Unifi network 9.0 : Zone based firewall, Cyber secure, 1000 Site for site magic

  Рет қаралды 37,652

Mactelecom Networks

Mactelecom Networks

Күн бұрын

Пікірлер: 120
@matejfoltyn
@matejfoltyn 2 күн бұрын
Oh how I need that deep dive into the zone-based policies. It seems so simple, yet I feel like I'm way over my head. A separate video will be highly appreciated!
@mjhns2
@mjhns2 2 күн бұрын
100% agree
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
I was going to show it in this video but feel I would have rushed through it, so separate video will be coming soon
@kbjp6406
@kbjp6406 2 күн бұрын
Looking forward to seeing it
@ZippyDooDa435
@ZippyDooDa435 2 күн бұрын
It’s simple, just be in the frame of mind of “from Zone A to zone B”. You put interfaces in different zones, and any in the same zone is the “same security level” which generally is a “allow all from Zone A to Zone A” You create rules just allowing or denying traffic sourced from a zone and destined to another zone. That’s it
@OGH3294
@OGH3294 2 күн бұрын
100% I have basic network with iot, wifi ,lan ,camera vlans
@andrewherd44
@andrewherd44 2 күн бұрын
How to migrate or setup the 3-4 vlans from your UDM setup videos would be great. Camera, Guest, IOT and secure.
@amsterfrans
@amsterfrans Күн бұрын
THIS :)
@bendodson9832
@bendodson9832 Күн бұрын
That would be really useful to see how it would apply to a real-world network
@Timi7007
@Timi7007 Күн бұрын
YES! I don't really feel like clicking a button and just seeing what it does to my network... Making sure everything is still the way I want it seems like a major task that I'm not looking forward to. I'm not interested in a breaking change, Ubiquiti!
@matejfoltyn
@matejfoltyn Күн бұрын
@@Timi7007 You don't need to worry about that. The logic will be kept even after you click that upgrade. It's just that I feel the rules after the migration are a bit all over the place and can be simplified in the new zones logic, but the existing setup won't be affected. At least mine wasn't ;)
@theruckman
@theruckman 2 күн бұрын
Curious how much bandwidth you lose up and down enabling that Cybersecure Proofpoint? Let us know maybe some quick tests?
@LostWorld42
@LostWorld42 16 сағат бұрын
I have been updating my network for about 6 mo. now. Someone had recommended Unifi to me. I am thoroughly impressed with them. The videos you make are extremely helpful, I like what is being shown in this one. Definitely would like to see videos that go more in detail depth on both.
@gnz8v
@gnz8v 2 күн бұрын
Got into Ubiquiti few days back thanks to your video! SOOOOOO much better than my TP-Link Deco that kept choking my network with CPU usage at 100% all the time.
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
Amazing have fun with it!
@MitchellEarl
@MitchellEarl Күн бұрын
Tough crowd, but I get why some are worried. A case could be made that some value added services would keep, what has always been free, free. As long as UI doesn't go to the CISCO (and others) model of buying hardware and then also renting it...
@AshleyAlthea
@AshleyAlthea 18 сағат бұрын
I understand why they want to add services, what I do not like is it being forced to me and replacing an existing working feature, also if my udm is “license-free” i do not want annoying trial pop-ups…
@bassbo1
@bassbo1 2 күн бұрын
I would really like to see how to separate IoT devices and communications per device basis, for example, using groups or something similar using zones.
@Tefty
@Tefty 2 күн бұрын
Cant wait for the zone based firewalling, been using it for years with Sonicwall firewall/routers and then installing Unifi was like "wtf is this mess" when configuring the firewall. Its a simple as source > destination > protocol which is great when dealing with 10+ vLans and wanting to restrict access between vLans except certain groups of machines etc...
@martinsoltau6926
@martinsoltau6926 13 минут бұрын
Wasnt this provided by the Traffic rules already?
@b00573d
@b00573d 2 күн бұрын
Will you be doing a new 2025 in depth full setup video with zone based firewall like your previous full setup video?
