- Видео 188
- Просмотров 601 370
777 or 404
США
Добавлен 29 ноя 2011
Network devices review/configurations for home lab/small business.
Synology Pi-hole Docker and VLANs (Ubiquiti UniFi / Macvlan)
Synology Pi-hole Docker and VLANs (Ubiquiti UniFi / Macvlan)
Просмотров: 245
Видео
Proxmox Pi-hole Container and VLANs (Ubiquiti UniFi / LXC )
Просмотров 1,1 тыс.18 часов назад
Proxmox Pi-hole Container and VLANs (Ubiquiti UniFi / LXC )
Ubiquiti UniFi Gateway - Device Identification (DPI/Device Fingerprint)
Просмотров 1 тыс.День назад
Ubiquiti UniFi Gateway - Device Identification (DPI/Device Fingerprint)
Ubiquiti UniFi Gateway - NetFlow (ipt_NETFLOW/pmacct)
Просмотров 960День назад
Ubiquiti UniFi Gateway - NetFlow (ipt_NETFLOW/pmacct)
HomeLab Migration from ESXi to Proxmox
Просмотров 803День назад
HomeLab Migration from ESXi to Proxmox
Ubiquiti UniFi Teleport VPN - Deep Dive
Просмотров 1,2 тыс.14 дней назад
Ubiquiti UniFi Teleport VPN - Deep Dive
Ubiquiti Mini Rack Stacking Kit UACC-Rack-Stacking-Kit
Просмотров 1 тыс.14 дней назад
Ubiquiti Mini Rack Stacking Kit UACC-Rack-Stacking-Kit
Ubiquiti UniFi Protect - Convert UNVR/UNVR Pro to NAS, and Why It Failed
Просмотров 3,6 тыс.21 день назад
Ubiquiti UniFi Protect - Convert UNVR/UNVR Pro to NAS, and Why It Failed
Ubiquiti UniFi Protect UNVR RJ45/SFP+ Speed Puzzles (UNVR Pro)
Просмотров 91421 день назад
Ubiquiti UniFi Protect UNVR RJ45/SFP Speed Puzzles (UNVR Pro)
Ubiquiti UniFi Site-To-Site IPsec VPN and OSPF
Просмотров 492Месяц назад
Ubiquiti UniFi Site-To-Site IPsec VPN and OSPF
Ubiquiti UniFi Gateway Dual WAN Failover - Android Ethernet Tethering, iPhone USB Tethering
Просмотров 1,4 тыс.Месяц назад
Ubiquiti UniFi Gateway Dual WAN Failover - Android Ethernet Tethering, iPhone USB Tethering
Ubiquiti UniFi Protect - ONVIF (Third-Party Cameras)
Просмотров 2,1 тыс.Месяц назад
Ubiquiti UniFi Protect - ONVIF (Third-Party Cameras)
Ubiquiti UniFi SD-WAN - Site Magic & OSPF
Просмотров 1,7 тыс.Месяц назад
Ubiquiti UniFi SD-WAN - Site Magic & OSPF
Ubiquiti UniFi Firewall Rule Action - Reject Vs. Drop (iptables, nmap)
Просмотров 806Месяц назад
Ubiquiti UniFi Firewall Rule Action - Reject Vs. Drop (iptables, nmap)
Ubiquiti UniFi AP - Packet Capture (802.11/Wireshark/tcpdump/sniffer)
Просмотров 1,6 тыс.2 месяца назад
Ubiquiti UniFi AP - Packet Capture (802.11/Wireshark/tcpdump/sniffer)
Ubiquiti UniFi Gateway - Distributed Load Balancing (iptables/mangle/routing)
Просмотров 6742 месяца назад
Ubiquiti UniFi Gateway - Distributed Load Balancing (iptables/mangle/routing)
Ubiquiti UniFi - Firewall Rule Vs. IP ACL Rule
Просмотров 9332 месяца назад
Ubiquiti UniFi - Firewall Rule Vs. IP ACL Rule
Ubiquiti UniFi Gateway - Masquerade NAT (NAT Overload / Global NAT Settings)
Просмотров 1,2 тыс.2 месяца назад
Ubiquiti UniFi Gateway - Masquerade NAT (NAT Overload / Global NAT Settings)
Ubiquiti UniFi Gateway - SNAT (Source NAT/1:1 NAT/1-to-1 NAT)
Просмотров 8843 месяца назад
Ubiquiti UniFi Gateway - SNAT (Source NAT/1:1 NAT/1-to-1 NAT)
Ubiquiti UniFi Gateway DNAT - Redirect Client DNS Request (NAT/Destination NAT)
Просмотров 1,4 тыс.3 месяца назад
Ubiquiti UniFi Gateway DNAT - Redirect Client DNS Request (NAT/Destination NAT)
Ubiquiti UniFi Gateway - DNAT and Port Forwarding (NAT/Destination NAT)
Просмотров 1,3 тыс.3 месяца назад
Ubiquiti UniFi Gateway - DNAT and Port Forwarding (NAT/Destination NAT)
