mattoddie.dev

Notes on things I'm building and things I'm interested in.

PORT 01 HOME LAB 2026-10-05 · 4 min /homelab/unifi-lab-network/
Port 01 · Home Lab · 4 min

Setting up a lab network with UniFi

A lab network is a place where you can break things without breaking anything else. In UniFi that comes down to three pieces: a virtual network with its own VLAN, switch ports that put machines on it, and a firewall zone that decides what it can reach.

This walk-through uses the UniFi Network application on a UniFi OS gateway with the zone-based firewall, which arrived in Network 9.0. The menu names below are from the current interface. Older versions with the legacy firewall can do the same thing with LAN In rules, but the steps differ.

Plan the addresses first

Pick a VLAN ID and a subnet before opening the controller, and write them down. Matching the third octet to the VLAN ID makes packet captures and firewall logs easier to read at a glance.

SettingValueNotes
NameLabShown in client lists and firewall zones
VLAN ID40Any unused ID from 2 to 4009
Gateway / subnet10.40.0.1/24254 usable addresses
Static range10.40.0.2 – .99Hypervisors, switches, anything you SSH to by address
DHCP range10.40.0.100 – .249Short-lived VMs and containers
Domainlab.home.arpahome.arpa is reserved for this by RFC 8375

Create the network

In UniFi Network, go to Settings → Networks → New Virtual Network. Give it the name, set the gateway IP and subnet, and open the advanced settings to set the VLAN ID manually. Leave DHCP mode as DHCP Server and set the range so it doesn't overlap your static block.

Set the domain name in the DHCP options too. Clients then get lab.home.arpa as their search domain, so ssh pve1 works without the full name once you add local DNS records for your static hosts.

If your version shows an Isolate Network option, leave it off. It blocks traffic between this network and every other one, including the traffic you want from your laptop. The firewall zone below gives you the same protection with one exception you control.

Put ports on the VLAN

A network exists on the gateway as soon as you save it. Machines join it through switch ports, and there are two kinds you need.

Access ports

For a machine that only ever lives on the lab network, such as a spare mini PC, open the switch in UniFi Devices, select the port in the Port Manager and set its Native VLAN / Network to Lab. Set tagged VLAN management to Block All so the port carries nothing else. The machine needs no VLAN configuration of its own.

Trunk ports

A hypervisor is different. Its own management address can stay on your main network while its VMs sit on Lab, so the port keeps your normal native network and carries Lab as a tagged VLAN. On Proxmox that means a VLAN-aware bridge, and each VM's network device gets VLAN tag 40.

/etc/network/interfaces on the Proxmox hostDebian
auto vmbr0
iface vmbr0 inet static
    address 192.168.1.20/24
    gateway 192.168.1.1
    bridge-ports eno1
    bridge-stp off
    bridge-fd 0
    bridge-vlan-aware yes
    bridge-vids 2-4094

Keep a way back inDon't move the switch's own management address onto the lab VLAN while you're connected through it. If the firewall rules aren't in place yet you lose the controller's path to the switch, and the fix is a factory reset. Change ports one at a time and check each before moving on.

Give it a firewall zone

The zone-based firewall groups networks into zones and sets one policy for each pair of zones. New networks land in the Internal zone, where everything can talk to everything. Open the zone settings in the firewall section of UniFi Network, create a custom zone called Lab and move the Lab network into it.

Then set the policies between Lab and the other zones:

  • Internal → Lab: allow. Your laptop can reach lab machines over SSH, the Proxmox web UI and anything else you run there.
  • Lab → Internal: block. A misbehaving VM can't scan or reach your other devices. Keep return traffic enabled on the Internal → Lab allow policy, so replies to connections you start still get back.
  • Lab → External: allow. Lab machines need the internet for package updates and container images.
  • Lab → Gateway: allow DNS and DHCP only. Restricting this stops lab machines from reaching the gateway's own management interface.
Firewall zones: Internal can reach Lab, Lab cannot reach Internal, and Lab can reach External and the gateway for DNS and DHCP. INTERNAL 192.168.1.0/24 LAB · VLAN 40 10.40.0.0/24 EXTERNAL GATEWAY DNS, DHCP allow block allow 53, 67
FIG 1Zone policies for the lab network. The only way in from home devices is a connection you start yourself.

Check it from both sides

From a machine on the lab network, confirm the address, the gateway and the block:

On a lab hostShell
# Address from the right range, search domain set
ip -brief addr
cat /etc/resolv.conf

# Gateway and the internet work
ping -c 3 10.40.0.1
curl -sI https://deb.debian.org | head -1

# A device on the main network should time out
ping -c 3 -W 2 192.168.1.50

Then from your laptop on the main network, SSH to a lab host by name. If that works and the last ping above fails, the lab is in place. Anything you start on VLAN 40 from now on can only reach the internet and the gateway's DNS, so you can try things out there without risking the rest of the network.

If you use unifi-mcp, a question like "which clients are on the Lab network?" is a quick way to see what has actually landed on the VLAN. That server, and how it was built, is the subject of a post in the AI category.

Written by · Markdown version