No video

UniFi Network - Firewall Rules for VLANS

  Рет қаралды 7,714

MrTimTech

MrTimTech

Жыл бұрын

In this video I will explain how to create Firewall Rules so that VLANS cannot talk to each other and also cannot talk to the main LAN.
However I will also explain how to create an additional Firewall Rule which will also allow devices in the Multi Media VLAN to access a NAS on the Main LAN for streaming music and videos to a Smart TV.
I would recommend watching my previous video in which I explain how to create VLANS and thus this Firewall Rule video takes in to account the creation of the VLANS in the previous video.
Link for the VLANS video is here:
• UniFi Network - Config...

Пікірлер: 24
@rikkretzinger8728
@rikkretzinger8728 Жыл бұрын
Tim - this is the one I have been waiting for and is very clear and to the point as always. Thanks so much for not going at a FAST PACE and losing me with a lot of extra content that is not well explained but seems to just be throwing content out for support of calling themselves an expert at this networking subject. WELL DONE and just what and how I need my learning experience to be!
@MrTimTech2022
@MrTimTech2022 Жыл бұрын
Hey Rik, you're very welcome and sorry for the delay, it's been so time consuming with moving home and trying to fit in household stuff, work and YT, but I'm getting there :-) Thanks so much for your very kind words, yes I've found others go so fast and making the videos so quick and hard to absorb. Glad it's been helpful for you and sorry for the wait.
@JsmeLabs
@JsmeLabs 9 ай бұрын
Thank you so much for this video, I finally setup my network and this explained everything perfectly! Now I know what to do and how to do it properly!
@MrTimTech2022
@MrTimTech2022 9 ай бұрын
Great to hear and you're very welcome. Hope you find some other videos useful on my channel too!
@zekeserrano5345
@zekeserrano5345 11 ай бұрын
Well done. But I would recommend explaining a bit more why you make the selections that your making so that we may understand the concept for the decisions. Might help us make different choices if we understand why the particular selections were made by you in creating a rule. TIA
@MrTimTech2022
@MrTimTech2022 11 ай бұрын
@zekeserrano5345 - Thanks for your appreciation and your feedback. Yes I see where you're coming from and in future I will try to explain in simple terms as possible why the selections are being done. I'm going to be doing a VPN access video soon so I will apply that method to that video :-)
@309hex
@309hex 10 ай бұрын
Very clear instructions, thank you.
@MrTimTech2022
@MrTimTech2022 10 ай бұрын
@309hex - You're very welcome, glad you found the instructions clear. Thank you for the positive feedback. Any suggestions for further videos you would like producing ?
@jpavett
@jpavett 4 ай бұрын
I’ve added all the relevant rules from your video but I have one issue. I have two DNS servers on one of my subnets / VLANs, but these requests are still getting through to them successfully, even with the Drop rule. I was going to add an additional file to allow the traffic through before releasing it was already getting through. DNS servers are on 10.44.3.0/24 and host using them is on 10.44.2.0/24. Not sure if you have any idea why. The rule does prevent pings between the devices?l!
@MrTimTech2022
@MrTimTech2022 4 ай бұрын
I believe you can ping DNS servers, from memory, it's been a while since I did this video. Are you able to ping client devices within those subnets ?
@BTC_Solo
@BTC_Solo Жыл бұрын
Hi, can you allow one specific VLAN to be connected to tor but not the other VLANs
@MrTimTech2022
@MrTimTech2022 Жыл бұрын
Having checked it looks like you can only use 'Ad blocking' on selected networks/VLANS. For such things as TOR and P2P it appears it can only be applied to all networks in the UniFi Network controller and not to specific/individual VLANS.
@BTC_Solo
@BTC_Solo Жыл бұрын