Ubiquiti UniFi U7-Pro-Max - WiFi7 and Spectrum Analysis
Просмотров 2,7 тыс.3 месяца назад
Ubiquiti UniFi U7-Pro-Max - WiFi7 and Spectrum Analysis
Ubiquiti UniFi Vantage Point (UNVR Stacking / Shadow Mode High Availability)
Просмотров 5213 месяца назад
Ubiquiti UniFi Vantage Point (UNVR Stacking / Shadow Mode High Availability)
Ubiquiti UniFi Gateway - DNS Filter (Content Filtering/Ad Blocking/whitelist/blacklist)
Просмотров 1,9 тыс.3 месяца назад
Ubiquiti UniFi Gateway - DNS Filter (Content Filtering/Ad Blocking/whitelist/blacklist)
Ubiquiti UniFi Gateway - Block Client's Custom DNS Settings (DoH/DoT)
Просмотров 2,4 тыс.3 месяца назад
Ubiquiti UniFi Gateway - Block Client's Custom DNS Settings (DoH/DoT)
Ubiquiti UniFi VLAN - Isolate Network vs. Guest Network
Просмотров 2,8 тыс.4 месяца назад
Ubiquiti UniFi VLAN - Isolate Network vs. Guest Network
Ubiquiti UniFi Switch - IP ACL vs. MAC ACL
Просмотров 7904 месяца назад
Ubiquiti UniFi Switch - IP ACL vs. MAC ACL
Ubiquiti UniFi Firewall Rule - State (conntrack / New, Invalid, Established, Related)
Просмотров 1,8 тыс.4 месяца назад
Ubiquiti UniFi Firewall Rule - State (conntrack / New, Invalid, Established, Related)
Thank for this as I was waiting for this video! I do have a question though. I understand proxmox can create vms and also containers inside vms. But is it better to manage and create the containers using portainer instead? My original idea was to install proxmox on a NUC, run 2 vms (one windows for general use and Ubuntu Vm for my apps held in docker containers) and to manage these containers using portainer. Looks like in your video, you've done this all within proxmox. Is there an advantage or disadvantage over doing it all within promox? Or have portainer manage the docker containers instead? What do you suggest? P. S this will be my first time setting this kind of thing up. I am a network engineer, just haven't done sys admin in a while so want to be sure I'm doing whatever method is most efficient and simple to manage
I have not used portainer, but my understanding is proxmox is acting in the same role as portainer when it comes to managing containers. However, proxmox can do other things, such as running VMs. I am a homelabber, so an all-purpose platform such as proxmox meets my needs better.
@hz777 I see, I appreciate your perspective and insight. Thank you! I intend to use this for my home lab also, I just don't have a full on Dell server to run this on. Intend to run it on a little geekom nuc. Your videos are really helpful, keep up the great work!
Great video! Unifi + Proxmox is my favorite way to run things,. You can build powerful infrastructure for you home lab and/or business. As for the learning curve, with the little bit of effort and guys like you it's not as steep as it can be. Thank you!
Hi: I have a Stratum 1 NTP server running at 192.168.99.241 (static). If I set the UDMP NTP server address to .241, will it get the time from my local NTP server? I've had it set that way for over 3 months, but i don't truly know if it's working like i thought it was. Thank you.
It should.
Thank you!
Excellent, thank you :-)
Do you recommend MTP/MPO-8, 12 or 16 for 100GbE?
I don't have experience with these fibers, and I even doubt they work with my old lab 100 GbE switch.
Hi, how can i watch it host diagnostic C3 oled?
