I posted this in Reddit but doing this here as well. I thought I saw in one Tom’s videos that he recommended having the network controller reside in a secured VLAN (instead of LAN) but could be wrong.
Anyway, below is my Reddit post, thank you in advance!
*I have a UCK Gen2+, several UniFI switches and a couple APs - they are all behind pfSense. I am very familiar on how to create VLANs in pfSense and UniFi.
I have a LAN (subnet 192.168.10.1) and then have created the following VLANs:
Admin- 192.168.20.1 (VLAN 20)
IoT- 192.168.30.1 (VLAN 30)
Camera-192.168.40.1 (VLAN 40)
*Would like to move and isolate all the UniFi devices to the Admin (or management) VLAN but I have been struggling quite a bit lately because when they are factory-reset, all UniFi devices (including the controller), will get their IP from LAN which is understandable. *
*However, changing their IPs to the Admin VLAN has been quite a struggle as I have not figured out the proper way and commands to make this possible. *
I have a couple of questions:
*1. What is the best way to change the UniFi devices IPs (including UCK Gen2+) from those in LAN to those VLAN 20? *
2. What are some of the proper UniFi commands that can be used to facilitate such IP change? I have tried the “set-inform”’ones but have not been successful.
3. What would be the proper path to follow when doing this? Start with the controller first, then move to the aggregate switch, other switches and lastly all APs?
3. Lastly, would you even bother to move all UniFi devices to a separate VLAN when you could simply leave them in the pfSense’s LAN and use the other VLANs to segregate all other devices?
Appreciate your thoughts and advice!