My Ubiquiti Home Network Setup with the UDM Pro - How To Do Network Segmentation

Поделиться
HTML-код
  • Опубликовано: 13 дек 2024
  • НаукаНаука

Комментарии • 112

  • @ShannonMorse
    @ShannonMorse  2 года назад +24

    Side note: While not included in this video, 2FA can be enabled after you set up your account. My Ubiquiti acct does have 2FA setup and I recommend you do the same! Here is how you do that! help.ui.com/hc/en-us/articles/115012986607-How-to-Enable-Disable-Multi-factor-Authentication-MFA-

  • @Bovafett
    @Bovafett Год назад +17

    another thing to consider for the IoT VLAN is to block port 80, 443, and 22 (23 also if you're super paranoid\secure) traffic to the gateway to keep anything from trying to log\brute-force into the gateway. I have also blocked ICMP to prevent network mapping\device discovery from a compromised device on the IoT. I've also gone as far as setting up a profile to restrict the bandwidth allowed to this network so that if something is compromised it doesn't eat up my bandwidth

  • @OlavAlexanderMjelde
    @OlavAlexanderMjelde 2 года назад +3

    Been running unifi for many years now, very happy with it.
    What is also fun is that if you have a second home, you can deploy your network there too and roam without connecting to a different SSID.

  • @mischl1
    @mischl1 2 года назад +11

    Hi Shannon, I have CenturyLink, and have the UDM Pro as well. I previously also put the wifi router (I believe same one you had, judging by the UI -- C4000XG) into bridge mode, but found out that you can completely remove the modem once you have bridge networking working. the modem turns out to be completely unnecessary (I just found this out today).
    Thanks for sharing your setup! I love finding new tips and tweaks I can use that I didn't know about.

  • @Rkiver
    @Rkiver 2 года назад +8

    I remember doing the same for my UDM Pro re the PPOE settings, the modem did not have the information available to the end user, so I rang the tech support, and said "I'm running my own equipment, pfsense boxes, UDM Pro and the like".
    "Let me check with my team lead" *covers, but doesn't mute*
    I hear "Pfsense? Yeah they know what they are doing, give them what they need."
    My modem is in it's original box. Just in case.

    • @ShannonMorse
      @ShannonMorse  2 года назад +2

      I was so confused, but I guess this is what you run into when you upgrade from a home router to a smb one

    • @Burn3r10
      @Burn3r10 2 года назад

      I'm pretty sure my ISP had given me someone else's login info because it looked like the login was generated off your name and mine did not match at all. Lol. but my internet worked so... idk. Though my new battle is getting them to figure out why they keep assigning my private IP addresses for my WAN IP. They keep just telling me "we'll send a tech".

  • @Burn3r10
    @Burn3r10 2 года назад +3

    Oh, so if you have android (idk if apple has it) you can share the wifi SSID/PW using a QR code (under network settings). I used that feature to create a qr code for my guest wifi. This way you can set a complex password and just have to secure the QR code and makes it easy to handout the password.

    • @ShannonMorse
      @ShannonMorse  2 года назад +1

      Yes, that's another option.

    • @BerserkeR_031
      @BerserkeR_031 2 года назад +1

      It's good if you have a guest network, keep in mind the QR code is just plain text. Your pw as well.

  • @InfernalOd1n
    @InfernalOd1n Год назад

    I went the same direction. Using a UDM-Pro SE and a 24-port POE+ switch and a 10g SPF+ switch. I use a HP DL360 Gen9 8 Bay 1U as node-1 with TrueNAS Scale. Works great.

  • @tstaake
    @tstaake Год назад +2

    I’m confused I thought the UDM Pro was a router not a modem and that you still needed a modem. Maybe it’s a fiber thing since I have cable internet and don’t see how I could get rid of the modem since there isn’t a coax connection on the udmp (at least I don’t think) and I need the cat cable to get a wan connection.

  • @Fitzeccentric
    @Fitzeccentric Год назад +1

    This was easily the most comfy and informative video on the UDM Pro ever. Also we need wifi pineapple plushies with angry eyes, if only so one can haunt your background staring at the camera so the new viewers get reminded who's talkin haha. Thanks so much for that end to end walk-through!

  • @ssquire
    @ssquire 2 года назад +11

    Yes always update, but autoupdating in Unifi has broken things in the past and only firmware is easy to roll back. The Network (Protect, etc.) Application(s) require a new installation, factory reset, and restoring a backup. Given how good the Release Theads are in the Community (suggest checking it if you haven't), it is a better plan to update regularly vice automatically. Also, Auto-Optimize is poorly named as it just sets AP power to high and may select good channels, but probably not. Manual wifi tuning is a far better approach.

