Internet -> Firewalla Gold -> UniFi USG (Nat Disabled)

Comments

3 comments

  • Avatar
    Robin St.Clair

    We have networks divided into 2 stacks, aka Sheep and Goats.

    The UniFi stack looks after the Goats (Guest WiFi, Multicast IPTV, other "untrusted" devices), whilst the other, Meraki, stack protects the sheep (secure workstations and WiFi), all storage and servers are hosted in Azure, which also handles secure gateway duties, DDNS etc.

    The MX 64's WAN port uplinks to the USG's LAN2 port. This port is configured as the DHCP server for the LAN (not VLAN) network 192.168.22.0/28. Using a LAN, as opposed to a VLAN is important.

    The dynamic external IP address is passed through to the MX64 and the Z3C. Surprisingly, we have not needed to disable NAT on the USG's LAN2 port, we use Bria VoIP software on standard Android/iPhone devices, without issue.

    On the USG's WAN port (eth0) we have configured a pseudo ethernet port which, along with a masquerade rule allows us to access the modem's GUI (192.168.2.1) from workstations on either of the stacks.

    I trust this gives you some pointers.

     

    0
    Comment actions Permalink
  • Avatar
    Anthony G

    Andew, I just replaced my USG with a Firewalla Gold and love it. Why are you keeping the device in the mix?

    0
    Comment actions Permalink
  • Avatar
    Giovanni Francesco

    Hey curious if you ever got this working (Unifi in transparent bridge + firewalla upstream)?

    0
    Comment actions Permalink

Please sign in to leave a comment.