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
Probably but later on in the year
@oakfig
@oakfig 2 күн бұрын
Bro we need it now!​@@MactelecomNetworks
@Greg.M
@Greg.M Күн бұрын
With the full setup I'd like to see it done with something like a Pro Max 24 PoE . . . Does the Zone Based Firewall make dealing with ACL rules in the switch easier or is it that nothing changes there (ie: if data doesn't transition VLAN's then the firewall rules never come into play)?
@danmaier2077
@danmaier2077 2 күн бұрын
Thanks for the info, I just updated to Network 9.0.108 but I don't see (Upgrade to the new Zone-Based Firewall) I use Unifi Gateway Ultra. I don't see Upgrade to CyberSecure by Proofpoint either. Thanks, Best regards from Austria
@Zaim-S
@Zaim-S 2 күн бұрын
Thats strange, on my UCG Ultra and UDM SE both options are available. Interesting thing on the UniFi EFG the Proofpoint protection costs 449€/y and has 95k+ signatures Also BR from Austria
@alel1531
@alel1531 2 күн бұрын
@@Zaim-S Maybe because you told your system to update with OS release candidates too? So your console already has 4.1.9?
@u1f98a
@u1f98a Күн бұрын
You have to update your gatewayt to version 4.1 or greater. Currently, that version isn't released for any non-cloud gateways. Right now, it's only on EFG, UCG-Max&Ultra and the Dream-series devices
@danmaier2077
@danmaier2077 Күн бұрын
@ OKAY, thank you! I have the UCG Ultra!
@alel1531
@alel1531 Күн бұрын
@@u1f98a Where can I find the official version 4.1 for UCG MAX? Sorry for the request, but I have recently got this device. Thanks
@JasonEfstathiou
@JasonEfstathiou 2 күн бұрын
Hey man, love your videos. Just a little bit of feedback, you tend to sometimes just read out loud 1:1 things written on dialogs etc. without adding anything yourself and then just moving ahead. Which is a bit superfluous I think because I can read that myself - I think it'd better if you either just quickly summarize what it says or add more detail / knowledge / whatever on top. Peace ✌️
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
Thanks for the feed back
@marksamuels6293
@marksamuels6293 2 күн бұрын
Looking forward to the deep dive as well, I started from scratch and I think I have a decent understanding now, but hearing and learning more is always welcome!
@YouTool
@YouTool Күн бұрын
It's nice to see some more improvements on the firewall side, thanks for the visual update! I really hope Ubiquiti expand the NGFW capabilities to compete even with the free Sophos Firewall Home Edition offerings, as opposed to having to find ways or merging these ecosystems.
@ivanlawrence2
@ivanlawrence2 20 сағат бұрын
You gave me the confidence to push the upgrade button but now I'm scared and confused. My dmz network isn't in the DMZ zone and I need my mommy. -- Thank you for the great video
@u1f98a
@u1f98a Күн бұрын
also, as a note, this is not available if you're using any of the Unifi (non cloud) gateways. I assume they're going to push it out in a release soon, but at time of writing the new firewall features are only on: UDM (Standard/Pro/ProMax/SE), UDR, UDW, EFG, UCG (Ultra/Max)
@weslogan1572
@weslogan1572 Күн бұрын
00:26 Interestingly, I upgraded my UDMPSE to Network 9.0.108 last night (UnifiOS was already at 4.0.21, with no other updates available), and I don't have the banner to do the upgrade to Zone-Based Firewalls under Settings > Security > Traffic & Firewall Rules as seen in your video at this point. Any suggestion on what to do to make it appear, or is it an undocumented requirement to actually reboot the UDMPSE (which I haven't yet done)
@TantissTheEmperor
@TantissTheEmperor Күн бұрын
Funny, zone based policies exists since ages in enterprise appliances. But It's great news Unifi steps up bit by bit and takes the useful things from enterprise grade without bringing the setup complexity. Looking forward to see what they have in the backlog.
@driver288
@driver288 2 күн бұрын
Hi! The new site magic hub model could potentially be something for us as consultants and hosting provider IF we can segment the VPNs so that some spokes can talk to specific networks at the hub. Is that how it’s supposed to be doing? And what hardware would the hub have to be to support 1000 sites? UXG Enterprise?
