Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
6/27/2025 5:16:30 PM EDT
I recently encountered issues with some devices being accessable on a seperate VLAN (IoT) from my main (LAN) right after the most recent update to UniFi OS 4.2.12 and Network 9.2.xx (now 9.2.87).  As soon as I did the update a few weeks ago I had a number of issues at at once (yes, I was on the early release channel and since changed back to Official).  Too many old backups that were not being auto-cleaned up caused Network, Protect, Talk not to start and until that was resolved, my Esphome based garage door openers (Ratgdo) on my IoT VLAN were not accessable so I moved them back to LAN until everything was resolved.  So after spending a few hours with a Unifi Support Teach on Teamviewer he came to the conclusion that a legacy firewall rule was blocking access to the IoT network.  Now, I installed these firewall rules to support the deployment of my core/LAN, IoT and Guest networks via the video created by Crosstalk Solutions about 3 or 4 years ago.  I have not changed or updated anything related to them or the VLAN's since. Removing one legacy rule enabled communication to the IoT network, I moved all remaining devices back there and all is well.

But the outcome of the call was, the tech recommending that I migrate to the ZBF asap.  He suggested deleting any self created firewall policy rules, as well as the system generated IPS rules, migrate to ZBF and then enable proper VLAN security via ZBF.   I need to read the Unifi docs on ZBF as well as I want to review a few Youtube videos on the topic, but I was wondering has anyone here made the move to ZBF?   If so, how did you do it.....like suggested and clean up existing, migrate, create all new.....or migrate what I have and clean it up under ZBF?

I would like to create at least a work VLAN after getting the core LAN, IoT, Guest networks properly isolated and configured too..  Maybe move my Protect cams to their own also.
6/27/2025 10:31:30 PM EDT
[#1]
I did but I setup my UCG Max up as new afterwards and I only setup a Unifi system at all last year.

My gut says if you have legacy rules you can't see anymore than to just reset the gateway as new and go from there. Just create a backup first and go through your settings and write down anything that stands out to you to change with a fresh start.

Basically you have to create zones and then tailor the policies to allow/disallow that zones communication internally and then to the external internet.

If you want to put work devices on an isolated VLAN that still has outside access create the work VLAN, create a work zone, and block internal traffic to other zones.

For things like cameras/security so only your devices can access them then create your own personal VLAN and security zone, security VLAN and security zone, and then tailor the security polices so only your personal VLAN can access the security VLAN.

So in this example I'm creating a policy to allow my personal network (Zombie Net) for my devices (phone/laptop/desktop/other) access to and from the IoT security zone/VLAN (all other VLAN's are blocked).

Attached File
6/27/2025 10:32:19 PM EDT
[#2]
Also check out Lawrence Systems video below. He has other videos on Unifi's recent updates, too.

UniFi Zone Firewall Rules Explained – Secure Your Network

6/28/2025 1:01:01 PM EDT
[#3]
I have not updated to ZBF. I have several udmpros configured using basically Crosstalk's videos. Mine have updated to the versions you stated, but have not seen any issues at all. Your thread prompted me to look into ZBF. I'm not sure how it's going to help me. I have used ZBF before on many RHEL boxes, but the way I set up my vlans on the UDMPros, they kinda are already like zones, as they sit. Consequently, I am not rushing to upgrade at this time. I don't need any more problems.

Could you give us an idea what the rule that fubar'd your network was?
6/28/2025 4:40:49 PM EDT
[#4]
Quote History
Quoted:
I have not updated to ZBF. I have several udmpros configured using basically Crosstalk's videos. Mine have updated to the versions you stated, but have not seen any issues at all. Your thread prompted me to look into ZBF. I'm not sure how it's going to help me. I have used ZBF before on many RHEL boxes, but the way I set up my vlans on the UDMPros, they kinda are already like zones, as they sit. Consequently, I am not rushing to upgrade at this time. I don't need any more problems.

Could you give us an idea what the rule that fubar'd your network was?
View Quote
I wish I could have stopped the support tech, he deleted the rule before I could ask him to just disable it.  it was the last one in the list.  I guess I could go back and rewatch the video from CTS and see what's missing.  Wonder if someone has a list of their rules available.  Let me look.
6/28/2025 4:54:15 PM EDT
[#5]
Quote History
Quoted:
I wish I could have stopped the support tech, he deleted the rule before I could ask him to just disable it.  it was the last one in the list.  I guess I could go back and rewatch the video from CTS and see what's missing.  Wonder if someone has a list of their rules available.  Let me look.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
I have not updated to ZBF. I have several udmpros configured using basically Crosstalk's videos. Mine have updated to the versions you stated, but have not seen any issues at all. Your thread prompted me to look into ZBF. I'm not sure how it's going to help me. I have used ZBF before on many RHEL boxes, but the way I set up my vlans on the UDMPros, they kinda are already like zones, as they sit. Consequently, I am not rushing to upgrade at this time. I don't need any more problems.

