Unifi Security Settings

  Рет қаралды 38,620

Toasty Answers

Toasty Answers

Күн бұрын

In this video I go over how to enable security services on the Unifi Security Gateway. This includes threat management as well as GEO IP filtering, and a couple other features.
This video applies to the Unifi Dream machine as well, but with a few exceptions. There are features that are supported by the UDM that are not available on the USG so the menus and options may vary depending on model.
I do not go over Firewall rules in this video, but instead hit on the other security features.
Unifi Guide Link: help.ui.com/hc...
Guide I am using: 0:29
New Vs. Old Settings Menu: 1:29
Enabling Threat Management: 1:53
Enabling Threat Management (Classic Menu): 4:04
GEO IP Filtering: 5:18
DNS Filtering (UDM Only): 10:13
Deep Packet Inspection (DPI): 11:00
Testing Restriction Groups: 15:13
Network Scanner & Honeypot: 16:03
Threat Management Testing: 18:20
Honeypot Menu (UDM Only): 19:50

Пікірлер: 38
@kge420
@kge420 3 жыл бұрын
Thanks so much for putting this together. Coming from an Edgerouter PoE5 and I've been a bit lost concerning security setup. This makes it very clear. Stay safe and healthy.
@jonnyzeeee
@jonnyzeeee 3 жыл бұрын
Thanks for this. You know your stuff and you are able to explain the technical details in a way that makes sense!
@kevinbrown4119
@kevinbrown4119 3 жыл бұрын
Thanks Toasty. This was extremely helpful for me setting up my DM. Appreciate You.
@jukai2k
@jukai2k 3 жыл бұрын
Thanks Toasty I see the benefits of getting the DM over the USG your videos are super helpful please keep up the great work. Happy Networking.
@peterruzevich7089
@peterruzevich7089 3 жыл бұрын
"I'm going to go ahead and block all of them" lol :D Thanks for the great tutorial.
@nerdwerx2292
@nerdwerx2292 3 жыл бұрын
A toast to Toasty! Thank you for the informative videos!
@Clive_Standish
@Clive_Standish 3 жыл бұрын
Really made me wish I had gotten a dream machine lol, Ill upgrade to that in the future for now going with a ubiquiti setup though so ill be watching many of your videos.
@carlyleroberts3995
@carlyleroberts3995 3 жыл бұрын
Excellent training video, thank you Toasty
@OthmanAlikhan
@OthmanAlikhan 3 жыл бұрын
Thanks for the video =)
@kevinhughes9801
@kevinhughes9801 3 жыл бұрын
Great stuff thanks
@procekim
@procekim 3 жыл бұрын
thank you, very informative.
@NicholasEJones
@NicholasEJones 3 жыл бұрын
So useful thank you
@carlyleroberts3995
@carlyleroberts3995 3 жыл бұрын
Excellent video!
@StePhanMckillen
@StePhanMckillen 3 жыл бұрын
10 out 10 bro
@crudge
@crudge 3 жыл бұрын
Perfect many fanx
@javiercamacho1673
@javiercamacho1673 3 жыл бұрын
Excellent video Toasty... I use full-featured UDM-Pro to protect a small business network, but I was wondering if there is a way to make an "exception list", for example my local server, so, stop generating alerts on the "Honeypot" when I use the tool "Advanced IP Scanner". On the other hand, if I have several VLANs, should I create different Honeypot IPs for each VLAN, or am I protecting everything with only one? Thanks
@kennethbell4681
@kennethbell4681 3 жыл бұрын
I have an SGW system with the latest software/firmware on all components and have had IDS/IPS turned. I have never received any threat in my events or alerts listing. Any idea why this might be?
@bradcfi2
@bradcfi2 3 жыл бұрын
Where can I receive (paid) direct support for Unifi gear, AP's and Security gateway?
@ldnzz
@ldnzz Жыл бұрын
Does anyone know what the throughput on UDR is for IPS/IDS?
@B1G_WH1T3
@B1G_WH1T3 3 жыл бұрын
Hi dude, quick question "internet threat management" is that really needed for the intermediate, semi-advanced user since you losing all that speed most fibre connection here by me is around 200mbps? reason I'm asking is I'm thinking of replacing my mikrotik 750G and replacing it with a USG & USW-lite 8 port with my existing UAP-AC-Lite to get a full circle unifi experience, but the drop in speed is kinda holding me back on making the switch from mikrotik to USG
@ToastyAnswers
@ToastyAnswers 3 жыл бұрын
I wouldn't say it is "needed". Personally, I don't use any kind of threat management on my own network, but it is a nice feature to have. I wouldn't recommend getting the USG these days as they are pretty dated at this point. The Dream Machine line has basically replaced the USGs and is more than capable of running the advanced features at 200Mbps (UDM up to 800Mbps and UDM Pro up to 3Gbps IIRC). I would upgrade to one of these to get the best of both worlds.
@B1G_WH1T3
@B1G_WH1T3 3 жыл бұрын
