UniFi Lab 04
Port profiles: Native vs Tagged
Guest WiFi associates. No IP. Someone put an access profile on the AP uplink.
Your job: trunk the AP uplink so Guest (VLAN 40) is tagged, without turning the printer port into a trunk.
This run: Break A. Guest VLAN 40. ZBF healthy.
Lab complete. The guest phone has a lease and Guest is tagged on the AP uplink.
connected_guest_vlan_taggedConnected, Guest VLAN taggedTopology
Site: Port Manager lab- InternetISP handoff on the gateway WAN portWAN up
- Guest → WAN: AllowedZBF is healthy in this lab. DHCP dies on the trunk, not the firewall.
- GatewayLAN + Guest VLAN 40. DHCP 192.168.40.0/24, gateway 192.168.40.1Online
- Port 1: Trunk, all VLANsGateway uplink. VLAN 1 untagged, VLAN 40 tagged.
- SwitchGuest traffic stops herePort Manager. Ethernet Port Profiles1Port 1, gateway uplink, link up2Port 2 empty3Port 3 empty4Port 4 empty5Port 5, AP uplink6Port 6 empty7Port 7, printer8Port 8 empty
Port 5 Native Guest · Tagged Block All
Port 7 IoT access (Native IoT, Tagged Block All)
- Port 5: Guest tags droppedAccess or incomplete trunk on the AP uplink. Link LED is still up.
- Access pointSSID Guest-WiFi → VLAN 40Online
- Guest-WiFi, 5 GHz: ConnectedAssociated. RF looks fine.
- Guest phoneVisitor device on Guest-WiFino_ipNo IPguest_access_on_uplinkAccess profile on AP uplink
Client list
1 client| Connection | Connected |
|---|---|
| Network | Guest (VLAN 40) |
| AP | Access point, Guest-WiFi |
| IP | No IP |
| Gateway | No gateway |
| VLAN on trunk | Not on trunk |
Legend
- Link passes Guest traffic
- Guest traffic dropped
- WiFi association
- Up or correct
- Failing symptom
- Teaching contrast
Controls
Port Manager settings for the AP uplink, plus a printer port contrast. ZBF stays healthy in this lab.
Port Manager, Port 5 (AP uplink)
- Guest SSID
- Guest-WiFi → VLAN 40
- Subnet
- 192.168.40.0/24
- ZBF Guest
- Healthy (not this lab)
Port 7 (wired printer, contrast)
Out of scope for this lab
Why this fails
copy key: guest_access_on_uplinkGuest access profile on the AP uplink
Connected, No IP
Field note: The phone associates, so RF looks fine. Guest is a tagged VLAN on the SSID. An access profile makes Native = Guest and drops other tags. Management may limp. Guest clients never get DHCP.
Fix: Trunk the AP uplink. Native = Default / management. Tagged = Allow All or include Guest.
Console words
- Connected, No IPShowing
- No DHCP leaseShowing
- Access profile on AP uplinkShowing
- Guest VLAN not on trunkClear
- Connected, Guest VLAN taggedClear
Access is for end devices. Trunks are for AP uplinks. Native is management. Tagged carries Guest.
Glossary
Core, Labs 01 to 03- Native
- Untagged VLAN on a switch port (PVID). Management traffic usually rides here on UniFi device uplinks.
- Tagged
- VLAN IDs carried with an 802.1Q tag on a trunk. Guest and IoT SSIDs need their VLANs tagged on the AP uplink.
- Access port
- One VLAN only, untagged. Fine for a printer. Wrong for an AP that serves multiple SSIDs.
- Trunk
- Native + tagged VLANs. Correct pattern for UniFi switch to AP / switch to gateway when multiple networks exist.
- ZBF
- Zone-Based Firewall. Policies between zones (Gateway, External, Internal, Guest, etc.), not just classic LAN IN rules.
- Gateway zone
- Where the router answers DHCP and DNS for a network. Block Guest to Gateway and clients get No IP or DNS unreachable.
- Client isolation
- WiFi setting that stops guest clients from talking to each other. Keep on for Guest.
- PoE class
- AF (~15 W), AT (~30 W), BT / PoE++ (higher). UniFi budgets on documented max draw, not quiet daytime watts.
- PoE budget
- Sum of max PD draws vs what the switch or injector can supply. Exceed it and devices disconnect.
- Injector
- Power source for a Flex or similar. Wrong class (AF on a loaded Flex) is a classic field fail.
- Max draw
- Datasheet maximum watts for a PD (IR on, boot). UniFi PoE budget math uses this, not the quiet live reading.
- Flex budget
- USW-Flex downstream totals by input: AF 8W, AT 20W, BT or 60W injector 46W (set Power Source to PoE Injector).
- Remote Unlock via Endpoint
- Access setting. When off, Endpoint receivers can talk on a call but cannot unlock.
- Door Attendant / receiver
- User assigned to get the door call. Not on the list means no Unlock for that door.
- Inform
- Device check-in URL to the Network application, usually controller host on port 8080, path /inform.
- STUN
- UDP 3478 helper for L3 / remote adoption. GUI on 443 is not the same path.
Fiber terms, glossary ready for later
MM and SM grades, cage form factors, DAC, AOC, and complementary BiDi ends. Full rows land with the fiber-sfp-dac lab.
Symptom words (overlay language)
Before and after
Diff rows marked| Setting or symptom | Broken start | Now |
|---|
Gear in this lab
- 1 Gateway
- 1 Switch
- 1 Access point
- 1 Guest phone
- 1 Wired printer (contrast)
Config only. The fix needs no new hardware. Counts only, no prices.
Takeaway
Access is for end devices. Trunks are for AP uplinks.
When Guest WiFi says Connected but has No IP, look at Port Manager on the AP uplink first. Never put a Guest access profile on an AP or switch uplink.
- Open Port Manager on the switch port that feeds the AP.
- Set Native to Default / management, not Guest.
- Set Tagged to Allow All, or a list that includes Guest.
- Leave access profiles on printers and other single network devices.
Want guest WiFi and VLANs set up like this at your place? We design managed guest networks as part of a UniFi install.
Related labs
All labs /labs
A teaching lab, not a quote and not a design for your site. Settings are simplified from the UniFi Network app. No account, and nothing from this lab is saved.