UDM Pro - Beginners Guide to Securing VLANs

Поделиться
HTML-код
  • Опубликовано: 3 фев 2025

Комментарии • 96

  • @christopherhoovermd-urolog9602
    @christopherhoovermd-urolog9602 Месяц назад

    Though this was posted a year ago, it's SO helpful. In addition to some VLAN theory and the actual practical walkthrough of setup, I'll add something I found particularly helpful: occasionally (and this really is NOT meant to be a criticism) you don't click on the right thing or like when you pushed enter instead of "Add" and had to go back in there -- this is EXACTLY what the experience will be for the rest of us, and seeing how you navigate those times is incredibly helpful. Or like when the AppleTV wouldn't cooperate -- we all will have to reboot stuff to get it to work. Thanks for this!

    • @ethernetblueprint
      @ethernetblueprint  Месяц назад

      You are welcome... Just do you know, I have done a refresh of this video a couple times. This was my oldest one and my first attempt. Thanks for your kind words. I haven't watched this one in a while and assume that it was pretty rough. Check my my playlists Unifi for Newbies. I redid it there and its on a newer version of code too. Thanks again!

  • @nikschlein9239
    @nikschlein9239 Год назад +2

    Just wanted to say thanks. This video really helped me. I've been struggling with implementing this. I understand all the benefits and reasons why VLAN'ing was important, but no other video I watched answered my questions like this one did.

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      Awesome... I did redo this video very recently using the new version of UDM so if there are any questions, maybe that new video may help... Its called "New to UNIFI VLANS, START HERE!!!" Glad this one helped though... I enjoyed making it!

  • @jeremybentham04
    @jeremybentham04 Год назад +3

    Really great, informative guide. I've seen other vids that basically show the same setup and so I already had most of this already configured. But the detail and explanation you give for everything is very helpful.

  • @Hechts
    @Hechts 11 месяцев назад +1

    This was super helpful. Thanks for taking the time to do this!

    • @ethernetblueprint
      @ethernetblueprint  11 месяцев назад +1

      So glad it helped. I do have a new version of the video as well called “Let’s make some VLANs”. It’s made with the newer interface changes.

  • @jrabbott34
    @jrabbott34 Год назад

    Great breakdown sir! Currently switching over from a TP-LINK Omada stack to Ubiquiti and really needed some thought behind it. I like the firewall features and index better than the Omada lines.

    • @ethernetblueprint
      @ethernetblueprint  Год назад +1

      Thanks. I’ll have an updated version using the newest OS version here very soon. Check back!!

    • @TheHipstersUnited
      @TheHipstersUnited Год назад

      @@ethernetblueprint That's great news looking forward to your updated video...any idea on when it's coming out? A week? two? I will hold off setting up my firewall rules until that video :)

  • @sacundai5371
    @sacundai5371 9 месяцев назад

    Awesome setup.. loved the Unifi lesson! 🧐

    • @ethernetblueprint
      @ethernetblueprint  9 месяцев назад

      Glad to hear it! I have also redone this video using the newer version of UniFi. It’s called “Let’s make some VLANs” if you wanted to check that out too.

  • @NicolasP1973
    @NicolasP1973 Год назад

    Great Video, thanks for helping seting up my VLan and Firewall for house and Iot. This video is still relevand for network 8.0.7 with very minoir tweaks.

    • @ethernetblueprint
      @ethernetblueprint  Год назад +1

      Thanks. I’m going to be redoing it using version 8 very soon.

  • @IT-Lord
    @IT-Lord Год назад

    Wonderful Video that helped me to establish a secure network. Exactly what I was looking for. Thank you so much :)

  • @micklockhart2673
    @micklockhart2673 Год назад

    Awesome video and perfect for my setup and the kids! Thanks very much :)

  • @iang8087
    @iang8087 Год назад

    WOW! very helpful and well done.

  • @gpchess2k
    @gpchess2k Год назад

    Great simple video! You should definitely mention your setup is totally acceptable for small business not just homes. Wider audience 😁. I had a thought as well: what if you shared a backup file of your config? Need to see if it's a safe idea of course.

