pjhtech Tools
UniFi

UniFi VLAN SSID Not Getting an IP Address

Configure the SSID VLAN and trace missing DHCP through AP native/tagged ports, switch uplinks and the gateway while preserving AP management.

If a UniFi SSID connects but gets no IP address, allow its VLAN on every AP-to-gateway uplink. If DHCP Discover already reaches the server, fix the server’s pool or a DHCP Guarding rule that excludes the real server. These are alternative causes, with separate corrections below.

Fix the VLAN, DHCP pool or trusted-server setting

Example: SSID IoT uses VLAN 30, gateway 10.42.30.1/24 and pool 10.42.30.100–10.42.30.200. Keep the AP’s existing management network. Choose the branch matching the missing DHCP message.

VLAN 30 is missing from an uplink

If Discover does not reach the server-side VLAN and VLAN Viewer shows that an uplink omits VLAN 30, open that port in Ports. Add IoT under Tagged VLAN Management → Custom, keeping the native network and existing tags. Repeat the client request and confirm it now reaches the gateway.

The DHCP server receives Discover but sends no Offer

In Settings → Networks, open IP Leases beside IoT. Then open the IoT network and check DHCP Range → Start / Stop. If the pool is exhausted, release only confirmed obsolete allocations or expand the range into verified unused addresses in the same subnet. Keep static addresses outside the pool. With a third-party DHCP server, inspect its scope and lease list in that server’s management interface. If free addresses are available, check its DHCP service and server policy before changing the range.

DHCP Guarding blocks the legitimate Offer

On a path with UniFi switches, if the correct server sends an Offer but the guarded path excludes it, compare its server IP with Settings → Networks → IoT → DHCP Guarding. Set the verified trusted server IP there; use 10.42.30.1 only when this UniFi gateway serves DHCP. Keep guarding enabled for unauthorized servers, then verify that the legitimate Offer reaches the client.

After editing a port, verify the AP remains managed and a fresh client lease includes the intended subnet, gateway and DNS. Restore the previous native/tagged settings at both ends if the change breaks the path.

Client gets an address from the wrong subnet: check the SSID network

Example: SSID IoT uses VLAN 30, subnet 10.42.30.0/24, gateway/DNS 10.42.30.1 and DHCP pool 10.42.30.100–10.42.30.200. AP management stays on its existing native network; this example does not enable Network Override.

  1. Open Settings → Networks → IoT. Check VLAN ID 30, gateway/subnet and DHCP Range Start/Stop. If creating the network, use Settings → Networks, create a virtual network with these values, enable DHCP Server and apply. The gateway must provide DNS at .1 if that is the advertised resolver.
  2. With a third-party router, configure VLAN 30 and these IP services on that router first, then create the UniFi network with Router → Third-party Gateway and VLAN ID 30. Use that router’s DHCP interface to inspect leases.
  3. Open Ports → VLAN Viewer and follow the AP port and every switch uplink to the gateway. On each affected port, inspect Native VLAN / Network and Tagged VLAN Management. With Custom tagging, include VLAN 30 while retaining every tag already needed downstream; with Allow All, confirm VLAN 30 exists in UniFi. Keep the existing native network at both ends.
  4. Open Settings → WiFi → IoT → Network and select the IoT network. For a new SSID, set its name and password, select the broadcasting APs and save. On a spare wired IoT access port, select Native VLAN IoT and Tagged VLAN Management Block All; do not apply this access-port setting to an AP.

Keep the AP’s native management network distinct from its tagged client VLANs. Network Override requires the management VLAN tagged at the connected port. VLAN troubleshooting also warns against using the same non-default VLAN as both that port’s native network and an SSID network.

If the failing part is unclear, capture one DHCP attempt

In Settings → Networks, use the IoT network’s IP Leases link to find the test client by MAC address. Compare its address with the expected pool. On a Windows test client, ipconfig /all shows IPv4 Address, Default Gateway, DHCP Server and DNS Servers. Disconnect and reconnect the test client’s Wi-Fi if it has no lease; do not disturb all clients to generate one request.

If the settings agree but the lease still fails, capture on the gateway’s client-VLAN interface using its authorized SSH access. Run ip address show and find the interface carrying gateway address 10.42.30.1/24; use that name from tcpdump -D in the capture below. For a third-party gateway use its documented capture tool on the client-facing VLAN interface.

Read-only capture • UniFi gateway; replace <vlan-interface>
tcpdump -npi <vlan-interface> -vv -c 100 'udp port 67 or udp port 68'

Start the capture before reconnecting the test client. Match its transaction ID through Discover, Offer, Request and ACK. Stop with Ctrl+C afterward; the packet limit is a second stop condition. To locate a missing message, capture on both sides of the suspect uplink or mirror that port. Keep captures private.

References