Unified IT
Unified IT
  • 43
  • 1 084 134
Zone-Based Firewall: The Best New Feature in UniFi 9.0
🧑🏻‍💻 Hire Us: www.unifiedit.tech
🎉 Referral Program: www.unifiedit.tech/referral
📺 Watch:
🔥 Backup your data with Backblaze (Affiliate): www.backblaze.com/cloud-backup.html#af9yeh
Timestamps:
---------------------------------------------------
0:00 Intro (ZBF)
0:57 What are Firewall Zones?
1:21 Unifi Builtin Zones
1:52 Why is this a BIG Deal?
2:28 Network Segmentation
3:00 Control Granularity
3:45 Zone Matrix
4:06 Zone and Policy Setup
5:39 Conclusion
#Networking #UniFi #ubiquiti #technology #tech #UniFiProtect
มุมมอง: 14 510

วีดีโอ

TOUR: MacStadium - A DC full of 🍎 Computers
มุมมอง 69K2 หลายเดือนก่อน
🍎 Deploy a Mac Cloud: (Not Sponsored): www.macstadium.com/ 🖥️ Download Orka: (Free macOS Virtualization): www.macstadium.com/orka-desktop 📐 Need Networking Engineering: (Hire Us): www.unifiedit.tech 🎉 Buy UniFi Gear: (Affiliate): store.ui.com/us/en/products/unas-pro?a_aid=UniFiedIT 👨🏻‍💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Persona...
Unboxing: UniFi UNAS Pro
มุมมอง 10K3 หลายเดือนก่อน
🎉 Buy UNAS: (Affiliate): store.ui.com/us/en/products/unas-pro?a_aid=UniFiedIT 👨🏻‍💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Personal & HomeLab: www.unifiedit.tech/consulting/unifi-consulting-home 🔗🔗 AFFILIATE LINKS 🔗🔗 🛜 Ubiquiti Store: store.ui.com/?a_aid=UniFiedIT 📡 StarLink: www.starlink.com/residential?referral=RC-916187-65417-22 C...
Starlink Mini: Unboxing & Setup (The Future is HERE!)
มุมมอง 11K4 หลายเดือนก่อน
🧑🏻‍💻 Hire Us: www.unifiedit.tech 🎉 Referral Program: www.unifiedit.tech/referral 🔥 Backup your data with Backblaze (Affiliate): www.backblaze.com/cloud-backup.html#af9yeh Timestamps: 0:00 Intro 0:49 Unboxing 1:53 Product Info 2:36 Starlink Aviation 4:10 Setup & Testing 5:58 Final Thoughts #Networking #UniFi #starlink #starlinkmini
25 GIGABIT 🤯 - Deploying and Testing UniFi EFG
มุมมอง 14K6 หลายเดือนก่อน
🎉 Buy EFG!!! (Affiliate): store.ui.com/?a_aid=UniFiedIT 👨🏻‍💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Personal & HomeLab: www.unifiedit.tech/consulting/unifi-consulting-home 🎥 SociallyU 📺 TH-cam: th-cam.com/channels/vWNq4fWhqimN_h7Z8lnYeA.html 🌎 Website: www.sociallyu.com 🔗🔗 AFFILIATE LINKS 🔗🔗 🛜 Ubiquiti Store: store.ui.com/?a_aid=Uni...
UniFi Network BEGINNERS Configuration Guide | 2024
มุมมอง 277K9 หลายเดือนก่อน
🎉 Buy UniFi Gear (Affiliate): store.ui.com/?a_aid=UniFiedIT 👨🏻‍💻 UniFi Consulting Pricing: 🏢 Business, Enterprise, & Government: www.unifiedit.tech/consulting/unifi 🏠 Personal & HomeLab: www.unifiedit.tech/consulting/unifi-consulting-home 🔗🔗 AFFILIATE LINKS 🔗🔗 10 Gig SFP DAC Cables: - ⚫️ Black SFP Cable: amzn.to/3Jngpus - 🔵 Blue SFP Cable: amzn.to/3Q2GMJW - 🟣 Dark Blue /Purple SFP Cable (1.5M):...
Unboxing: HL-15 / The BEST NAS Case We Have Ever Seen!
มุมมอง 4.7Kปีที่แล้ว
Unboxing: HL-15 / The BEST NAS Case We Have Ever Seen!
Unboxing: UniFi Express
มุมมอง 9Kปีที่แล้ว
Unboxing: UniFi Express
Mosyle: Our Favorite Apple MDM!
มุมมอง 16Kปีที่แล้ว
Mosyle: Our Favorite Apple MDM!
Unboxing: UniFi Cable Modem (UCI)
มุมมอง 130Kปีที่แล้ว
Unboxing: UniFi Cable Modem (UCI)
Visiting SpaceX StarBase | Unified IT
มุมมอง 797ปีที่แล้ว
Visiting SpaceX StarBase | Unified IT
UniFi VPN: Send all your network traffic over a VPN! - UniFi VPN Configuration
มุมมอง 10Kปีที่แล้ว
UniFi VPN: Send all your network traffic over a VPN! - UniFi VPN Configuration
🛩️ UniFi Network & Protect Upgrade at an Airport | Unified IT
มุมมอง 27Kปีที่แล้ว
🛩️ UniFi Network & Protect Upgrade at an Airport | Unified IT
UniFi Network Setup & Configuration Guide | 2023
มุมมอง 253Kปีที่แล้ว
UniFi Network Setup & Configuration Guide | 2023
Apple Business Essentials Walkthrough & Configuration Guide (2023)
มุมมอง 51Kปีที่แล้ว
Apple Business Essentials Walkthrough & Configuration Guide (2023)
⚡️Florida killed our UniFi G4 Pro Camera 😔
มุมมอง 2.5K2 ปีที่แล้ว
⚡️Florida killed our UniFi G4 Pro Camera 😔
UniFi Protect & Network Upgrade at School | Part Two | Unified IT
มุมมอง 34K2 ปีที่แล้ว
UniFi Protect & Network Upgrade at School | Part Two | Unified IT
UniFi Protect & Network Upgrade at School | Part One | Unified IT
มุมมอง 27K2 ปีที่แล้ว
UniFi Protect & Network Upgrade at School | Part One | Unified IT
Complete TrueNas Setup Guide (2022)
มุมมอง 13K2 ปีที่แล้ว
Complete TrueNas Setup Guide (2022)
UniFi Next Generation Security Gateway | Unboxing and Install
มุมมอง 21K2 ปีที่แล้ว
UniFi Next Generation Security Gateway | Unboxing and Install

