Hi guys,

Im trying to find some guides or documentation for setting up our new unifi ap onto our sonicwall network.

I have a nsa 5600, and a unifi ac/pro ap.

Sonic points are pretty straight forward to me, but im a bit confused about how i’d add these unifi devices. It seems to me that these would go on their own interface using 2 vlans 1 for guest, and 1 for internal traffic. But then i came across a video that said you should add them as vlans under the lan interface. This doesn’t seem to make sense to me though because how would i separate the guest traffic from the lan traffic if its all running under the main lan interface.

3 Spice ups

Sonicwall VLANs have their own virtual interface under the X0 interface. The VLAN is then tagged through your managed switches otherwise you will create another zone and assign an Specific hardware interface to it.

The rest would be the same.

So the way i’ve always done this was to have the wireless on its on interface, with 2 vlans under it one vlan for internal, and 1 for guest, then i’d configure these settings differnlty on sonicpoints for the devices.

So in this case woudl i just make 2 vlans under x6 interface, and then make rules alloing the internal vlan access to the internal network, and then access rules on the other vlan only allow it to the web?

The switch connected to the lan port does not currently support vlans on it, its pretty old, so my plan had been to use the x6 interface with a new unifi switch with the ap’s connected if these work out.

1 Spice up

Not sure why you will need to have a VLAN for internal traffic since it will be in the same network.

1 Spice up

i was thinking i needed that vlan since i was using the x6 port to connect the unifi gear to, instead of them being plugged into the switch that connected to the x0 interface. can i instead just tell it that x6 is also lan zone and make a single vlan under that for guest traffic?

1 Spice up

Yes. it seems you answered your own question.

X0 and X6 would be same Lan, then a VLan for your guest traffic also in X6 (where you are connecting your unifi poe switch)

I have a similar setup with 3 vlans, faculty students and guest and so far not a problem.

good luck with your setup

1 Spice up

Yes, you can do that as well.

1 Spice up

ok i have ran into another issue. my global VPN uses DHCP, and has a range within the lan. How can i setup a second DHCP range on the lan, and tell it the ap’s to only use that range.

Our VPN DHCP range points to external DNS servers, and our wifi devices will need to point to our Internal DNS servers.

So the rest of your devices in the network are setup with Static IP addresses?

1 Spice up

yes, and our wifi devices currenlty are on a seperate zone and port.

The VPN dhcp range’s dns points to pubic dns servers, but i be those could just be changed to point to the internal DNS server.

Just change the DHCP to point to internal DNS server across the board. No need to be inconsistent :slight_smile: that way your VPN devices can access systems in your network by the DNS name.

1 Spice up

Got it all setup, and i must say the interface and range of these definitely trumps the sonic points we were using.

2 Spice ups

Nice! Ubiquiti rocks!

2 Spice ups