cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Virtual LAN Vlan

Nauflilleiss67
Modérateur
1 of 4

Hello,

 

how can I create VLAN - virtual LAN sub networks within LAN to isolate traffic generated by IoT devices. Would you recommend some proven solutions that work with IB3 and WLAN Boxes.

 

I've tried to connect Unifi Security Gateway enbaling DMZ on Internet Box 3 but Unifi Controller is not able to detect USG router.

 

Thank you.

3 Comments 3
DomiP
Modérateur
2 of 4

Maybe @Tux0ne can help you with this problem 🙂

Gruess, Cordial salids, Cordialement, Cordiali Saluti, Cheers!
Dominik

Nauflilleiss67
Modérateur
3 of 4

I have followed the instructions written on https://community.swisscom.ch/t5/Router-Hardware/IB-with-USG-Unifi-Security-Gateway/td-p/626803

 

1. Put IB on 192.168.0.1, network mask 255.255.0.0. Set DHCP range in IB to 192.168.0.101-192.168.0.254

2. Add static DHCP route for USG in IB configuration, give it 192.168.1.1

3. Factory reset USG, connect to IB 1 gbps LAN port

4. Put USG in DMZ in IB config

5. Restart AP, adopt USG

But on my UNIX system Unify application does not detect USG.

So maybe there are some alternatives for setting up a VLAN with IB3.

 

Tchris
Modérateur
4 of 4

My suggestions:

  1. Ignore everything to do with Swisscom (IB, Internet, DMZ, port-forwards, blah-blah-blah) for now. All that stuff is easy to do once your Linux controller has adopted the USG (and any other UI items), and you have bullet-proof admin control.
  2. Make yourself a wired Admin sub-net (10.11.12.0/24 for example). Switch your Linux box to the Admin sub-net (10.11.12.200 for example), wire to the USG, and persuade your UI app to adopt the USG (similarly any other UI devices).

Adoption is the only hard part of the process …almost everybody gets lost the first time. 

There is plenty of help on the UI website. 

I don’t use USG so cannot offer any USG-specific advice.

 

In my network I run Guest & IoT “naked” — a UI AC-PRO does client-isolation and is wired directly to the Swisscom IB. AC-PRO is managed (wired) by UI app on the admin Ubuntu machine.

 

Private & Admin VLANs are behind a pfSense box (not USG, but doing a similar job).

Admin VLAN is wired-only, and connects to managed devices over untagged ports.

Private VLAN wifi uses several UI Flex-HD controlled by UI Cloud-Key. C-K web-interface accessed from Ubuntu machine over Admin VLAN.

 

Chris

Back to top