ความคิดเห็น

  • @devinedwards9178
    @devinedwards9178 วันที่ผ่านมา

    Are you required to do the subscription? Can you add and manage devices without this option? Looking to manager devices for a small organization without a monthly fee.

  • @alexandrerj5980
    @alexandrerj5980 2 วันที่ผ่านมา

    Hello, thanks for the video. In the rules I try fo filter by domain names. For some domains, the filter doesn’t work, any idea?

  • @lordanubis5965
    @lordanubis5965 3 วันที่ผ่านมา

    Context?

  • @blackprincegt
    @blackprincegt 5 วันที่ผ่านมา

    this man has glasses

  • @HansPeterRuhl
    @HansPeterRuhl 7 วันที่ผ่านมา

    Thank you, extremely well explained

  • @billtcheng2316
    @billtcheng2316 9 วันที่ผ่านมา

    Can you activate your subscription in no services zone? Or do you have to pre-Subscribe before you enter no service zone?

    • @billtcheng2316
      @billtcheng2316 4 วันที่ผ่านมา

      I logged on to my Starlink App and went to support to ask this question. The Starlink Assistance’s answer is Yes.

  • @gediminasvenclova117
    @gediminasvenclova117 11 วันที่ผ่านมา

    I have a simple question, i have a kid, and I need to block all traffic to his PC except several domains and I cant get it to work. I have created 2 rules one allows selected domains and another blocks all traffic, I have arranged it in order, allow rule is above block rule, and it still don't work, what I'm missing here? its all done in one zone, external, and source is set as my child PC for both rules, and destination set as block any and allow selected domains?

