The NEW UniFi Zone-Based Firewall is AWESOME! (complete walkthrough)

The NEW UniFi Zone-Based Firewall is AWESOME! (complete walkthrough)
Spread The Viralist



Learn about the changes in the UniFi Network 9.0 Zone-Based Firewall, and learn if it’s worth the upgrade!
🎯 Hire me: https://www.wundertech.net/wundertech-consulting/

🚀 Tutorials, comparisons, reviews: https://www.wundertech.net/
⚡Best Synology NAS Devices: https://www.wundertech.net/which-synology-nas-should-i-buy/
⚡Product Recommendations: https://link.wundertech.net/rmYt
🔔 Subscribe for more tech-related tutorials and overviews: https://link.wundertech.net/ssYt

DISCLAIMER: The information in this video has been self-taught through years of technical tinkering. While we do our best to provide accurate, useful information, we make no guarantee that our viewers will achieve the same level of success. WunderTech does not assume liability nor responsibility to any person or entity with respect to damage caused directly or indirectly from its content or associated media. Use at your own risk.

WunderTech is a trade name of WunderTech, LLC.

0:00 Intro
0:48 UniFi Zone-based Firewall vs. Existing Firewall
1:38 Upgrading to the Zone-Based Firewall
2:13 UniFi Zone-Based Firewall Changes
5:09 Firewall Rules Changes (Policies)
13:53 Creating Networks (and adding it to a zone)
15:01 Isolated VLANs + Zone Matrix
16:39 Zones and How They Work
18:28 Final Thoughts

#unifi #ubiquiti

source

Recommended For You

About the Author: WunderTech

38 Comments

  1. Interesting video and good explanation. I really like the matrix overview, but I doubt Unifi will ever replace my Juniper and OPNsense firewalls, which have had zones for many years already.

  2. @6:03 – Doesn't the firewall BLOCK by default?
    so why do you need to create so many block rules?
    I expected you will need to create a lot of allow rules.

  3. Nice. Those RFC1918 are mainly duplicates and need to be removed. The scope of the zones is defined by the ip ranges of the Networks in source and destination Zones. Anything that is not a locally defined Network or VPN range is handled by the {zone} – External zone pairs. That is the only place RFC1918 has relevance.

  4. Your videos are the best! You explain everything so clearly and in great detail making it easy to understand. I especially appreciate how you address confusions that others overlook like the multiple rules that split into zones in the UniFi firewall. Keep up the amazing work

  5. "industry leading from a ease of use perspective"
    I'm going to assume you haven't used literally any other ZBFs.
    If you haven't that's fine, just try to avoid statements like that because, to me, its cringe. Ive been a NE for over 15 years.

  6. Would you relocate the IoT network into a new zone or keep it inside 'Internal'. I wanted to get a clear picture of policies applied on IoT network with ZBF but I'm not sure if moving out of internal would break things.

  7. I don't like Unifi's interface. I find it overly complicated for no reason. Albeit what you are talking about today is not though. I hope they take this way of doing and visualizing things to their other hardware areas.

  8. It works great, a little bit of adjustment at first but the only thing I think is missing is the possibility to select many zone in source and destination.

    Sometime you need to create the same access-list to work with many source or destination networks, for example, my DNS are on a separate vlan and ALL zones need to have access to those.

    But overall, Ubiquiti are getting better and better !

  9. I'll have to watch this one more than once. Firewall rules are confusing to me. The concept is understandable. I like the change with LAN IN and LAN OUT I get into a tailspin with that when I try to implement rules.

  10. Finally, was I was waiting for since long time. Thanks for showing us the new setup and thanks to Ubiquiti 😅 it’s great 👍

  11. Newbie here. Just wondering, how do you clean up the individual threat actors' IPs that have been blocked in the firewall page? It's populating more and more and I can't seem to group them up.

  12. Zones arent new – its not a "new way to…" zones are handy, but it depends from scenerio. In enterprise environment, using zones depends from various things, but basic of this are still FW rules. Zones can be tricky to manage, so it depends. I think that ubi should simplify FW rules first and then supply it with zones, if ever needed for home users. In fact, inter vlan routing should be prohibited out of the box as good FWs does in terms of "zero trust concept".

  13. Upgraded CGM OS/Network (UniFi OS 4.1.13/Network 9.0.108) a few hours ago. I was going to wait a day or two to update to the Zone based FW. Nope.. just did that too. Took like 5 seconds and I already found some Plex rules I need to remove. I went ahead and subscribed to CyberSecure too. Not so sure about that, but yeah. Usually don't use their IPS/IDS, but wanted to give it a try.

  14. Fantastic stuff, hopefully this is a full release by the time I put in a Unifi stack (hopefully this year). Are you goign to redo the Unifi firewall tutorial with this new paradigm?

Comments are closed.