FWG + Ubiquti Switch 48 500W POE with VLANs

Comments

9 comments

  • Avatar
    Firewalla

    Did you try different ports on the switch? and also checked the wiring? 

    0
    Comment actions Permalink
  • Avatar
    Jan Baniewicz

    by wiring you mean cables ? - tried on two diffrient ones (both brand new) but will try another one.

    Will try diffirent ports right now.

    Most curious is that port link on ubiquti is blinking  green (1gbps) 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    One problem we had before was using a switch port that's configured under a VLAN before, and it caused the unit not able to get an IP. The port you connect to firewalla must be a trunk or tagged port, this is the most common mistake we see. 

    0
    Comment actions Permalink
  • Avatar
    Jan Baniewicz

    Actually there is no trunk/tagged and untagged ports in Ubiquiti hardware.

    Currently Ubiquiti Console (software) gives possibility to set what Network (their name for VLAN - in Networks tab you can set VLAN + DHCP related to it and name it ie LAN or IoT) is for managing - i would see that as Tagged port, like below:

    And in every prot you can set Port Profile which is also related to ALL - untagged on every VLAN/"network" or turned off or untagged on specified VLAN/"Network", like below:


    0
    Comment actions Permalink
  • Avatar
    Jan Baniewicz

    I would like to set switch as menaged from LAN (VLAN 1 - where firewalla is 192.168.88.1,  and networks 2-254) but gives possiblitiy for other ports as Profile "All" - to APs where i broadcast wifis related to VLANs. 

    0
    Comment actions Permalink
  • Avatar
    Jan Baniewicz

    Ok, i've tested more cables (wiring also cinfirmed by tool) and also more ports - nothing helped.

    Also tested:

    1. if on port 2 (direct connection to US48) is set only network LAN VLAN1. - didn't helped.

    2. after connecting to netgear, adopting, set some ports to Network LAN (VLAN1), then connected to them - didn't helped

    3. after point 2 - tried to connect to ports where profile was set as ALL - didn't helped

    4. after point 3 - set static ip configuration pointing proper ip, subnet mask  gateway and primary DNS (same as gateway) - didn't helped

    After every step i have rebooted both devices to be sure is somehow related to not aplying new rules.

    So for now i see no possibility to connect to FGW any Ubiquiti Switch (with up to date firmware), when there are VLAN set on FGW. I also noticed that on FGW in app when i unplugged connection thru netgear and plugged direct to FGW cable name of device "Ubiquiti" has swiched to "Unknown". Of course in Unifi app switch went offiline and aftre some time also in FireWalla app this device went offline.

    Please help. 

    I feel it is related to that i can't set on FGW VLANs are those ports tagged/untagged or none. Is it possible to add this in some quickfix? Or maybe its something else, im not IT guy so please guide me how to troubleshoot that. Maybe its need to be untagged ?

    0
    Comment actions Permalink
  • Avatar
    Jan Baniewicz

    Problem solved.
    First network for Ubiquiti devices such as switches gateways, directly connected UAPs etc. HAS to be type LAN - not VLAN1. If it will be set as type VLAN with its ID, Unifi products won't recognize it during setup. Later under switch settings it is possible to set Native Network - same as first one set on FWG and other networks - different vlans.

    0
    Comment actions Permalink
  • Avatar
    MikeS

    Hi Jan,

    Jan, can you perhaps explain a bit more on how you solved your problem?

    I'm have a similar problem - FWB and want to setup two VLANS (ID 10 & 20) on FWG port #1. I then have a Unifi USW-90 switch connected to the FWG.

    Problem is that when FWG is setup as VLan with ID 10 there is no connection at all with the Unify Switch!

    All work well when FWG #1 Interface setup as LAN - then all devices connect and get IPs etc.

     

    0
    Comment actions Permalink
  • Avatar
    Jan Baniewicz

    As far as I remember leave main lan network as not vlan just lan. Then rest of vlans as you want.

    0
    Comment actions Permalink

Please sign in to leave a comment.