    • @tablatronix
      @tablatronix 2 года назад

      Ditto , I turned off auto, especially since my whole stack is running EA. However the cutting edge updates have stabilized a lot. And i have only had to enable legacy UI twice in the past 6 months

    • @rgrtht
      @rgrtht 2 года назад +2

      Thank you so much for these few but extremely valuable words for a UniFi first timer 🙏

  • @ericdaniels4912
    @ericdaniels4912 4 месяца назад

    Thanks!

    • @ShannonMorse
      @ShannonMorse  4 месяца назад

      Thank you so much! I appreciate you!

  • @MactelecomNetworks
    @MactelecomNetworks 2 года назад +8

    Great video you wont have to worry about heat issues they don't run overly hot :)

    • @BDBD16
      @BDBD16 2 года назад

      So funny to see you both post similar videos in the same, what day? two?

    • @ShannonMorse
      @ShannonMorse  2 года назад +1

      Very true!

    • @MactelecomNetworks
      @MactelecomNetworks 2 года назад

      @@BDBD16 pure coincidence you’ll always have this happen between RUclips channels. I love seeing how others configure the network as well

  • @LarryWright2
    @LarryWright2 2 года назад

    Thx for sharing. Been on UDMP for 2 yrs during Covid. About to factory wipe it due to LAN locked down the WAN settings and won’t let me change. But your go back to old GUI is new idea this morning to try before that and lose all my Vlans, VPN, and Wi-Fi’s.

  • @MechnoSferatu
    @MechnoSferatu 9 месяцев назад +1

    My comment is really late to the party, but I'm considering getting a UDM Pro for my home network. One thing that I find really off-putting is that it has to talk with Ubiquiit to get set up.
    From what I read, there's no way to set this up without having it "phone home". Was that your finding?
    Thanks for the video!

  • @totaltrinkets
    @totaltrinkets Месяц назад

    Question Shannon. What's that service that you use that you use to get rid of all the places that are tracking you.

  • @widgetweekly
    @widgetweekly Год назад

    My U6 Pro AP lived atop my network rack for a year and a half.... 😂 Last week I finally moved it to be wall mounted... Best place for it? maybe not. But I can't be bothered to actually mount it to my ceiling lol!

    • @ShannonMorse
      @ShannonMorse  Год назад

      Do whatever works best for you! It's your home, no one else's. If it gives you good speeds then you're good

  • @PhoenixKnightDesigns
    @PhoenixKnightDesigns 2 года назад

    Just started setting mine up this week

  • @psroliveira
    @psroliveira 9 месяцев назад

    Great video, particularly for a newbie like me. Thank you! 😄

  • @gogorichie
    @gogorichie 2 года назад

    Another great video Shannon the Ubiquiti Unifi product line has a huge following!!!!!!

  • @udmnoob1724
    @udmnoob1724 2 года назад +1

    Please excuse the amateur question come on but I have charter cable and the modem I have is only coaxial and there's no way to SSH into it. How do I get my modem information or do I just get in be a coaxial to Ethernet adapter and put that directly into the UDM question? please there is no way to bridge, or SSH into it. How do I do it at this point?

  • @pavelow36
    @pavelow36 2 года назад

    was waiting for this

  • @n8sdesign
    @n8sdesign 2 года назад +1

    Awesome! Thanks for the tips and ideas for our New Home network hardware upgrades 🍻

  • @smarteman9983
    @smarteman9983 Месяц назад

    My ISP said i can't do it 😒 ill have to try again . Also how did you find the modem I don't see mine at all

  • @hatless-cluncky-capsize
    @hatless-cluncky-capsize 2 года назад +5

    Thank you so much for this video. Packed with information, love it. I will be using it as a guide (along with other resources) to set up my parents house.

  • @F14Mavrick
    @F14Mavrick 2 года назад

    Sometimes with Ubiquiti it is not that easy is factory wipe or roll back. If you don't have it setup properly, you are going to have to console into the unifi just to roll it back and even at that point when it is boot looping cause you do a firmware upgrade, it is also a hassle just to get it to talk.
    The unifi forums talk about this in details and for unifi machines, it is best practice to wait a bit and see what the community is saying and then make the decision. FYI.

  • @christianlempa
    @christianlempa 2 года назад +1

    Great video! I was wondering if you can do segmentation on the Ubiquiti switches 😉

    • @toddtalkstesla6913
      @toddtalkstesla6913 2 года назад

      Yes, I’m doing exactly that. My Unifi switches are running multiple VLANS assigned to each port depending on need and then each network is restricted by function. E.g. anything goes, IOT only, kids, etc. I’m using a combination of VLANS, port isolation, bandwidth profiles, and firewall rules. Wireless networks are assigned those same VLANS so they follow the same rules. Your imagination is the limit.

