OPNsense Forum

English Forums => General Discussion => Topic started by: malakez on January 27, 2021, 05:54:55 AM

Title: Opensense + Unifi Dream machine questions
Post by: malakez on January 27, 2021, 05:54:55 AM
Hello,

What i'm missing here? I'm using shuttle ds77u as Opnsense box and Unifi Dream machine + USW Mini switch.

Topology: VDSL-modem in bridged mode -> Opnsense -> UDM -> Unifi USW Flex mini -> desktop

Networks on Opnsense and UDM
IP addresses
UDM doesn't show up at all in in DHCP leases on Opnsense, USW flex mini does on the LAN interface.
Questions:
A) Why cannot I access 192.168.3.2 from the 10.10.10.0/24 VLAN network?
B) Why I don't have internet access on 192.168.3.0/24 LAN network?
C) Why doesn't Opnsense give IP to UDM?
Title: Re: Opensense + Unifi Dream machine questions
Post by: athurdent on January 27, 2021, 09:08:15 AM
Shuttle/Opnsense box IP 192.168.3.1 (set by opnsense LAN settings)
UDM IP 192.168.3.2 (set by UDM in its LAN settings)


That will not work, at least not in this setup:
> Opnsense -> UDM ->
You need to plug in the UDM WAN interface into the OPNsense LAN. And change either the OPNsense LAN network to a different /24, or re-IP your LAN network to something different. You cannot use the same network for LAN & WAN.
Title: Re: Opensense + Unifi Dream machine questions
Post by: malakez on January 27, 2021, 12:38:06 PM
Not quite what I was looking for for that does double NAT
Title: Re: Opensense + Unifi Dream machine questions
Post by: malakez on January 27, 2021, 01:03:42 PM
Hello,

I switched unifi LAN to 192.168.2.1 and Opnsense box to 192.168.6.1. Now I have Double-NAT situation which I don't want

Tracing route to google.com [172.217.21.142]
over a maximum of 30 hops:

  1    <1 ms    <1 ms    <1 ms  unifi.localdomain [192.168.2.1]
  2    <1 ms    <1 ms    <1 ms  192.168.6.1
  3    12 ms    12 ms    11 ms  dsl-nnnnn []

Is this because I have now connected Opnsense box to WAN port of UDM? Should I just switch to LAN port then so Opnsense could do firewall stuff?
Title: Re: Opensense + Unifi Dream machine questions
Post by: malakez on January 27, 2021, 03:27:47 PM
Hello,

My idea is to use UDM as a managed switch/unifi controller/wireless access point and firewall/dhcp and everything else would be managed on Shuttle Opnsense. Is this even possible or do I need "plain" unifi managed switch + unifi network controller on a raspberry pi etc.
Title: Re: Opensense + Unifi Dream machine questions
Post by: athurdent on January 27, 2021, 03:50:27 PM
It kind of expects to be the router, so you could plug it into LAN (with it's LAN interfaces) and if your OPNsense box had a spare NIC, you could give that a new IP network and plug UDM WAN in there, for the UDM to "think" it has WAN, too.
If you have a managed switch, you can also do this with VLANs.

For a more clean way, maybe get a UniFi switch / nanoHD/FlexHD (or a new U6 LR / Lite) and install the controller locally or get a CloudKey G2.