ChosenHillIT Posted May 19 Posted May 19 (edited) Afternoon I am trying to plan to install a UI Dream Machine Pro into my exisiting network but am have a mind blank. We have out internet provided by ExaNetworks via a Ubiquiti EdgeRouter. The LAN Port of the EdgeRouter (Eth0) is plugged directly into a port A1 on my Core Switch (HP ProCurve). I know I need to put the UDMPro inline between the EdgeRouter and the Core switch but for the life of me can I figure out the best settings for this that has minimal impact to the network or doesnt require a rebuild. Any advise would be most gratefully received. Edited May 19 by ChosenHillIT
ZeroHour Posted May 19 Posted May 19 Where is DHCP? You will need to get it setup with a static ip thats on a different subnet from your main network then all ports etc forwarded from the EdgeRouter to it to allow things to work.
Synkrox Posted May 19 Posted May 19 Will Exa not let you just plug the internet fibres straight into the UDM? I see no reason for the added point of failure otherwise. Setup the UDM offline with the same config as the edgerouter, and just drop it in place.
ChosenHillIT Posted May 20 Author Posted May 20 @ZeroHour - Our DHCP servers sit in the network, hanging off a vlan on the Core Switch. Not sure if this helps: Edge Router LAN Port has IP of 10.1.102.253 Core Switch is 10.1.102.1 vlans are 10.1.*.1 - On Access switches the gateways are set to the IP of the VLAN on Core Switch. On Core Switch, the gateway is 10.1.102.253 Was planning on setting up the UDMPro as vlan 140 (10.1.140.1) on the networ interfaces. On the WAN port: 10.1.102.250 and then remove the WAN cable from the core switch into the WAN port on the UDMPro? @Synkrox - I wish. I ask that question and they said no!
ZeroHour Posted May 20 Posted May 20 You ideally would need the Edge Router to be on say 192.168.0.X or similar subnet with your unifi on a static ip on that range for its WAN connection. The edgerouter should forward traffic ports for openvpn, wireguard to the unifi and ICMP to the static ip used on the UDM WAN IP. I presume the Edge Router is managed by Exa? I have my UDM behind an EE router basically (PPPoE is still a bit slow) and other than ipv6 being limited to one vlan it works well enough but the EE router blocks ICMP.
ChosenHillIT Posted May 21 Author Posted May 21 @ZeroHour so having the gateway address on the WAN port of the UDM? that way all internal traffic point to the UDM for the internet and not the edgerouter.... Hmm I'll as the question
ZeroHour Posted May 21 Posted May 21 Ideally you would hand back the edge router and just stick the UDM into the WAN cable it uses and then enter the ip details Exa has but if you have to use the edge router you need to ensure the 2 internal subnets are different, aka the edge -> UDM being say on 192.168.0.0 and UDM -> network being as is set right now with ports forwarded for openvpn and wireguard for vpn functionality with the UDM wan being a static 192.168.0.X ip that is forwarded traffic to as a DMZ device. IPv6 will be limited unless Exa give you a /48 I think if you still have the edge router in the mix. Quote so having the gateway address on the WAN port of the UDM? that way all internal traffic point to the UDM for the internet and not the edgerouter. Yes your internal network would point to the internal address of the UDM unless you are wanting the UDM just for managing wifi / switches in which case a UDM might be overkill as you only need the Network app part. Right now the edge router is acting as your firewall but the UDM can easily do that job.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now