UniFi VLAN Configuration: Corporate, IoT and Guest Networks - 夜莺博客

UniFi VLAN Configuration: Corporate, IoT and Guest Networks

A VLAN on UniFi is three settings in three different screens, and creating the network is only the first of them. Devices land on the wrong broadcast domain most often because the SSID, the switch port profile and the firewall policy were configured by three different people at three different times. This guide wires all three consistently for the standard three-network design — corporate, IoT and guest — and covers the isolation step that most deployments skip.

Plan Before You Click

Network VLAN ID Subnet Purpose
Corporate 10 192.168.10.0/24 Workstations, servers, AP management
IoT 20 192.168.20.0/24 Cameras, sensors, smart TVs, appliances
Guest 30 192.168.30.0/24 Visitors, internet-only

Never build on VLAN 1 — keep the default network for management during the change, so a mistake does not take away your way back in.

Step 1: Create the Networks

In Settings → Networks → Create New Network, for each VLAN set:

  • Name — something a human recognises in a firewall rule six months later.
  • Purpose — Corporate for internal segments, Guest for the visitor network (Guest auto-applies LAN-blocking firewall rules).
  • VLAN ID — 10, 20, 30.
  • Gateway/Subnet — define explicitly, do not accept the auto range.
  • DHCP — enabled per network unless a firewall or Windows server owns DHCP.

Step 2: Map SSIDs to VLANs

In Settings → WiFi → Create New WiFi Network, select the network you just built and, under advanced options, enable Use VLAN with the matching ID. For the guest SSID also enable the guest policy so client isolation and LAN blocking apply.

One subtlety that costs hours: many IoT platforms rely on mDNS and UPnP discovery. Multi-device protocols (Chromecast, AirPlay, some printers) break the moment you isolate the VLAN. Enable multicast enhancement on the IoT SSID, and expect to add narrow allow rules for discovery if a device still cannot be found.

Step 3: Wired Ports and Port Profiles

In Devices → [your switch] → Ports, set the port profile:

  • All — the native/untagged network, used for ordinary workstations.
  • VLAN Only (tagged) — a trunk toward another switch or an AP.
  • Native VLAN / Network on a specific port — for a wired IoT device such as a camera or access-control panel, so its untagged traffic lands in VLAN 20 without any device-side VLAN awareness.

Create named profiles in Settings → Profiles → Switch Ports rather than editing ports ad hoc; a profile called IoT-Access-20 documents itself.

Step 4: The Isolation Rules Everyone Skips

Creating a VLAN does not, by itself, stop anything from reaching anything else in every UniFi configuration. Add explicit firewall rules in Settings → Firewall & Security → Firewall Rules, ordered above any broad allow:

Rule Source Destination Action
Block IoT → LAN 192.168.20.0/24 192.168.10.0/24 Drop
Block LAN → IoT 192.168.10.0/24 192.168.20.0/24 Drop (or allow for management hosts)
Allow IoT → Internet 192.168.20.0/24 WAN Accept
Block Guest → LAN 192.168.30.0/24 192.168.10.0/24 Drop

Add narrowly scoped allow rules above the block rules for exceptions: a smart display that must reach a media server, a camera NVR on the corporate VLAN, or a captive portal controller. Specific rules go above general ones — UniFi evaluates top-down and stops at the first match.

Step 5: Verify Isolation, Do Not Assume It

# From an IoT-VLAN client, these must fail:
ping 192.168.10.1        # corporate gateway
nslookup internal.corp   # internal DNS

# These must succeed:
ping 1.1.1.1
curl -sI https://example.com | head -1

Also check the boring failure modes: a client that associates and never gets an IP usually has a VLAN mismatch between the SSID and the switch port profile, or a DHCP server that is not enabled on the new network.

Observability Worth Having

If your gateway supports IDS/IPS, enable it on the IoT VLAN — that segment produces the most noise and the least legitimate east-west traffic, so anomaly detection there is unusually high-signal. Document VLAN IDs, subnets and rule intent somewhere other than the UniFi UI; the next person to touch it will thank you.

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://carthageelectronics.com/set-up-vlan-unifi-iot-devices-2026-guide