Ubiquiti Networks - Deep Packet Inspection - DPI Introduction

preview_player
Показать описание
This video will give you a quick introduction to Ubiquiti's Deep Packet Inspection before we begin building firewall rules with it.

From the Ubiquiti Site:
Compared to traditional packet analysis tools which only give a glimpse of packet information such as port number and IP address, Deep Packet Inspection is a method used to analyze the actual data contents in the IP packet, in some cases even encrypted traffic.

When enabled (whether via GUI or CLI), the DPI engine drills down to the core of the packet, collecting and reporting information at the Application-layer, such as traffic volume of a particular application used by the host. To omit information about application type, select hosts only.

By default, the DPI engine recycles data after 30 minutes of inactivity. However, the DPI engine still retains data for any combination of host and application that passes traffic without 30 minutes of activity.

Compared to the expensive and slow DPI methods in today’s router market, Ubiquiti’s proprietary DPI tool integrates with EdgeRouter’s hardware offload feature. This means the DPI supports the most common network traffic and protocols, including IPv4, VLAN tags, PPPoE, and more.



Conveniently, EdgeOS uses an automatic signature update mechanism (daily cronjob scheduled at 06:25) to ensure that your router is using the latest DPI signatures for comprehensive traffic analysis. Routinely, Ubiquiti pushes updates to your EdgeRouter, extending the functionality of the DPI mechanism.

Please subscribe! Give a thumbs-up, comment, and share!
Рекомендации по теме
Комментарии
Автор

Great stuff! I've been waiting to see this!

jrmbtr
Автор

I just bought an ER-X and I'm really enjoying the DPI/top hosts reporting. Is there a way to generate reports for a given day?

someguy
Автор

Another great video, keep them coming... !!

mrrosslwilliams
Автор

First off I want to say that I watch all your videos on EdgeMAX they are very easy for a noob such as me to understand. My question is.
Can a specific device on my network be omitted from DPI ?

cvtierney
Автор

This was a very nice video. I am going to get a USG along with a nice Edge Router and Switch for my home network segment. Could you do a proper webcast on a full Ubiquiti stack setup?

RedWollip
Автор

That's an impressive display of dpi by ubiquiti. I have a edgerouter lite with an ap pro. If I purchased a usg I guess I wouldn't have a need for an edgerouter. Any Input willie ?

jungleboyfromoz
Автор

Is there a way to list complete urls that have been requested?

vespinonl
Автор

Great Video.
have they updated the GUI any so someone can use the firewall to block say KIK or similar, in your video i seen snapchat

ShaneS
Автор

what's the time frame of the EdgeMax is gathering all this info? is it the duration of the uptime, or withing 24 period? I'm looking at mine and it says "Web-Other as 10.87Gbytes/7.25Gbytes". Seems heavy.

theSilentWill
Автор

Willie hello how are you.
I'm having some trouble regarding this Traffic Analysis. I have a Synology with many "OTHER" traffic that i'd like to name, and i know it's from my plex server. I tried to add a Category to it and the "Apps" section doesn't seem to work. How to add this?

RoqueSantosJunior
Автор

Hi, have you tried with flow analysis? I read about it and it says it would not be able to indicate the message hidden the packet. From this statement, if it is done Flow Analysis, we will not able to tell the categories that are shown under streaming media..etc. Am I right?

roverteam
Автор

I really like how Unifi presents traffic data inside the controller - but as you said that requires an USG and I use an Is there any way to get similar traffic statistics with an EdgeRouter?

ChrisHolzer
Автор

Is there a way I can see which websites are my clients browsing?

marlon
Автор

Some DPI setups require a certificate be added to the clients. I assume they are taking apart https packet info. Watch guard routers I administer are this way.

willrunfun
Автор

Looks like the Unifi site is a killer resource. How does one gain access to this?

linuxpcme
Автор

Willie nice video, can you please point me, how can I secure a SOHO network using edge router, I have a client that is concerned about hacker and inbound attack. So that I can provide to him simple firewall solution

raphalink
Автор

I am new to Unifi and was looking at DPI data. The data make no sense without time dimension. Simple google search shows me unifi users arguing the case since 2015 for inclusion of time based analysis but unifi has no action. People as influential as you and cross talk guy should make your pitch as after all your clients should not accept such limitations. The info from DPI now is rubbish without time dimension. Well I can see two options. I have home assistant where I have over 100 sensors pushing info to time series database influxdb (open source) and use grafana (opensource) to make various graphs and in a second when I select time/data/range all my info get refreshed in database. So
a) Unifi allow users a path to pull info to their own install of influxdb or similar from which we could use tool a like grafana to do charting or analysis. These software can be easily hosted in a docker container. This is for advanced users. I am anyway running unifi controller on a Debian->proxmox VE-> windows 7 and I have Prxmox ve-> Debian in the another LVM running docker and on top of that various docker containers
b) build in influxdb or similar time series into the unifi controller software to store info and because info in a time series adding time dimention is very easy rather than retaining data in a normal dabase. Influxdb is open source product so with a donation to the community it should be easily adopted

ianrobertson
Автор

I am new to Unifi and was looking at DPI data. The data make no sense without time dimension. Simple google search shows me unifi users arguing the case since 2015 for inclusion of time based analysis but unifi has no action. People as influential as you and cross talk guy should make your pitch as after all your clients should not accept such limitations. The info from DPI now is rubbish without time dimension. Well I can see two options. I have home assistant where I have over 100 sensors pushing info to time series database influxdb (open source) and use grafana (opensource) to make various graphs and in a second when I select time/data/range all my info get refreshed in database. So
a) Unifi allow users a path to pull info to their own install of influxdb or similar from which we could use tool a like grafana to do charting or analysis. These software can be easily hosted in a docker container. This is for advanced users. I am anyway running unifi controller on a Debian->proxmox VE-> windows 7 and I have Prxmox ve-> Debian in the another LVM running docker and on top of that various docker containers
b) build in influxdb or similar time series into the unifi controller software to store info and because info in a time series adding time dimention is very easy rather than retaining data in a normal dabase. Influxdb is open source product so with a donation to the community it should be easily adopted

ianrobertson
visit shbcf.ru