Oh how I need that deep dive into the zone-based policies. It seems so simple, yet I feel like I'm way over my head. A separate video will be highly appreciated!
@mjhns22 күн бұрын
100% agree
@MactelecomNetworks2 күн бұрын
I was going to show it in this video but feel I would have rushed through it, so separate video will be coming soon
@kbjp64062 күн бұрын
Looking forward to seeing it
@ZippyDooDa4352 күн бұрын
It’s simple, just be in the frame of mind of “from Zone A to zone B”. You put interfaces in different zones, and any in the same zone is the “same security level” which generally is a “allow all from Zone A to Zone A” You create rules just allowing or denying traffic sourced from a zone and destined to another zone. That’s it
@OGH32942 күн бұрын
100% I have basic network with iot, wifi ,lan ,camera vlans
@andrewherd442 күн бұрын
How to migrate or setup the 3-4 vlans from your UDM setup videos would be great. Camera, Guest, IOT and secure.
@amsterfransКүн бұрын
THIS :)
@bendodson9832Күн бұрын
That would be really useful to see how it would apply to a real-world network
@Timi7007Күн бұрын
YES! I don't really feel like clicking a button and just seeing what it does to my network... Making sure everything is still the way I want it seems like a major task that I'm not looking forward to. I'm not interested in a breaking change, Ubiquiti!
@matejfoltynКүн бұрын
@@Timi7007 You don't need to worry about that. The logic will be kept even after you click that upgrade. It's just that I feel the rules after the migration are a bit all over the place and can be simplified in the new zones logic, but the existing setup won't be affected. At least mine wasn't ;)
@theruckman2 күн бұрын
Curious how much bandwidth you lose up and down enabling that Cybersecure Proofpoint? Let us know maybe some quick tests?
@LostWorld4216 сағат бұрын
I have been updating my network for about 6 mo. now. Someone had recommended Unifi to me. I am thoroughly impressed with them. The videos you make are extremely helpful, I like what is being shown in this one. Definitely would like to see videos that go more in detail depth on both.
@gnz8v2 күн бұрын
Got into Ubiquiti few days back thanks to your video! SOOOOOO much better than my TP-Link Deco that kept choking my network with CPU usage at 100% all the time.
@MactelecomNetworks2 күн бұрын
Amazing have fun with it!
@MitchellEarlКүн бұрын
Tough crowd, but I get why some are worried. A case could be made that some value added services would keep, what has always been free, free. As long as UI doesn't go to the CISCO (and others) model of buying hardware and then also renting it...
@AshleyAlthea18 сағат бұрын
I understand why they want to add services, what I do not like is it being forced to me and replacing an existing working feature, also if my udm is “license-free” i do not want annoying trial pop-ups…
@bassbo12 күн бұрын
I would really like to see how to separate IoT devices and communications per device basis, for example, using groups or something similar using zones.
@Tefty2 күн бұрын
Cant wait for the zone based firewalling, been using it for years with Sonicwall firewall/routers and then installing Unifi was like "wtf is this mess" when configuring the firewall. Its a simple as source > destination > protocol which is great when dealing with 10+ vLans and wanting to restrict access between vLans except certain groups of machines etc...
@martinsoltau692613 минут бұрын
Wasnt this provided by the Traffic rules already?
@b00573d2 күн бұрын
Will you be doing a new 2025 in depth full setup video with zone based firewall like your previous full setup video?
@MactelecomNetworks2 күн бұрын
Probably but later on in the year
@oakfig2 күн бұрын
Bro we need it now!@@MactelecomNetworks
@Greg.MКүн бұрын
With the full setup I'd like to see it done with something like a Pro Max 24 PoE . . . Does the Zone Based Firewall make dealing with ACL rules in the switch easier or is it that nothing changes there (ie: if data doesn't transition VLAN's then the firewall rules never come into play)?
@danmaier20772 күн бұрын
Thanks for the info, I just updated to Network 9.0.108 but I don't see (Upgrade to the new Zone-Based Firewall) I use Unifi Gateway Ultra. I don't see Upgrade to CyberSecure by Proofpoint either. Thanks, Best regards from Austria
@Zaim-S2 күн бұрын
Thats strange, on my UCG Ultra and UDM SE both options are available. Interesting thing on the UniFi EFG the Proofpoint protection costs 449€/y and has 95k+ signatures Also BR from Austria
@alel15312 күн бұрын
@@Zaim-S Maybe because you told your system to update with OS release candidates too? So your console already has 4.1.9?
