how can I create VLAN - virtual LAN sub networks within LAN to isolate traffic generated by IoT devices. Would you recommend some proven solutions that work with IB3 and WLAN Boxes.


I've tried to connect Unifi Security Gateway enbaling DMZ on Internet Box 3 but Unifi Controller is not able to detect USG router.


Thank you.

Maybe @Tux0ne can help you with this problem 🙂

I have followed the instructions written on


1. Put IB on, network mask Set DHCP range in IB to

2. Add static DHCP route for USG in IB configuration, give it

3. Factory reset USG, connect to IB 1 gbps LAN port

4. Put USG in DMZ in IB config

5. Restart AP, adopt USG

But on my UNIX system Unify application does not detect USG.

So maybe there are some alternatives for setting up a VLAN with IB3.


My suggestions:

  1. Ignore everything to do with Swisscom (IB, Internet, DMZ, port-forwards, blah-blah-blah) for now. All that stuff is easy to do once your Linux controller has adopted the USG (and any other UI items), and you have bullet-proof admin control.
  2. Make yourself a wired Admin sub-net ( for example). Switch your Linux box to the Admin sub-net ( for example), wire to the USG, and persuade your UI app to adopt the USG (similarly any other UI devices).

Adoption is the only hard part of the process …almost everybody gets lost the first time. 

There is plenty of help on the UI website. 

I don’t use USG so cannot offer any USG-specific advice.


In my network I run Guest & IoT “naked” — a UI AC-PRO does client-isolation and is wired directly to the Swisscom IB. AC-PRO is managed (wired) by UI app on the admin Ubuntu machine.


Private & Admin VLANs are behind a pfSense box (not USG, but doing a similar job).

Admin VLAN is wired-only, and connects to managed devices over untagged ports.

Private VLAN wifi uses several UI Flex-HD controlled by UI Cloud-Key. C-K web-interface accessed from Ubuntu machine over Admin VLAN.



