How to set up a firewall that blocks telemetry at home
Connected devices constantly send information away from your home network. Some of it is necessary for a service to work, such as an update check or a weather forecast. Other traffic reports usage patterns, device identifiers, diagnostics, advertising IDs and behavioural data to manufacturers, analytics companies or advertising brokers. A firewall can reduce this flow, but effective protection requires more than ticking a “privacy” setting in a router app.
The practical aim is to control outbound connections without making the household unusable. You need to identify which devices are communicating, decide which destinations they actually need, and apply restrictions in a place the devices cannot easily bypass. This approach works for a typical Australian home using an NBN connection, a supplied ISP router and a growing collection of televisions, speakers, cameras, lights and streaming boxes.
Understand what telemetry looks like
Telemetry is the broad category of data sent from a device to its maker or associated services. A smart television may transmit viewing activity, application usage and device status. A phone may contact advertising and analytics domains even when its owner is not actively using an app. Smart speakers, fitness watches, printers and light bulbs can send diagnostic events, account identifiers and connection details.
The traffic is often encrypted, so a firewall may not be able to read its contents. It can still inspect useful metadata: the device making the connection, the destination domain or IP address, the time of the request and the volume of data transferred. DNS requests are particularly valuable because they frequently reveal the service a device is trying to contact before an encrypted connection begins.
This matters in Australia because household data practices sit alongside a complicated privacy environment. The Privacy Act and Australian Privacy Principles regulate many organisations, with oversight from the Office of the Australian Information Commissioner, but they do not turn every personal device into a private network by default. A household firewall gives you a direct technical way to reduce collection rather than relying solely on corporate policies or consent screens.
Before changing anything, list the devices connected to the network. Include the NBN connection box, router, phones, laptops, game consoles, televisions, streaming dongles, cameras, smart meters where accessible, lights and appliances. The list should record the device name, owner, purpose and whether it still needs internet access.
Put control in the right place
The simplest arrangement is a router with useful outbound controls. Some ISP-provided routers in Australia offer basic access schedules and parental controls but limited domain blocking. If yours cannot create reliable DNS rules, VLANs or outbound policies, you can place a separate router behind it, or replace it with equipment running OpenWrt, OPNsense or pfSense. Check compatibility with your NBN service before making changes, especially if your provider uses specific VLAN, PPPoE or authentication settings.
A DNS filtering server is an accessible starting point. Pi-hole and AdGuard Home can run on a small computer, virtual machine or compatible network appliance. Configure the router to distribute the filtering server as the DNS resolver through DHCP. The resolver then compares requests against blocklists and returns no useful address for unwanted domains. This can stop advertising, tracking and telemetry endpoints across many devices without installing software on each one.
DNS blocking is not the same as a complete firewall. A device might use a hard-coded DNS server, connect directly to an IP address, use DNS over HTTPS, or contact a shared cloud endpoint that also carries essential traffic. A stronger router can redirect ordinary DNS requests to your resolver, block outbound port 53 except from the resolver, and restrict known DNS-over-TLS or DNS-over-HTTPS paths. This should be tested carefully because aggressive blocking can affect browsers, operating systems and apps.
Keep your network design understandable. Put ordinary computers and phones on a main network, untrusted smart-home equipment on an IoT VLAN, and guests on a separate guest network. The IoT segment should be able to reach the internet only when necessary and should have limited access to laptops, network storage and printers. This separation reduces the damage caused by a poorly secured camera or appliance, even if its telemetry cannot be completely stopped.
Build a useful blocklist
Begin with broad, maintained lists rather than copying hundreds of random domains into a firewall. A reputable advertising and tracking list can remove common analytics services, but it will produce false positives. Manufacturer-specific lists may be useful for a television or speaker, yet they can also block firmware updates or account login functions. Start with one general list and add targeted entries only after reviewing logs.
Give each device a policy based on its purpose. A smart light may need to contact a cloud service for remote control, while a bedside lamp that is controlled locally should need no internet access at all. A streaming box requires access to content providers but may not need advertising measurement domains. A security camera may need time synchronisation and remote viewing, but unrestricted access to dozens of analytics hosts is difficult to justify.
For a deeper example of why ordinary household items deserve scrutiny, read this smart lightbulb review. The important lesson is that privacy exposure is not limited to phones and social media. A device that appears simple can still have a manufacturer account, cloud dependency and several communication paths that are invisible during normal use.