  • @benwebster5117
    @benwebster5117 Год назад

    Very helpful, thank you!

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      Glad it was helpful! Just so you know, I updated and rerecorded this video very recently. Maybe check it out.

  • @abdullahtiry6394
    @abdullahtiry6394 7 месяцев назад

    Awesome video, tanx

    • @ethernetblueprint
      @ethernetblueprint  7 месяцев назад +1

      Just so you know I have an updated version of this video called “Let’s make some VLANs” on my page that uses the newer interface of UniFi. Less long and more to the point as well.

  • @Polkster13
    @Polkster13 Год назад

    Willie Howe and PowerCert Animations are two other really great channels.

  • @FamilyHatch6
    @FamilyHatch6 11 месяцев назад

    Great guide that made it easy for me to set up my firewall rules. I did have a question about the ports that you selected for the UDM Pro Access Ports "Port Group". You threw out some numbers but it was not clear what those numbers correlated to. I have a UDR and a mini flex switch that both have a port 1. How do I differentiate between the two?

    • @ethernetblueprint
      @ethernetblueprint  11 месяцев назад

      If you are talking about in the port mapping area, there is a dropdown selection on the top-left that you can select which device you’re looking at. Both should be listed in there.

  • @RJ-ul8jw
    @RJ-ul8jw 7 месяцев назад

    This is a great video. My question is, if I'm only interested in six wired devices now (cameras, doorbell and chime, AP, and IOT device), can I buy a Dream Machine SE and expand to a switch later when I need more ports? Thanks

    • @ethernetblueprint
      @ethernetblueprint  7 месяцев назад +1

      Yes you can. Just make sure that whatever you plug in, meets the power requirements of the SE. There are 6 standard POE ports and 2 POE+ ports. By the look of your list, should be just fine. Your AP may require one of the POE+ ports though.

  • @Polkster13
    @Polkster13 Год назад +1

    Very good video with good explanations. Your sound was a bit rough in stat your arm kept brushing against your microphone (making a scratching sound) and blocking the sound which made the volume drop.
    One additional rule that I would add is a "Drop Invalid State" rule after the "Established and Related" rule.

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      I was so bummed about the sound quality. I went and got a new set of earbuds after that. Hopefully that was the last bad sound quality video I’ll do

  • @Frances-777
    @Frances-777 5 месяцев назад

    Thank you 🙏🏽

    • @ethernetblueprint
      @ethernetblueprint  5 месяцев назад

      You are so welcome. Just so you know, I have redone my firewall setup content. This video is outdated now... Check out my channel for more updated FW config how tos...

  • @Kixbox78
    @Kixbox78 10 месяцев назад

    excellent video - thank you

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад +1

      Thank you for the Feedback. I did create a more updated version called "lets make some VLANs" that has the updated network app if you get stuck...

    • @Kixbox78
      @Kixbox78 10 месяцев назад

      @@ethernetblueprint that is good to know, I will go and check it out. I have one small question re: Allow Rule #3. What is the best approach to exclude all VLANs from the 'Default' one which I'd like to dedicate to myself for administration. Using your examples, how can I exclude Kids VLAN from getting to Default VLAN - is this a silly question?

    • @Kixbox78
      @Kixbox78 10 месяцев назад

      @@ethernetblueprint I just checked out th new video, wow - thank you again.

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      Did you get your question answered in the video or is that still lingering?

    • @Kixbox78
      @Kixbox78 10 месяцев назад

      @@ethernetblueprint fully answered, thank you. It’s that camera example that cleared it up for me. Keep up the good work and much success for you.

  • @rodrazvan9656
    @rodrazvan9656 Год назад

    Thank you for this great video; it is very clear and easy to understand. A question..... How about the ubiquiti own camera like G5, for example? Do we need a VLAN and firewall specific for them? What if someone unplugs the camera from outside and gets into the network? Thank you

    • @ethernetblueprint
      @ethernetblueprint  Год назад +1

      I typically put the cameras on their own network for that very reason.