Is the workaround to set pihole to it's own separate vlan?
Why did you removed my comment?
Why did you think I removed your comment? I just checked the on-hold comment (by RUclips), but saw none.
@@hz777 well thats strange, I posted a comment . Bug in YT then I supposed. I tried now also again and again. it removes every time. maybe because there is a hyperlink inside the message..
Thanks for sending me the email. That explains why your comments were removed by RUclips: because of the paths. Url, IP address, and path may cause the comments to be removed by RUclips. Go back to the docker Hostname issue you described. As I know, unifi gateway gets the client's hostname during the DHCP process. For a docker, it may not have its hostname, so your dhclient approach makes sense. This is an interesting topic, so I may make a video about it!
@@CasaTropical I just did some testing, but did not observe similar issues as yours. I created several proxmox containers using debian 12 template. I gave them different hostnames. They were all correctly displayed wit the correct names in UniFi's client list. I also used Wireshark to see the DHCP requrests, and did see correct hostname info in the requests.
@@hz777 thank you for the time and for the response, indeed the containers will get hostnames, its about a docker inside that container . Case: debian 12 template as LXC in Proxmox. Then install docker on that debian, then in that docker place (example) a alpine python or a new debian. You'll will see no hostname in de UDM-P only the MAC. When you install the dhclient, and inside that .conf chage the name "hostname"it does. Again thanks for the great videos and time.
Thanks for such a great walk-through of your debugging and investigation process.
I wish you could add your own icons or submit VERY Popular products
yeah it has been around for the longest time (maybe from controller 4.x?) and i find it very gimmcky
thank you
Besides, after reboot, I see that commands in cli are lose, I already try "write memory" but still lose config after reboot.
Yes, that's expected. Ubiquiti never officially supports it.
Can reflector port#5 be used on normal traffic? Can I use the uplink port#1 as reflector port as well? Thanks
No and no.
Thank you! You helped me understand HoneyPot more. If i have (for example) 10 VLANs in UniFi, should i create 10 HoneyPot IPs? Thank you!
If the bad guys scan VLAN B from VLAN A, you do not need a Honeypot in VLAN A for VLAN B. Otherwise, you do.
@@hz777 so in my environment, I block (for example) Access to VLAN B, from VLAN A, and reverse. I believe this is where “otherwise” comes in, lol. There’s no inter-vlaning in the network, so that’s why I asked if all VLANs should have HoneyPot, but Insee your point and I thank you for your response.
@@buenologysorry it seems my original reply is not clear. if no inter-vlan, each VLAN may need its Honeypot if you have concerns there.
Thanks!
I am glad to have found your videos. Excellent work! I subscribed!!
Hey mate, thanks for this video. Did you see any performance impact?
So far I only use it in my lab environment, so no impact yet.
@@hz777 Thanks, what about IPv support ? And also L3 routing on the USW ?
IPV6? I don't use ipv6, so don't know. L3 switch's inter-vlan traffic doesn't go to gateway, so I don't think it's supported. @@FTLN
Awesome! Thank you for the explanation!👌
noticeable performance differences in your VMs with the same allocated resources?
Not yet.
Great video, thank you for sharing. Any chance the Apple TV Protect app improved after the 9 months of this video?
Just checked but did not notice anything. I don't think Ubiquiti has any incentives to improve it.
Hi there again. I'm trying to aggregate my USW Pro 24 PoE with the USW Pro Aggregation switch. For some reason when I try to complete the configuration on the Pro Agg. switch the USW Pro 24 PoE goes offline and the aggregation state is not enabled on the Agg Pro. Did you encounter anything similar or do you have any ideas how to prevent this? I am doing the configuration on the downstream switch first then on the Pro Agg. switch. I have a somewhat similar setup to yours where the pf sense device is the firewall and I have the Pro max 24 , the 24 Pro PoE and a 16 PoE Ubiquiti devices. Thanks.
If switch A is closer to router, and you work on switch B first, switch B is expected to be offline. I don't see a problem there. But after you finish switch A, switch B will be back. I don't understand why switch B going offline can impact switch A's configuration changes.
