- 43
- 1 084 134
Unified IT
United States
เข้าร่วมเมื่อ 7 ก.ย. 2021
Zone-Based Firewall: The Best New Feature in UniFi 9.0
🧑🏻💻 Hire Us: www.unifiedit.tech
🎉 Referral Program: www.unifiedit.tech/referral
📺 Watch:
🔥 Backup your data with Backblaze (Affiliate): www.backblaze.com/cloud-backup.html#af9yeh
Timestamps:
---------------------------------------------------
0:00 Intro (ZBF)
0:57 What are Firewall Zones?
1:21 Unifi Builtin Zones
1:52 Why is this a BIG Deal?
2:28 Network Segmentation
3:00 Control Granularity
3:45 Zone Matrix
4:06 Zone and Policy Setup
5:39 Conclusion
#Networking #UniFi #ubiquiti #technology #tech #UniFiProtect
🎉 Referral Program: www.unifiedit.tech/referral
📺 Watch:
🔥 Backup your data with Backblaze (Affiliate): www.backblaze.com/cloud-backup.html#af9yeh
Timestamps:
---------------------------------------------------
0:00 Intro (ZBF)
0:57 What are Firewall Zones?
1:21 Unifi Builtin Zones
1:52 Why is this a BIG Deal?
2:28 Network Segmentation
3:00 Control Granularity
3:45 Zone Matrix
4:06 Zone and Policy Setup
5:39 Conclusion
#Networking #UniFi #ubiquiti #technology #tech #UniFiProtect
มุมมอง: 14 510
วีดีโอ
TOUR: MacStadium - A DC full of 🍎 Computers
มุมมอง 69K2 หลายเดือนก่อน
🍎 Deploy a Mac Cloud: (Not Sponsored): www.macstadium.com/ 🖥️ Download Orka: (Free macOS Virtualization): www.macstadium.com/orka-desktop 📐 Need Networking Engineering: (Hire Us): www.unifiedit.tech 🎉 Buy UniFi Gear: (Affiliate): store.ui.com/us/en/products/unas-pro?a_aid=UniFiedIT 👨🏻💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Persona...
Unboxing: UniFi UNAS Pro
มุมมอง 10K3 หลายเดือนก่อน
🎉 Buy UNAS: (Affiliate): store.ui.com/us/en/products/unas-pro?a_aid=UniFiedIT 👨🏻💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Personal & HomeLab: www.unifiedit.tech/consulting/unifi-consulting-home 🔗🔗 AFFILIATE LINKS 🔗🔗 🛜 Ubiquiti Store: store.ui.com/?a_aid=UniFiedIT 📡 StarLink: www.starlink.com/residential?referral=RC-916187-65417-22 C...
Starlink Mini: Unboxing & Setup (The Future is HERE!)
มุมมอง 11K4 หลายเดือนก่อน
🧑🏻💻 Hire Us: www.unifiedit.tech 🎉 Referral Program: www.unifiedit.tech/referral 🔥 Backup your data with Backblaze (Affiliate): www.backblaze.com/cloud-backup.html#af9yeh Timestamps: 0:00 Intro 0:49 Unboxing 1:53 Product Info 2:36 Starlink Aviation 4:10 Setup & Testing 5:58 Final Thoughts #Networking #UniFi #starlink #starlinkmini
25 GIGABIT 🤯 - Deploying and Testing UniFi EFG
มุมมอง 14K6 หลายเดือนก่อน
🎉 Buy EFG!!! (Affiliate): store.ui.com/?a_aid=UniFiedIT 👨🏻💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Personal & HomeLab: www.unifiedit.tech/consulting/unifi-consulting-home 🎥 SociallyU 📺 TH-cam: th-cam.com/channels/vWNq4fWhqimN_h7Z8lnYeA.html 🌎 Website: www.sociallyu.com 🔗🔗 AFFILIATE LINKS 🔗🔗 🛜 Ubiquiti Store: store.ui.com/?a_aid=Uni...
UniFi Network BEGINNERS Configuration Guide | 2024
มุมมอง 277K9 หลายเดือนก่อน
🎉 Buy UniFi Gear (Affiliate): store.ui.com/?a_aid=UniFiedIT 👨🏻💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Personal & HomeLab: www.unifiedit.tech/consulting/unifi-consulting-home 🔗🔗 AFFILIATE LINKS 🔗🔗 10 Gig SFP DAC Cables: - ⚫️ Black SFP Cable: amzn.to/3Jngpus - 🔵 Blue SFP Cable: amzn.to/3Q2GMJW - 🟣 Dark Blue /Purple SFP Cable (1.5M):...
Unboxing: HL-15 / The BEST NAS Case We Have Ever Seen!
มุมมอง 4.7Kปีที่แล้ว
Unboxing: HL-15 / The BEST NAS Case We Have Ever Seen!