@Strangerwithoutaname
@Strangerwithoutaname Күн бұрын
There is no UI hardware yet that can support up to 1000 S2S tunnel at the same time. And I‘m pretty sure with an 18ARM, 16GB EFG you can not even handle 500 stable S2S tunnel.
@jonathanfleck5419
@jonathanfleck5419 2 сағат бұрын
1:57 Take it the install is in Jilani Place shared workspace? (Blur dropped off)
@MactelecomNetworks
@MactelecomNetworks 2 сағат бұрын
Correct and that's fine we film here all the time and will have a case study about it soon :)
@appyours3311
@appyours3311 19 сағат бұрын
i'm wondering, i think most people are: is paying for the cybersecure upgrade worth the money?
@tobiasvdberg
@tobiasvdberg 21 сағат бұрын
I wish they made the firewall rules page like pfSense has it. The new zone based firewall is even more confusing for me..
@jonathantx
@jonathantx 21 сағат бұрын
I have a UDM, but I'm interested in upgrading my Gateway, switch and adding a more powerful AP. What would you recommend and is it possible to migrate current config over to new gateway??
@gonxme4
@gonxme4 11 сағат бұрын
Please complete video for the new software!
@wolfgangk4952
@wolfgangk4952 6 сағат бұрын
Hallo Cody. could you create a video on “high isp latency detected” notices? Why it happens, and how to fix?
@MikeJones__Who
@MikeJones__Who 2 күн бұрын
I was wondering when Ubiquity would start pushing subscription services....
@djvincon
@djvincon Күн бұрын
This is very normal. Pfsense and most other firewalls have this aswell
@MikeJones__Who
@MikeJones__Who Күн бұрын
@djvincon Its more of the reality these companies can not sustain themselves on just equipment sales. Sooner or later, they'll have to push for more subscription based services just to maintain income growth
@TK-le8wd
@TK-le8wd Күн бұрын
I have the UDM Pro SE. I've updated and restarted but don't see any of this stuff. What am I missing here?
@schism8286
@schism8286 Күн бұрын
Damn bro, you have a signed Ibanez TOD10N. SICK. Fellow Polyphia fan here
@MactelecomNetworks
@MactelecomNetworks Күн бұрын
Going to see them In the summer with SOAD. 😁 also have the TOD10
@schism8286
@schism8286 Күн бұрын
@@MactelecomNetworks Heck ya!
@MaDeX-k2w
@MaDeX-k2w Күн бұрын
Can you guys check the VPN server, some funky stuff saying I cant save changes and I can connect using WG, however see packets to and from but no connectivity - I have the latest new version (for zone based) however VPN function doesn't look right - Support are also trying to investigate.
@JP-ou3ht
@JP-ou3ht 2 күн бұрын
How good is CyberSecure as compared to dedicated firewall like Sophos?
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
Not sure I don’t use Sophos
@MariuszSnioncyNoname
@MariuszSnioncyNoname Күн бұрын
When it will be avaible on gateway ultra?
@BerserkeR_031
@BerserkeR_031 2 күн бұрын
I'll watch this for sure as soon as I'm done here at the dentist. Thanks! 😄
@BerserkeR_031
@BerserkeR_031 2 күн бұрын
Oh yeah, I would definitely like a more in-depth video about the zone based firewall. Blocking gateways and RFC1918 etc..
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
That’ll probably come out next week. Already have other videos waiting to be released :)
@davesmith7797
@davesmith7797 Сағат бұрын
Thanks!
@MactelecomNetworks
@MactelecomNetworks 10 минут бұрын
Thanks for the super sticker much appreciated:)
@jalati
@jalati Күн бұрын
Full setup including ipv6 rules for firewalls is what I’d like to see.
@andrewcost6157
@andrewcost6157 Күн бұрын
Any tips for making wifi faster on unifi? Just got my first system using a cloud gateway max & 2 U6-LR's. Ive manually set channels & removed auto optimization but unfortunately my wifi speeds are around 200mb on a 1g connection. Thanks so much
@pauldisalvo2866
@pauldisalvo2866 Күн бұрын
Try changing your channel width to 80MHz on the 5GHz band on both AP’s if you haven’t already! I believe it’s the default for new setups now in 9.0 and is long overdue.
