My Full Unifi Network Setup - Firewall Rules, VLANs, WiFi, and more

แชร์
ฝัง
  • เผยแพร่เมื่อ 25 มิ.ย. 2024
  • My Unifi Affiliate Link - store.ui.com/us/en?a_aid=RaidOwl
    UDM Pro - store.ui.com/us/en/pro/catego...
    Enterprise 24 PoE - store.ui.com/us/en/pro/produc...
    Enterprise XG - store.ui.com/us/en/pro/produc...
    Enterprise 8 - store.ui.com/us/en/pro/produc...
    Flex XG - store.ui.com/us/en/pro/produc...
    Flex Mini - store.ui.com/us/en/pro/produc...
    IW HD - amzn.to/46L7MmG
    U6 Pro - store.ui.com/us/en/pro/catego...
    U6 Enterprise - store.ui.com/us/en/collection...
    U6 LR - store.ui.com/us/en/pro/catego...
    -------------------------------------------------------------------------------------------
    🛒 Amazon Shop - www.amazon.com/shop/raidowl
    👕 Merch - www.raidowlstore.com
    🔥 Check out today's best deals from Newegg: howl.me/clshD8fv8xj
    -------------------------------------------------------------------------------------------
    Join the Discord: / discord
    Become a Channel Member!
    / @raidowl
    Support the channel on:
    Patreon - / raidowl
    Discord - bit.ly/3J53xYs
    Paypal - bit.ly/3Fcrs5V
    My Hardware:
    Intel 13900k - amzn.to/3Z6CGSY
    Samsung 980 2TB - amzn.to/3myEa85
    Logitech G513 - amzn.to/3sPS6yv
    Logitech G703 - shop-links.co/cgVV8GQizYq
    WD Ultrastar 12TB - amzn.to/3EvOPXc
    My Studio Equipment:
    Sony FX3 - shop-links.co/cgVV8HHF3mX / amzn.to/3qq4Jxl
    Sony 24mm 1.4 GM -
    Tascam DR-40x Audio Recorder - shop-links.co/cgVV8G3Xt0e
    Rode NTG4+ Mic - amzn.to/3JuElLs
    Atmos NinjaV - amzn.to/3Hi0ue1
    Godox SL150 Light - amzn.to/3Es0Qg3
    links.hostowl.net/
    0:00 Intro
    1:11 Unifi hardware in my network
    5:20 Wifi UI
    7:26 WAN setup/failover
    8:45 Wifi Config
    10:35 VLANs and inter-vlan rules
    20:57 Firewall rules
    24:22 VPNs
    25:37 Conclusion
  • บันเทิง

ความคิดเห็น • 81

  • @DPCTechnology
    @DPCTechnology 4 หลายเดือนก่อน +5

    Thanks for the walk thru, grabbed a couple of nuggets...

  • @FatherJoeMcCorny
    @FatherJoeMcCorny 4 หลายเดือนก่อน +1

    Thank you once again mister Owl for the great video ❤. Have my inter-vlan rules now set up via firewall rules but this inspires me to try traffic rules instead.

  • @DavidMaciasPhoto
    @DavidMaciasPhoto 4 หลายเดือนก่อน

    Awesome Tutorial Brett.

  • @Mollernak
    @Mollernak 4 หลายเดือนก่อน

    Thank you so much, helped sort my inter-vlan rules, well at least for now

  • @tomtech1537
    @tomtech1537 10 วันที่ผ่านมา +1

    I've designed networks to handle 10's of thousands of machines, engineered external networks to deal with millions of concurrent users, written thousands of ACL's and stateful firewall rules, debugged incredibly complex asymmetric routing issues, reverse engineered router firmware to find ring buffer limits... ALL of this is FAR easier than the sore excuse for firewall management that exists in the UDM line.

  • @GrishTech
    @GrishTech 4 หลายเดือนก่อน +3

    The fitting word for unifi in an enterprise: Uniprise. Well said. That was not an error on your part. 😂

  • @alexk.9598
    @alexk.9598 7 วันที่ผ่านมา

    Awesome - thanks a lot for video. I'm a Unifi Newbee and this helped me a lot 👍👍

  • @kristopherleslie8343
    @kristopherleslie8343 4 หลายเดือนก่อน

    Excellent video buddy

  • @NightHawkATL
    @NightHawkATL 4 หลายเดือนก่อน +2

    Unifi has come a long way in just a few years. I had lots of issues trying to setup a few networks I was doing for clients but finally got them going. But I was trying to use the USG and they eventually crapped out with all the traffic. I couldn't justify the bigger gateways at the time with the cost of them.