@u1f98aКүн бұрын
You have to update your gatewayt to version 4.1 or greater. Currently, that version isn't released for any non-cloud gateways. Right now, it's only on EFG, UCG-Max&Ultra and the Dream-series devices
@danmaier2077Күн бұрын
@ OKAY, thank you! I have the UCG Ultra!
@alel1531Күн бұрын
@@u1f98a Where can I find the official version 4.1 for UCG MAX? Sorry for the request, but I have recently got this device. Thanks
@JasonEfstathiou2 күн бұрын
Hey man, love your videos. Just a little bit of feedback, you tend to sometimes just read out loud 1:1 things written on dialogs etc. without adding anything yourself and then just moving ahead. Which is a bit superfluous I think because I can read that myself - I think it'd better if you either just quickly summarize what it says or add more detail / knowledge / whatever on top. Peace ✌️
@MactelecomNetworks2 күн бұрын
Thanks for the feed back
@marksamuels62932 күн бұрын
Looking forward to the deep dive as well, I started from scratch and I think I have a decent understanding now, but hearing and learning more is always welcome!
@YouToolКүн бұрын
It's nice to see some more improvements on the firewall side, thanks for the visual update! I really hope Ubiquiti expand the NGFW capabilities to compete even with the free Sophos Firewall Home Edition offerings, as opposed to having to find ways or merging these ecosystems.
@ivanlawrence220 сағат бұрын
You gave me the confidence to push the upgrade button but now I'm scared and confused. My dmz network isn't in the DMZ zone and I need my mommy. -- Thank you for the great video
@u1f98aКүн бұрын
also, as a note, this is not available if you're using any of the Unifi (non cloud) gateways. I assume they're going to push it out in a release soon, but at time of writing the new firewall features are only on: UDM (Standard/Pro/ProMax/SE), UDR, UDW, EFG, UCG (Ultra/Max)
@weslogan1572Күн бұрын
00:26 Interestingly, I upgraded my UDMPSE to Network 9.0.108 last night (UnifiOS was already at 4.0.21, with no other updates available), and I don't have the banner to do the upgrade to Zone-Based Firewalls under Settings > Security > Traffic & Firewall Rules as seen in your video at this point. Any suggestion on what to do to make it appear, or is it an undocumented requirement to actually reboot the UDMPSE (which I haven't yet done)
@TantissTheEmperorКүн бұрын
Funny, zone based policies exists since ages in enterprise appliances. But It's great news Unifi steps up bit by bit and takes the useful things from enterprise grade without bringing the setup complexity. Looking forward to see what they have in the backlog.
@driver2882 күн бұрын
Hi! The new site magic hub model could potentially be something for us as consultants and hosting provider IF we can segment the VPNs so that some spokes can talk to specific networks at the hub. Is that how it’s supposed to be doing? And what hardware would the hub have to be to support 1000 sites? UXG Enterprise?
@StrangerwithoutanameКүн бұрын
There is no UI hardware yet that can support up to 1000 S2S tunnel at the same time. And I‘m pretty sure with an 18ARM, 16GB EFG you can not even handle 500 stable S2S tunnel.
@jonathanfleck54192 сағат бұрын
1:57 Take it the install is in Jilani Place shared workspace? (Blur dropped off)
@MactelecomNetworks2 сағат бұрын
Correct and that's fine we film here all the time and will have a case study about it soon :)
@appyours331119 сағат бұрын
i'm wondering, i think most people are: is paying for the cybersecure upgrade worth the money?
@tobiasvdberg21 сағат бұрын
I wish they made the firewall rules page like pfSense has it. The new zone based firewall is even more confusing for me..
@jonathantx21 сағат бұрын
I have a UDM, but I'm interested in upgrading my Gateway, switch and adding a more powerful AP. What would you recommend and is it possible to migrate current config over to new gateway??
@gonxme411 сағат бұрын
Please complete video for the new software!
@wolfgangk49526 сағат бұрын
Hallo Cody. could you create a video on “high isp latency detected” notices? Why it happens, and how to fix?
@MikeJones__Who2 күн бұрын
I was wondering when Ubiquity would start pushing subscription services....