@PrzemoPSzynku
@PrzemoPSzynku Күн бұрын
Will this new feature work on Cloud Gateway Ultra? or only on the Dream Machine Pro?
@u1f98a
@u1f98a Күн бұрын
yes
@SquashPile
@SquashPile Күн бұрын
I'm still too paranoid to update lol. I'm still on UniFi OS 4.0.20 and Network 8.6.9. I'll give it a few days then I won't be able to take it any longer.
@rainingtalent
@rainingtalent 2 күн бұрын
Are we going to eventually be forced to use zone based firewall settings? The existing rules work fine.
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
That I’m not sure of
@51av0sh
@51av0sh 2 күн бұрын
Great video as usual. I don't have the option to enable CyberSecure. I just see the banner for it and at the bottom it says "Can be activated by the owner of this site". I'm logged in with my "owner" credentials. Any idea what I need to do? I use Identity Enterprise in case it matters.
@51av0sh
@51av0sh 2 күн бұрын
Looks like I can activate it from Site Manager but I'm still curious why I'm not being considered as "owner" if I'm logged in with the user designated as the owner. Any tips would be highly appreciated 🙏🙏
@ragtop50
@ragtop50 Күн бұрын
@@51av0sh Look on your dashboard in the bottom left, that is where I have the option to activate CyberSecure
@Gonzo02021995
@Gonzo02021995 2 күн бұрын
I have two sites, each with an UXG Max but none of them showing up to activate zone based firewall. Is that feature limited to some specific gateway models?
@sebastiansimon9737
@sebastiansimon9737 Күн бұрын
You need a FW update on the UXG Max (UniFi Gateway 4.1.3) that is not out yet.
@FranciscoSendra-zs1eg
@FranciscoSendra-zs1eg Күн бұрын
Why KZbinr that always talk about Ubiquiti don’t make a video about how many people including me getting ether dream machine or any switch with screen stuff on update !!!! Working normal but screen stuck on updating btw my problem in on my enterprise 8
@chriswatchingyt
@chriswatchingyt 2 күн бұрын
Completed the upgrade to 9.0 but not getting the "Upgrade to zone-based firewall" or Cybersecure features. Guess it's not available on a UDM-Pro. :(
@MikeBraedel
@MikeBraedel 2 күн бұрын
Gotta wait for UniFi OS 4.1.9 to be released to the official channel first
@chriswatchingyt
@chriswatchingyt 2 күн бұрын
@@MikeBraedel I see it now... Zone-Based Firewall settings "Requires UniFi (Cloud) Gateway firmware version 4.1 or newer." and CyberSecure by ProofPoint "Requires UniFi Cloud Gateway 4.1.8/UniFi Gateway 4.1.3 and newer.". Oh well...
@filipkudlac237
@filipkudlac237 2 күн бұрын
UniFi OS 4.1.13 is already out as official, so just wait a little bit,
@theruckman
@theruckman 2 күн бұрын
@@filipkudlac237 same here
@vctgeek
@vctgeek Күн бұрын
I can't see the Upgrade to new Firewall zone.
@u1f98a
@u1f98a Күн бұрын
make sure your gateway is up to date, but the update hasn't rolled out to all gateway models just yet
@NathanSweet
@NathanSweet Күн бұрын
Can I block without notify? I really don't need the notifications!
@TheRealGulltop
@TheRealGulltop 2 күн бұрын
Devices > Locate & Restart: Easier way to get those is to just upgrade to the 'Legacy' interface. :)
@brucehopkins7015
@brucehopkins7015 Күн бұрын
Kinda going after PaloAlto 440's for small business....!
@andrewenglish3810
@andrewenglish3810 2 күн бұрын
Your using this on a UDM-PRO MAX?
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
Yup this was a pro max
@kylef4641
@kylef4641 Күн бұрын
Cyber secure seems kinda pricey considering Firewalla has 100,000's of signatures for free..
