Help Understanding default vLANS..I think

I am setting up a new Unifi UCG Max. For some reason when connecting to the Staff SSID I get assigned an IP from the management network. I set the native vlan of the port to the AP to Management but I allow the Staff network as well. The Staff SSID is assigned to the Staff subnet with DHCP guarding.

The Student and Guest SSIDs work as intended, the only thing different about the Staff is that it’s the default vLAN and in a different FW zone. I want the unifi devices on the Management network.

I realize I can make the port vlan 1 and move the unifi devices to the management subnet however I am trying to learn and understand why this doesn’t work.

See below and thank you.

network config

Screenshot 2025-08-22 120101

port

​​

​​

These are not Cisco devices and don’t need to have a special management network since the transport layer and control is all encrypted. Create VLANs (as it appears you have) for the other networks. The AP should be attached to a port set to “Allow All” and the native VLAN and then have the setting in the SSID setup choose what network should be used.