  • @user-ww9lj5nm2v
    @user-ww9lj5nm2v 4 หลายเดือนก่อน

    Love your videos! I'm just learning more about networking and have heard your discontent regarding Unify Networks. I'm thinking about going with an Omada setup because I think I can get it to do what I want for about a third less than what I would spend on Unify. Is there no networking "Brand" out there that does what you want or is there such a cost disparity that you settle for Unify? Just curious!

  • @Bictor20
    @Bictor20 3 หลายเดือนก่อน +1

    Thank you for this nice overview of your network setup. I briefly saw that you have a Chromecast and I was wondering if you could elaborate on how you have it set up? I have my Chromecast on my IoT VLAN and I can't cast from my main network no matter what I try.

  • @Richard_GIS
    @Richard_GIS 4 หลายเดือนก่อน +1

    Loved it, thy

  • @FENATECH
    @FENATECH 3 หลายเดือนก่อน

    Thank you for your videos. I am new to Unifi and have been learning a lot from them.
    I have a couple of questions. In the video you mention that one section of security area I believe “Traffic Rules” is not specific in the order that they are created and that these rules are processed by Allows first then Blocks. However, “Firewall” Rules are processed in the specific order from top to bottom. Do I have that correct?
    Traffic rules are similar to Firewall rules but a more simplistic/generic approach? Not sure I understand the difference between them.
    Thank you again.

  • @jadan2000
    @jadan2000 26 วันที่ผ่านมา

    this was very interesting to see. can I ask what is in your main vlan? also if you have smart tvs, where would they be?

  • @nerd_fathersons5468
    @nerd_fathersons5468 4 หลายเดือนก่อน

    Get a USW Pro Aggregation and run the swiches from that, it have SFP28 for the 10G switch

  •  4 หลายเดือนก่อน +2

    Yessir! MF legend is back and just in time for my new UniFi setup.

  • @paulmoody1859
    @paulmoody1859 21 วันที่ผ่านมา

    Maybe down the road you could expound upon the steps you took to work through the ATT Fiber gateway and into the UDM Pro. I have the Arris BGW210-700 and it seems as though everyone has different steps to get a good signal to the UDM. It only has a pass-through capability but it would be great to hear how you did it. Thanks.

  • @LIKKLEbitCsale
    @LIKKLEbitCsale 3 หลายเดือนก่อน

    Hey Raid Owl I got a question for you: any tips or suggestions on how to get "Local DNS Record" working with IP address reservations for your self hosted services?

  • @CampRusso
    @CampRusso 4 หลายเดือนก่อน

    🤔 was there an update that change the main dashboard to not show the firewall image? I used to see the USG but now it's a PC image. 🤨

  • @JonathanTalksHW
    @JonathanTalksHW 4 หลายเดือนก่อน

    Nice

  • @babisral
    @babisral 4 หลายเดือนก่อน

    when I did my rules for my iot vlan I blocked trafic to and from all local networks, and then I made an allow rule for the ports and ips I need. Are there any downside from doing it that way? I only put a hue bridge, tv and surround on it so far. I also made an allow rule for the plex server hosted on another vlan.

  • @kc0eks
    @kc0eks 4 หลายเดือนก่อน

    Thank you for using a good mic and not having insane lip smack sounds like some other tech you tubers. Ruins their content.

  • @pwnz0riz0r
    @pwnz0riz0r 4 หลายเดือนก่อน

    If I'm converting from an Orbi router connected to two wired satellites, would I only need a Dream Machine and 2 APs?

  • @sku2007
    @sku2007 4 หลายเดือนก่อน

    I don't hard limit my guest network. But it has a very low QoS priority :D

  • @saeedahmad3748
    @saeedahmad3748 6 วันที่ผ่านมา

    I had AT&T fiber internet, looking at your diagram it goes direct to UTM pro without any router in-between, is it possible with UDM pro? please help me.

  • @RobertWelchman
    @RobertWelchman 4 หลายเดือนก่อน +2

    would love a follow up and more detail on the PI VPN setup...I didn't realize you could do that! Thanks!