Could you give us an idea what the rule that fubar'd your network was?
I wish I could have stopped the support tech, he deleted the rule before I could ask him to just disable it.  it was the last one in the list.  I guess I could go back and rewatch the video from CTS and see what's missing.  Wonder if someone has a list of their rules available.  Let me look.
@SR712
I found the CTS video, but I'm looking for just a list of rules vs. listening/watching the entire video.  Here is a pic of what firewall rules are left.  the "brickwall" icon is for user added rules, and the one he deleted was at the very bottom (and he had selected all, so it was showing everything).  I left out the IPS rules.  What is missing compared to yours??



6/28/2025 6:41:46 PM EDT
[#6]
Quote History
Quoted:
@SR712
I found the CTS video, but I'm looking for just a list of rules vs. listening/watching the entire video.  Here is a pic of what firewall rules are left.  the "brickwall" icon is for user added rules, and the one he deleted was at the very bottom (and he had selected all, so it was showing everything).  I left out the IPS rules.  What is missing compared to yours??

https://i.imgur.com/AyDHJQv.png

View Quote

My vLANs are different, and I don't use a Guest Network, so those things for me will be different. These are my bottom two rules:
Attached File

So maybe it was the Gateway Port Block for IoT? Don't know why he didn't just disable it instead of deleting it. Seems rather aggressive with someone else's firewall.
I've watched several videos on the ZBF, and it sure looks to me, in my cases, like it just adds another layer of complication to the firewall. I have 6 UDMPros in 5 different locations. Some pretty remote. It just feels like I don't get many benefits for a bit of headaches. Once these are configured, they will pretty much stay the same until they die.

This guy has a pretty good video:
How to use Zone Based Firewalls - Step by Step Tutorial
6/29/2025 1:38:58 PM EDT
[#7]
Quote History
Quoted:

My vLANs are different, and I don't use a Guest Network, so those things for me will be different. These are my bottom two rules:
https://www.ar15.com/media/mediaFiles/215839/Untitled-2_jpg-3575166.JPG
So maybe it was the Gateway Port Block for IoT? Don't know why he didn't just disable it instead of deleting it. Seems rather aggressive with someone else's firewall.
I've watched several videos on the ZBF, and it sure looks to me, in my cases, like it just adds another layer of complication to the firewall. I have 6 UDMPros in 5 different locations. Some pretty remote. It just feels like I don't get many benefits for a bit of headaches. Once these are configured, they will pretty much stay the same until they die.

This guy has a pretty good video:
https://www.youtube.com/watch?v=WMTfGOgyLDk
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
@SR712
I found the CTS video, but I'm looking for just a list of rules vs. listening/watching the entire video.  Here is a pic of what firewall rules are left.  the "brickwall" icon is for user added rules, and the one he deleted was at the very bottom (and he had selected all, so it was showing everything).  I left out the IPS rules.  What is missing compared to yours??

https://i.imgur.com/AyDHJQv.png


My vLANs are different, and I don't use a Guest Network, so those things for me will be different. These are my bottom two rules:
https://www.ar15.com/media/mediaFiles/215839/Untitled-2_jpg-3575166.JPG
So maybe it was the Gateway Port Block for IoT? Don't know why he didn't just disable it instead of deleting it. Seems rather aggressive with someone else's firewall.
I've watched several videos on the ZBF, and it sure looks to me, in my cases, like it just adds another layer of complication to the firewall. I have 6 UDMPros in 5 different locations. Some pretty remote. It just feels like I don't get many benefits for a bit of headaches. Once these are configured, they will pretty much stay the same until they die.