@CyberSaffer
@CyberSaffer Күн бұрын
I would think of those as funny numbers that dont matter. If they keep up to date everyday is the most important I would say.
@u1f98a
@u1f98a Күн бұрын
my firewall has 100,001 signatures for free. they might all be checking for compliance with RFC 3514, but still, bigger number better right?
@JasonsLabVideos
@JasonsLabVideos 2 күн бұрын
OH YEAH !!!!
@nrocobc581
@nrocobc581 2 күн бұрын
I thought one of the benefits to UniFI was an escape from licensing fees and in-app fees. I've been endorsing that feature to my clients. Now it seems something has changed. Lets hope UBNT decides not to charge for standard OS updates.
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
So you don’t need cyber secure this is an add on for people who want more threat signatures.
@jasonklems8584
@jasonklems8584 2 күн бұрын
@nrocobc581 - I am with you there. Unifi APs have been my go to for years now because of the subscription costs of the big brands. I primarily install Sonicwalls and Fortigates for most of my clients who have Servers/Data sitting behind the firewall (with security subscriptions); but lately we have been rolling out UDMs for clients that are purely cloud based and just have data living in the cloud; so Unifi Firewalls have been a good alternative for them. This new introduction to subscription based security leads me to believe in order to play with the big boy space with Sonicwall/Fortinet/Meraki, they need to give the option to MSPs to provide the enhanced security features offered by the other brands. think "Gartner Magic Quadrant"; as it were. the financial decision makers are more technical these days and they want assurance, this "New Kid on the Block" (Ubiquiti) can play ball with the established brands.
@TechTails
@TechTails Күн бұрын
@@MactelecomNetworksyou’re sponsored by them aren’t you? I get the conflict of interest but realistically this is a slow but steady descent into them testing the waters for charging for other things. If you’re denying that….I think you might be denying reality
@TechTails
@TechTails Күн бұрын
Seems they’re just like other businesses who have investors that want to milk and dime their customers. Shocker. At least hopefully we can stop seeing those absolutely stupid Jack Quaid ads now 😂
@MactelecomNetworks
@MactelecomNetworks Күн бұрын
@@TechTails I’m not sponsored by Ubiquiti. I have an affiliate link yes but that doesn’t mean sponsor. Also the affiliate link doesn’t work towards cyber secure. The ids/ips system is exactly the same as it’s been for years before this launch today and that won’t change you still get roughly 20,000 signatures
@nope6417
@nope6417 2 күн бұрын
You are a little bit late, this update was from 2024 :)
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
We’re both right. EA was 2024 GA 2025 :)
@Cucaracha_512
@Cucaracha_512 Күн бұрын
Greetings from Russia! )
@RobertFleming
@RobertFleming 19 сағат бұрын
Would be cool if you could make a video on migrating the settings used in the Dream Machine SE vid linked below to the zone based system. kzbin.info/www/bejne/aamliqGpeK-dm8Usi=K-QSyheV_6hTP7YZ
@metalunits
@metalunits 2 күн бұрын
Tbh this feels like a shill/ad for cybersecure?
@MactelecomNetworks
@MactelecomNetworks 2 күн бұрын
No lol what do I gain from it
UniFi OS 4.1.13 & UniFi Network 9 - Big changes!
19:29
Willie Howe
Рет қаралды 14 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
I'VE WAITED SO LONG - 100Gb/s Switches from Ubiquiti
20:41
ShortCircuit
Рет қаралды 400 М.
Public Video and Data Feeds of Highway License Plate Readers
15:24
HomeLab Hardware Tour (Early 2025)
27:10
Techno Tim
Рет қаралды 61 М.
The Honey Scam: Explained
10:53
Marques Brownlee
Рет қаралды 5 МЛН
UniFi Zone-Based Firewall: The Update That Changes Everything!
14:26
I’ve Never Been This ANGRY and CONFUSED - AMD 2025 Product Update (CES)
12:14
Tech that Died in 2024
5:42
CNET
Рет қаралды 658 М.
The Apple Time Capsule Reimagined!
30:25
Snazzy Labs
Рет қаралды 174 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН