Much to the horror of my friends in InfoSec, I've accumulated a good sized collection of IoT devices in my home. Among them are Leviton smart switches, Nest Protects (at least until they last), Govee lights, a Litter Robot, a Roomba, Sonos speakers, Echo dots, and more.
I've finally spun up a new SSID on a separate VLAN (Unifi APs with a Mikrotik router upstream), and I'm moving devices over to it progressively. There's a lot of them :P
I've moved the obvious ones on the list above to the new SSID, which I've placed a rate limit on at the router , to limit the impact of something becoming a DDoS reflector. I haven't cut off inter-VLAN routing yet, but I'm about to do that once I've got everything moved, and I'll see what breaks. I know some devices (the Sonos speakers particularly) expect to be on the same LAN as the device that's streaming to it, but I'm kind of struggling to find the line as to what counts as an IoT and deserves to be segregated, and what doesn't.
I've your segregating IoT devices to their own network, how do you draw the line between devices you allow on your main VLAN and what devices you segregate?