UniFi VPN: Send all your network traffic over a VPN! - UniFi VPN Configuration
มุมมอง 10Kปีที่แล้ว
UniFi VPN: Send all your network traffic over a VPN! - UniFi VPN Configuration
🛩️ UniFi Network & Protect Upgrade at an Airport | Unified IT
มุมมอง 27Kปีที่แล้ว
🛩️ UniFi Network & Protect Upgrade at an Airport | Unified IT
UniFi Network Setup & Configuration Guide | 2023
มุมมอง 253Kปีที่แล้ว
UniFi Network Setup & Configuration Guide | 2023
Apple Business Essentials Walkthrough & Configuration Guide (2023)
มุมมอง 51Kปีที่แล้ว
Apple Business Essentials Walkthrough & Configuration Guide (2023)
⚡️Florida killed our UniFi G4 Pro Camera 😔
มุมมอง 2.5K2 ปีที่แล้ว
⚡️Florida killed our UniFi G4 Pro Camera 😔
UniFi Protect & Network Upgrade at School | Part Two | Unified IT
มุมมอง 34K2 ปีที่แล้ว
UniFi Protect & Network Upgrade at School | Part Two | Unified IT
UniFi Protect & Network Upgrade at School | Part One | Unified IT
มุมมอง 27K2 ปีที่แล้ว
UniFi Protect & Network Upgrade at School | Part One | Unified IT
UniFi Next Generation Security Gateway | Unboxing and Install
มุมมอง 21K2 ปีที่แล้ว
UniFi Next Generation Security Gateway | Unboxing and Install
Are you required to do the subscription? Can you add and manage devices without this option? Looking to manager devices for a small organization without a monthly fee.
Hello, thanks for the video. In the rules I try fo filter by domain names. For some domains, the filter doesn’t work, any idea?
Context?
this man has glasses
Thank you, extremely well explained
Can you activate your subscription in no services zone? Or do you have to pre-Subscribe before you enter no service zone?
I logged on to my Starlink App and went to support to ask this question. The Starlink Assistance’s answer is Yes.
I have a simple question, i have a kid, and I need to block all traffic to his PC except several domains and I cant get it to work. I have created 2 rules one allows selected domains and another blocks all traffic, I have arranged it in order, allow rule is above block rule, and it still don't work, what I'm missing here? its all done in one zone, external, and source is set as my child PC for both rules, and destination set as block any and allow selected domains?
I might have missed it… what was the name of the brand for the rails sold on Amazon?
This helped me so much Thank you
Hey, love the content. Do you have 'n video or instructions to setup advance QOS and queues on a UniF network? Keep up the great work
People should be aware that a lot of the features mentionedhere require Mosyle's Fuse subscription which is a higher tier plan. Such as the integration with an external IdP.
Great video. Second one should be about firewall rules for this setup. 🙂
So just to be clear.. If I want to use Mosyle my customers, or my company, will have to wipe all the customer MacBooks in order to enroll them? Show stopper..
No. You can either use open enroll or there‘s a way to add your Apple customer number or dealer number to your Apple business manager to enroll devices. But that‘s a function of Apple Push Notification Service, so you have it with all MDMs.
Good stuff thanks for making this video
Or u can just tick the box "isolate" and it does it for u
Excellent video! It would be helpful if you edited with a picture in picture of your talking head shot so we could spend more time orienting to the screen you are on. Your instructions are so clear I feel like I can take this VLAN configuration on myself!
Has anyone figured out how to change the default rule between to zones? e.g.: VPN to Internal is "Allow All" and there is no option to change that default rule to "Block All". The only way to make that happen is to create an additional rule, which results in a quite comic Block and Allow rule in the overview. Unfornately it also bypasses the overview matrix: it doesn't show "Block all", it shows "See policies". For me, it makes the overview matrix somewhat useless.
Master!
Love you Man! you made my day Simple yet most powerful starter 👍
10:42 So China is bad even with no precedent of breach or any known case of spying. Btw the NSA is trustworthy as shown by Mr. Snowden! 😅
I just saw this today on my unify network and installed it. As a newbie in networking, how do I set this up to “control” what apps or websites my young kids use?
I noticed that there isn't a way to limit a device network speed. I use to create a firewall for specific devices to limit their speed that uses the wired connection
Should be able to do this if you set those devices onto another network and then use the speed rules, I have this set up on my Guest network at work.
fix the dang loggin
Can I use .lan instead of .local? I get a multicast warning, and I also cant seem to visit it from my browser. Thanks for the great video though this has really helped :)
still trying to work out how to do something , allow only extremal traffic from a region ( The UK ) to a in internal IP , but still allow that IP allowed to get to any region .
Would you relocate the IoT network into a new zone or keep it inside 'Internal'. I wanted to get a clear picture of policies applied on IoT network with ZBF but I'm not sure if moving out of internal would break things.
FortiGate has Zone and it makes simply firewall policy.
Zone-Based firewall is a feature that the mainstream firewall manufactures have had for years. It's nice to see Ubiquiti has taken the Apple out of their firewall and started to get closer to what their high-end competitors have been doing for years.
