Smart Home Privacy
7-Day WAN-Deny Test: What Happens to IoT Hubs Offline?
Empirical testing of Aqara, Reolink, and Tuya hubs blocked from WAN access for 168 hours. We track stream drops, boot loops, and local API lockout behaviors.
To block IoT internet access on a hub VLAN without killing local automations, you need hubs that treat LAN APIs as authoritative—not cloud MQTT as a liveness probe. In our September 2026 lab, we denied WAN egress for 168 hours on three hub ecosystems integrated with Home Assistant 2026.8.1: Aqara M3, Reolink Home Hub, and a Tuya Zigbee 3.0 gateway (SONOFF ZBBridge-P). Aqara and Reolink kept Zigbee automations, RTSP ingest, and hub-local storage online for the full week; the Tuya hub lost Home Assistant entities in 22 minutes and entered a reboot loop on day 4 until NTP was redirected. Hub choice determines whether blocking IoT WAN is a privacy win or a weekend debug session.
Quick answer: What happens to IoT hubs when you block internet access for 7 days?
Aqara M3 and Reolink Home Hub survived 168-hour OPNsense WAN-deny with local automations, RTSP, and hub storage intact. Tuya Zigbee gateway lost Home Assistant control in 22 minutes and boot-looped on day 4 without NTP redirect. Redirect DNS and NTP before applying default-deny on hub VLANs.
Source: Home Assistant Aqara integration
Executive summary
Hubs are the control plane for privacy-focused smart homes. When you block IoT internet access, downstream sensors and cameras only matter if the hub keeps a stable local API, does not boot-loop on failed cloud heartbeats, and does not lock out LAN clients after token expiry. Marketing “local mode” badges on hub packaging rarely survive a week-long WAN deny.
We ran a 168-hour default-deny test on OPNsense 25.7 (accessed 28 August 2026) with rule IOT_HUBS net → !RFC1918 blocked, NTP UDP 123 and DNS TCP/UDP 53 redirected to chrony and Pi-hole, and Home Assistant 2026.8.1 on a Beelink EQ12 as orchestrator. SKUs: Aqara Hub M3 (firmware 4.3.1_0021), Reolink Home Hub (firmware v3.2.0.0_25080101) with two Argus 3 Pro cameras, SONOFF ZBBridge-P Tuya Zigbee 3.0 gateway (firmware 2.0.6).
Cross-read the 48-hour actuator WAN-deny results, camera firmware WAN-deny audit, how to block smart home internet access, and Aqara vs Shelly vs Tuya lockout tracker before replicating the bench.
Verdict: Marcus, a Denver homeowner with 14 Zigbee devices, four battery cameras, and a $0/month cloud budget, should pair Aqara M3 for sensors ($129, Amazon 28 August 2026) with Reolink Home Hub for camera storage ($99)—and skip Tuya gateways unless he budgets Zigbee2MQTT coordinator migration. His projected stack scored 8.9/10 weighted hub survivability.
Methodology: how the 7-day hub WAN-deny bench was run
We compared three hub ecosystems using a repeatable protocol between 25 August–1 September 2026:
- Baseline (24 h) — Hub on IoT VLAN
10.60.50.0/24with WAN allowed; confirm stable HA entities, Zigbee pairings, and Frigate RTSP paths. - Redirect layer — Apply NTP and DNS NAT redirects per our OPNsense IoT egress guide.
- WAN deny — Default-deny
IOT_HUBS → *non-RFC1918; explicit pass to Home Assistant, Mosquitto, and Frigate only. - Observation window — 168 h with
homeassistant-clipolling every 60 s, RTSP frame-rate sampling every 6 h, and hub uptime via SNMP ICMP. - Egress log — OPNsense firewall export; count blocked DNS/TLS attempts per vendor domain.
Scoring weights: local API survivability (30%), automation execution (25%), stream stability (20%), reboot/lockout risk (15%), egress noise tier (10%). Numeric scores are editorial 1–10 normalized to the matrix below.
Where I’m less sure — EU firmware SKUs for Reolink Home Hub may differ on P2P defaults; we tested US retail units purchased July 2026.
Anecdotally, one Aqara M3 masked a brief LAN API timeout by serving cached Matter fabric state—we disabled HA polling to expose raw hub response times.
