Jobos Posted February 10, 2025 Posted February 10, 2025 I have inherited a unifi network consisting of USW Pro, USW Lite switches and AC LR APs. The router is a small HP model but I have no access to it. The network is completely flat but they have the main SSID and a guest SSID all on the same network with no isolation between them. At my old school I used VLANs to separate the networks and the ISP did their bit on the router and there were no issues. Here the ISP seems reluctant to create VLANS on the router and instead said I could isolate the networks using Unifi alone. Is this so and how would I achieve this?
pablo007 Posted February 10, 2025 Posted February 10, 2025 In your wireless network settings for the ssid you need to isolate, choose 'Apply guest policies (captive portal, guest authentication, access)'
Davit2005 Posted February 10, 2025 Posted February 10, 2025 (edited) Use another router/fw to terminate the Guest network, you will prob need ISP to add a route from the ISP router to the new router. Once you get that far you could also move potentially do the same and move other internal vlans to the same router/fw two and get back control :-) Edited February 10, 2025 by Davit2005
Olliedawg Posted February 10, 2025 Posted February 10, 2025 Do you have a firewall after the ISP router? Can you configure the VLANS here? That’s what I do. ISP Fibre modem > ISP Router > school owned firewall (VLANS here) > Core switch 1
jmak Posted February 10, 2025 Posted February 10, 2025 You should be able to achieve satisfactory isolation without VLANs*: https://help.ui.com/hc/en-us/articles/23352709241495-UniFi-Switches-and-Access-Control-Lists-ACLs You can also configure client isolation at the AP: https://help.ui.com/hc/en-us/articles/23948850278295-Best-Practices-Guest-WiFi#:~:text=UniFi%20allows%20you%20to%20create,maintaining%20control%20over%20your%20network. This isn't like the old-fashioned Unifi approach of just putting the guest network on a separate subnet. Ubiquiti Unifi is a pretty full featured SDN platform now. *Note: Cyber Essentials doesn't recognise this method of isolation - yet 2
Jobos Posted February 10, 2025 Author Posted February 10, 2025 Use another router/fw to terminate the Guest network, you will prob need ISP to add a route from the ISP router to the new router. Once you get that far you could also move potentially do the same and move other internal vlans to the same router/fw two and get back control :-) I see where you’re going with this but unfortunately we do not have a spare router and no chance of getting one either as orders have stopped until Easter. We are in contract with the ISP for another 12 months so later in the year we will be looking for a new provider anyway. Do you have a firewall after the ISP router? Can you configure the VLANS here? That’s what I do. ISP Fibre modem > ISP Router > school owned firewall (VLANS here) > Core switch See answer above.
Jobos Posted February 10, 2025 Author Posted February 10, 2025 You can also configure client isolation at the AP: https://help.ui.com/hc/en-us/articles/23948850278295-Best-Practices-Guest-WiFi#:~:text=UniFi%20allows%20you%20to%20create,maintaining%20control%20over%20your%20network. I like this so will try this first method first.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now