HCHTech
Well-Known Member
- Reaction score
- 4,178
- Location
- Pittsburgh, PA - USA
I recently did my first install with a Gen2 Cloud Key. I've got about a dozen or so installs out there with Gen1 Cloud Keys, so we have that procedure locked in and well-documented. Since we deal mostly with small businesses, our normal setup involves a small Unifi POE switch that we place on a separate LAN port on the firewall. That lets us put that traffic in a separate zone and we can control it there. We setup VLANs in the Unifi settings for Guest vs. Private.
This current setup is different, the client needed a new main network switch, so I went with the Unifi 48 POE-500. Maybe a little overkill, but I wanted the 10Gb port for the server. We have 5 APs. Because of this, we have only a single connection from the switch to the firewall, so configuration is a bit more complicated. Also, I wanted to use this setup to update our SOP.
I did the initial setup on my bench where I had more control. I setup a router to provide the same LAN configuration as the client's firewall, plugged in the switch, CK and all of the APs. During the setup where you configure the cloud key, I noticed there was a 'guided setup wizard' available if you chose the basic setup (as opposed to advanced). Because this was new, I decided to run through that to see what all it did, and didn't do. I specified the wifi setup I wanted and answered the various questions. To my surprise, this resulted in everything working as desired. We had:
Well, being me, I didn't like not knowing how they did this. I reset everything to factory defaults and re-did the setup manually, using VLANs like normal. This also worked as expected, I got the configuration i wanted and I knew how it got there.
I decided to do a chat with Ubiquiti to see if I could ferret-out what the wizard did to accomplish that initial setup. No surprise, but they were not really interested in helping me understand. It's like they didn't even know about the wizard setup. "You didn't use VLANs?" "Does it work now"? After 30 minutes of back and forth like that I gave up. I love Ubiquiti, but it makes me crazy that their support consists almost entirely of pointing you to their tech notes. I even offered to do the wizard setup again and have them remote in to look at the screens I was seeing, but it was very clear that either they don't do this anymore, or at the very least, they save it for true emergencies. In any event, they declined.
So, I doubt I'll see a setup similar to this anytime soon. Can anyone more familiar with the Gen2 Cloud Keys offer an opinion on exactly how that guided setup accomplished the traffic isolation without creating VLANs?
This current setup is different, the client needed a new main network switch, so I went with the Unifi 48 POE-500. Maybe a little overkill, but I wanted the 10Gb port for the server. We have 5 APs. Because of this, we have only a single connection from the switch to the firewall, so configuration is a bit more complicated. Also, I wanted to use this setup to update our SOP.
I did the initial setup on my bench where I had more control. I setup a router to provide the same LAN configuration as the client's firewall, plugged in the switch, CK and all of the APs. During the setup where you configure the cloud key, I noticed there was a 'guided setup wizard' available if you chose the basic setup (as opposed to advanced). Because this was new, I decided to run through that to see what all it did, and didn't do. I specified the wifi setup I wanted and answered the various questions. To my surprise, this resulted in everything working as desired. We had:
- Both WLANs present and secured
- Clients on the Guest WLAN were isolated from clients on the LAN
- Clients on the Guest WLAN were isolated from clients on the private WLAN
- Clients on the Guest WLAN were isolated from each other
- Clients on the Private WLAN could see and ping clients on the LAN, and vise versa
Well, being me, I didn't like not knowing how they did this. I reset everything to factory defaults and re-did the setup manually, using VLANs like normal. This also worked as expected, I got the configuration i wanted and I knew how it got there.
I decided to do a chat with Ubiquiti to see if I could ferret-out what the wizard did to accomplish that initial setup. No surprise, but they were not really interested in helping me understand. It's like they didn't even know about the wizard setup. "You didn't use VLANs?" "Does it work now"? After 30 minutes of back and forth like that I gave up. I love Ubiquiti, but it makes me crazy that their support consists almost entirely of pointing you to their tech notes. I even offered to do the wizard setup again and have them remote in to look at the screens I was seeing, but it was very clear that either they don't do this anymore, or at the very least, they save it for true emergencies. In any event, they declined.
So, I doubt I'll see a setup similar to this anytime soon. Can anyone more familiar with the Gen2 Cloud Keys offer an opinion on exactly how that guided setup accomplished the traffic isolation without creating VLANs?