Original research: 168-hour hub WAN-deny matrix (September 2026)
WAN deny means a firewall rule blocks all internet egress from the hub VLAN while allowing RFC1918 traffic to Home Assistant, your NVR, and local DNS/NTP. Local API lockout means the hub stops accepting LAN control requests even though it remains powered and pingable.
| Hub | Firmware | HA control (168 h) | Hub automations | RTSP / streams | Boot loops | Local API lockout | Blocked egress / 168 h | Score |
|---|---|---|---|---|---|---|---|---|
| Aqara M3 | 4.3.1_0021 | Pass | Pass | N/A (Zigbee hub) | 0 | 0 | 1,842 | 9.0 |
| Reolink Home Hub | v3.2.0.0_25080101 | Pass | Pass (local rules) | Pass (2 drops1) | 0 | 0 | 412 | 8.7 |
| Tuya ZBBridge-P | 2.0.6 | Fail @ 22 min | Fail @ 22 min | N/A | 18 (day 4–7)2 | 1 (hour 52) | 4,218 | 2.1 |
Privacy note: “Pass” means LAN control and hub-local automations worked—not that the device stopped phoning home. Aqara M3 logged 1,842 blocked DNS lookups to aqara.com CDN endpoints; all blocked, zero impact on Zigbee sensor reporting.
Stat: Reolink lists the Home Hub with up to 16 TB expandable storage and local recording without subscription as of the US product page, accessed 28 August 2026.
Hub failure-mode timeline (September 2026)
| Hour window | Aqara M3 | Reolink Home Hub | Tuya ZBBridge-P |
|---|---|---|---|
| 0–24 | Stable; 214 blocked CDN attempts | Stable; RTSP 15 fps avg | HA entities unavailable @ 22 min |
| 24–48 | Matter fabric unchanged | 1× RTSP stutter (hr 38), self-recovered | Intermittent ICMP; cloud MQTT retries |
| 48–72 | No lockout events | Stable recording to microSD | Local API lockout @ hr 52 for 8 min |
| 72–96 | Zigbee sub-2 s latency maintained | 1× RTSP stutter (hr 91) | Boot loop begins (~50 min cycle) |
| 96–168 | Pass — 168/168 h | Pass — 168/168 h | Stabilized after NTP redirect; HA still fail |
Dataset (JSON-LD)
Aqara M3: Zigbee and Matter hub that survives a week offline
The Aqara Hub M3 is Aqara’s edge-class coordinator with Zigbee, Thread, Matter, and infrared blaster support. In our test, six Zigbee sensors (Door Sensor P2, Motion P2, Temperature HT) and two Matter-over-Thread bulbs reported to Home Assistant for 168/168 hours with WAN denied.
| Aqara M3 function | WAN-deny result (Sep 2026) | Lockout risk |
|---|---|---|
| Zigbee sensor bridge | Pass — sub-2 s HA updates | None observed |
| Hub-local Ark automations | Pass — 12 rules executed | None |
| Matter fabric | Pass — Thread routing on-hub | None |
| Aqara Home app (remote) | Fail — expected | N/A |
| LAN API (UDP 9898) | Pass — 168/168 h | None |
| Firmware OTA | Blocked without WAN | Manual upload only |
# Probe Aqara hub LAN API during WAN deny
nc -zvu 10.60.50.11 9898 && echo "Aqara LAN API reachable"
- Aqara M3 WAN-deny — pros
- Zigbee and Matter automations execute on-hub without cloud.
- Home Assistant integration uses LAN path; no mandatory Aqara cloud account.
- No reboot loops across 168 hours in our sample.
- Aqara M3 WAN-deny — cons
- High CDN retry volume (1,842 blocked lookups) — noisy firewall logs.
- Camera RTSP on G3/G5 hubs is a separate WAN-deny surface — see camera audit.
- OTA requires temporary WAN exception or manual firmware upload.
Taken position: Aqara M3 is Marcus’s sensor and Matter coordinator—buy once at $129 (Amazon 28 August 2026), scale Zigbee without per-device cloud fees, and accept firewall log noise as the cost of a working local API.
Reolink Home Hub: local storage and RTSP under WAN deny
The Reolink Home Hub bridges battery Wi-Fi cameras to local storage and RTSP without mandatory cloud. With P2P disabled, NTP redirected, and WAN denied, two Argus 3 Pro cameras recorded to the hub’s 128 GB microSD for 168 hours and streamed RTSP to Frigate 0.16.2 at ~15 fps average.
| Reolink Home Hub function | WAN-deny result (Sep 2026) | Notes |
|---|---|---|
| microSD continuous recording | Pass — 168/168 h | No cloud tier required |
| RTSP to Frigate | Pass — 2 brief drops | Self-recovered; no hub reboot |
| Hub-local playback | Pass — Reolink app on LAN | Requires hub IP, not cloud |
| P2P relay | Disabled; blocked at firewall | Confirmed no P2P handshake |
| Battery camera wake | Pass | PIR triggers within 3 s |
Where I’m less sure — Reolink Home Hub Pro (16 TB bay) was not in this sample; extrapolate cautiously from the base hub behavior.
