UniFi Lab 05
Camera VLAN vs NVR / Protect
Protect camera will not adopt, or it goes offline after you isolate it. VLAN and Protect ports.
Your job: adopt on the same VLAN as the NVR, then isolate on Cameras VLAN with Protect ports open.
This run: Break A. NVR on LAN. Cameras VLAN 60.
Lab complete. The camera is Online with a healthy stream on the Cameras VLAN.
online_stream_healthyOnline, stream healthyTopology
Site: Protect adopt lab- Console / NVRProtect on Default / LANOnline
- Protect ports: BlockedTCP 7442 / 7444 / 7550 / 7552 and related ports.
- SwitchProtect path stops hereCamera PoE port + uplink12345678
Port 4 VLAN Cameras VLAN 60
- Camera path: Protect blocked or wrong VLANDiscovery or stream fails here.
- Protect cameraG4 / G5 class on PoENot adoptedadopt_missing_wrong_vlanAdopt not available
Protect device list
1 camera| Protect status | Not adopted |
|---|---|
| Adopt | Adopt not available |
| Camera VLAN | Cameras VLAN 60 |
| NVR VLAN | Default / LAN |
| Protect ports | Blocked |
| Stream | No stream |
| Management ping | No reply |
Legend
- Protect path open
- Protect path blocked
- Up or allowed
- Failing symptom
- Ping only, not Protect
Controls
Same-VLAN adopt first, then move and open Protect ports. Ping is not the Protect path.
Switch, camera PoE port
Protect device list
- NVR VLAN
- Default / LAN
- Cameras VLAN
- 60
- BOM on win
- none
Only works when the camera shares the NVR VLAN.
Firewall between Cameras VLAN and NVR
Out of scope for this lab
Why this fails
copy key: adopt_missing_wrong_vlanCamera is on the wrong VLAN for first adopt
Adopt not available
Field note: New cameras often need to share a VLAN with the CloudKey or NVR to show Adopt. Isolation between Cameras VLAN and the console blocks discovery.
Fix: Put the camera on the same VLAN as the NVR for adopt, then move and open Protect ports.
Console words
- Adopt not availableShowing
- Camera OfflineClear
- Protect ports blockedShowing
- Stream unhealthyClear
- Online, stream healthyClear
Glossary
Core, Labs 01 to 03- Native
- Untagged VLAN on a switch port (PVID). Management traffic usually rides here on UniFi device uplinks.
- Tagged
- VLAN IDs carried with an 802.1Q tag on a trunk. Guest and IoT SSIDs need their VLANs tagged on the AP uplink.
- Access port
- One VLAN only, untagged. Fine for a printer. Wrong for an AP that serves multiple SSIDs.
- Trunk
- Native + tagged VLANs. Correct pattern for UniFi switch to AP / switch to gateway when multiple networks exist.
- ZBF
- Zone-Based Firewall. Policies between zones (Gateway, External, Internal, Guest, etc.), not just classic LAN IN rules.
- Gateway zone
- Where the router answers DHCP and DNS for a network. Block Guest to Gateway and clients get No IP or DNS unreachable.
- Client isolation
- WiFi setting that stops guest clients from talking to each other. Keep on for Guest.
- PoE class
- AF (~15 W), AT (~30 W), BT / PoE++ (higher). UniFi budgets on documented max draw, not quiet daytime watts.
- PoE budget
- Sum of max PD draws vs what the switch or injector can supply. Exceed it and devices disconnect.
- Injector
- Power source for a Flex or similar. Wrong class (AF on a loaded Flex) is a classic field fail.
- Max draw
- Datasheet maximum watts for a PD (IR on, boot). UniFi PoE budget math uses this, not the quiet live reading.
- Flex budget
- USW-Flex downstream totals by input: AF 8W, AT 20W, BT or 60W injector 46W (set Power Source to PoE Injector).
- Remote Unlock via Endpoint
- Access setting. When off, Endpoint receivers can talk on a call but cannot unlock.
- Door Attendant / receiver
- User assigned to get the door call. Not on the list means no Unlock for that door.
- Inform
- Device check-in URL to the Network application, usually controller host on port 8080, path /inform.
- STUN
- UDP 3478 helper for L3 / remote adoption. GUI on 443 is not the same path.
Fiber terms, glossary ready for later
MM and SM grades, cage form factors, DAC, AOC, and complementary BiDi ends. Full rows land with the fiber-sfp-dac lab.
Symptom words (overlay language)
Before and after
Diff rows marked| Setting or symptom | Broken start | Now |
|---|
Gear in this lab
- 1 Console / NVR (Protect)
- 1 Switch
- 1 Protect camera
Config only. VLAN and Protect ports. Counts only, no prices.
Takeaway
Adopt on the same VLAN. Isolate with Protect ports open.
A locked camera VLAN is fine after adopt. Blind firewall blocks are not. Ping can look healthy while the stream path is dead.
- Put the camera on the NVR VLAN for first adopt.
- Adopt in Protect while discovery works.
- Move the camera to the Cameras VLAN.
- Allow Protect ports between Cameras VLAN and the console / NVR. TCP 7442, 7444, 7550, 7552, plus related 7441, 7443, 7445, 7447, and 7888.
BOM delta on win: none. Nothing new to buy. This was VLAN and firewall configuration.
Want Protect and a clean camera VLAN designed for your place? We plan that as part of a UniFi install.
A teaching lab, not a quote and not a design for your site. Settings are simplified from the UniFi Network app. The header and footer are the site header and footer.