@@hz777 Well I don’t either I configure ports 25-26 on switch B (the USW Pro 24 PoE) first and you can see it takes the aggregation. Then I try to configure ports 6-7 on the other switch A and as soon as I hit “Apply”. the web page freezes and then when I access the cloud key again switch A (the Aggregation Pro switch) now shows no ports aggregated and switch B (the USW Pro 24 PoE) shows offline and I have to disconnect the aggregation port cables to it and restart to adopt it again. So the aggregation fails. I was talking with Ubiquiti tech support and went through the procedure with the tech (connecting only 1 cable while doing the process) and experienced the exact same symptoms. The only suggestion he had was to send him the support file and he would “get back to me”.
@@Kehf27 is usw pro's 25-26 connect to 6-7 of aggregation switch? One thing I don't follow is you said after configure 25-26, you could see usw pro takes the change. What did you mean? What you expect to see is usw pro going offline. If you can still see it online, something is wrong already.
@@hz777 yes 6-7 of the AGG Pro switch is connected to 25-26 of the USW Pro24 PoE Hmm I don’t actually see the Pro 24 going offline when I configure aggregation on it It just almost immediately shows aggregated.
Just an update for you. You have been extremely helpful in my journey thus far. I had multiple problems configuring LAGG with my hybrid pfsense/Unifi setup. Firstly, on the Unifi side I was trying to effect the aggregation on the switch ports that had the active connection to the cloud key controller. So I connected another cable (with the active connection) in parallel with the ports I was trying to aggregate then configured the most downstream switch ports in aggregate. I then configured the next upstream switches and so on. For the pfsense side I had a similar problem and the solution was similar. Additionally the ports on the pfsense device I was trying to aggregate included an existing LAN with associated VLANs already defined. With the help of the pfsense documentation I was able to migrate that LAN to a new LAGG and also transfer the existing VLANs to the new LAGG. This involved multiple steps and shuffling around and included having to effect the configuration from another LAN in parallel since the configuration steps caused me to lose communication with the cloud key controller and internet and the existing configuration on the pfsense device. I was able to complete this successfully however. Now I have a downlink of 30GB from the pfsense device to the Agg Pro switch and downstream links of 20GB between the other Pro Max switches. Thanks again for your excellent suggestions.
Hi, is the UDM (non pro) capable of SQM at 1 gigabit speeds? If not, do you know of a router which is relatively plug and play which can support this?
I don't own a non-pro udm, so don't know the answer.
Thank you! I truly appreciate you unpacking this... When I was looking into Content Filtering, my Android Ap states that both Work AND Family will block VPN. However, the Web GUI claims that Family filter will block VPNs. Can you demonstrate whether any of the filters will actually block a VPN ? Thanks again!
I checked the android app, but did not see content filtering setting at all... Where did you see it?
"Is it worth it? Of course, no." 🤣
Thanks bro
do u know how can we connect teleport using native wireguard client
I am afraid that will not be feasible. Even though the VPN itself is WireGurad, to initiate it (to make UniFi gateway connect to turn server) needs wifiman.
We run a few of these for conferences and AV set ups. Mostly pushing Dante and NDI. They work well.
It's already explained in the udm pro case. Teleportd does the magic.
Could you please explain how the teleport client communicates with the uxg-pro? I understand that uxg-pro uses WireGuard to connect to the STUN server, but I would like to know why the WireGuard peer is set to "endpoint:127.0.0.140813". Additionally, how the teleport client through STUN server to find out the uxg-pro?
Great idea. I advice make a profile on the mac networking settings.
Is 20 sites max with Site Magic?
As I checked last time, it's 15. But you know, it's not really a hard limit. It may change any time in the future.
@@hz777 in your video it stated 20 at the beginning when you did choose networks?
Maybe...idk...if you saw that, it's the correct limit at that time.
I really appreciate you making this video. One flaw I see is that you are referencing the client's received RSSI (how loud it hears the AP). But the RSSI limit is on the AP side, so it is the Unifi side where you need to monitor if the RSSI cutoff works. The RSSI level the AP hears from the iPad will never be the same as the RSSI level the iPad hears from the AP since these are received levels from 2 different radios. I would love to see this experiment repeated where the RSSI of the client is monitored from the AP, instead of the client.
I remember I used two devices to capture WiFi frames, one close to the roaming device, one close to the ap.
Another great video. Question for you...Have you been able to disable Ubiquity device discovery 10001 from constantly pinging the network?