Use logs as evidence rather than blocking everything that looks unfamiliar. A domain may belong to an update service, content delivery network or certificate provider. Look for repeated connections, timing patterns and requests that continue when the device is idle. Block one category at a time, then test the device. Keep a short record of what was blocked and why, so another household member can understand the decision later.
Test rules without breaking the house
Make a backup of the router configuration before applying restrictions. Change one setting at a time and test common activities: streaming ABC iview or Netflix, making a phone call over Wi-Fi, using banking websites, printing, casting video and controlling lights. A rule that looks harmless in a log can disable a login flow several steps later.
Start with observation mode where possible. Let the DNS resolver collect requests for a day or two, then identify the busiest destinations. For a television, watch what happens when it is powered on, when an application opens and when it sits idle overnight. For a phone, remember that the device may be using mobile data rather than the home firewall, so Wi-Fi logs do not represent all of its communication.
IPv6 deserves specific attention. If the router filters only IPv4, a device may continue using an IPv6 connection outside the intended policy. Either configure equivalent IPv6 rules and DNS handling or disable IPv6 temporarily while you learn how your equipment behaves. Do not assume that a successful IPv4 block proves the device is quiet.
Encrypted DNS is another bypass route. Modern browsers and operating systems may select their own resolver through DNS over HTTPS. Disable that feature on managed household devices where appropriate, or use a router and network policy that supports controlled encrypted DNS. Some devices cannot be configured cleanly; placing them on a restricted VLAN is usually safer than pretending the policy is comprehensive.
The goal is a stable rule set with clear exceptions. Allow essential update and authentication services when there is no practical alternative. If a device stops functioning after a block, record the exact domain, permit it temporarily, and investigate whether a local-only replacement or a less connected device would be preferable.
Maintain privacy as devices change
Telemetry blocking is ongoing maintenance because domains, firmware and cloud providers change. Review firewall and DNS logs monthly, especially after a router update or the addition of a new appliance. Remove old devices and stale DHCP leases. Update the filtering software and blocklists, but read release notes when a list becomes unusually aggressive.
Change the router’s administrator password, disable remote administration from the internet and install security updates promptly. Use a separate password for the Wi-Fi network and enable WPA2 or WPA3, depending on device compatibility. If an old appliance cannot receive updates, place it on the IoT network and restrict its access rather than allowing it to share a flat network with personal computers.
Australian homes have practical constraints. In a Sydney apartment or a Melbourne terrace, wireless congestion from nearby networks may make a separate access point more reliable than increasing transmit power. In regional areas, an outage or a slow NBN connection can make cloud-dependent appliances frustrating, so local control is valuable. Households that stream sport, use telehealth or work from home should prioritise availability and create narrowly tailored exceptions instead of applying a universal block.
Privacy also involves habits and expectations. Explain to family members why a device might lose remote access, and agree which functions matter. Someone who wants to control lights while travelling may accept a particular cloud connection; someone else may prefer a local button. Thinking through those trade-offs is part of the wider digital awareness explored in Brain Food, where technology is considered as a social and personal issue rather than merely a collection of settings.
| Approach | What it blocks well | Main limitation | Suitable use |
|---|---|---|---|
| Router blocklists | Known telemetry and advertising domains | Limited visibility and weak device-level control | Small networks and first steps |
| Pi-hole or AdGuard Home | DNS-based tracking across many devices | Bypassed by hard-coded or encrypted DNS | General household filtering |
| IoT VLAN | Lateral movement and access to private devices | Does not automatically block cloud traffic | Smart appliances and cameras |
| OPNsense, pfSense or OpenWrt | Detailed outbound rules, VLANs and logging | More setup and maintenance | Households wanting granular control |
| Full internet deny rule | Almost all external telemetry | Breaks cloud features and updates | Offline devices or tightly controlled appliances |
A sensible home firewall is therefore a process of reducing unnecessary communication, not a promise that every packet can be identified. Start with a device inventory, install DNS filtering, secure IPv6 and alternate DNS paths, then isolate appliances that cannot follow your rules. This gives you measurable control while preserving the services the household actually uses.
Tonight, log in to the router, export its configuration, and write down every connected device before blocking a single domain.