UniFi VLAN Setup: Segment Your Network the Right Way
Flat networks are simple until the day a cheap smart plug or a guest laptop becomes the weak link that reaches everything else. VLANs fix that by splitting one physical network into isolated virtual ones — a trusted LAN, an IoT network, a guest network — each with its own rules. UniFi makes this genuinely approachable, and this guide walks the whole thing end to end. The gear below is in stock at Javelin Networks.
Why segment at all
Three reasons: security (a compromised IoT device can't see your PCs or NAS), performance (chatty devices stay off your work traffic), and control (guests get internet only, never your LAN). The classic split is a trusted LAN, an IoT/smart-home VLAN, and a guest VLAN — add a work or camera VLAN as needed.
What you need
Any UniFi gateway and UniFi switches: the gateway routes between VLANs and enforces the firewall rules, and the switches carry the tagged traffic to each port. A Cloud Gateway Ultra or a Dream Machine SE plus a managed switch like the USW Lite 16 PoE is a perfect VLAN-capable setup. Everything is configured in the UniFi Network application (the UniFi Help Center has the deep reference). Browse gateways and switches.
Step 1: Create the networks (VLANs)
In the UniFi Network app go to Settings → Networks → New Virtual Network. Create one per segment and give each a VLAN ID, for example:
- LAN — your default trusted network (VLAN 1).
- IoT — VLAN 20 for smart-home and untrusted devices.
- Guest — VLAN 30, flagged as a Guest network so client isolation turns on automatically.
Each network gets its own subnet and DHCP scope automatically; leave those at the defaults unless you have a reason to change them.
Step 2: Put Wi-Fi SSIDs on the right VLAN
Under Settings → WiFi, create or edit an SSID and set its Network to the VLAN you want it on. A common layout is one SSID on LAN for your devices, one on IoT for smart-home gear, and one Guest SSID on the Guest VLAN. The access points tag the traffic automatically — no per-AP config needed.
Step 3: Assign switch ports
For wired devices, open the switch in the app, click the port, and set its Native (untagged) VLAN to the segment that device belongs to — for example a camera port to the camera VLAN. Leave uplink ports between switches and the gateway carrying all VLANs (the default) so tagged traffic can pass.
Step 4: Lock it down with firewall rules
This is the step that actually makes segmentation mean something. The goal is simple: segments can reach the internet, but not each other. UniFi's newer policy-based firewall (or traditional rules on older versions) makes this straightforward:
- Block IoT → LAN and Guest → LAN (and typically IoT ↔ Guest).
- Allow established/related return traffic so your LAN can still initiate to IoT (e.g. to cast to a TV) while IoT can't start a connection back.
- Allow the specific exceptions you need — for example your phone on LAN reaching a smart speaker on IoT.
Guest networks flagged as "Guest" already isolate clients from each other and the LAN by default, which is why that checkbox matters.
Frequently asked questions
Do I need UniFi switches for VLANs, or just the gateway?
For Wi-Fi-only segmentation the gateway and APs are enough. For wired devices on different VLANs you need managed switches — UniFi switches are managed and VLAN-aware out of the box.
What's the difference between a tagged and untagged (native) VLAN on a port?
An untagged/native VLAN is the single VLAN a plain device on that port belongs to. Tagged VLANs ride the same cable with VLAN labels and are used on uplinks between switches/APs that carry several VLANs at once.
How many VLANs should a home or small office have?
Three is a great start: trusted LAN, IoT, and Guest. Add a camera VLAN and a work VLAN if you want cameras isolated and work devices separated. Don't over-segment — every VLAN is firewall rules to maintain.
Will VLANs slow my network down?
No. Routing between VLANs happens on the gateway at line rate for home and small-office loads, and keeping chatty devices on their own segment usually makes the network feel better, not worse.
My IoT device can't be reached after I segmented it — why?
That is the firewall doing its job. Add a specific allow rule from your trusted device to that IoT device (or enable mDNS so discovery crosses VLANs), rather than opening the whole segment.
Building a segmented network? Browse VLAN-capable gateways and switches, or everything Ubiquiti at Javelin Networks.