  • @samer229
    @samer229 10 месяцев назад

    This is awesome. Thank you. What I dont understand though is how to secure the actual switch ports. I get how all the networks are isolated and how they talk to each other. But say have a hard wired pc connected on the default network to port 4 of my switch - what's to stop someone simply taking the cable out and plugging into port 4 and getting access to the default network? That's the missing part for me. I would like, in addition to the wifi - to limit someone simply plugging into a configured ethernet port and gaining access to a trusted network. Help?

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      My most recent video is 100% based on switch port security. If you still have questions, let me know.

  • @Mr6D9
    @Mr6D9 Год назад +1

    15:30... How can you Ping the computer but the computer can't ping you back? ICMP works both ways?

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      If one VLAN allows for established traffic and the other doesn’t, then it would work one way but not the other. The FW will allow the traffic from the established VLAN. (Hope that makes sense)

    • @Mr6D9
      @Mr6D9 Год назад

      Exactly. So you'll be able to Ping the other computer but you won't know if your packet got sent to the other computer so it would look like the packet wasn't ever sent but it was. That's not what he shows in the video. the packet is able to go the other second computer and come back to his computer. Which breaks the FW rule@@ethernetblueprint

  • @EricWieber-mi9yj
    @EricWieber-mi9yj Год назад

    Amazing Videos. I have a question for you. How do I protect my access Points in Unifi controllers?

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      Are you wanting to restrict access to them? What exactly are you wanting to do? You could always put them in their own VLAN and lock them down however you like. You just need to update their Native VLAN so that is where they pull their IP from... But, I am not sure if that is what you are asking...

    • @EricWieber-mi9yj
      @EricWieber-mi9yj 10 месяцев назад

      @@ethernetblueprint I really appreciate your reply. My AP has been hijacked several times. I can ensure that I created different Username & strong Passwords. I followed your amazing tutorial but not sure if I did it correctly. I used the sample of the IOT setup but maybe I logged it up too much. I also changed Vlan settings from "All" to "Custom" . Would you have a suggestions as to what be a better setup?

  • @jhermans7297
    @jhermans7297 8 месяцев назад

    Thanks for this video. I didnt manage to follow. Maybe due to new version Network 8.1.127 ? Some differences.

    • @ethernetblueprint
      @ethernetblueprint  8 месяцев назад +1

      I have redone the video on using the newer 8 version. It’s called “Let’s make some VLANs”. Check that one out. It’s better and less talkie-talkie too.

  • @jfair1962
    @jfair1962 Год назад

    Thank you for the informative video. One question on SONOS, I have my Amazon Alexa devices on the IOT network. If I put the SONOS speakers on the Default network and we have blocked traffic out from the IOT Network. Alexa will no longer be able to work with the speakers? Would I need to open ports to the default to allow Alexa access to the SONOS speakers on the default network?

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      That is a good point. You may need to play around with that feature to see if you could make that work with VLANs. Like I said. Double edge sword.

  • @carlo_thewhatt
    @carlo_thewhatt 11 месяцев назад

    Hi,great video,very clear.But i have some questions,why you don't block kids from access to router,or to guest network?i understand that with your config you can ping from kids to guest,and from kids to gateway.you also can only allow kids to some of iot devices,not all of them.thanks and waiting for the new video❤

    • @ethernetblueprint
      @ethernetblueprint  11 месяцев назад

      All fair points. Your specific situation should dictate the rules that are created. These are just examples. I did redo this video on the newer version of OS in hopes that it helps know the ins and outs of making FW rules. The new video is called Let’s Make Some VLANs.

  • @phillipwithers7520
    @phillipwithers7520 5 месяцев назад

    Hey Tim, have you found any workable way to allow Sonos on an IOT VLAN or do you still recommend keeping it on the default for UDMP?

    • @ethernetblueprint
      @ethernetblueprint  5 месяцев назад

      Not really. Sonos doesn't play well with more complex networks. Sorry.

