this post was submitted on 26 Nov 2023
1 points (66.7% liked)

Home Automation

79 readers
2 users here now

Home automation is the residential extension of building automation.

It is automation of the home, housework or household activity.

Home automation may include centralized control of lighting, HVAC (heating, ventilation and air conditioning), appliances, security locks of gates and doors and other systems, to provide improved convenience, comfort, energy efficiency and security.

Warning: Working with electricity can result in injury, property damage, or even death if it is not done properly. Please keep this in mind while assisting others. If you are not sure about what you are doing, hire a licensed professional.

Rules

founded 1 year ago
MODERATORS
 

I have a Hisense TV. I was wondering if there's an easy way to firewall their TV so that it only has access to Google Store and Netflix? Make it so the TV can't reach anything else?

I don't currently have any firewall. I have ddwrt as my main router. I can whip up a pihole if needed.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 0 points 11 months ago

Yes. You will need to use firewall rules to allow the IPs of the desired services and then deny all other traffic to-from the TV.

You're challenge is that DDWRT only supports numeric IP addresses in its rules, and not Fully Qualified Domain Names(FQDN). So, for your current firewall, you will need to create a list of all the desired IP addresses and then create allow rules for each, or each subnet(range). You'll need to update this list regularly as the individual IPs change semi-frequently.

A Pi Hole might work but it would be prone to leakage, letting undesired traffic pass, and not block hard coded IPs.

If you had a firewall that allowed you to use FQDNs in rules/policies then you could easily achieve your goal. there are several somewhat pricey commercial firewalls that can do FQDN policies. On the free side, pfSense/OPNsense can do FQDN policies using aliases. There may also be others that I am not aware of.