@djvinconКүн бұрын
This is very normal. Pfsense and most other firewalls have this aswell
@MikeJones__WhoКүн бұрын
@djvincon Its more of the reality these companies can not sustain themselves on just equipment sales. Sooner or later, they'll have to push for more subscription based services just to maintain income growth
@TK-le8wdКүн бұрын
I have the UDM Pro SE. I've updated and restarted but don't see any of this stuff. What am I missing here?
@schism8286Күн бұрын
Damn bro, you have a signed Ibanez TOD10N. SICK. Fellow Polyphia fan here
@MactelecomNetworksКүн бұрын
Going to see them In the summer with SOAD. 😁 also have the TOD10
@schism8286Күн бұрын
@@MactelecomNetworks Heck ya!
@MaDeX-k2wКүн бұрын
Can you guys check the VPN server, some funky stuff saying I cant save changes and I can connect using WG, however see packets to and from but no connectivity - I have the latest new version (for zone based) however VPN function doesn't look right - Support are also trying to investigate.
@JP-ou3ht2 күн бұрын
How good is CyberSecure as compared to dedicated firewall like Sophos?
@MactelecomNetworks2 күн бұрын
Not sure I don’t use Sophos
@MariuszSnioncyNonameКүн бұрын
When it will be avaible on gateway ultra?
@BerserkeR_0312 күн бұрын
I'll watch this for sure as soon as I'm done here at the dentist. Thanks! 😄
@BerserkeR_0312 күн бұрын
Oh yeah, I would definitely like a more in-depth video about the zone based firewall. Blocking gateways and RFC1918 etc..
@MactelecomNetworks2 күн бұрын
That’ll probably come out next week. Already have other videos waiting to be released :)
@davesmith7797Сағат бұрын
Thanks!
@MactelecomNetworks10 минут бұрын
Thanks for the super sticker much appreciated:)
@jalatiКүн бұрын
Full setup including ipv6 rules for firewalls is what I’d like to see.
@andrewcost6157Күн бұрын
Any tips for making wifi faster on unifi? Just got my first system using a cloud gateway max & 2 U6-LR's. Ive manually set channels & removed auto optimization but unfortunately my wifi speeds are around 200mb on a 1g connection. Thanks so much
@pauldisalvo2866Күн бұрын
Try changing your channel width to 80MHz on the 5GHz band on both AP’s if you haven’t already! I believe it’s the default for new setups now in 9.0 and is long overdue.
@PrzemoPSzynkuКүн бұрын
Will this new feature work on Cloud Gateway Ultra? or only on the Dream Machine Pro?
@u1f98aКүн бұрын
yes
@SquashPileКүн бұрын
I'm still too paranoid to update lol. I'm still on UniFi OS 4.0.20 and Network 8.6.9. I'll give it a few days then I won't be able to take it any longer.
@rainingtalent2 күн бұрын
Are we going to eventually be forced to use zone based firewall settings? The existing rules work fine.
@MactelecomNetworks2 күн бұрын
That I’m not sure of
@51av0sh2 күн бұрын
Great video as usual. I don't have the option to enable CyberSecure. I just see the banner for it and at the bottom it says "Can be activated by the owner of this site". I'm logged in with my "owner" credentials. Any idea what I need to do? I use Identity Enterprise in case it matters.
@51av0sh2 күн бұрын
Looks like I can activate it from Site Manager but I'm still curious why I'm not being considered as "owner" if I'm logged in with the user designated as the owner. Any tips would be highly appreciated 🙏🙏
@ragtop50Күн бұрын
@@51av0sh Look on your dashboard in the bottom left, that is where I have the option to activate CyberSecure
@Gonzo020219952 күн бұрын
I have two sites, each with an UXG Max but none of them showing up to activate zone based firewall. Is that feature limited to some specific gateway models?
@sebastiansimon9737Күн бұрын
You need a FW update on the UXG Max (UniFi Gateway 4.1.3) that is not out yet.