  • @TheHipstersUnited
    @TheHipstersUnited Год назад

    What VLAN do you suggest putting your synology NAS in this setup IOT or Default? If I want it to talk to IOT devices like an amazon firestick or nvidia shield as a plex server. Thank you! Video was excellent! I subscribed

    • @ethernetblueprint
      @ethernetblueprint  Год назад +1

      I personally put mine in my default and create rules for IOT devices. However, I will say I don’t use plex. It may be better for you to put it in the IOT and then makes sure you can access it from different devices on the default network. I think the overall function of the Synology and the number of rules you need to make dictates where you place it.

  • @bygco
    @bygco Год назад

    Great vidéo! Crystal clear!
    However, I hava a problem.
    My goal is to create a CCTV VLAN network.
    First, I create this VLAN and before creating the firewall rules, I want to check that all the traffic is authorized.
    I can ping a device from LAN to VLAN,but I cannot ping a device from VLAN to LAN.
    I thought that by default everything was authorized.
    What do you think?

  • @alfadat
    @alfadat 10 месяцев назад

    Is Unifi good enough for the company environment?

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      I replied to the other comment... but yes, you can use Unifi in business. Although, I do think there is a size limit as to where it doesn't make sense anymore. I typically see it used in small to medium sized businesses....

  • @phillipwithers7520
    @phillipwithers7520 10 месяцев назад

    It would seem that the predefined rules (I'm using Network Version 8.1.113) already account for the rule sets you define/create in the video. Is this the result of the version updates since your video or am I missing something fundamental?

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      Predefined rules? Maybe I don't understand, but there aren't any intervlan rules set by default. Am I not understanding maybe?

    • @phillipwithers7520
      @phillipwithers7520 10 месяцев назад

      @@ethernetblueprintCertainly between the two of us, it would be me that doesn't understand; however, when I look at the predefined runs that have the 'lock' icon in front of them that are created dynamically on the fly when network or wifi configurations are done or updated, there they are. Wish I could upload a screenshot of them to alleviate any misunderstanding but they appear under the traffic and firewall rules of security.

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      Tell you what, why don't you email me at tim@ethernetblueprint.com and I will see if I can help you. Please send screenshots...

    • @phillipwithers7520
      @phillipwithers7520 10 месяцев назад

      @@ethernetblueprint I certainly appreciate the offer, but I've been working with Unifi support to unsnarl a few other things and have resolved it issue(s) including seeing the correct firewall configs. Thanks for your amazingly simplified lessons - they were (are) helpful.

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      Awesome. I am glad to hear this... and with Unifi support no less. That is reassuring that they are taking support more seriously now. That hasn't always been the case!

  • @tomsedragon
    @tomsedragon Год назад

    great video thanks!!, you should do something about your mic though. when you speak a little loud, which happens quite often, your voice distorts and clicks are heard, and sometimes when you speak too low it sounds like you're speaking into a can (mostly happens in part 1) - plenty of thins has been updated in version 8.0 - time for a new vid? :-)

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      I will do that. Sorry for the distraction. I will be redoing this video in my new series I am recording right now... I hope you'll tune in.

    • @tomsedragon
      @tomsedragon Год назад

      @@ethernetblueprint thank you, I will :-) (I too have created vids with bad sound, believing everything was in good order) - I can also recommend you look at open broadcast studio which doesn't limit your recording time (I believe you mentioned that in part 1?)

  • @adampozek
    @adampozek 11 месяцев назад

    What happens if I use my phone to control IoT devices remotely? For example, using Apple Home. If I am on vacation and need to remotely unlock my front door, would these firewall rules prevent me from doing so?

    • @ethernetblueprint
      @ethernetblueprint  11 месяцев назад

      I answered this on the other video too, but wanted to answer here too. To answer your question about HomeKit, yes you can still control things when you’re away from home even if the devices are on the IOT network. I don’t have a ton of experience with this yet, but I’m in the process of setting up Home Assistant with Apple HomeKit and will have to do more testing. So far I have Phillips Hue lights hub on my IOT network running in HomeKit and it works great remotely using these exact firewall rules. More to come though

  • @treloarw
    @treloarw 10 месяцев назад

    having a very confusing problem that contradicts your statement regarding "all vlan's can talk to each other by default". Mine cannot. Followed part 1 of this series and for some reason I am unable to access other devices on other vlan's from my pc on the default network.

