A managed switch is not just a box with Ethernet ports. The way those ports handle VLANs, power and traffic determines how the rest of the network behaves.
Practical example: segmenting a 45-user office
Gateway policy controls which VLANs may communicate. Guest access can be restricted to the Internet.
Scenario: One managed switching environment carries servers, staff devices, VoIP, CCTV and guest WiFi.
| Example VLAN | Purpose | Example policy |
|---|---|---|
| 10 | Servers | Accessible only from authorised business networks |
| 20 | Staff | Access to approved internal services and Internet |
| 30 | Voice | Restricted to required voice and management services |
| 40 | CCTV | Camera traffic restricted to required recording and management systems |
| 50 | Guest WiFi | Internet access, blocked from internal business networks |
Decision: VLANs provide the logical separation. The router, firewall or Layer 3 policy determines which networks may communicate.
Common mistakes and selection checklist
Common mistakes
- Creating VLANs but allowing unrestricted routing between them.
- Using VLAN IDs without documenting IP subnets, DHCP, gateways and access policy.
- Configuring trunk and access ports inconsistently across switches and access points.
What happens if you get it wrong?
The network can look segmented while providing little security benefit, or devices can lose connectivity because tagged and untagged traffic is handled differently at each hop.
Selection checklist
- Define the purpose and subnet of every VLAN.
- Document which VLANs may communicate and on which services.
- Configure gateway or Layer 3 firewall policy explicitly.
- Verify access ports, trunks and native or untagged VLAN behaviour end to end.
- Test DHCP, DNS, Internet access and blocked inter-VLAN paths after deployment.
Access ports and trunk ports
Ubiquiti defines an access port as a port that carries only its native untagged VLAN. A trunk port allows tagged VLAN traffic in addition to its native VLAN. This distinction becomes important when connecting switches, access points, routers and VLAN-aware devices.
| Connection | Typical VLAN behaviour |
|---|---|
| Office PC | Usually an access-style port for one client network |
| IP phone plus PC | May use a voice VLAN with the workstation on the native network |
| Access point | May need a native management network plus tagged client VLANs |
| Switch to switch | Normally carries multiple tagged VLANs |
| Gateway to switch | Depends on the gateway and VLAN design, but commonly carries multiple networks |
Native VLAN
The native VLAN is the network assigned to untagged traffic on a port. A common mistake is to change the native VLAN without checking the upstream and downstream path. Ubiquiti specifically warns that incorrect VLAN tagging can make UniFi devices unreachable and can prevent wireless clients from receiving network connectivity.
PoE is a separate design calculation
The switch must have enough total PoE availability for all connected powered devices. Ubiquiti currently documents 15.4 W maximum at the PSE for 802.3af, 30 W for 802.3at and 60 W or 100 W for the two 802.3bt types. The actual power available to the powered device is lower than the PSE figure.
For example, if a switch is expected to power four 21 W U7 Pro access points, the access points alone represent 84 W of expected consumption. Other PoE devices must then be added to the calculation.
Other switch functions worth understanding
- Port isolation
- Storm control
- Loop protection
- Spanning Tree Protocol
- Port mirroring for packet capture
- Link aggregation
- 802.1X authentication
- Voice VLAN and LLDP-MED
- Ubiquiti UniFi Switch Settings
- Ubiquiti Switch Port VLAN Assignment
- Ubiquiti PoE Availability and Modes
Technical information in this article is based on current manufacturer documentation available at the time of writing. Product availability and specifications can change.
Confirm the exact product specification, supported configuration and compatibility before ordering. Platform generation, firmware, licences and optional components can change what a product supports.