Jump to content

Recommended Posts

Posted

Hi,

 

Sorry im new to all this I am going to a unifi network and when i do i want to implement VLANs .

 

 

I've got a smoothwall as our firewall

and a self hosted unifi controller with a USW-PRO-Aggregator as the "core?"

 

Ive got the VLANS setup working with DHCP etc but how do i go about giving them access to the outside?

 

lol sorry again #noob

 

Thanks

Posted

Some people (I understand) have the Smoothwall do all the routing, and it has an IP interface in all the VLANs. I'm sure those that do this can talk you through how to set this up.

 

Another way is to have the core switch handle the internal routing between the subnets (with suitable ACLs to prevent say the BYOD subnet being able to send traffic to your MIS or other sensitive servers)

Devices in each internal subnet/vlan should have the core switch's ip address (in that subnet) set as their default gateway. (Typically this is done in DHCP scope options, but needs to be done by hand for any manually configured IP stacks e.g servers, printers, door entry systems etc.)

The default switch should have a default route set to use the internal IP address of the smoothwall.

The Smoothwall then NATs traffic between its internal interface(s) and external interface(s), with additional packet/content filtering as required.

Posted
psydii's second solution is how we have it. All VLANS and devices have the core switch as their gateway, the core has the Smoothwall as its gateway and Smoothwall then has the router as its gateway.
  • Thanks 1
Posted (edited)

If your routing the vlans on the core switch you will prob have to put a static route on the smoothwall to that subnet via the core switch IP address as it's next hop.

 

Routers will only forward IP network traffic if they have a route for it.

Edited by Davit2005
  • Thanks 1
Posted
Hi,

 

Sorry im new to all this I am going to a unifi network and when i do i want to implement VLANs .

 

 

I've got a smoothwall as our firewall

and a self hosted unifi controller with a USW-PRO-Aggregator as the "core?"

 

Ive got the VLANS setup working with DHCP etc but how do i go about giving them access to the outside?

 

lol sorry again #noob

 

Thanks

the easiest way is to use your smoothwall as the router.

 

setup another port on the smoothwall and connect it to a port with that vlan configured on it or setup the new interface with vlans on it, probably a guide on the kb for it - then the smoothwall will do all the donkey work/sets up the routes.

 

you could also reconfigure the port you currently use to have the vlans on it but its a bit of a chore if things go wrong.

Posted
I'd normally not use Smoothwall to do our inter-vlan routing, however I've never rated Unifi as a L3 solution. Trunking all the VLANs to the Smoothwall will probably be easier in your instance.
Posted
I'd normally not use Smoothwall to do our inter-vlan routing, however I've never rated Unifi as a L3 solution. Trunking all the VLANs to the Smoothwall will probably be easier in your instance.

fair, but this sounds like they just want to provide internet to the vlan so its no more of a performance impact on the smoothwall as in either config its going through it

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...