pjhtech Tools
UniFi

UniFi Guest Isolation Not Blocking Local Devices

Block Guest access across VLANs and between clients on the same VLAN, while keeping intentional Trusted-to-IoT exceptions.

If Guest clients can reach your private VLANs, enable Network Isolation for Guest. If clients on the same Guest VLAN can still reach each other, add the appropriate WiFi client isolation and supported switch ACL isolation; gateway inter-VLAN rules do not cover that local path.

Guest can reach another VLAN

Open Settings → Networks → Guest → Network Isolation and enable it. Repeat for IoT only when it should have complete inter-VLAN blocking. If Trusted must reach selected IoT services, use the specific controller-to-device policy example instead.

Guest clients can reach each other on the same VLAN

Open Settings → WiFi → select the Guest SSID and enable Client Device Isolation. For a supported switch path, open Settings → Networks, enable Device Isolation (ACL) and select Guest. Apply these controls only to networks whose clients do not need peer communication, then verify the whole path. Test two clients on one AP, clients on different APs, and a wireless client against a wired host on the same VLAN. Use an application that works before isolation, then try a new session after enabling the control; a closed service cannot demonstrate blocking. A captive portal is an access workflow; it is not a substitute for traffic separation.

Device Isolation (ACL) requires a network routed by a UniFi gateway or L3 switch. Check every switch on the client path against the switch ACL support list. Traffic that stays inside an unsupported switch will need isolation on that switch or a change to the client connection path.

Keep a selected printer or speaker reachable from Trusted

For a Trusted phone that needs an IoT printer or speaker, enable only the required mDNS sharing and the actual service-port permit. Use the AirPrint/AirPlay procedure; keep Guest outside that scope.

Test isolation

Run an allowed service test and a blocked new-session test for each row in your plan. Repeat on IPv6 where provisioned. Check management access from a trusted recovery device before committing gateway restrictions. If a feature breaks, locate the failed discovery or service flow instead of disabling every isolation layer.

References