    • @ethernetblueprint
      @ethernetblueprint  10 месяцев назад

      I am sorry for your troubles. I would need to know a little more about your setup and would be happy to try and help offline if you like. Send me an email to tim@ethernetblueprint.com and we can dive in a little easier.

  • @jeremybentham04
    @jeremybentham04 Год назад

    I'm not sure why but in my configuration (which seems to be nearly identical to the one in the vid), even without the "block x-vlan-x to router" rule, I still can't reach the console login on any vlan except the default. Which is how it should be but in the vid, you were able to do so prior to adding the rule. Am I missing something? I know these vids were done about 9mos ago so maybe the software is updated but I doubt it would change something fundamental like that.

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      Sorry for your issues. Typically you can access the console from other VLANs by default. However it is done by typing the gateway of each of the particular VLAN. (VLAN 1 - 1.1, VLAN 2 - 2.1…) I’m going to be redoing the VLAN video very soon in my new series I’m recording.

  • @marcpawelczyk9705
    @marcpawelczyk9705 Год назад

    on my kids network i dont have the option for content filtering, is that UDM pro only?

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      You can do it with the Dream Router too, but it is part of the UDM products only

  • @DojoVu
    @DojoVu Год назад

    can you do a Beginners Guide to Unifi Protect VLANs

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      Do you mean having your network gear and cameras on a different VLAN?

  • @evanporch7455
    @evanporch7455 Год назад

    Followed this pretty much to a T, and but I cannot ping or SSH into devices onto my IOT network. Any idea why?

    • @evanporch7455
      @evanporch7455 Год назад

      Even stranger, one of my IOT devices is hosting a simple webpage. When i go to the local IP for that device, I can see the webpage. But I cannot ping it on command prompt or access it using SSH.

    • @evanporch7455
      @evanporch7455 Год назад

      Nevermind, i figured it out. I had originally connected the device to default and then changed the port it was plugged into to be IOT network - and the IP address update (192.168.1.x to 192.168.3.x) didn't take place until the device was restarted.

    • @ethernetblueprint
      @ethernetblueprint  Год назад

      I would check the order of your firewall rules. The rules are processed in order so your allow rules have to be above the blocking rules. Without seeing them, it would be difficult for me to say for sure.

  • @meekerfrailer
    @meekerfrailer 9 месяцев назад

    Part 1 - UDM Pro Beginner's Guide to Setting up VLANs - GuestWiFi on Guest Network - 7:44 timestamp (may be others)
    Part 2 - UDM Pro Beginner's Guide to Securing VLANs - GuestWiFi on Default Network - 32:32 timestamp (may be others).
    If you want to help viewers, provide (as a follow up) document(s) on how to set these up rather than an extra 30 minutes of discussion that you think is important to explain. Give clickable links in the documentation to take the viewer to the explanation.

    • @ethernetblueprint
      @ethernetblueprint  9 месяцев назад

      These videos are some of my earlier ones, so I admit I didn't have all my ducks in a row. I have since redone the video using Version 8.X with Unifi. It is called "lets make some VLANs" and should be a better representation of the process.

  • @MrFoulkes
    @MrFoulkes 5 месяцев назад

    Great content but poor audio. You'd benefit from rerecording the audio to clear up your voice ans make the video more audible.

    • @ethernetblueprint
      @ethernetblueprint  5 месяцев назад

      Yes, true. That is an earlier video. I have redone this video a couple times now and the new versions, I think, are better. Check out my Let's make some VLANs" ruclips.net/video/B_0dXLNCGp8/видео.html or check out my 8 part mini series where I also go over this. Thanks for bearing with some of my early stuff!

  • @davidgarrett7673
    @davidgarrett7673 Год назад +2

    need an update using new interface...this is NOT intuitive at all