I don't use Ubiquiti Device Discovery. Do you have UniFi network controller self hosted? I know it may use port 10001. If a packet is sent for a legitimate reason, I would not block it. If there are packets you are not sure where they came from, you may want to spend time to eliminate the source.
@@hz777 The issue is running a LAN scan and Ubiquity Device Discovery Service seems to publish all the Gateway IP's even though VLAN access blocks gateway crosstraffic. 🤔
I have not encountered such a thing so I don't know... In your case, were the packets from gateway's default network IP address to other VLANs? If so that's strange...
@@hz777 i will have to investigate further. The android app "ping tools" aggressively scans the network and it can find more than nmap. Thanks for the insight
Will iperf3 be gone once you have the unit reboot? Thanks.
No, if just after a reboot. But it won't survive an upgrade
Whoa I did not expect them to be this flexible. Great Video :)
Thanks for showing the clip of the jello rack. Holy janky. I feel like you have several real, full size racks. What then is this tower of wobble for?
My other racks cannot be moved. I need the wheels :)
Is there a script yet to get the system running after a firmware upgrade?
I believe there must be such a script on GitHub, but I have never searched for it.
hey, any idea if i can do something like this rspan to a vds ? ruclips.net/video/-VanRFpeUSI/видео.html
I know this sounds dumb, but I was looking for that deal you mentioned at the beginning of the video(camera with NVR purchase). It doesn't seem to be there anymore. Is it an occasional promotion?
You may need to login first.
@@hz777 Doesn't seem to have changed anything. Must be something else. Anyway thanks for the suggestion.
Another issue is that you're going to get different package versions (for say unifi os) between the two devices due to phasing. If you have to factory reset a device to be able to adopt it, why allow different versions after adoption? makes no sense
I recently encountered an issue while using Magic Site. When I enable Policy Routes, the remote transmission speed drops by more than half. However, as soon as I disable the Policy, the speed returns to normal. Have you experienced a similar issue?
I think what you are doing here is great and i want to encourage you to continue - Good Job!
disabling archiving for stacked nvrs is frustrating
thank you!!
Great to see you explore this non-intended usage for the UNVR. I have had 3x UNVRs running as 'NAS' since they came out. They key differences I do is A) systemctl stop/disable and apt remove all UBNT packages I don't need (unifi-protect unifi-core ulp-go ubnt-report unifi-pion-gw unifi-assets-unvr uid-agent analytic-report-go nginx node18 node20 nodejs python3-unifi-console-protos postgresql*) B) have a single service wich mounts your storage disk(s) partition(s), i.e. to /opt C) have a single service which executes your subsystem on your mounted partition(s) (not the usb-flash/emmc one) D) have as much software as possible, and all your NAS stored files/mounts, on your partition and not the system usb/emmc partition. I mainly use entware (github.com/Entware/Entware ) for that but I suppose there are other posibilities. E) In general, make sure you have scripts ready which can easily apply point A, B and C to the system partition; that is scripts to remove unneeded ubnt packages, service files and configurations for mounting your disk partition(s), service file which initiates your 'sub'start-system F) Before doing a UniFi OS software upgrade. 1) Shutdown the UNVR. 2) Eject all your drives. 3) Turn the UNVR on again. 4) Do the update. 4a) Optionally factory reset the UNVR. 5) If you factory reset the unvr, but also just in general, check and ensure that A, B and C are applied to the system partition (using your scripts). 6) Shutdown the UNVR. 7) Insert your disks. 8) Turn it on again (your 'sub'system should now be mounting and starting.
Wow! Thanks for sharing such detailed steps! Your way is much more aggressive and is to use the device solely as NAS.
great video, thanks for spending the time to do all the testing. Going to try to setup as an iscsi target as well - have a small home lab and currently running VMs on a synology over 1Gbe iscsi only so would be great to take advantage of the 10Gbe
Just a great video! Thank you very much. You really shared a valuable experience
Hello, I have UDM PRO MAX which has Built-in 128 GB SSD for NVR detection recordings, can I use this as NAS ?
I don't own a udm pro max, but assume it should be easy. Can you find the mount point for the SSD in /proc/mounts? If yes, simply use that mount point when configuring smbd. AGAIN, ABOVE IS JUST MY GUESS. TAKE YOUR OWN RISKS IF YOU WANT TO PROCEED.
@@hz777 Thanks, will give it a miss then :)