This looks _so_ nice! Can't wait to get it on my UDMP! I've managed to get a decent set of firewall-rules for my VLANs thanks to your videos, but firewalls is not my thing. This makes firewalls so much more user-friendly!
Major firewall vendors have had this for years.
Isn't this the same as using aliases in other firewalls like OPNsense? Been looking for a way to upgrade from my 2.5GbE OPNsense firewall, to something that can do 10Gb IDS/IPS. Just saw Unifi has their Enterprise Gateway that does exactly this but if they are just now adding in something as simple as firewall aliases (Zones), they are way too far behind other firewalls still.
I could be mistaken, but as I understand it from working with other firewall brands zones are groups of interfaces. Doesn't really change anything if you only have two interfaces, but it can simplify things if you have multiple lan or wan interfaces.
Firewalling is the most fun part of networking... until you have to do it on a Ubiquity firewall. This is why all IT Pros are NOT using Unifi DM/DMP/Fortress to secure their network, although they might be using their switches and other hardware. We stick to true firewalls like Netgate, Fortigate, SonicWall, Watchguard, CheckPoint to just name a few. Edit: The fact that you still need to define policies to BLOCK traffic between networks or zones is a fundamental flaw in the way Unifi implement security. That behavior is the same as an L3 switch where you have it route traffic and where you need to add ACLs to prevent traffics between networks. A modern firewall blocks EVERTYHING from the get go, and you just need to open what you need. That is why it is inherently more secure then having to think to block everything and not forget anything.
Absolutely! We completely agree that Zero Trust is the gold standard for modern network security. Unifi is making strides to bring their existing user base closer to this approach, and it’s an encouraging step forward. While it’s true that Unifi’s solutions aren’t perfect, their market share suggests that many “IT Pros” are indeed using their products. They’re also providing upgrade paths and aligning more with industry standards, which is commendable. Additionally, when you create a new network in Unifi, you can specify which Zone it belongs to. For example, you can create a “block-by-default” zone, requiring manual traffic allowances, which aligns more closely with Zero Trust principles.
@@unified-it I was waiting for something more substantial from their part, but I might just buy one of their DMP and try it out 'again' ;)
@@Traumatree it seems to work great right up till you want to try using one of their L3 switches to route one of the VLANS.. then the vlan mysteriously disappears like Unifi doesn't manage it, you can't assign it to a zone and it is just lumped in with the 'external' zone. Then good luck figuring out how to allow traffic to it since it seems to ignore rules and break all of the port forwards unless I move the vlan back to the UDM to route ;)
I just updated to 9.x, but I dont see the ZBF options enabled on my UDM-Pro. anyone else having this issue ?
Do you have installed the new firmware version? It's not available at all versions at the moment.
@@renehoehle You need to install the new unifi OS as well, then go into the security and update to the zone based management
@@1stGruhn That was not my question :D i know that why i've said that he need the new firmware.
Whats really impressive that Ubiquiti listen to the Community and change things very quick and makes the product better and better.
They don't change the right thing though. Their way of doing firewalling is from the 2000-2010 era. We have moved away from that way of doing things and are now far ahead of this. They need to update the way they do security if they want to be taken seriously.
@@Traumatree The question is whats your goal and how big is your customers. I have some customers with UDM Pro which is working perfectly fine. When you have something that is really important and should be highly secure and you need a low of features then other solutions might be better.
@@Traumatree Genuine question, what's so outdated about Ubiquiti's firewalling systems? It's largely comparable to Meraki in my opinion
@@TomGibbs-z6m They way to doing rules is archaic. It looks more like a Layer-3 switch ACLs that you need to add everywhere to block traffic, instead of everything getting blocked by default - like every other firewall out there.
Best Unifi configuration Guide I've seen thus far!
Oh, this update seems awesome. I can't wait to tinker.
So it’s basically the same as in OpenWRT
I've been in the networking business for over 40 years, so I chuckled when he referred to the old days of networking. Having been around for a while, I'm in a good position to say that this is one of the best instructional videos I've ever watched -- on any subject. I'm considering covering my consumer-grade home network to UniFi and this will be something I refer to again and again. Thanks!
Curious as to why you set the DNS server at the individual network level rather than at the WAN level? Also, what's the advantage of going changing classes of IP addresses?
Great video! Very good lighting. Easy to understand. ❤
Should you use a management vlan for UniFi devices?
Default network is on vlan 1. I read it’s best practice to skip vlan 1
Hi sir I'm fan of your video can I ask question? if I don't have controller and I have unifi A6plus AP.. how I can open it ? it is okay to buy a poe adaptor with 24volts? I hope you Will reply thank you..
I'm still using the USG-8-XG still working great for a 1G WAN connection.
Great video, I have I full unifi network and have deployed one for my local Shrine. the one questions I have is how to block networks from getting to the web interface of the gateway.
I have att fiber, ubiqui get very high latency at times, speed test is good but my computer at times crawls along with 20 to 30 second delay. Any suggestions ???? Thanks
Seconds!?!? And not milliseconds?