Unifi inter VLAN communication stopped working

I have setup a seperate vlan for iot stuff. Everything has been working fine until recently, but now devices on the iot vlan can no longer communicate with the other network. I have setup firewall rules around this to specifically only allow them to connect only to the mqtt server on the other network. But even removing all rules and adding additional rules to allow absolutely everything to every private IP does not fix it. From the regular default network I can however access the devices on the vlan just fine. So it works one way.

Can’t pinpoint what changed tbh. I do not remember changing anything recently. Only noticed that all the things that connect via wifi in home assistant are gone.

I did reinstall the controller now. Used the linuxserver.io docker container. Previously it has been on some debian 10 vm that I now retired. Restored from backup, re-adopted everything. Same issue, but now running the most recent controller version.

The firewall rules are setup like this

(there are a few more rules below that, but they are all system managed can´t edit them)

I did try to disable the block inter vlan rule, added an addtional rule to allow the iot network to connect to all private ips (it´s gone now) and tried to disable the gateway management rules too. I connected my notebook to the network. Same thing cannot connect to anthing. Can connect to the internet if I disable that rule. Can connect to the gateway management ui’s (if i disable those rules) also the one on the regular network. Can also connect to devices on the same vlan, but not devices on the regular network (except management ui).

Not really sure what to share tbh. I do not believe that this is a firewall issue at this point, but something else that is not working out.

Solved it but in the most unsatisfying way possible.

Created a new VLAN, transfered all the rules to the new VLAN. Deleted the old VLAN. Works again now…

1 Like

Nevermind, me conversing with myself here… :sweat_smile:

Maybe it helps someone at some point.


This happened again and the more “smart” things I add to my home the more annoying this gets tbh.

I was pretty quick to blame unifi and considering throwing out the aging usg-pro-4 for something completely different.

But turns out the routing was working just fine. The traffic got from the IoT vlan to my proxmox server and then… it disappeared and never made it into the vm.

I did now add a second vnic to the vm with the vlan tag of the IoT vlan and that fixed it.
Not sure if thats the best way to do it. Since the nic on my proxmox server has 2 plugs I could also disable vlan awareness on proxmox and have 2 physical nics that I can configure to belong to different vlans. But this was A way to do it without needing to craft another network cable and just click buttons instead.

1 Like