Ubiquiti Switch Management¶
Attention
Before getting started, ensure that you have completed the VLAN and Switch Planning and addressed any comments provided by the instructor.
If you're using a Unifi Flex Mini (5-port switch), please ensure that you've adjusted your VLAN plan to avoid assigning any network to VLAN 1.
Follow the instructions provided at Installing the UniFi Network Application1 to install the web-based network controller used to manage the Unifi switches on your laptop.
Prerequisites¶
Complete the configuration of the physical and tag-based LANs on your Raspberry Pi and then configure the physical network between your laptop, pi, and the two switches that is documented in your Switch and VLAN plan. You won't need your teammates devices at this stage, but it is important that:
- Your laptop and Pi are attached to their assigned switch / ports.
- The switches are connected via ethernet across the two trunk ports
In this setup, your Pi will serve DHCP addresses to your laptop (running the Unifi controller) and to the pair of switches. All devices will be on the same subnet and the controller will be able to communicate with both switches.
Adopt UniFi Switches¶
Launch the UniFi controller application and open a new browser window to manage the application. Navigate to the UniFi Devices view (represented in the far left colum by a circular icon). The right pane should list two devices labeled as USW-Flex-Mini with a Click to Adopt link in the Status column.
Click on the first switch. In the configuration pane (appearing on the right side of the browser), verify that your switch has been given an IP address in your LAN and then click Adopt Device. Repeat this process on the second switch and wait for the status to change to Online.
Once both switches are online, check the overview in the right configuration pane to see a list of attached clients. Use this list of connections to determine which switch is Switch #1 and which is Switch #2. We recommend opening the Settings tab in the device configuration pane and renaming each switch now to minimize confusion later.
Create VLANs and Port Profiles¶
Configuration for the switches is done on a port-by-port basis, but before you can do this, you need to define each of your VLANs in the UniFi console and create custom port profiles for ports that require one or more tagged VLANs.2 To get started, open the UniFi Network Application and navigate to Settings / Networks.
With the Networks panel open, click on the Create New Network link to begin creating your first VLAN. This will open up a new configuration panel titled New Network. Near the top of the panel, click in the check-box labled VLAN-only Hetwork. For each VLAN you wish to create, you will need to provide a network name and VLAN ID. Once you are done, click on the Add Network button at the bottom of the page. Repeat this process until you've defined the following VLANs:
- A VLAN network for each team member's LAN.
- A VLAN network for each routing link identified in your planning documentation, including the links between your ISP/Edge networks and the upstream link reserved for the class.
- A VLAN network for your upstream connection to the class.
If you are using a switch that supports custom port profiles, click on the Profiles link in the left-hand side of the settings screen. And scroll to the bottom of the Switch Ports section to click on the Create New Port Profile link. Provide a meaningful name to each profile, and select the networks to associate with the port. For each profile, you may select one native network and any number of tagged networks. Once you are done, click Apply Settings at the bottom of the page. Repeat this process to define the following profiles based on your own planning documentation:
- A profile associated with each team member's Pi, with the native VLAN to the team member's LAN and tagged VLANs for each routing connection available to that Pi.
- If you are connecting 2 or more switches, create an additional port profile for the trunk links between your switches. This profile should included tagged networks for each of the routing links in your planning document and one tagged network associated with the switch management VLAN.
Apply Port Configurations¶
Unifi Flex Mini (5-port switch)
The Unifi Flex Mini does not support custom port profiles. You may set either assign a native VLAN to a port or enable trunking by applying the all
profile.
The UniFi console allows you to make changes one at a time, with each change taking effect immediately. Since it's possible to get the switch in the state where the controller cannot connect to the internal management interface, we recommend that you disconnect your computer from the switch temporarily while you configure the ports. To get started with the port configuration process, return to the UniFi Devices section of the controller and select one of the switches. Switch to the Ports tab of the configuration pane that opened on the righthand side of the screen and then click on the port number that you wish to configure. Select the appropriate Port Profile, and then click Apply Changes to save your progress.
Refer to your planning documentation to identify the requirements for each port:
- LAN access ports, used to connect to your PC/Mac and to the uplink for the class, should be set to the native VLAN identified in your documentation. To do so, click on the Port Profile and identify the VLAN by name in the drop down list.
- The routing connections between your Pi's rely on tagged VLANs. If your switch supports custom port profiles, select an appropriate profile by each port. If you're configuring a Flex Mini switch, confirm that each of these ports is set to the
all
profile. - Repeat this last step for any ports providing a trunk between switches, applying either a custom port profile or verifying that the ports are set to allow all VLAN tags.
Configure Managment VLAN¶
By default the management interface for UniFi switches is attached to VLAN 1. Before you reconnect the controller to the switch, update this selection on each switch based on the managment network you selected during planning. Navigate to Unifi Devices and select a device to update. Within Settings/Services, change the management VLAN to the VLAN designated for your LAN. Repeat this step once for each switch.
Connect the Switches¶
In order to apply the configuration changes to your switch(es), connect your trunk between the switches (if applicable) and attach your Pi and your computer (each on their designated ports). Power on the switches and provide a moment for the configuration process to complete. If your Pi has been set up on the correct VLAN, your switches should appear online again once the reconfiguration process is complete.
If only one of the switches comes back online, temporarily reconnect your computer to the second switch and allow time for the configuration to apply. After a few moments, restore the connection to the designated port and wait for the switches to come online.
Additional Resources¶
- Installing UniFi Network Controller
- Verifying Tagged VLAN Setup on the Pi
- Configuring VLANs on UniFi Switches
-
The 5-port UniFi Flex Mini switches do not support custom port profiles. You can still create the profiles in the UniFi controller, but you won't be able to apply them in the next step. ↩