Recommended Posts

Very soon we will be replacing our old Cisco switches with new Unifi USW-Pro-48 and the new Cloud key Gen2. We also have 2 access gateways, one is our FortiGate which is our main 200/200Mbps fiber connection, the other is a Draytek to our 40/20 FTTC used as a backup and guest internet. We want to create 2 wifi networks, one connects company hardware to the main LAN, the other to connect and isolate guests using unifi's guest profile to the internet only through the Draytek. 

 

I have created 2 networks, Main for the corporate network and Guest for visitors and associated them to their respective wifi networks. Both have DHCP set to relay with the IP address of the DHCP server, yet in testing on the guest network, the device I connect doesnt get an IP address and using a static IP doesnt allow me to ping anything on the subnet.

 

I am hoping that @BudMan has played enough witht he unifi networks to advise, ideally we want to avoid VLANs as we want to reduce the complexity or our network (there is only around 40 people in this building) and from what I can tell, it is very possible but struggling to get DHCP to relay from the Draytek.

 

Any thoughts?

Link to comment
https://www.neowin.net/forum/topic/1421837-unifi-wifi-setup-with-guest-access/
Share on other sites

On 27/09/2022 at 06:08, StrikedOut said:

ideally we want to avoid VLANs

This would be done with vlans.  Its not complex, setup a vlan for your guest network.  Set that up in the unifi AP to put the vlan ID on the ssid your guests will use.

 

I have zero play/testing with unifi guest feature, but I can you for sure the proper way to do this would be with vlans.  Guest network is normally setup when everything is on the same network and you just limit your guest from talking to other devices, on that same network.  Guest network in soho routers and even unifi is for home users that do not have the ability to setup vlans to be honest.

Thanks @BudMan, although I wanted to avoid VLANs as I have limited experience plus there are only 40 people in htis office but it is inevitable and have started making the change but still having issues.

 

New setttings for the Guest Network are;

Network -> Guest profile. VLAN-only network on ID 99

WiFi -Guest WiFi profile. Double checked the network showed the correct network. Wifi type is standard.

Profiles -> Switch Ports. Created a new profile, left native network as default and added the guest network as a tagged network, left everything else on auto.

On the switch, selected the 2 ports being used for testing and changed the port profile to the new profile created above.

 

I am getting an IP address but no internet access and on a network scan, I see no other devices where there should be several.

 

What am I missing?

On 27/09/2022 at 11:19, StrikedOut said:

Network -> Guest profile. VLAN-only network on ID 99

Did you auth to the portal?  I could enable guest services I guess  on unifi and play with it..

 

What gateway are you getting?  Can you ping that IP?  This is your other router right?

On 27/09/2022 at 21:16, BudMan said:

Did you auth to the portal?  I could enable guest services I guess  on unifi and play with it..

 

What gateway are you getting?  Can you ping that IP?  This is your other router right?

'Did you auth to the portal?' - Gonna sound stupid but can you carify what you mean?

 

I can connect to the guest wifi and get a valid IP address and the correct gateway and DNS IP addresses but am unable to ping anything on this subnet, the router is the DHCP server and I can see my device in its ARP and DHCP lease tables.

If I change the network the wifi profile is using to default (no VLAN), it works as expected.

Did you enable auth to a portal when you setup your guest network..

 

guest.jpg.76034de00074c4f8a31b2be0af29496e.jpg

 

This isn't difficult - you want a "guest" network that is not connected to your normal network.  This is a simple ssid on a vlan.. Turn off all that guest stuff...

Guest Landing page is definately off.

 

image.png.a5341c85b20ec7b9461d0acf6f686eda.png

 

The Wifi is also set to be a standard type, not guest.

 

image.png.e20eb77abd8b7a2629b446e80d01ef7c.png

 

And the network is set to VLAN-only mode.

 

image.png.7428c08915b03f16fb76098941f1fc3c.png

 

The profile for the switch ports are set as default for the native network and the guest network is tagged.

 

image.png.f4511a211d30989285f9f756759e3db8.png

 

And this profile is set on the ports I am testing with, I believe I have set it all correctly so taking a closer look at the router to see if there is something set on there I haddnt seen previously. It has been in use for some time and I have seen some settings that I wouldnt have set in other systems.

Edited by StrikedOut
  • 1 month later...

Quick update.

Completed this last weekend and what stumped me was the term for the trunk ports, UNifi just use an 'All' profile. So now have 5, USW-Pro-48-PoE Plus a could of Flex switches in areas not originally designed to be networked and the original nano AP, all using 3 VLANs for main, guest and CCTV.

These are the finished results for our comms cabinet.

image.png.3c26475b61c27d403487ab93f28198d1.png

So satisfying the get this finilly finished with a much needed shove from @BudMan.

On 11/11/2022 at 00:46, BudMan said:

What an improvement - sweet!

 

But that is not how you mount an AP hehehehe

But mounting it that way makes the wi-fi stronger in the vertical right?? 😉 

That was a temp so the cable was used, it now screwed to the wall. Still got a couple of changes to go, The fiber needs to be routed under those cables and secured, got new fiber to swap out but not had a day off this month so it can wait a little while!

On 11/11/2022 at 03:25, StrikedOut said:

way makes the wi-fi stronger in the vertical right?? 😉 

Yeah sure, and the metal cabinet also amplifies the signal - hehehe rofl

On 11/11/2022 at 10:08, BudMan said:

Yeah sure, and the metal cabinet also amplifies the signal - hehehe rofl

At least it's not inside a mesh cabinet... seen that before at a DC...