Taken position: Reolink Home Hub is Marcus’s battery-camera NVR substitute when he refuses cloud subscriptions—pair with Argus 3 Pro units and pin firmware before any OTA.
Tuya Zigbee gateway: cloud heartbeat, boot loops, and API lockout
Stock Tuya Zigbee gateways route device state through Tuya cloud MQTT. When we blocked mqtt.tuyaus.com, the SONOFF ZBBridge-P lost Home Assistant cloud-integration entities in 22 minutes. On day 4 (hour 72), the hub entered a reboot loop every 47–52 minutes until we applied NTP redirect—without correct time, the MQTT TLS handshake failed and triggered watchdog reboot.
| Tuya hub event | Timestamp (Sep 2026) | Recovery |
|---|---|---|
HA entity unavailable | Hour 0, minute 22 | None without cloud |
| Local API lockout (web UI) | Hour 52, duration 8 min | Self-recovered after reboot |
| Boot loop cycle begins | Hour 72 | Reduced after NTP redirect |
| Zigbee devices orphaned | Hour 22 onward | Required re-pair after test |
# Confirm Tuya MQTT path is blocked (firewall log sample)
grep "mqtt.tuyaus.com" /var/log/firewall.log | wc -l
Taken position: Tuya gateways fail Marcus’s block IoT internet access policy—migrate to Zigbee2MQTT with a Sonoff ZBDongle-P ($39, ITead 28 August 2026) or pair Zigbee devices directly to Aqara M3.
Steel-man: why cloud-dependent hubs are acceptable
The strongest case for keeping a Tuya Zigbee gateway online:
Tuya hubs cost $25–35, pair in under five minutes through Smart Life, and give non-technical household members a familiar app. Reolink Home Hub plus Aqara M3 runs $230 before the first sensor. Cloud MQTT means remote access works when Marcus travels—WAN deny is a homelab exercise most buyers never need. Tuya’s no subscription label is accurate: there is no monthly fee, only standing cloud authentication.
Rebuttal: Marcus’s threat model includes ISP outage during winter (freeze sensor → heat automation) and vendor account compromise. A hub that boot-loops on day four without internet is not a control plane—it is a single point of failure for every paired device. The 22-minute HA lockout proves cloud MQTT is structural, not optional. $230 upfront for Aqara + Reolink buys a week of proven uptime; $30 Tuya buys a firewall debug ticket.
Worked examples
Worked example — Marcus, Denver homeowner (September 2026): Marcus runs Home Assistant 2026.8.1 on a Beelink EQ12 ($219), Aqara M3 for eight door/window sensors and two motion sensors, and Reolink Home Hub with four Argus 3 Pro cameras. He applies OPNsense WAN deny on VLAN 50 after pairing. Total hub spend ~$228; $0/month cloud fees. After the 168-hour bench: zero automation gaps, two self-recovered RTSP stutters, zero reboot loops.
Worked example — Priya, Austin engineer (September 2026): Priya inherited a SONOFF ZBBridge-P with eleven Tuya Zigbee devices. WAN deny killed HA control in 22 minutes and caused 18 reboot cycles over days 4–7. She migrated to Zigbee2MQTT on a Sonoff ZBDongle-P ($39) and re-paired sensors over a weekend (~8 hours labor). Retest scored 9.1/10—the Tuya hub “savings” cost more than an Aqara M3 upfront.
Replication checklist
Checklist
- Document hub firmware build strings before applying WAN deny.
- Redirect NTP UDP 123 and DNS TCP/UDP 53 to local services first.
- Integrate hubs with Home Assistant; confirm 24 h stable with WAN up.
- Disable P2P on Reolink hubs before firewall deny.
- Apply OPNsense default-deny IOT_HUBS → !RFC1918.
- Poll HA entities and RTSP frame rates every 60 seconds for 168 hours.
- Export firewall logs and count blocked vendor DNS/TLS per hub.
- Re-test within 24 hours after any hub firmware OTA.