    • @griffinsteffy
      @griffinsteffy 4 หลายเดือนก่อน

      Crosstalk has a video I believe

  • @lucasmonteiroi
    @lucasmonteiroi 4 หลายเดือนก่อน +1

    Awesome setup, it's possible to have a cheap Network devices for homelab? Unifi it's a little expensively

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน +1

      Check out my Omada Short Stack video

    • @enjibkk6850
      @enjibkk6850 4 หลายเดือนก่อน

      That's what I did, super happy so far

    • @BoraHorzaGobuchul
      @BoraHorzaGobuchul 18 วันที่ผ่านมา

      Omada.
      If not cheap enough, there's used.
      If not cheap enough, there's Chinese stuff, but it will be painful to manage and risks are somewhat higher depending on yourv paranoia re ccp/Chinese hackers

  • @kevinstevenson5787
    @kevinstevenson5787 28 วันที่ผ่านมา

    I cannot get into my dashboard any more... used to have a link, but that was deleted. I thought it used the router ip address, but that isnt wokring. I have 3 discs in my home network and cannot update them any more. Help!

  • @jehlybean636
    @jehlybean636 4 หลายเดือนก่อน

    No PPSK?

  • @corbynt
    @corbynt 4 หลายเดือนก่อน

    Are you able to get close to 10G inter-vlan routing from the UDMP? I was wondering if I'd need a layer 3 switch like the EnterpriseXG-24 for full 10G routing across vlans. Curious if you tested this maybe with/without IDS on if that is the bottleneck.

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน +1

      Much faster without ids. Saw around 6-7 which is enough for me.

    • @corbynt
      @corbynt 4 หลายเดือนก่อน

      @@RaidOwl I’ve never thought about running without IDS/IPS on. Is it that much of a risk or do you use other tools to do something similar?

  • @js1360
    @js1360 4 หลายเดือนก่อน

    have you considered star topology for switches ? and APs? connecting those to UDM instead of switch. One less single point of failure, routing would be optimal.

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน

      Yeah I’ve configured it a few different ways. This one is the flavor of the month lol

  • @misckicirina
    @misckicirina 4 หลายเดือนก่อน

    Can I ask what made you switch from a pfsense gateway to Unifi DM Pro?

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน +3

      I had the unifi switches and APs so I wanted to see what the whole ecosystem was all about.

  • @subsonicbass
    @subsonicbass 4 หลายเดือนก่อน

    Any chance you could do a video on WireGuard set up in Unifi? Tried a few times to get it set up and while I can hit my UDM Pro, I get no internet access from the inside 😢

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน

      Might be able to help you out in the Discord. Link in the video description.

  • @larsa.andersen8255
    @larsa.andersen8255 4 หลายเดือนก่อน

    Can you please comment on the noise level of the XG-24? I have an US-16-XG that is a little bit to loud to have in the room next to my bedroom but I can't find any comment on the noise level of the XG-24 so your input will be greatly appreciated.

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน

      It’s extremely quiet. No shot you hear it a room over.

  • @domadox
    @domadox 4 หลายเดือนก่อน

    I wonder whats your total power consumption for this setup? Do you have numbers?

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน +2

      Just for the networking? I don’t. I’ll have to dig down in there

  • @ayden8901
    @ayden8901 4 หลายเดือนก่อน

    So i take it u like Unifi now? I remember ur video trying it out coming from open or pfsense and u didnt seem to like unifi all that much :)

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน

      I never disliked 'Unifi' I just don't particularly like how they approach firewall rules. Everything else has been great.

  • @cdoublejj
    @cdoublejj 2 หลายเดือนก่อน

    surley distributed falls back to failover if one isp dies it would be pretty dumb if it just stopped routing when one goes down

    • @RaidOwl
      @RaidOwl  2 หลายเดือนก่อน

      Maybe 🤷🏻‍♂️

  • @JasonsLabVideos
    @JasonsLabVideos 4 หลายเดือนก่อน +1

    Don't tell ANYONE but I have a UDM Pro in my rack ATM ! :O

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน +1

      I can’t believe it

    • @JasonsLabVideos
      @JasonsLabVideos 4 หลายเดือนก่อน

      I LIKE IT !!@@RaidOwl

  • @bentheguru4986
    @bentheguru4986 4 หลายเดือนก่อน +1

    Idea on Inter-VLAN is not fully correct. You have Gen-2 switches that are L2/L3, I will let you figure out the rest.
    Your network ports, if you don't set the VLAN's on the port, they are trunk and your devices are exposed to ALL VLAN's on your network.
    Gateway monitoring works loosely. If you have a UXG, be prepared for fustration as you need to reboot the turds every few days as they stop recording/reporting.
    WAN DNS is just that, WAN side, so I am guessing you have possibly double NAT and a PITurd infront? If you want DNS done for your network, do it in the NETWORKS. WAN side doesn't sneak back inside the network for WAN DNS. More on this shortly.
    DHCP snooping on UniFi is known for being resource hungry. Turn ON Flow Control.
    I did see that your "external" network is possibly open, now refer to my second line comment. Your switch ports are open and exposed.... I'm out of here.

