Setting up a lab network with UniFi
A lab network is a place where you can break things without breaking anything else. In UniFi that comes down to three pieces: a virtual network with its own VLAN, switch ports that put machines on it, and a firewall zone that decides what it can reach.
This walk-through uses the UniFi Network application on a UniFi OS gateway with the zone-based firewall, which arrived in Network 9.0. The menu names below are from the current interface. Older versions with the legacy firewall can do the same thing with LAN In rules, but the steps differ.
Plan the addresses first
Pick a VLAN ID and a subnet before opening the controller, and write them down. Matching the third octet to the VLAN ID makes packet captures and firewall logs easier to read at a glance.
| Setting | Value | Notes |
|---|---|---|
| Name | Lab | Shown in client lists and firewall zones |
| VLAN ID | 40 | Any unused ID from 2 to 4009 |
| Gateway / subnet | 10.40.0.1/24 | 254 usable addresses |
| Static range | 10.40.0.2 – .99 | Hypervisors, switches, anything you SSH to by address |
| DHCP range | 10.40.0.100 – .249 | Short-lived VMs and containers |
| Domain | lab.home.arpa | home.arpa is reserved for this by RFC 8375 |
Create the network
In UniFi Network, go to Settings → Networks → New Virtual Network. Give it the name, set the gateway IP and subnet, and open the advanced settings to set the VLAN ID manually. Leave DHCP mode as DHCP Server and set the range so it doesn't overlap your static block.
Set the domain name in the DHCP options too. Clients then get lab.home.arpa as their search domain, so ssh pve1 works without the full name once you add local DNS records for your static hosts.
If your version shows an Isolate Network option, leave it off. It blocks traffic between this network and every other one, including the traffic you want from your laptop. The firewall zone below gives you the same protection with one exception you control.
Put ports on the VLAN
A network exists on the gateway as soon as you save it. Machines join it through switch ports, and there are two kinds you need.
Access ports
For a machine that only ever lives on the lab network, such as a spare mini PC, open the switch in UniFi Devices, select the port in the Port Manager and set its Native VLAN / Network to Lab. Set tagged VLAN management to Block All so the port carries nothing else. The machine needs no VLAN configuration of its own.
Trunk ports
A hypervisor is different. Its own management address can stay on your main network while its VMs sit on Lab, so the port keeps your normal native network and carries Lab as a tagged VLAN. On Proxmox that means a VLAN-aware bridge, and each VM's network device gets VLAN tag 40.
auto vmbr0
iface vmbr0 inet static
address 192.168.1.20/24
gateway 192.168.1.1
bridge-ports eno1
bridge-stp off
bridge-fd 0
bridge-vlan-aware yes
bridge-vids 2-4094
Keep a way back inDon't move the switch's own management address onto the lab VLAN while you're connected through it. If the firewall rules aren't in place yet you lose the controller's path to the switch, and the fix is a factory reset. Change ports one at a time and check each before moving on.
Give it a firewall zone
The zone-based firewall groups networks into zones and sets one policy for each pair of zones. New networks land in the Internal zone, where everything can talk to everything. Open the zone settings in the firewall section of UniFi Network, create a custom zone called Lab and move the Lab network into it.
Then set the policies between Lab and the other zones:
- Internal → Lab: allow. Your laptop can reach lab machines over SSH, the Proxmox web UI and anything else you run there.
- Lab → Internal: block. A misbehaving VM can't scan or reach your other devices. Keep return traffic enabled on the Internal → Lab allow policy, so replies to connections you start still get back.
- Lab → External: allow. Lab machines need the internet for package updates and container images.
- Lab → Gateway: allow DNS and DHCP only. Restricting this stops lab machines from reaching the gateway's own management interface.
Check it from both sides
From a machine on the lab network, confirm the address, the gateway and the block:
# Address from the right range, search domain set
ip -brief addr
cat /etc/resolv.conf
# Gateway and the internet work
ping -c 3 10.40.0.1
curl -sI https://deb.debian.org | head -1
# A device on the main network should time out
ping -c 3 -W 2 192.168.1.50
Then from your laptop on the main network, SSH to a lab host by name. If that works and the last ping above fails, the lab is in place. Anything you start on VLAN 40 from now on can only reach the internet and the gateway's DNS, so you can try things out there without risking the rest of the network.
If you use unifi-mcp, a question like "which clients are on the Lab network?" is a quick way to see what has actually landed on the VLAN. That server, and how it was built, is the subject of a post in the AI category.
Written by Matt Oddie · Markdown version