making VLANS + Ubiquiti WIFI

Hello,

I have not tinkered with VLANs yet. I need help and advice how to correctly proceed. Here is my situation:
2 x Ubiquiti AP
1 x hAP AC2
1 x CRS326-24G-2S+

I want to build 3 VLANS:

  1. Main for my family
  2. IoT partly blocked from Internet. I need most of the devices blocked from Internet, but there is some devices which would need Internet. They should all reach my HomeAsistant server.
  3. Guest VLAN, just for WIFI and maybe casting to streamer or TV.

There will be 3 SSID: IoT, Main, Guest.

First things first how should I connect my APs? Better to connect them straight to router or switch?
If I have some IoT devices connected over Wifi and some over LAN on switch, how should I program my router/switch?
Thanks in advance, if something is unclear, please ask :slight_smile:

The switch comes in handy for any traffic within the same vlan from user to another.
The router comes into play between user and internet and traffic between different vlans.

I understand that. So basically I could wire everything to switch, tag ports (for lan), on Unifi AP create VLANs and hook switch to router. More interested about firewall and nat rules to succeed in blocking partially and allowing some services.

All very doable.

So anyone could guide?

If you have IoT network then why blocking some devices… Just block IoT VLAN access to the other VLANs (but leave communication open to the HA server)

Did you created VLANs on Mikrotik ? If not here is great tutorial for that: http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1

Read it, try it yourself and if you get stuck of course someone will help you.

Ubiquiti will be the easiest to set up.