    • @rynoz9711
      @rynoz9711 2 года назад

      Most likely the answer is yes. You can create segmentation or what is called VLANs on a managed switch. That being said that is not the only part, in order for your VLANS to get to the internet they need to be routed. So, you need a router that can support multiple LANs. I believe all Unifi UDM can create Sub interfaces. IE make more ports out of one for your VLANs to talk to one another. Sorry for long winded answer. But segmentation kind of take two parts.

  • @MrSoulMonk
    @MrSoulMonk 9 месяцев назад

    Great video, as always. I am double-natted since my ISP requires the use of their modem, but I have never asked if they could give me the credentials to directly connect my FW. I will ask them that. Thank you.

  • @Flimofly
    @Flimofly 2 года назад +1

    Wait so can you completely dispense with the ISP modem? You still need it in bridge mode right, right? Because you mentioned you put it away in a cupboard somewhere.

    • @ShannonMorse
      @ShannonMorse  2 года назад

      It is completely disconnected from my fiber line and boxed up in a cupboard. You heard that right.

  • @ddr874
    @ddr874 2 года назад

    Always interesting and informative!

  • @EricWieber-mi9yj
    @EricWieber-mi9yj Год назад

    Hi Shannon, I love your presentation. How can I connect my coaxial (ISP Provider) to my Unifi Dream machine SE?

  • @scholziallvideo
    @scholziallvideo 2 года назад

    hi,
    perfect video.
    i use the switches and accesspoints from ubiquiti but router/firewall i use other because the problems with site2site VPNs in USG or other Router/firewalls from ubiquiti.
    You cannot use it with Double NAT and some VPN Features doesent work

  • @pjohnson21211
    @pjohnson21211 2 года назад

    100% agree, just patch the things.....and the answer to "what if this breaks something?" "factory reset and restore from recent backup"

  • @jsclayton
    @jsclayton 2 года назад +1

    I really need to redo my UniFi network to segment devices. Any thoughts on starting from scratch vs trying to migrate in an existing setup? Thanks!

    • @ShannonMorse
      @ShannonMorse  2 года назад

      I guess it just depends on how labor intensive the options would be. Which one would take the longest?

  • @Cemilaws
    @Cemilaws Год назад

    it was a lot shorter than other channels an yet you explain better , i will be switching to unifi gear this year for auto lock for outide door,1x g5 pro,g4 pro doorbell and i need to switch my isp modem to udm se, idk that my provider will give me admin credentials when logging in to router, also the router is wifi 6 with 2 free access points with 2.5gbe ports also wifi 6, i dont think i will switch to ubnifi wifi 6 ap but iam gonna wait for wifi 7 aps, also i need 4 10gbe ports from my isp router that has 1 10gbe port, i looked and 4 port unifi and 8 port sfp switch was ideal, the adapter cost is high but i think 8 port sfp is better than 4 port 10gbe switch from unifi, i have a 8500/1500 fiber connection to my home by proximus (i live in belgum), can you reccomend extras ? i will be using power adapter for poe cables,no poe switch needed.

  • @710blodgett74
    @710blodgett74 2 года назад

    my fav online geek

  • @Ryan-rz4ig
    @Ryan-rz4ig 2 года назад

    It would be interesting to see this with packet fence installed along side it

  • @tablatronix
    @tablatronix 2 года назад +1

    I wonder if i can get ATT fiber to remove my box.. hmm

  • @Bruce.-Wayne
    @Bruce.-Wayne 2 года назад

    Do these Ubiquiti devices offer a CLI option or are they all GUI based?

  • @pudelz
    @pudelz 2 года назад

    I have a udm pro, their 10G switch aggregation thing, and a gigabit poe switch all next to each other in the rack. The room does get pretty warm (carpet and no a/c in the room) but I haven't had heat related issues but that might be because I installed fans inside my rack so air would move. One thing I do recommend is enabling 2FA for your account. I'd guess you did this off camera but just wanted to mention it.
    P.S. Whenever I see people get full uploads, I always get jealous... Here they're like "we can give you gigabit or more download but the best we can do is 40Mbs upl" (of course, that's without getting a business line)

    • @pudelz
      @pudelz 2 года назад

      hehe, just saw your pinned comment about enabling 2FA, really should of looked before just commenting 🤣

    • @ShannonMorse
      @ShannonMorse  2 года назад +1

      i knew someone would point it out so i pointed it out first, ha!

