mjp66 / Ubiquiti

765 stars 70 forks source link

Question about communication between two device on VLAN 7 #9

Closed khat2 closed 6 years ago

khat2 commented 6 years ago

I am trying to setup a SAMBA server on VLAN 7 (wifi IOT eth4 switch0,7) and to have other computers access that SAMBA computer but I cannot get the two devices to ping. I can ping all devices from the Wired home network (eth3). The configuration is as explain in the documentation with the exception of Quad 9 used instead of OpenDNS.

config.boot.zip

mjp66 commented 6 years ago

You probably need a managed (VLAN aware) switch to connect all these devices together. Sorry, but I'm not a network engineer.

I suggest you either search the Ubiquity EdgeMax forum at https://community.ubnt.com/t5/EdgeMAX/bd-p/EdgeMAX or create an account and ask them. If you ask the forum, they will probably want you to post your (slightly redacted) ER-X configuration file and/or network map.

If you post, you can reference this github repository as source or https://community.ubnt.com/t5/EdgeMAX/New-ERX-AC-AP-LR-setup-guide-for-beginners/td-p/1906477 as source or neither.

Help this helps, -Mike

mjp66 commented 6 years ago

See also potential answers to question in section 26, I.e. Vlan info.

khat2 commented 6 years ago

Update to why I could not ping device to device on VLAN 7.

The configuration on the Ubiquiti AP-AC-LR. Wireless Networks => Edit Wireless Network Iot WIFI => Guest Policy => enable. With this enable I could not ping between device on the VLAN7. When disabled ping is possible and I was able to create/access my SAMBA share on the VLAN7 subnet. Enabling Guest Policy will make the network more secure but for my purposes I need to be able to communicate between device on the subnet.

Thanks for a GREAT write up and I learned a lot about ERX and AP from your document. Ken

mjp66 commented 6 years ago

@khat2 Great you figured that out. Sorry, but I misinterpreted your question as Wired IOT. Since you disabled the Guest policies, you may want to add a couple more firewall rules between Networks. -Mike