Troubleshooting - Firewalla Gold added to Unifi network

Comments

7 comments

  • Avatar
    Michael Bierman

    Do you need the USG?

    I run all UniFi APs and switches and use the controller running on my NAS (can also run on FWG). It works wonderfully. I can see all devices in both management systems.

    0
    Comment actions Permalink
  • Avatar
    Adam M.

    I have considered replacing it entirely, but I had hoped to continue using it and phase it out in another step. Also, my understanding is that the guest portal and guest isolation policies require the usg... do you use guest network and portal? If so, do they still work as expected?

    And, as far as using the unifi devices goes, how did you set up your cut-over the FWG? Were you able to get all of your current client devices to transition to their expected networks? Or did you have to set them all up?

    0
    Comment actions Permalink
  • Avatar
    Donald Chan

    I literally did this a few days ago when I received my FWG.

    I previously used a USG-3 in my network along with Unifi Switches and APs. I had configured 3 networks (2 of which were VLANS) and 3 SSID (one of which was Guest and used the built-in Hotspot Manager).

    Prior to decommissioning the USG, I made sure that the cloud-key, all switches and APs were set to DHCP so that they would receive a new IP address from the FWG. 

    Then in the FWG, I replicated the same three networks on the ethernet port where my Unifi switch would connect to with the same IP ranges and VLAN ids.  Once this was done, I did have to go and find the IP of my Cloud Key and go in there to reconfigure the networks that were previously configured to be VLAN only networks.  This way, the FWG would be responsble assigning IP addresses to devices connecting to those VLANS.  To my surprise, the Hotspot Manager was still an active option on my Cloud Key and I could continue to use the Portal Landing page and generate vouchers for people to access the guest network.

    I'm not familiar with the Unifi Controller app outside of the Cloud Key so can't say for sure if this is hardware related but, I know at the moment, my network looks and operates the same as before when the USG was present. 

    My only gripe at the moment is that the FWG does not connect to my ISP via PPPoE which I'm trying to figure out.

     

    0
    Comment actions Permalink
  • Avatar
    Adam M.

    @Donald Chan , @Michael Bierman

    Thank you both for the responses and advice.

    I decided to remove the USG entirely from network and connected the FWG to the main Unifi switch. The implementation went very smoothly: since I had already configured the matching network ranges in the FWG, most of the devices seamlessly transferred over.

    There were a few devices where I had some issues: for most part, it seems that any devices that were in a sleep/hibernate state when the FWG took over the network came back online with some connection issues. I did have to identify each of these devices, and then use the device console to go through a reboot cycle. This was pretty awkward for a couple of computers that were set up as headless servers. Otherwise, anything that was offline during the cut over and came back online afterwards connected to the network seamlessly.

    I am having an issue with the Unifi guest portal... the portal page seems get blocked on android devices, but not in browsers (windows/linux) so I am looking into device settings.

    On the whole, the cut over from the USG to the FWG has gone very well so far. I think that configuring the networks in the FWG ahead of time worked really well (and I think it was mentioned in another discussion thread... I'll update with a link later).

    edit: spelling

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    Guest portal can work fine. There are some strategies to ease the IPs migration, but probably too late to be helpful at this point. 

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    @Donald what issue are you having with PPPoE?

    0
    Comment actions Permalink
  • Avatar
    Donald Chan

    @Michael Bierman, not sure at the moment.  Unable to log in with my PPPoE credentials so will investigate further.  Currently have another router in front of the FWG but that does not have passthru or bridge mode so having to deal with double nat-ing until I work out what it is.  Might just be powering down the NTD and restarting it.

    0
    Comment actions Permalink

Please sign in to leave a comment.