I suppose we have to wait for the next update because I reached out to the technical team @ ubiquity and they said will raise this concern to high up to be considered. Thanks for your educated video and keep the good work 😊
@MrTimTech2022
@MrTimTech2022 Жыл бұрын
Thanks @crypto_1enthusiast945 - Yes I thought they might look in to it, seeing that you mentioned it, it does sound a useful suggestion. So good on you reaching out to UI Tech Support for this 👍. You're very welcome, pleased you like my videos and yes I will keep producing them. Next one on the list is 'DHCP options' 🤫
@Cr4ft3r99
@Cr4ft3r99 11 ай бұрын
Many thanks Tim ... followed your VLAN set-up guide and firewall rules and all worked as expected. One small request, it would help me and I'm sure others just starting out on their Unifi journey to understand a bit more about why some of these settings are as they are ... e.g. when setting up the RFC1918 group, why did we add the 172.16.0.0/12 and 10.0.0.0/8 (and why are the subnet number not 16, like the main IP range?) - cheers
@MrTimTech2022
@MrTimTech2022 11 ай бұрын
Hey @MartinWade99 - Thanks for your kind words and your suggestions, in fact someone else said the same that it would be helpful to explain why things are being done and yes I will certainly take that onboard. I will be doing a VPN connecting video coming soon and this will have firewall rules applied to it including RFC1918, so I will try to explain in simple terms why things are being done that way. Hope you're subscribed and enjoying some other videos too :-)
@angelical791
@angelical791 10 ай бұрын
I am confused. can you tell me what Network do you use for each vlans? Because on the previous video you used total different networks , Example 192.168.2.0/24, 192.168.3.0/24.....
@MrTimTech2022
@MrTimTech2022 10 ай бұрын
You can use .2.0/24 and .3.0/24 or .10.0/24 and .20.0/24, as long as they are not used and spare you can use any sequence of VLAN network address ranges, just keep them consistant and that they correspond with the VLANS that you have previously created. Hope that makes sense.
@lmisiura
@lmisiura 10 ай бұрын
thx
@MrTimTech2022
@MrTimTech2022 9 ай бұрын
You're welcome fella
@ass8ash
@ass8ash 8 ай бұрын
Along with the inter-vlan drop rule, Wouldn't it be better to also have another LAN Local rule preventing access to the gateway?
@MrTimTech2022
@MrTimTech2022 8 ай бұрын
@assBash - I guess you could add Gateway prevention rules if you so wish, however if devices need access to the Gateway then you would have to make sure to allow those to their own IP address for the Gateway's IP within those VLANS.
@you_tube754
@you_tube754 Жыл бұрын
What does the first rule do? Thanks for the great video
@MrTimTech2022
@MrTimTech2022 11 ай бұрын
You must ensure you set the first rule as it basically sets a rule to make sure it allows traffic to travel around that should do and is allowed.
UniFi Network - DHCP Options
14:25
MrTimTech
Рет қаралды 6 М.
NEW to UNIFI VLANs??  START HERE!!!
41:06
Ethernet Blueprint
Рет қаралды 65 М.
Stay on your way 🛤️✨
00:34
A4
Рет қаралды 31 МЛН
Can A Seed Grow In Your Nose? 🤔
00:33
Zack D. Films
Рет қаралды 32 МЛН
A teacher captured the cutest moment at the nursery #shorts
00:33
Fabiosa Stories
Рет қаралды 61 МЛН
Spot The Fake Animal For $10,000
00:40
MrBeast
Рет қаралды 210 МЛН
UniFi Network - Easy Setup - Creating Firewall Rules
17:09
Unifi Traffic Rules secure your network the easy way!
15:19
LoRes DIY
Рет қаралды 3,8 М.
UNIFI FIREWALL RULES EXPLAINED
13:54
Willie Howe
Рет қаралды 51 М.
How To Setup VLANs With pfsense & UniFi 2023
21:57
Lawrence Systems
Рет қаралды 192 М.
Configure VLANs on Unifi Switches
20:13
Ethernet Blueprint
Рет қаралды 22 М.
pfSense vs UniFi Firewall: May 2024 Edition
23:30
Lawrence Systems
Рет қаралды 71 М.
Unifi Network Complete Setup 2024
43:19
Mactelecom Networks
Рет қаралды 76 М.
Stay on your way 🛤️✨
00:34
A4
Рет қаралды 31 МЛН