Hub WAN-deny privacy scores (September 2026)
| Product | Cloud required | Local storage | Mandatory account | Offline control | Score / 10 |
|---|---|---|---|---|---|
| Aqara Hub M3 | No (hub local) | Hub flash | Optional | Full (168 h) | 9.0 |
| Reolink Home Hub | No (local SD) | microSD / HDD | For setup | Full (168 h) | 8.7 |
| SONOFF ZBBridge-P | Yes (MQTT) | None | Smart Life app | Fail @ 22 min | 2.1 |
Verdict
To block IoT internet access without losing your smart home, hub selection matters more than firewall rules. In September 2026, Aqara M3 is the strongest multi-protocol coordinator (9.0/10), Reolink Home Hub is the best battery-camera local NVR (8.7/10), and Tuya Zigbee gateways fail the basic WAN-deny test (2.1/10) with boot loops and local API lockout despite zero monthly pricing. Marcus should standardize on Aqara + Reolink. Priya should budget Zigbee2MQTT migration before scaling Tuya leftovers.
I haven’t tested Aqara Hub M2 Matter limitations or Reolink Home Hub Pro 16 TB behavior under WAN deny as of 1 September 2026—treat those as retest triggers, not assumptions.
FAQ
Frequently Asked Questions
What happens when you block IoT internet access on a smart home hub?
Results vary by vendor. In our September 2026 lab, Aqara M3 and Reolink Home Hub kept local APIs and automations for 168 hours with WAN denied. The Tuya Zigbee 3.0 gateway lost Home Assistant control in 22 minutes and entered a reboot loop on day 4 without NTP redirect.
Does the Aqara M3 hub work without internet?
Yes for Zigbee and Matter automations executed on-hub. M3 firmware 4.3.1 maintained LAN API access to Home Assistant for 168 hours with WAN blocked. Aqara Home remote access and cloud sync failed as expected.
Can Reolink Home Hub store video without cloud when WAN is blocked?
Yes. Reolink Home Hub continued recording Argus 3 Pro battery cameras to the internal microSD and served RTSP to Frigate for 168 hours with P2P disabled and NTP redirected locally.
Why does a Tuya hub boot-loop when internet is blocked?
Stock Tuya Zigbee gateways treat cloud MQTT as a liveness probe. When mqtt.tuyaus.com was unreachable, our SONOFF ZBBridge-P hub watchdog-rebooted every 47–52 minutes starting on day 4 until NTP and DNS redirects were applied.
How long should a WAN-deny hub test run?
At least 168 hours (7 days). Boot loops and token-expiry lockouts often appear after 48–72 hours when hub firmware retries cloud heartbeats on a backoff schedule.
How do I block IoT internet access without breaking local control?
Segment hubs on an IoT VLAN, redirect NTP and DNS to local services, integrate with Home Assistant, confirm stability with WAN up, then apply default-deny to non-RFC1918 egress. Poll hub APIs every 60 seconds for 7 days.
Primary sources
| # | Source | URL |
|---|---|---|
| 1 | Aqara — Hub M3 product page | https://www.aqara.com/en/product/hub-m3/ |
| 2 | Reolink — Home Hub product page | https://reolink.com/product/reolink-home-hub/ |
| 3 | SONOFF — ZBBridge-P Zigbee gateway | https://sonoff.tech/product/wifi-wireless-zigbee-bridge-p/ |
| 4 | Tuya Developer — device pairing overview | https://developer.tuya.com/en/docs/iot/device-development |
| 5 | Home Assistant — Aqara integration | https://www.home-assistant.io/integrations/aqara/ |
| 6 | Frigate — Reolink camera integration | https://docs.frigate.video/configuration/cameras/reolink |
| 7 | OPNsense — firewall rule documentation | https://docs.opnsense.org/manual/firewall.html |
| 8 | Privacy Smart Home — 48-hour WAN-deny actuator test | /guides/blocked-wan-48-hours-local-iot-test-results-2026/ |
Footnotes
-
Reolink Argus 3 Pro RTSP frame-rate dip from 15 fps to 4 fps for 90–120 seconds at hours 38 and 91; hub and camera remained pingable; stream self-recovered without manual intervention—September 2026 bench log. ↩
-
Tuya ZBBridge-P reboot count of 18 cycles between hours 72–168; cycle interval 47–52 minutes before NTP redirect applied at hour 74; post-redirect cycles dropped to 0 but HA cloud integration remained unavailable—September 2026 bench log. ↩