  • @JW-jl8iq
    @JW-jl8iq Год назад

    Who was your ISP

  • @UNICORNSF3ProgameplayProRACER
    @UNICORNSF3ProgameplayProRACER 2 года назад +1

    Super interesting🙂

  • @wertherland
    @wertherland Год назад

    Great video! never seen someone using Unifi UDM as a modem, all that PPoE thing. I still use my modem as a modem in Bridge mode, I have Gen 2 Controller. Would you explain better why and how bad exactly is Double NAT? Thanks!

    • @ShannonMorse
      @ShannonMorse  Год назад

      So, when I was looking into it, apparently it has to do with clients not being able to communicate with each other correctly. This forum thread sums it up pretty well: www.reddit.com/r/homelab/comments/42fnqv/why_is_double_nat_a_bad_thing/

    • @wertherland
      @wertherland Год назад

      @@ShannonMorse Thank you!

  • @christopherguy1217
    @christopherguy1217 2 года назад

    Thanks for the information, the video wasn't long at all.

  • @jeffhale1189
    @jeffhale1189 2 года назад

    Thanks for sharing. Blessings on your day.

  • @MrJoseJasso
    @MrJoseJasso 2 года назад

    Great video! Awesome content. Any idea if I could set up multiple wifi networks for each of my three kids? Keep them separate so I could monitor each kid? Thanks

    • @ShannonMorse
      @ShannonMorse  2 года назад +1

      I looked it up and you'd by limited to four SSIDs total, or 8 if you set them to either 2.4 or 5 Ghz. Here's more info: UniFi has a limit of 4 SSIDs per band, per AP group. You can stretch this to 8 total SSIDs if you limit your networks to a single band. You can have up to four 2.4 GHz and up to four 5 GHz networks, or four dual-band SSIDs

    • @MrJoseJasso
      @MrJoseJasso 2 года назад

      @@ShannonMorse you are awesome! Thanks for taking the time to respond with such a thorough answer! Long time fan!

  • @WreckDiver99
    @WreckDiver99 2 года назад

    Always been here snubs...but you know...some things peak my interest more than others. I'm looking at doing a full rack system in my new house...when I build it. Unfortunately I'm not sure I'll be permitted to do what you are doing. I haven't done the legwork yet since I'm still about 5 years out from the new home build. I know I'd like to be able to run fiber between my home and the shop (60x40 or 80x50 Post Frame Building) that could be about 500' away from the home....which really moves me into this kind of thing I imagine.

    • @BDBD16
      @BDBD16 2 года назад

      Any local muncipal issues that would prevent you from doing that? Its your property, its your ground to trench.

    • @ShannonMorse
      @ShannonMorse  2 года назад +1

      you shouldn't have a problem building a rack. HOAs don't care about the interior use of a home, and as long as the power is within code, you should be fine.

    • @WreckDiver99
      @WreckDiver99 2 года назад

      Nothing to do with "codes". Much has to do with my ISP selection. We have 2 available to us. Neither of them allow me to use something like what you are doing, not without moving to a business system. I can't even use my own modem...well, I can, but I still must pay $15 per month for theirs. Welcome to just having 2 available items. The other reason? swmbo....lol

  • @michaelwinter5292
    @michaelwinter5292 2 года назад

    Curious, and I am still a relative networking beginner, but why separate your home and work networks?

    • @ShannonMorse
      @ShannonMorse  2 года назад

      WFH justifies the need to separate work networks from home networks, but I would argue not everyone needs to do that. If you're accessing sensitive customer data or proprietary information for work, you may want to consider using a separate network from the one the rest of your family uses, in case there are any security issues with your home products.

  • @joeltyler3427
    @joeltyler3427 2 года назад

    5:33 oh you forgotten about Backup up your configuration settings and eccetera..

    • @BDBD16
      @BDBD16 2 года назад +1

      But thats so boring!

    • @ShannonMorse
      @ShannonMorse  2 года назад +2

      agreed, i skipped the boring stuff lol

  • @lindamora7
    @lindamora7 8 месяцев назад

    Can you help me? How do we get in touch with you?