  • @TheRealSydneyLi
    @TheRealSydneyLi 11 วันที่ผ่านมา

    I might have missed it… what was the name of the brand for the rails sold on Amazon?

  • @Cola_ZA
    @Cola_ZA 12 วันที่ผ่านมา

    This helped me so much Thank you

  • @borrisdieblokman
    @borrisdieblokman 14 วันที่ผ่านมา

    Hey, love the content. Do you have 'n video or instructions to setup advance QOS and queues on a UniF network? Keep up the great work

  • @JustaFan-ss2yy
    @JustaFan-ss2yy 16 วันที่ผ่านมา

    People should be aware that a lot of the features mentionedhere require Mosyle's Fuse subscription which is a higher tier plan. Such as the integration with an external IdP.

  • @xtr85
    @xtr85 16 วันที่ผ่านมา

    Great video. Second one should be about firewall rules for this setup. 🙂

  • @carlallen8894
    @carlallen8894 16 วันที่ผ่านมา

    So just to be clear.. If I want to use Mosyle my customers, or my company, will have to wipe all the customer MacBooks in order to enroll them? Show stopper..

    • @ekkehardendruweit7382
      @ekkehardendruweit7382 6 วันที่ผ่านมา

      No. You can either use open enroll or there‘s a way to add your Apple customer number or dealer number to your Apple business manager to enroll devices. But that‘s a function of Apple Push Notification Service, so you have it with all MDMs.

  • @nickl8830
    @nickl8830 17 วันที่ผ่านมา

    Good stuff thanks for making this video

  • @alefey3819
    @alefey3819 19 วันที่ผ่านมา

    Or u can just tick the box "isolate" and it does it for u

  • @sporter555
    @sporter555 20 วันที่ผ่านมา

    Excellent video! It would be helpful if you edited with a picture in picture of your talking head shot so we could spend more time orienting to the screen you are on. Your instructions are so clear I feel like I can take this VLAN configuration on myself!

  • @fredvanzet
    @fredvanzet 22 วันที่ผ่านมา

    Has anyone figured out how to change the default rule between to zones? e.g.: VPN to Internal is "Allow All" and there is no option to change that default rule to "Block All". The only way to make that happen is to create an additional rule, which results in a quite comic Block and Allow rule in the overview. Unfornately it also bypasses the overview matrix: it doesn't show "Block all", it shows "See policies". For me, it makes the overview matrix somewhat useless.

  • @dorianr5042
    @dorianr5042 23 วันที่ผ่านมา

    Master!

  • @jamalsarwar
    @jamalsarwar 24 วันที่ผ่านมา

    Love you Man! you made my day Simple yet most powerful starter 👍

  • @igorhenrique835
    @igorhenrique835 24 วันที่ผ่านมา

    10:42 So China is bad even with no precedent of breach or any known case of spying. Btw the NSA is trustworthy as shown by Mr. Snowden! 😅

  • @jimave
    @jimave 24 วันที่ผ่านมา

    I just saw this today on my unify network and installed it. As a newbie in networking, how do I set this up to “control” what apps or websites my young kids use?

  • @taniksambo1969
    @taniksambo1969 25 วันที่ผ่านมา

    I noticed that there isn't a way to limit a device network speed. I use to create a firewall for specific devices to limit their speed that uses the wired connection

    • @subsonicbass
      @subsonicbass 19 วันที่ผ่านมา

      Should be able to do this if you set those devices onto another network and then use the speed rules, I have this set up on my Guest network at work.

  • @TheRDB46
    @TheRDB46 25 วันที่ผ่านมา

    fix the dang loggin

  • @reqtified
    @reqtified 25 วันที่ผ่านมา

    Can I use .lan instead of .local? I get a multicast warning, and I also cant seem to visit it from my browser. Thanks for the great video though this has really helped :)

  • @peteradshead2383
    @peteradshead2383 25 วันที่ผ่านมา

    still trying to work out how to do something , allow only extremal traffic from a region ( The UK ) to a in internal IP , but still allow that IP allowed to get to any region .

