• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Why are WAPs leased on their own Guest Network?

Scheduled Pinned Locked Moved DHCP and DNS
10 Posts 2 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    AR15USR
    last edited by Jun 15, 2017, 3:24 AM Jun 14, 2017, 1:54 PM

    Hello,

    I have noticed that both of my Unifi PRO WAPS keep appearing in the DHCP lease list as leased to their own Guest network. They are statically assigned to 192.168.1.x, but as you can see in the pics they keep appearing as leased to 192.168.40.x which is the Guest vlan. I have the Unifi controller running a guest network (vlan 40) with the Unifi captive Portal, and a vlan (192.168.40.1/24) in pfSense to control routing/access.

    Any ideas as to why this is happening?

    -New screenshots below-


    2.6.0-RELEASE

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Jun 14, 2017, 2:56 PM

      sounds like you have your vlans configured wrong..

      Not sure what we are to gain from you posts when you hide the macs which would allow us to see what specific interface is doing a request, etc.

      The management IP of your AP will be untagged.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      • A
        AR15USR
        last edited by Jun 14, 2017, 4:52 PM

        I will repost the pics with no obfuscation, and post pics of the AP Controller settings as well when I get home tonight..

        If you think of a specific pic you need to see before then let me know.

        Thanks in advance..


        2.6.0-RELEASE

        1 Reply Last reply Reply Quote 0
        • A
          AR15USR
          last edited by Jun 15, 2017, 4:39 PM Jun 15, 2017, 3:37 AM

          A topology description: pfSense is connected through igb2 (lan) to a Cisco-SG300 to a trunk port which is a member of all vlans. The two WAPs are connected direct to the sg-300 via trunk ports which are a member of all vlans. Both the Unifi controller and the sg-300 switch have WifiGuest vlan ID as 40. I see no entries in the Unifi Controller Events log relating to the WAPs at all.

          Here are the new screencaps, let me know if you need anything else. The two DHCP log entries are a search for 192.168.1.3, which also shows as 192.168.40.21


          2.6.0-RELEASE

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Jun 15, 2017, 10:12 AM

            So you set this vlan 40 as guest network in unifi with the captive portal running then..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • A
              AR15USR
              last edited by Jun 15, 2017, 1:07 PM

              @johnpoz:

              So you set this vlan 40 as guest network in unifi with the captive portal running then..

              Yes (the captive portal is in Unifi, not in pfSense to be clear). The Guest Wireless Network in Unifi is set as a Guest Network with Guest Policies activated and is assigned the vlan ID of 40. The Guest Portal only displays the TOS, no authentication happens. Then I created a vlan in pfsense with same ID. Devices that connect to the Guest Wifi ssid get assigned the correct 192.168.40.x IPs, and are properly displayed the Portal TOS before being allowed to continue to browse. They are also properly segregated from any other network (LAN, IOT, etc).

              Is that what you were getting at?


              2.6.0-RELEASE

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Jun 15, 2017, 2:47 PM Jun 15, 2017, 2:27 PM

                Yes that is going to be required when you do that..

                Here I just enabled guest portal and tos of one of my vlans - bam dhcp request from the AP for an IP on that guest network

                guestunifi.png
                guestunifi.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • A
                  AR15USR
                  last edited by Jun 15, 2017, 3:37 PM Jun 15, 2017, 3:23 PM

                  Ah, so the request for an IP on the guest vlan in pfsense is expected behavior when setting up Unifi like it is then, correct?

                  Is this behavior proper? Is it a risk in anyway? Or just something to ignore?


                  2.6.0-RELEASE

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Jun 16, 2017, 11:56 AM

                    It is expected - what sort of risk is there?  Its not a management IP of the AP..

                    Your best to ask such a question on the unifi forums.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • A
                      AR15USR
                      last edited by Jun 16, 2017, 5:16 PM

                      Roger, thanks for your help…


                      2.6.0-RELEASE

                      1 Reply Last reply Reply Quote 0
                      4 out of 10
                      • First post
                        4/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received