On 11/11/2022 at 23:21, Matthew S. said:

At least it's not inside a mesh cabinet... seen that before at a DC...

To be honest, I am finding the APs in 'less that ideal' positions at this office. In cupboards, behind printers etc. Not a priority as the signal is strong enough to work but its on my todo when the more important tasks are complete.

That is odd, since most offices have drop ceilings - which makes it very simple to correctly place and install APs

Does this office not have a drop ceiling? Getting a ethernet into a cupboard seems odd for sure.

 

On 13/11/2022 at 13:23, BudMan said:

That is odd, since most offices have drop ceilings - which makes it very simple to correctly place and install APs

Does this office not have a drop ceiling? Getting a ethernet into a cupboard seems odd for sure.

 

Has drop ceilings and raised floors, was just a lazy approach to the instal. Those that did get put into the ceiling were placed on top of the tiles. Shame, it only takes a couple minutes to install properly. This place is going to be a work in progress for a while but the company are good and seem ready to back the choices being made. We have an £18k budget to replace our storage with a high speed device, currently using 2 small SOHO NAS, one QNAP, the other Synology 1U, 4 bay storage and there are 3 USB attached storage devices connected to servers. Also have agreed a second high capacity NAS for archive, CCTV and other non critical storage. On top of the other quility of work life improvements, going to be a fun year.

On 13/11/2022 at 16:57, StrikedOut said:

are 3 USB attached storage devices connected to servers

Well seems you have some real lowing hanging fruit to pick..  WTF so they had no it before, the the guy was just clueless??

On 14/11/2022 at 07:18, StrikedOut said:

turn it off and back on/have you Googled it.

Which are valid IT troubleshooting methods ;) heheh ROFL..  Just ask anybody that has a home router - they will tell you how to fix anything. Just have to reboot it and let it sit for 30 seconds then plug it back in.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Posts

    • Subscription upon subscription... That old Xzibit Pimp my ride meme comes to mind
    • EA reached out to our reporter that mainly does gaming content and reviewed loads of other games, why would this be shocking to anyone? I admit maybe we were considered this time around because of the extra coverage UFC was getting and they wanted a broader audience for this release? IDK. I can tell you that we aren't paid to do the reviews, the fun part of it is (mostly) being able to keep what we review and giving an honest opinion on what we're reviewing.
    • Save over $430 on Sterling Stock Picker (lifetime subscription) by Steven Parker Today's highlighted Neowin deal comes via our Apps + Software section of the Neowin Deals store, where you can save 88% off on a lifetime subscription to Sterling Stock Picker. Sterling Stock Picker (SSP) is an award-winning platform designed to make stock investing accessible to everyone, regardless of expertise. The software offers multiple methods to identify winning stocks that align with your personal values, investment preferences, and risk tolerance. By handling all the complex calculations, it allows you to focus on making informed investment decisions. The patent-pending North Star technology provides clear guidance on whether to buy, sell, hold, or avoid a particular stock. Ask Finley, your personal AI financial coach Finley is your personal AI financial coach providing real-time data access, strategic investment advice, risk assessment, and educational support to help you make informed decisions. Whether you're a seasoned investor or just starting, Finley is equipped to help you achieve your financial goals. Feel free to ask any questions about your portfolio or the stock market. PERSONALIZED FINANCIAL GUIDANCE Custom Recommendations: Get stock picks tailored to your risk tolerance, portfolio performance, and investment goals. Dynamic Insights: Access detailed financial, technical, earnings, growth, and risk analysis for smarter investing. ENHANCED PORTFOLIO MANAGEMENT Done-For-You Portfolio Builder: Easily construct a diversified portfolio based on your risk tolerance and investment goals. Analysis and Suggestions: Receive data-driven portfolio adjustments to optimize returns based on your risk acceptance score. Risk Assessment Overview: Understand your risk level and receive stock recommendations aligned with your investment strategy. STRATEGIC INVESTMENT ADVICE Stock Rockets: Discover top-performing companies with over 50% quarterly revenue growth and the highest North Star rankings. Concentrated Portfolio Strategy: Focus on high-potential stocks instead of broad diversification to maximize growth. Industry and Sector Insights: Stay ahead with detailed performance narratives and sector-specific trends. EDUCATIONAL SUPPORT & COMMUNITY Verbose Explanations: Break down complex financial concepts with in-depth explanations for beginners. Investment Strategies: Learn and apply various investment strategies with expert-backed insights. Community Chat Forum: Connect with fellow investors to share insights, ask questions, and discuss investment strategies. Build your Stock Portfolio in 3 easy steps! Discover Your Risk Tolerance: Take a quick 5-minute questionnaire to assess your ability to handle risk effortlessly. Search Stocks Aligned With Your Personal Values: Use an intuitive stock-picking interface to confidently find winning stocks. Build Your Portfolio: Utilize the Done-For-You Portfolio Builder to simplify investing and remove the guesswork. Good to know: Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: desktop or mobile Only available to new users Updates included A lifetime subscription to Sterling Stock Picker normally has a suggested price of $486, but you can pick it up for just $54.90 for a limited time - that represents a saving of $431.10 (88% off). For a full description, specs, and license info, click the link below. Sterling Stock Picker lifetime subscription for $54.90 (was $486) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
  • Recent Achievements

    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      545
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      82
    4. 4
      ATLien_0
      64
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!