How-to: Group Wired PoE Security Cameras in a VLAN using Unifi

In my tutorial on how to block IP cameras from accessing the Internet using a Unifi USG firewall, I used the example of wireless security cameras.

But what if you have wired IP cameras and want to achieve the same result – block PoE IP cameras from accessing the Internet? Fear not, all you need to have is a managed Unifi switch like the one I have – Unifi Switch 8.

Assuming you have already created a VLAN as described in Step 1 of this tutorial, here are the steps to group or assign wired Ethernet devices into a VLAN:

Step 1: Create a switch port profile

  1. Log into your Unifi Controller dashboard and click on the settings button (gear icon)
  2. From the settings menu, select ‘Profiles’, and then select the ‘Switch Ports’ tab
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 1 001 - VueVille
  3. Click ‘Add New Port Profile’
  4. Type in a profile name, I like to use the same name as the VLAN  created ‘IPCameras’.
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 1 002 - VueVille
  5. Select the VLAN under the Tagged Networks section.
  6. Click Save
back to menu ↑

Step 2: Plug in your Ethernet device

Into a port of your Unifi managed switch, and note the port number. Let’s assume it is a PoE device, so let’s pick port 6.

back to menu ↑

Step 3: Assign Unifi switch port to the new switch port profile

  1. From your Unifi Controller dashboard and click on the Devices button from the left menu
  2. Click on your Unifi Switch, this should open a slide-out menu on the right
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 3 001 - VueVille
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 3 002 - VueVille
  3. Click on the Ports section
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 3 003 - VueVille
  4. Click on the edit button (pencil icon) next to port 6
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 3 004 - VueVille
  5. Click the dropdown called ‘Switch Port Profile’
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 3 005 - VueVille
  6. Select the switch port profile you created earlier and click the apply button.
     
    How to Group Wired PoE Security Cameras in a VLAN using Unifi Step 3 006 - VueVille

The switch will now provision the port and after a few minutes, you are in business!

back to menu ↑

Conclusion

Liked this tutorial? Let me know in the comments below what else you would like me to cover.

Get notified when I post new content

Join 131 other VueVille fans! Don't worry, I hate spam too!

I am Daniel and VueVille is where I document my DIY smart home journey. I focus on 100% local-processing and local-storage because that’s the only way to secure my family’s safety and privacy. Oh and I don’t like monthly subscriptions!

4 Comments
  1. HI, i plan to follow your setup, may i check if i can substitute the usg, cloud key and managed switch with Unify Dream pro machine please. Will buy Hikvision cameras and QNAP 253de.

    Thanks,
    Arnold

    • I am not sure the Dream Pro machine supports all the advanced features that the USG does. You will have to check with Unifi please.

  2. Hugely helpful, between this and your other tutorial about securing cameras! One thing I’m not clear on – is the switch port profile necessary if you want that switch port to be only on the VLAN? My version of the controller doesn’t allow the same name to be used for both VLAN creation as well as port profile creation as yours seems to, and when I apply the port profile to a port (which doesn’t look like how yours looks above, it shows up under a heading called “Custom”, below networks) the device still remains using the same IP as the untagged LAN. However, when I select the VLAN itself (as you appear to above), it all works fine, but that seems to skip the port profile creation entirely. I’m pretty green, so is there something I’m missing?

    • > One thing I’m not clear on – is the switch port profile necessary if you want that switch port to be only on the VLAN?
      Yes the port profile is used to tag all traffic through a port with the VLAN assigned to that port profile.

      > However, when I select the VLAN itself (as you appear to above), it all works fine, but that seems to skip the port profile creation entirely.
      Maybe you are on a newer or older controller version? As long as your rules are being applied to the , I think you’re fine.

    Leave a reply

    VueVille
    Logo