  • @hurgoz2426
    @hurgoz2426 2 года назад

    Hi! Real interesting video! Thanks! Ubiquiti is a great hardware and software provider; there network solution is more or less like a Network as a Software. I've setup some of them, but never the dreammachine. Does the Unifi controller is including directly in and you don't need to intalling it on another client/server?
    Other question, at the begining of the video, regarding the internet setup, you are inputing a Vlan (201). Does it a ISP requirement or does you using it for the network segmentation?
    Last question: does you filtering traffic betwin network, or it's only deny?
    Last question 2: does your ISP provide you phone and TV support, and, if yes, how do you manage it with your setup?
    Thanks! :)

    • @ShannonMorse
      @ShannonMorse  2 года назад +1

      1) no additional client/server is required to setup the ubiquiti udm pro.
      2) iirc it was an ISP thing
      3) filtering for just one port, all others are denied for the secure network. The other ports on the switch can communicate between networks np.
      4) no phone and TV. I suspect that would add a lot of headache to this setup.

  • @Baaddu
    @Baaddu 2 года назад +1

    Your setup is overkill for my network but I appreciate the information and tips. I refuse to use any iot devices and have a guest network to set up televisions and other devices requiring internet connection to be used then disable access once the device is working. With exception of a television I do not see why microwaves or other home appliances need internet connection.

    • @harri3020
      @harri3020 2 года назад +2

      You say "overkill" then state that you don't trust IOT devices? Her set up will allow home users to effectively isolate IOT devices. While I agree, it will be sometime before an internet connected fridge or washing machine becomes essential, smart lights, home assistants, wireless speakers, smart TVs connected to streaming platforms and security cameras are all part of the 21st century home.

  • @CyphDragon
    @CyphDragon 2 года назад

    The switching from light to dark UI...uggghhhhh. Companies really need to implement the ability to switch between the two on any device with a GUI!

  • @jugamath
    @jugamath Год назад

    Thanks Shannon. Bookmarking this if I decide to switch to the UDM Pro.
    I purchased a UDM (not pro) back in Jan 2021 right before Krebs on Security started reporting about a Ubiquiti breach. Ubiquiti was very tight-lipped at the time and I turned on 2FA. Krebs continued to report on breach details, and I have to admit I felt betrayed. So I disconnected my UDM and AP and replaced them with another product's mesh.
    Of course, now we know that Krebs was getting his info from the very insider who was extorting Ubiquiti. Still I was spooked by the existence of a malicious insider, and I'm thinking of just putting a pfsense FW on the inside of my other router.

  • @toolate6971
    @toolate6971 11 месяцев назад

    Ubiquiti should have purchased or at least teamed up with Reolink for a complete camera/nvr solution.

  • @janokartal5690
    @janokartal5690 2 года назад

    Nice shannon

    • @mlegos
      @mlegos 2 года назад

      Which ISP do you have?

  • @MitchOfCanada
    @MitchOfCanada 2 года назад

    a MUST, pihole for custom DNS :D. Ubiquiti is more expensive than crack cocaine i have found. once down this rabbit hole there is no going back

  • @BDBD16
    @BDBD16 2 года назад

    I still find it so strange when PPPoE is used by providers on modern circuits.

  • @adrianteri
    @adrianteri 2 года назад

    Great but content but don't like another party having access to my home network. Would rather run pfsense + tailscale (self hosted node) or any other 'overlay' network + a VPN on it if I wanted to access it away from home.

  • @juddaustin399
    @juddaustin399 Месяц назад

    i mean, I'm impressed, but man. good thing Ubiquiti is as inexpensive as it is.

  • @lamius
    @lamius 10 месяцев назад

    Tell me you are new to Snubz without telling me your new to Snubz: "why is your AP in your rack?"

  • @RifniMohamed
    @RifniMohamed 2 года назад

    Super

  • @bluwng
    @bluwng 2 года назад

    She is so pretty 😍😍😍😍

  • @harrietgallagher152
    @harrietgallagher152 2 года назад

    😇 promosm

  • @JAkino266
    @JAkino266 2 года назад

    Why 201?

  • @degenhexican9355
    @degenhexican9355 11 месяцев назад

    Pineapples are fruit not wifi devices... geez you dont know anything 😜❤

  • @Highqman1974
    @Highqman1974 2 года назад

    Ha Ha. Wifi Police....SCOLDED!!!

  • @tweetoryt
    @tweetoryt 8 месяцев назад

    would be nice if you made more pauses when speaking

    • @davidpower3102
      @davidpower3102 6 месяцев назад

      Pro tip - RUclips has a pause button. Try it, it works.

  • @bc5891
    @bc5891 2 года назад +1

    You would be SHOCKED it you saw how many MikroTik and Ubiquiti devices are on the dark web with full working backdoors into those devices which are currently active. I will only advise this 1 time - use 18 or higher password that is completely separate from any other password you have used, 2 factor auth, do not open ports allowing inside your network from the outside and create a strong internal wireless password possibly with cert base auth. Open source is a complete b***h these days with security!