hole reveal who phones where, turning invisible leakage into actionable lists. Combine domain blocking with firewall egress rules for belt‑and‑suspenders certainty. Give your hub a memorable hostname and TLS via local certificates. With clean naming and accountable lookups, your automations remain easy to reason about, logs become readable, and silent background chatter no longer dictates what your household exposes.