For anyone with UniFi network 8.4.x. They have now updated network to have set options for "Isolate Network" and "Allow Internet Access" that saves you from needing to set these firewall rules manually. Isolate Network specifically let's the devices on that VLAN to communicate with each other and not with any other networks, exactly what you'd want for IoT devices!
I am fairly new to home networking/Linux and I found this episode to be the ONLY explanation I have understood of VLANs. Thank You. lol
One year after you made this, and today you helped me fix my IoT (already VLAN'd). Thanks a TON.
In the IT space here on YouTube, I think Tim is the best teacher. Dude's got skills.
Thanks for this! I made it through the VLAN’s myself and got intimidated by the FW rules. Now I can follow what you have and finish the job!
Calling out the changes to dashboard is really smart. Good thinking. Great video.
Great video Tim! Easy to follow and under stand. For blocking inter-vlan routing I just use 1 rule ( Rfc1918 to Rfc1918) just condenses the list a bit As for LAN local this is gateway, you would need to put block rules for your gateway so the other networks ( IoT) can’t hit the firewall interface. Have a great weekend very entertaining :)
At 10:44 yes I am watching and yes you got it right! :)
I have been having massive issues with my udm idk what the hell was going on but i decided to create some vlans to get some more control on whatever is going on. Changed all ports and added rules. Now things are working like they should. Big thanks for taking the time to go through how to set things up. much appreciated. for days my network was sometimes working off and on. This was a huge help. thanks.
I watched so many videos about setting up vlans on UniFi and this was the first one that was simple, easy to follow and actually included everything needed to make this work. The firewall portion is where I was hung up. This is my first venture into enterprise grade hardware and learning advanced networking. Thank you. Please accept my sub and like.
I am a CCNA and you did a great job.
Literally was working on some VLAN stuff last night, great timing to make sure I have everything buttoned up properly. Thanks!
At 10:40 with the trunk port, you're mostly right. Ha. A trunk port does include traffic from multiple VLANs (or in this case all of them), but they're NOT untagged. They do in fact have their VLAN tags. This is how you can connect multiple switches together with both switches being able to communicate on all the VLANs.
Worth mentioning this is now much, much simpler with Traffic Rules. It can be done in a single rule. Action: Block Category: Local Network Local Network: IOT-Better Traffic Direction: Traffic from all local networks Device/Network: All Devices Schedule: Always Name: Block IOT-Better to All
There's a humble vibe behind your videos that is really appreciated. Great videos. This one in particular as a future owner of a DreamMachine SE. Thank you for the content
This is awesome....period! I had no idea how to set my Unfi gear up. This video walked me thru step by step. I learned so much along the way. Again, this was top notch! Thank you man. :)
I just bought the UDM SE and this video was the best I found to explain how to make an IoT network. Thank you!
Thank you sooooo much, we manage to fix a problem we had thanks to your video 😊😊
This video is fantastic. I have a controller and AP's and have been thinking about using a gateway but putting it off for ages. This covers pretty much all the questions I had.
@TechnoTim