Gbit Tech (818) 809-6743
C-7 #1050088  ·  Liability insured  ·  UniFi Certified PartnerNever the cheapest. Built to last.

UniFi Lab 01

Guest VLAN with no internet

Guest WiFi shows Connected but has no usable network.

IntroAbout 8 minConfig only

Your job: get the guest phone online without opening the LAN.

This run: Break A. VLAN 40, subnet 192.168.40.0/24.

Guest phoneno_ip

Connected, No IP

no_ipNo IP

Goal: online, with Guest → LAN still blocked

Controls Why

Topology

Site: Guest WiFi lab
  1. InternetISP handoff on the gateway WAN portWAN up
  2. Guest → WAN: AllowedGuest traffic reaches the internet.
  3. GatewayRoutes LAN and Guest. DHCP for 192.168.40.0/24, gateway 192.168.40.1
    • Guest → Gateway (DHCP/DNS)Allow
    • Guest → External / WANAllow
    • Guest → LAN / InternalBlock
    • Guest DNSAuto
  4. Port 1: Trunk, all VLANsGateway uplink. VLAN 1 untagged, VLAN 40 tagged.
  5. SwitchGuest traffic stops herePoE switch with port profiles

    Port 5 profile Access (LAN only)

  6. Port 5: VLAN 1 untagged, VLAN 40 droppedGuest tags dropped at the switch. Link LED is still up.
  7. Access pointSSID Guest-WiFi → VLAN 40Online
  8. Guest-WiFi, 5 GHz: ConnectedAssociated. RF looks fine.
  9. Guest phoneVisitor device on Guest-WiFi
    no_ipNo IP

Client list

1 client
ConnectionConnected
NetworkGuest (VLAN 40)
APAccess point, Guest-WiFi
IPNo IP
GatewayNo gateway
DNSDNS unreachable
InternetNo
LAN (ping NAS)Isolated from LAN

Legend

  • Link passes Guest traffic
  • Guest traffic dropped or blocked
  • WiFi association
  • Up or allowed
  • Failing symptom or block
  • Warning, not a win

Controls

The six settings you can change in this lab. Everything else is fixed.

Switch, Port 5 (to the AP)

AP uplink port profile

Guest network, VLAN 40

VLAN ID
40
DHCP mode
DHCP Server
Gateway IP
192.168.40.1
Subnet
192.168.40.0/24
Guest DNS

Zone-Based Firewall

Guest → Gateway
Guest → External / WAN
Guest → LAN / Internal

WiFi, Guest-WiFi

Client isolation

Guests cannot reach each other. Keep it on.

Out of scope for this lab

Full ZBF matrixVPNContent filterThird party switch

Why this fails

copy key: no_ip_trunk

The AP uplink is an access port

Connected, No IP

Field note: the phone associates, so RF looks fine. Guest is a tagged VLAN. An access-only uplink drops those tags, so DHCP never arrives.

Fix: Trunk the AP uplink: Native = LAN/management, Tagged = Guest or Allow All.

Why Broken and Fixed
D01 Trunk: Native vs Tagged, BrokenBroken. Switch port to AP uplink labeled Access: LAN only. SSID chips LAN and Guest 40. Guest 40 is greyed with No IP.BrokenSwitch portAccess: LAN onlyAPLANGuest 40No IPD01 Trunk: Native vs Tagged, FixedFixed. Uplink labeled Native: Default and Tagged: Guest. Guest 40 shows 192.168.40.x.FixedSwitch portNative: DefaultTagged: GuestAPLANGuest 40192.168.40.x
Guest rides tagged on the AP uplink. Access-only drops it.

Console words

  • No IPShowing
  • No gatewayShowing
  • DNS unreachableShowing
  • Traffic blocked by firewallClear
  • Connected, no internetShowing
  • Isolated from LANYes, keep it

Associated is RF. Online is DHCP + gateway + DNS + WAN, with LAN still denied for guests.

Glossary

Core, Labs 01 to 03
Native
Untagged VLAN on a switch port (PVID). Management traffic usually rides here on UniFi device uplinks.
Tagged
VLAN IDs carried with an 802.1Q tag on a trunk. Guest and IoT SSIDs need their VLANs tagged on the AP uplink.
Access port
One VLAN only, untagged. Fine for a printer. Wrong for an AP that serves multiple SSIDs.
Trunk
Native + tagged VLANs. Correct pattern for UniFi switch to AP / switch to gateway when multiple networks exist.
ZBF
Zone-Based Firewall. Policies between zones (Gateway, External, Internal, Guest, etc.), not just classic LAN IN rules.
Gateway zone
Where the router answers DHCP and DNS for a network. Block Guest to Gateway and clients get No IP or DNS unreachable.
Client isolation
WiFi setting that stops guest clients from talking to each other. Keep on for Guest.
PoE class
AF (~15 W), AT (~30 W), BT / PoE++ (higher). UniFi budgets on documented max draw, not quiet daytime watts.
PoE budget
Sum of max PD draws vs what the switch or injector can supply. Exceed it and devices disconnect.
Injector
Power source for a Flex or similar. Wrong class (AF on a loaded Flex) is a classic field fail.
Max draw
Datasheet maximum watts for a PD (IR on, boot). UniFi PoE budget math uses this, not the quiet live reading.
Flex budget
USW-Flex downstream totals by input: AF 8W, AT 20W, BT or 60W injector 46W (set Power Source to PoE Injector).
Remote Unlock via Endpoint
Access setting. When off, Endpoint receivers can talk on a call but cannot unlock.
Door Attendant / receiver
User assigned to get the door call. Not on the list means no Unlock for that door.
Inform
Device check-in URL to the Network application, usually controller host on port 8080, path /inform.
STUN
UDP 3478 helper for L3 / remote adoption. GUI on 443 is not the same path.

Fiber terms, glossary ready for later

OM3 / OM4OS2SFPSFP+DACAOCBiDi

MM and SM grades, cage form factors, DAC, AOC, and complementary BiDi ends. Full rows land with the fiber-sfp-dac lab.

Symptom words (overlay language)

No IPNo gatewayDNS unreachableConnected, no internetConnected, isolated from LANTraffic blocked by firewall

Gear in this lab

  • 1 Gateway
  • 1 Switch
  • 1 Access point
  • 1 Guest phone
Change on win: none

Config only. The fix needs no new hardware. Counts only, no prices.

A teaching lab, not a quote and not a design for your site. Settings are simplified from the UniFi Network app. No account, and nothing from this lab is saved.