Quote from: OPNenthu on Today at 05:56:09 AMBased on what @mooh wrote the default for these devices is that they use link-local addresses, which limits their access to what the hub provides them from its own uplink to the IOT network. That is easy enough to firewall because all you would have to do is block the hub and everything downstream of it is also walled off.Exactly. Don't worry about the thread devices. They only know the thread network and can't get out. Any traffic between the thread network and the rest of the world is via the border-router. The fact that the thread network uses link-local IPv6 addressing is entirely irrelevant for your LAN design.
ey are not able to get beyond the IOT network, but your controllers on other VLANs can still get to them (if their rules permit).