  • @rajivvishwa
    @rajivvishwa 25 วันที่ผ่านมา

    Would you relocate the IoT network into a new zone or keep it inside 'Internal'. I wanted to get a clear picture of policies applied on IoT network with ZBF but I'm not sure if moving out of internal would break things.

  • @LVang152
    @LVang152 25 วันที่ผ่านมา

    FortiGate has Zone and it makes simply firewall policy.

  • @andrewenglish3810
    @andrewenglish3810 25 วันที่ผ่านมา

    Zone-Based firewall is a feature that the mainstream firewall manufactures have had for years. It's nice to see Ubiquiti has taken the Apple out of their firewall and started to get closer to what their high-end competitors have been doing for years.

  • @SnorreSelmer
    @SnorreSelmer 25 วันที่ผ่านมา

    This looks _so_ nice! Can't wait to get it on my UDMP! I've managed to get a decent set of firewall-rules for my VLANs thanks to your videos, but firewalls is not my thing. This makes firewalls so much more user-friendly!

  • @mtc-tech
    @mtc-tech 26 วันที่ผ่านมา

    Major firewall vendors have had this for years.

  • @ZombieLurker
    @ZombieLurker 26 วันที่ผ่านมา

    Isn't this the same as using aliases in other firewalls like OPNsense? Been looking for a way to upgrade from my 2.5GbE OPNsense firewall, to something that can do 10Gb IDS/IPS. Just saw Unifi has their Enterprise Gateway that does exactly this but if they are just now adding in something as simple as firewall aliases (Zones), they are way too far behind other firewalls still.

    • @RubberDuckDebugger
      @RubberDuckDebugger 25 วันที่ผ่านมา

      I could be mistaken, but as I understand it from working with other firewall brands zones are groups of interfaces. Doesn't really change anything if you only have two interfaces, but it can simplify things if you have multiple lan or wan interfaces.

  • @Traumatree
    @Traumatree 26 วันที่ผ่านมา

    Firewalling is the most fun part of networking... until you have to do it on a Ubiquity firewall. This is why all IT Pros are NOT using Unifi DM/DMP/Fortress to secure their network, although they might be using their switches and other hardware. We stick to true firewalls like Netgate, Fortigate, SonicWall, Watchguard, CheckPoint to just name a few. Edit: The fact that you still need to define policies to BLOCK traffic between networks or zones is a fundamental flaw in the way Unifi implement security. That behavior is the same as an L3 switch where you have it route traffic and where you need to add ACLs to prevent traffics between networks. A modern firewall blocks EVERTYHING from the get go, and you just need to open what you need. That is why it is inherently more secure then having to think to block everything and not forget anything.

    • @unified-it
      @unified-it 26 วันที่ผ่านมา

      Absolutely! We completely agree that Zero Trust is the gold standard for modern network security. Unifi is making strides to bring their existing user base closer to this approach, and it’s an encouraging step forward. While it’s true that Unifi’s solutions aren’t perfect, their market share suggests that many “IT Pros” are indeed using their products. They’re also providing upgrade paths and aligning more with industry standards, which is commendable. Additionally, when you create a new network in Unifi, you can specify which Zone it belongs to. For example, you can create a “block-by-default” zone, requiring manual traffic allowances, which aligns more closely with Zero Trust principles.

    • @Traumatree
      @Traumatree 26 วันที่ผ่านมา

      ​@@unified-it I was waiting for something more substantial from their part, but I might just buy one of their DMP and try it out 'again' ;)

    • @evenacona
      @evenacona 26 วันที่ผ่านมา

      @@Traumatree it seems to work great right up till you want to try using one of their L3 switches to route one of the VLANS.. then the vlan mysteriously disappears like Unifi doesn't manage it, you can't assign it to a zone and it is just lumped in with the 'external' zone. Then good luck figuring out how to allow traffic to it since it seems to ignore rules and break all of the port forwards unless I move the vlan back to the UDM to route ;)

  • @jasonklems8584
    @jasonklems8584 26 วันที่ผ่านมา

    I just updated to 9.x, but I dont see the ZBF options enabled on my UDM-Pro. anyone else having this issue ?

    • @renehoehle
      @renehoehle 26 วันที่ผ่านมา

      Do you have installed the new firmware version? It's not available at all versions at the moment.

