Easily Manage Local Traffic in UniFi

By default, UniFi gateways allow traffic from anywhere to all. While this is easy for a basic setup, you may want to block certain networks from access other networks in your environment.

In my environment, I have my default LAN (trusted devices), IoT VLAN (smart cameras, TVs, smart bulbs) and Guest VLAN. I do not want the IoT and Guest VLANs to be able to get over to my LAN network in case of an exploited device.

There are a ton of videos out there showing how you can manage this sort of thing and more often that not, those videos are 20 minutes long and have a million unecessary steps. In this article, I’ll show you how to make this super easy.

In this instance, I am using a UDM Pro running UniFi OS 3.0.20.

Log into your UniFi gateway and head over to the Settings menu:

UniFi dashboard for a UDM Pro on UniFi OS 3.0.20 with the settings gear icon highlighted in the sidebar

Click on Traffic Management to bring up the new “firewall rules”

UniFi Network settings with Traffic Management selected, showing the Rules, Routes and Static Routes panels

Click on “Create New” under Rules

Traffic Management Rules panel with the Create New link highlighted

I am going to create a rule to block the IoT and Guest networks from accessing the LAN.

Block rule with category Local Network, source IoT and Guest, target LAN, schedule Always

So in this case, we are saying the anything on the IoT and Guest networks is not allowed to go over to the LAN side at all times of the day.

The “Rules” under Traffic Management is really powerful, you can use domains, apps, networks, IPs and more as a way to manage traffic inside your network environment.

Need help with your website?

Dynamic Technologies builds, hosts and maintains websites for small businesses in Coeur d'Alene and North Idaho.