Unifi USG Network Segmentation
Budget: £18 – £36 GBP
I have a very small site running on a Unifi Security Gateway together with a couple of Unifi PoE switches. All of my IoT gadgets sit on the default network and I now want to move three office PCs (one a sever) onto their own, fully-isolated VLAN while still allowing those three machines to see each other without restriction.
Here is what I need done:
• Re-configure the USG and switches to create a new internal VLAN for the three PCs, including the necessary firewall rules so this segment is completely walled off from the IoT-heavy default network. Called "Office Network" 192.168.10.265/24 with DHCP 192.168.10.64 onward, and gateway at 192.168.10.254
• Spin up a dedicated Wi-Fi SSID for that VLAN, secured with WPA3. "Office" WPA2/WPA3
• Make sure an existing network printer remains reachable from every VLAN (both the new PC VLAN and the original default one). Probably needs to go on new network, unless otherwise advised
• Provide a short, plain-English guide that shows exactly how I can add more wired or wireless devices to the segregated network in the future—step-by-step screenshots or a concise checklist are fine.
All changes must be carried out through the Unifi Controller so the setup survives reboots and future firmware updates. Once complete, I should be able to:
• See full, unrestricted traffic between the three office PCs.
• Keep the IoT devices locked out of that segment.
• Connect a laptop or new desktop to the new SSID and land directly on the PC VLAN.
• Print from any device on any VLAN without extra routing tweaks.
If you have solid experience with Unifi USG/VLAN architecture and can walk me through the final result, I’m ready to get started right away.
Here is what I need done:
• Re-configure the USG and switches to create a new internal VLAN for the three PCs, including the necessary firewall rules so this segment is completely walled off from the IoT-heavy default network. Called "Office Network" 192.168.10.265/24 with DHCP 192.168.10.64 onward, and gateway at 192.168.10.254
• Spin up a dedicated Wi-Fi SSID for that VLAN, secured with WPA3. "Office" WPA2/WPA3
• Make sure an existing network printer remains reachable from every VLAN (both the new PC VLAN and the original default one). Probably needs to go on new network, unless otherwise advised
• Provide a short, plain-English guide that shows exactly how I can add more wired or wireless devices to the segregated network in the future—step-by-step screenshots or a concise checklist are fine.
All changes must be carried out through the Unifi Controller so the setup survives reboots and future firmware updates. Once complete, I should be able to:
• See full, unrestricted traffic between the three office PCs.
• Keep the IoT devices locked out of that segment.
• Connect a laptop or new desktop to the new SSID and land directly on the PC VLAN.
• Print from any device on any VLAN without extra routing tweaks.
If you have solid experience with Unifi USG/VLAN architecture and can walk me through the final result, I’m ready to get started right away.
Related categories:
System Admin
Linux
Network Administration
Technical Documentation
Network Security
VPN
Network Monitoring