    • @1stGruhn
      @1stGruhn 26 วันที่ผ่านมา

      @@renehoehle You need to install the new unifi OS as well, then go into the security and update to the zone based management

    • @renehoehle
      @renehoehle 26 วันที่ผ่านมา

      @@1stGruhn That was not my question :D i know that why i've said that he need the new firmware.

  • @renehoehle
    @renehoehle 26 วันที่ผ่านมา

    Whats really impressive that Ubiquiti listen to the Community and change things very quick and makes the product better and better.

    • @Traumatree
      @Traumatree 26 วันที่ผ่านมา

      They don't change the right thing though. Their way of doing firewalling is from the 2000-2010 era. We have moved away from that way of doing things and are now far ahead of this. They need to update the way they do security if they want to be taken seriously.

    • @renehoehle
      @renehoehle 26 วันที่ผ่านมา

      @@Traumatree The question is whats your goal and how big is your customers. I have some customers with UDM Pro which is working perfectly fine. When you have something that is really important and should be highly secure and you need a low of features then other solutions might be better.

    • @TomGibbs-z6m
      @TomGibbs-z6m 8 วันที่ผ่านมา

      @@Traumatree Genuine question, what's so outdated about Ubiquiti's firewalling systems? It's largely comparable to Meraki in my opinion

    • @Traumatree
      @Traumatree 8 วันที่ผ่านมา

      @@TomGibbs-z6m They way to doing rules is archaic. It looks more like a Layer-3 switch ACLs that you need to add everywhere to block traffic, instead of everything getting blocked by default - like every other firewall out there.

  • @RhubyT
    @RhubyT 26 วันที่ผ่านมา

    Best Unifi configuration Guide I've seen thus far!

  • @Nshelton5683
    @Nshelton5683 26 วันที่ผ่านมา

    Oh, this update seems awesome. I can't wait to tinker.

  • @borisov_dev
    @borisov_dev 26 วันที่ผ่านมา

    So it’s basically the same as in OpenWRT

  • @emmgeevideo
    @emmgeevideo 28 วันที่ผ่านมา

    I've been in the networking business for over 40 years, so I chuckled when he referred to the old days of networking. Having been around for a while, I'm in a good position to say that this is one of the best instructional videos I've ever watched -- on any subject. I'm considering covering my consumer-grade home network to UniFi and this will be something I refer to again and again. Thanks!

  • @MikeJones__Who
    @MikeJones__Who หลายเดือนก่อน

    Curious as to why you set the DNS server at the individual network level rather than at the WAN level? Also, what's the advantage of going changing classes of IP addresses?

  • @eaqrp
    @eaqrp หลายเดือนก่อน

    Great video! Very good lighting. Easy to understand. ❤

  • @BloodlyKill
    @BloodlyKill หลายเดือนก่อน

    Should you use a management vlan for UniFi devices?

  • @BloodlyKill
    @BloodlyKill หลายเดือนก่อน

    Default network is on vlan 1. I read it’s best practice to skip vlan 1

  • @kimharoldpilon8354
    @kimharoldpilon8354 หลายเดือนก่อน

    Hi sir I'm fan of your video can I ask question? if I don't have controller and I have unifi A6plus AP.. how I can open it ? it is okay to buy a poe adaptor with 24volts? I hope you Will reply thank you..

  • @Cooper3312000
    @Cooper3312000 หลายเดือนก่อน

    I'm still using the USG-8-XG still working great for a 1G WAN connection.

  • @jeffreyschlieve590
    @jeffreyschlieve590 หลายเดือนก่อน

    Great video, I have I full unifi network and have deployed one for my local Shrine. the one questions I have is how to block networks from getting to the web interface of the gateway.

  • @davidgrasscutter6545
    @davidgrasscutter6545 หลายเดือนก่อน

    I have att fiber, ubiqui get very high latency at times, speed test is good but my computer at times crawls along with 20 to 30 second delay. Any suggestions ???? Thanks

    • @robertt9342
      @robertt9342 หลายเดือนก่อน

      Seconds!?!? And not milliseconds?