Unifi New Port profiles and Traffic management

preview_player
Показать описание
In this video we take a look at the new way Ubiquiti is doing switch port profiles and traffic restrictions. I also take a look at Traffic management and the different traffic directions when blocking or allowing local networks

▶ Hire us on our website

▶ Join our Discord Channel:

------------------------------------------------------------------------------------
Affiliates I use:

▶ VOIP.MS

▶Canadian Amazon Store front:

▶USA Amazon store front:

------------------------------------------------------------------------------------
▶ Find us on social media:

▶ Instagram:

▶ Facebook:

▶ Twitter:

▶ TikTok:

▶ Linkedin:

▶ Twitch:

0:00 Intro
0:38 Taking a look at Switch port profiles
4:24 Looking at how traffic management directions work
8:00 Final thoughts
Рекомендации по теме
Комментарии
Автор

These new management scheme is confusing AF. Great explanation Cody but i wish Ubiquiti would have released a primer and some details about how this works before mass deployment.. Great Job as usual supporting your community Cody!

czummo
Автор

I used to think that the Cisco CLI was confusing but at least that's concise and consistent. The Ubiquiti GUI is fast becoming a bloated clusterfuck!

Chris-hyjy
Автор

That's such a great improvement for managing the traffic between VLANS. This method looks so much more user friendly than the previous firmware process of creating port groups, established & related rules etc, etc Great job and nice clear instructions !

ashleywebber
Автор

Your videos are awesome, Cody! Thanks for all the work you do to bring this content to your audience. So during the pandemic, my wife moved her creative agency into our house. This is also where I permanently work now. I'd love to see step-by-step setup for a small business, myself as a remote worker, and a home network all under one UDM-SE setup with wired LAN, Wi-Fi, IoT, wired and wireless cameras, client and server VPN, and Talk including firewall rules.

john-meyer
Автор

Solid content as usual Cody! Thanks for explicitly going through it. Like many others in the thread --- I think it is ridiculously confusing and I would have had it all backwards. Looking forward to the 2023 Complete you mentioned as well.

michaelogrady
Автор

Yay now what used to be 1 click is now 3! Thank you Ubiquiti for making my wrists hurt even more on large roll outs!

MillerTechnicalServices
Автор

Great video!!! I am not sure why a simple source and destination setup couldn't be created with the rules page with UI. As for the port profile I'll just say it works... I guess I am just old when I want to see terms like native VLAN and allowed VLAN/s. Either way Cody as I said before great video.

seanwoods
Автор

Great Video Cody, Always delivering above and beyond! Cheers!

ryanmiller
Автор

This is a good video, thanks!

I should move some of my firewall rules over to traffic management really.

I agree with you on the rules being confusing.

I think if the "traffic direction" dropdown was above the "local network" box and if the "target" box was called something else, you could see where the designer was coming from. But ultimately, it's bad UX.

marc
Автор

and for the 2023 i'd love to see the usual setting up a couple networks (i.e. guest, main, iot, cameras) plus this video that for the ppl that find the 2023 setup and do not know about this one, its gonna be great for them to see about ports and traffic.

MrSamucbr
Автор

Awesome videos - Would be really cool to see a full install with VLAN and best practice.

itsgeorgenz
Автор

Great video Cody - thx. In your next series it would be great if you could cover the firewall rules for things like Airplay, Sonos and Casting from your Default or trusted network to the IoT network please. Thx.

deonh
Автор

this is solid, easy and i loved the diagrams !

Poiisonfire
Автор

To me, this makes far more sense than the old way.

PrinceLX
Автор

Thanks Cody. For your upcoming 2023 network build video, I would like to see the basic setup with firewall rules for Main Network, Guest Network including both Wifi and Guest Ethernet Ports on VLAN, IoT both WiFi and IoT Ethernet Ports on VLAN, a WireGuard VPN setup like a Guest Network (Safe Video Streaming and shopping while traveling), and a shared printer setup between Main and Guest Networks. Maybe also some example of setting up multiple WiFi networks in a manner to enable/disable individual APs or even separating 2 and 5 Ghz channels per AP for testing purposes.

DavidBaldwin-kp
Автор

Cody - thanks for the info as always! In a recent live stream, you mentioned that the inter-vlan routing firewall rules are now giving some issues…I think you said specifically with devices trying to watch playback/video feed of Protect cameras on a separate camera network. In the next 2023 build, could you go over firewall rules and the updated ones you recommend for blocking/allowing inter-vlan routing?

petesiravo
Автор

Good video, thanks. Would love to see a session on Traffic Management and the available granular control of defining endpoints on network or apps and assigning them to a Wan interface, assuming using load balancing. Example, I want a group of endpoints (PCs, Macs) to always use one of the Wan interfaces (unless that interface goes down). Or, ability to do same at the application level.

Mark-jive
Автор

Thanks for this nice overview.
Still need to try it out but if they also improved the API for this, i'm all for it. There were so many awkward things due to the reliance on port profile overrides; the other fuckup was when you wanted to cleanly deprecate the default vlan. I mean cleanly, as in, it'll work well enough that you could for example replace a switch without odd crap.

If it improves... And i hope that somehow it will... Then it's not too far till we can drive this from netbox.
But for that you need to be able to say that all ports, globally should not carry X or Y except this one

udirt
Автор

With the traffic rules, what helps is to remember that across all the types of rules - "target" is the device or collection of devices or network that the rule is being applied to. So when the target is IoT, and local network is YouTube, and you are blocking traffic "to all local networks" - that's a rule that applies to traffic from IoT (target) to the YouTube network.

I do really wish thay they had used source and destination terminology because that would be consistent with the way the REST OF THE KNOWN UNIVERSE understands networking.

"Target" is just too close in meaning to "destination", hence the confusion.

woltjerl
Автор

I would like to see Unifi move "Port Profiles" up before "restrictions".
This would encourage Port Profile creation.
When you start a new setup, you have no port profiles defined, you would then select "create new profile" from the port profile drop-down, and fill out the allow and/or restrict sections, just as you would in the current setup.
But you would be able to name and save the profile for future use. 
This avoids the individual detailed setup of each port, avoiding mistakes on other ports needing the same settings, as you most likely will do under the current setup.

fishermansnook