  • @romayojr
    @romayojr 4 หลายเดือนก่อน +10

    all of us to unifi:
    23:49

  • @shephusted2714
    @shephusted2714 4 หลายเดือนก่อน +6

    ubiquiti is not really ready for ent deployments due to poor ipv6 support - try it yourself and see how terrible it is

    • @maxbroomfield5392
      @maxbroomfield5392 4 หลายเดือนก่อน +2

      At least the routing. UniFi routing is horrible. Their switching and AP’s are pretty good.

    • @wodn184fn8
      @wodn184fn8 4 หลายเดือนก่อน +1

      only 1% uses ipv6. Routing, yes its not their best thing, but at least they give you the easy options of sd wan and shadow mode which works perfect.

    • @mr_DIY
      @mr_DIY 3 หลายเดือนก่อน

      And who is doing it right?

    • @antoniobowden4849
      @antoniobowden4849 หลายเดือนก่อน +2

      Who tf cares about ipv6

    • @mr_DIY
      @mr_DIY หลายเดือนก่อน

      those where spec say ipv6 only?

  • @headlibrarian1996
    @headlibrarian1996 24 วันที่ผ่านมา

    Unifi routes VLAN traffic through the UDMP? That's nuts, inter-client traffic such as workstationNAS that doesn't go to the Internet should never hit your UDMP, it should be routed in the switch.

    • @RaidOwl
      @RaidOwl  24 วันที่ผ่านมา

      Next Unifi Network update will make you happy ;)

    • @headlibrarian1996
      @headlibrarian1996 24 วันที่ผ่านมา

      @@RaidOwl Oh? Do tell.

  •  4 หลายเดือนก่อน

    abou wifi...than U see me that I give password almost to everyone...xd

  • @LiLBitsDK
    @LiLBitsDK 4 หลายเดือนก่อน

    makes no sense that the 8port would have to go all the way back to the dreammachine and then down the tree again? if that network worked correct it would go up 1 step and then down 1 step the other side of the tree and be done...

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน

      Unifis implementation of L3 switches isn’t as intuitive as you’d think. You CAN have the switch perform inter vlan routing but not with actual firewall rules so it’s not very useful.

    • @LiLBitsDK
      @LiLBitsDK 4 หลายเดือนก่อน

      @@RaidOwl that's an insane amount of wasted network traffic that is not needed... mindblown...

  • @jorisdevaan6845
    @jorisdevaan6845 4 หลายเดือนก่อน

    OCD instantly kicks in when I see 4 switches connected to each other in a chain :) I would never set my network up like this, so many points of potential failure.

  • @YHK_YT
    @YHK_YT 4 หลายเดือนก่อน

    Unify the subscribe button with the bell, the like button as the best man while commenting is the ring man !!11

  • @PowerUsr1
    @PowerUsr1 4 หลายเดือนก่อน +2

    Writing those firewall rules is ASS

    • @tomtech1537
      @tomtech1537 10 วันที่ผ่านมา

      Forgot how bad they are and just redid my network with unifi...
      Redoing firewall rules now and I have incredible amounts of regret...

  • @rileysalm3108
    @rileysalm3108 3 หลายเดือนก่อน

    Please stop using vlan 1 it hurts to see

    • @RaidOwl
      @RaidOwl  3 หลายเดือนก่อน +3

      No

    • @tomtech1537
      @tomtech1537 10 วันที่ผ่านมา

      Less painful than trying to coerce a unifi network into not using it.

  • @dimitristsoutsouras2712
    @dimitristsoutsouras2712 4 หลายเดือนก่อน

    Too much radiation in your house. Are you living in a factory size space? Have you ever measured this radiation or you re kind of live fast -> die young-> stay pretty type of guy?

    • @RaidOwl
      @RaidOwl  4 หลายเดือนก่อน

      You think I’m pretty??? 😍😍

    • @dimitristsoutsouras2712
      @dimitristsoutsouras2712 4 หลายเดือนก่อน

      @@RaidOwl hahahah its a rephrase of Jim Morrison's punch line.

    • @BoraHorzaGobuchul
      @BoraHorzaGobuchul 18 วันที่ผ่านมา

      Oh my. The radiation. Saul Goodman's brother, aintchya?