UniFi Zone-Based Firewall: The Update That Changes Everything!

Поделиться
HTML-код
  • Опубликовано: 5 фев 2025

Комментарии • 31

  • @QuikTechSolutions
    @QuikTechSolutions Месяц назад +2

    Glad Unifi has finally added this feature. Well delivered and easy to understand Avi.

    • @TechMeOut5
      @TechMeOut5  Месяц назад

      Thanks for watching Tony! I hope you are doing well.

  • @WunderTechTutorials
    @WunderTechTutorials Месяц назад

    Been using this for a little over a week with the RC update and it's awesome! Great video, Avi! Loved seeing another point of view on it.

    • @TechMeOut5
      @TechMeOut5  Месяц назад

      Thank you so much! I am glad that you are enjoying the new features and thanks for watching buddy

  • @BavariaR
    @BavariaR 21 день назад +1

    You could have looked at the default rules (with Lock) first which are created automatically for Zones and then you would have figured that many of your additional rules have no further effect, just redundant... this might confuse some listeners as they don't understand why you do this!

  • @evenacona
    @evenacona Месяц назад +3

    Thanks for making the video - ZBF is awesome as long as all the VLANs are managed by the UDM. The moment you are using VLAN's routed by a Unifi L3 switch they are just thrown into the 'External' zone and there is no way to add them to a zone at all ...

    • @whiskerjones9662
      @whiskerjones9662 Месяц назад +3

      This is a self-inflicted problem. If you're using UniFi L3 switches to route VLANs instead of the UDM, you're deliberately bypassing your security appliance. Of course those VLANs show up as "External" - from the UDM's perspective, that traffic isn't under its control anymore. Unless you can clearly articulate why you need L3 switching (with actual throughput numbers to back it up), you're likely overcomplicating your network and compromising your security posture for no real benefit. Let your gateway be a gateway and your switches be switches.

    • @evenacona
      @evenacona Месяц назад +4

      @@whiskerjones9662 Without going into all the details, simply a case of having a lot of 25Gb connected devices in my setup (30+). By having the UDM manage the VLAN routing vs my Aggregation Pro's, unless I put all 25Gb devices on the same VLAN, the inter vlan route will force all traffic up the 10Gb UDM pipe to be routed even between VLAN's on the same Agg pro, which would slam the UDM.

  • @fredvanzet
    @fredvanzet 26 дней назад +1

    Has anyone figured out how to change the default rule between to zones? e.g.: VPN to Internal is "Allow All" and there is no option to change that default rule to "Block All". The only way to make that happen is to create an additional rule, which results in a quite comic Block and Allow rule in the overview. Unfornately it also bypasses the overview matrix: it doesn't show "Block all", it shows "See policies". For me, it makes the overview matrix somewhat useless.

  • @ggarp4806
    @ggarp4806 Месяц назад

    Great video. Can’t wait for this to be out of the beta phase. I don’t know about the USW issue, but ubiquiti is making some amazing moves as of the last year. I’m sure they’ll get this feature fixed for use with the USW.

  • @rayk32
    @rayk32 Месяц назад

    Great explanation. Thanks!

  • @asong26
    @asong26 28 дней назад

    Thanks for the great video. You actually use an example use-case scenario to make things easier to understand. One thing I've always had trouble understanding is the inter-vlan communications such as clients to printers, or client to say door bell camera. Your video not only showed me how to use the zones, but also helped me to solve this issue. Thank you!

    • @TechMeOut5
      @TechMeOut5  28 дней назад

      Glas i was able to help

  • @domadox
    @domadox Месяц назад

    It seems that this feature is not available on all UCG or UXG/UCK models. Are you aware of any specific limitations regarding this?

    • @TechMeOut5
      @TechMeOut5  Месяц назад +1

      Certain devices have a different cadence. Im pretty sure that this will be available on all platforms and sooner than later it will become the new default

    • @joefratianni8693
      @joefratianni8693 8 дней назад

      USG line will not get this update. So USG3p and USG Pro 4 for example.

  • @jeffnew1213
    @jeffnew1213 Месяц назад

    It looks like the ability to turn rules on and off (for testing or temporarily changing a restriction) is missing. Can you confirm this? If missing, seems like an oversight on Ubiquiti's part.

    • @marksamuels6293
      @marksamuels6293 Месяц назад

      It’s not missing, it is present in the zone based firewall

    • @driver288
      @driver288 Месяц назад +1

      You can see the pause feature if you click manage and then tick the rule you want to alter state on

    • @jeffnew1213
      @jeffnew1213 Месяц назад +1

      @@driver288 Great! Thank you.

    • @jeffnew1213
      @jeffnew1213 Месяц назад

      @@marksamuels6293 Excellent. Thank you.

  • @ronald0122
    @ronald0122 Месяц назад

    can you make a video about dns shield. i see nobody using it

    • @GingerTechIT
      @GingerTechIT Месяц назад

      Its great for basic secure DNS..i used to use it but now use NextDNS DNS provider so needs to be disabled. Only reason i use the provider is so i have more granular control over my traffic coming in.

  • @RupertoCamarena
    @RupertoCamarena Месяц назад

    Could you make a video explain how pihole or adguard work in unifi?

    • @TechMeOut5
      @TechMeOut5  Месяц назад

      Hi. To be honest, I'm failing to understand the question. Adguard and pihole are applications that filter dns queries. What's the connection to unifi?

  • @alefey3819
    @alefey3819 17 дней назад

    Ahhh light mode my eyes

  • @pauldunecat
    @pauldunecat Месяц назад

    Welcome to the 20th century Ubiquiti with the ZoneBased firewalling! 🙂

  • @driver288
    @driver288 Месяц назад +1

    Hmm the rules you created for blocking traffic were completely unnecessary since the block all rule already take care of what you wanted to accomplish. On the other hand you created them as a demo on how to create rules without changing anything, that is what you did. It seems like the block all rule is automatically created when you create the zone.

    • @TechMeOut5
      @TechMeOut5  Месяц назад +2

      Hi. The main focus was the rule creation and how to use the matrix to help administer them. That was the main goal.

  • @Volt-Imperium
    @Volt-Imperium Месяц назад +2

    Not using dark mode should be a crime 😂

    • @DavidM2002
      @DavidM2002 20 дней назад

      Lock me up. I have never understood the fascination with dark mode. I think it depends on our eyes and how we deal with the contrast but my eyes like normal mode.