@FranciscoSendra-zs1egКүн бұрын
Why KZbinr that always talk about Ubiquiti don’t make a video about how many people including me getting ether dream machine or any switch with screen stuff on update !!!! Working normal but screen stuck on updating btw my problem in on my enterprise 8
@chriswatchingyt2 күн бұрын
Completed the upgrade to 9.0 but not getting the "Upgrade to zone-based firewall" or Cybersecure features. Guess it's not available on a UDM-Pro. :(
@MikeBraedel2 күн бұрын
Gotta wait for UniFi OS 4.1.9 to be released to the official channel first
@chriswatchingyt2 күн бұрын
@@MikeBraedel I see it now... Zone-Based Firewall settings "Requires UniFi (Cloud) Gateway firmware version 4.1 or newer." and CyberSecure by ProofPoint "Requires UniFi Cloud Gateway 4.1.8/UniFi Gateway 4.1.3 and newer.". Oh well...
@filipkudlac2372 күн бұрын
UniFi OS 4.1.13 is already out as official, so just wait a little bit,
@theruckman2 күн бұрын
@@filipkudlac237 same here
@vctgeekКүн бұрын
I can't see the Upgrade to new Firewall zone.
@u1f98aКүн бұрын
make sure your gateway is up to date, but the update hasn't rolled out to all gateway models just yet
@NathanSweetКүн бұрын
Can I block without notify? I really don't need the notifications!
@TheRealGulltop2 күн бұрын
Devices > Locate & Restart: Easier way to get those is to just upgrade to the 'Legacy' interface. :)
@brucehopkins7015Күн бұрын
Kinda going after PaloAlto 440's for small business....!
@andrewenglish38102 күн бұрын
Your using this on a UDM-PRO MAX?
@MactelecomNetworks2 күн бұрын
Yup this was a pro max
@kylef4641Күн бұрын
Cyber secure seems kinda pricey considering Firewalla has 100,000's of signatures for free..
@CyberSafferКүн бұрын
I would think of those as funny numbers that dont matter. If they keep up to date everyday is the most important I would say.
@u1f98aКүн бұрын
my firewall has 100,001 signatures for free. they might all be checking for compliance with RFC 3514, but still, bigger number better right?
@JasonsLabVideos2 күн бұрын
OH YEAH !!!!
@nrocobc5812 күн бұрын
I thought one of the benefits to UniFI was an escape from licensing fees and in-app fees. I've been endorsing that feature to my clients. Now it seems something has changed. Lets hope UBNT decides not to charge for standard OS updates.
@MactelecomNetworks2 күн бұрын
So you don’t need cyber secure this is an add on for people who want more threat signatures.
@jasonklems85842 күн бұрын
@nrocobc581 - I am with you there. Unifi APs have been my go to for years now because of the subscription costs of the big brands. I primarily install Sonicwalls and Fortigates for most of my clients who have Servers/Data sitting behind the firewall (with security subscriptions); but lately we have been rolling out UDMs for clients that are purely cloud based and just have data living in the cloud; so Unifi Firewalls have been a good alternative for them. This new introduction to subscription based security leads me to believe in order to play with the big boy space with Sonicwall/Fortinet/Meraki, they need to give the option to MSPs to provide the enhanced security features offered by the other brands. think "Gartner Magic Quadrant"; as it were. the financial decision makers are more technical these days and they want assurance, this "New Kid on the Block" (Ubiquiti) can play ball with the established brands.
@TechTailsКүн бұрын
@@MactelecomNetworksyou’re sponsored by them aren’t you? I get the conflict of interest but realistically this is a slow but steady descent into them testing the waters for charging for other things. If you’re denying that….I think you might be denying reality
@TechTailsКүн бұрын
Seems they’re just like other businesses who have investors that want to milk and dime their customers. Shocker. At least hopefully we can stop seeing those absolutely stupid Jack Quaid ads now 😂
@MactelecomNetworksКүн бұрын
@@TechTails I’m not sponsored by Ubiquiti. I have an affiliate link yes but that doesn’t mean sponsor. Also the affiliate link doesn’t work towards cyber secure. The ids/ips system is exactly the same as it’s been for years before this launch today and that won’t change you still get roughly 20,000 signatures
@nope64172 күн бұрын
You are a little bit late, this update was from 2024 :)
@MactelecomNetworks2 күн бұрын
We’re both right. EA was 2024 GA 2025 :)
@Cucaracha_512Күн бұрын
Greetings from Russia! )
@RobertFleming19 сағат бұрын
Would be cool if you could make a video on migrating the settings used in the Dream Machine SE vid linked below to the zone based system. kzbin.info/www/bejne/aamliqGpeK-dm8Usi=K-QSyheV_6hTP7YZ