@@ToastyAnswers Thanks for the advise, dream machines are really expensive in my country and looks like the only supplier is out of stock
@ahtoh1
@ahtoh1 3 жыл бұрын
Does this provide good security for SMB?
@juzbuz
@juzbuz 3 жыл бұрын
Seeking your professional advice, using USG-3P's as home use device which have had IPS enabled. Such limiting 85 Mbps throughput? How will this affect video calls or FaceTime quality when 4-5 devices onboard (Zoom for education, Team for WFH) at the same time?
@ToastyAnswers
@ToastyAnswers 3 жыл бұрын
There will be other factors at play, but 85Mbps should be more than enough for 4-5 devices using video/audio calls. If you are experiencing issues, this could be a reason but I look at the usage statistics to see if a device is pulling an abnormal amount of data. If you aren't experiencing issues I wouldn't worry about it. Unless you are paying for speeds much higher than 85Mbps (In this case, you won't be getting what you pay for).
@juzbuz
@juzbuz 3 жыл бұрын
@@ToastyAnswers Appreciate the honest input, recalled in the video you mention UDM, will replacing USG with this to match my BB at 1 Gb make sense? What will be other factors you will be considering before shelling out hefty price for UDM. Cheerios
@ToastyAnswers
@ToastyAnswers 3 жыл бұрын
The UDM has more features and performance overall, but there is quite a lot that can come into play when deciding on the upgrade is worth it. You mention matching your "BB" at 1Gb. Is this your ISP connection or your local interface? I'll give a couple scenarios where an upgrade would probably be worth it. If your internet connection is 100Mbps or more then you are leaving 15Mb of throughput on the table by using the USG. The UDM can support all security features at 800Mbps. Now, if you are lucky enough to have a 1Gbps ISP connection, then a UDM pro would probably be what you want to look at since it can support 3.5Gbps with security services. If you have multiple networks configured (VLANs, Dual-LAN, Etc.) then you are limited to the 85Mbps as well. For example, if you have wireless devices on one subnet, and a file server on another then you may want to upgrade since your file transfers will be limited. If you are using one network, with wireless and switches, and are only concerned about local traffic then there may not be a need to upgrade. If you only have a 50Mb ISP connection and have everything on one network then you really won't see much benefit in upgrading besides gaining a few more features and having a bit more headroom down the road.
@oakfig
@oakfig 3 жыл бұрын
Hoping you get the udm pro for some awesome tutorial on it!
@ToastyAnswers
@ToastyAnswers 3 жыл бұрын
I hope so too!
@ghz3112
@ghz3112 3 жыл бұрын
Can i use usg with mikrotik?
@ToastyAnswers
@ToastyAnswers 3 жыл бұрын
Yes, you can use the USG with any other standard equipment.
@alan.macrae
@alan.macrae 3 жыл бұрын
cue the banjo music.
@adamjones7497
@adamjones7497 3 жыл бұрын
85 Mbps? That’s icky bad. Basically dial-up.
@ToastyAnswers
@ToastyAnswers 3 жыл бұрын
Words circa 2005 me would think could never be said. But yeah... it's not great.
@r3dhorse
@r3dhorse 3 жыл бұрын
I'm confused why folks would buy this instead of just remoting in over VPN and so on.
@jonnyzeeee
@jonnyzeeee 3 жыл бұрын
Different set of features shown here. These features provide different controls and more insight. You can have all this and a VPN server.
@georgepcguy
@georgepcguy 3 жыл бұрын
Thanks for showing test results. Wondering what was your speedtest.net before and after the install.
VLANs on Unifi
19:41
Toasty Answers
Рет қаралды 56 М.
He bought this so I can drive too🥹😭 #tiktok #elsarca
00:22
Elsa Arca
Рет қаралды 46 МЛН
Angry Sigma Dog 🤣🤣 Aayush #momson #memes #funny #comedy
00:16
ASquare Crew
Рет қаралды 49 МЛН
拉了好大一坨#斗罗大陆#唐三小舞#小丑
00:11
超凡蜘蛛
Рет қаралды 16 МЛН
Modus males sekolah
00:14
fitrop
Рет қаралды 14 МЛН
BEST WiFi Optimization Settings!
20:25
Crosstalk Solutions
Рет қаралды 340 М.
5 Security Features in UniFi You Need to Enable (And Why)
9:11
Tech Me Out
Рет қаралды 6 М.
Unifi Security Gateway - First Time Setup
17:35
Toasty Answers
Рет қаралды 183 М.
How To Setup VLANs With pfsense & UniFi 2023
21:57
Lawrence Systems
Рет қаралды 195 М.
UNIFI FIREWALL RULES EXPLAINED
13:54
Willie Howe
Рет қаралды 51 М.
UniFi Network BEGINNERS Configuration Guide | 2024
46:14
Unified IT
Рет қаралды 174 М.
the UniFi Dream Machine Pro....the nerdiest home router
10:09
NetworkChuck
Рет қаралды 736 М.
He bought this so I can drive too🥹😭 #tiktok #elsarca
00:22
Elsa Arca
Рет қаралды 46 МЛН