This guy has a pretty good video:
https://www.youtube.com/watch?v=WMTfGOgyLDk

@SR712

Yes, those rules you posted look very familiar.  I think I only had one, but will review the CTS video again because now my curiosity is really kicked in.  The support rep kept saying the rule or rules at the bottom were redundant and not needed...not sure if that was really accurate or if he knew it was causing some issue and just wanted it or them out of the way.  Of course, all of this was running fine for years and only after the UDM Pro console and network app updates was their conflict.  When he disabled the rule I could immediately reach/get a response from the device on IoT.  But other IoT devices were accessible, so it could have been a port range too.  Hard to say, I'll try to find the definitive rule that was deleted.  I wish there was a transcript of the chat or video support session, I assumed there was and didn't record it.

Yes, started watching another of that guy's Unifi videos and it shows a lot of promise.  I am not looking for a total redo of my current network, but this experience had me thinking I need to review and update to take advantage of any improvements with ZBF and/or whatever the current state of the art is for network/VLAN security.
6/29/2025 2:50:51 PM EDT
[#8]
Quote History
Quoted:

@SR712

Yes, those rules you posted look very familiar.  I think I only had one, but will review the CTS video again because now my curiosity is really kicked in.  The support rep kept saying the rule or rules at the bottom were redundant and not needed...not sure if that was really accurate or if he knew it was causing some issue and just wanted it or them out of the way.  Of course, all of this was running fine for years and only after the UDM Pro console and network app updates was their conflict.  When he disabled the rule I could immediately reach/get a response from the device on IoT.  But other IoT devices were accessible, so it could have been a port range too.  Hard to say, I'll try to find the definitive rule that was deleted.  I wish there was a transcript of the chat or video support session, I assumed there was and didn't record it.

Yes, started watching another of that guy's Unifi videos and it shows a lot of promise.  I am not looking for a total redo of my current network, but this experience had me thinking I need to review and update to take advantage of any improvements with ZBF and/or whatever the current state of the art is for network/VLAN security.
View Quote View All Quotes
View All Quotes
Quote History
Quoted:
Quoted:
Quoted:
@SR712
I found the CTS video, but I'm looking for just a list of rules vs. listening/watching the entire video.  Here is a pic of what firewall rules are left.  the "brickwall" icon is for user added rules, and the one he deleted was at the very bottom (and he had selected all, so it was showing everything).  I left out the IPS rules.  What is missing compared to yours??

https://i.imgur.com/AyDHJQv.png


My vLANs are different, and I don't use a Guest Network, so those things for me will be different. These are my bottom two rules:
https://www.ar15.com/media/mediaFiles/215839/Untitled-2_jpg-3575166.JPG
So maybe it was the Gateway Port Block for IoT? Don't know why he didn't just disable it instead of deleting it. Seems rather aggressive with someone else's firewall.
I've watched several videos on the ZBF, and it sure looks to me, in my cases, like it just adds another layer of complication to the firewall. I have 6 UDMPros in 5 different locations. Some pretty remote. It just feels like I don't get many benefits for a bit of headaches. Once these are configured, they will pretty much stay the same until they die.

This guy has a pretty good video:
https://www.youtube.com/watch?v=WMTfGOgyLDk

@SR712

Yes, those rules you posted look very familiar.  I think I only had one, but will review the CTS video again because now my curiosity is really kicked in.  The support rep kept saying the rule or rules at the bottom were redundant and not needed...not sure if that was really accurate or if he knew it was causing some issue and just wanted it or them out of the way.  Of course, all of this was running fine for years and only after the UDM Pro console and network app updates was their conflict.  When he disabled the rule I could immediately reach/get a response from the device on IoT.  But other IoT devices were accessible, so it could have been a port range too.  Hard to say, I'll try to find the definitive rule that was deleted.  I wish there was a transcript of the chat or video support session, I assumed there was and didn't record it.

Yes, started watching another of that guy's Unifi videos and it shows a lot of promise.  I am not looking for a total redo of my current network, but this experience had me thinking I need to review and update to take advantage of any improvements with ZBF and/or whatever the current state of the art is for network/VLAN security.
@SR712

I just watched the original CTS video again and found out what's missing as well as the likely issue I was having.  If you watch the video again, starting at 23:37 is when he starts to discuss the last rule, the one thats missing off of my list and what the support tech must have deleted.   Chris @ CTS is saying, block access to the UDM-Pro GUI (login) via ports, but leave access to the gateway for each network so you have internet access.  Its done by a 3 step process:  

1) create an "All Gateways Group" which has a list of all network gateway ip address i.e. 192.168.1.1, 192.168.10.1, ....20.1, etc.
2) Create UDM-Pro Access Ports Group: 80, 443, 22
3) Create LAN LOCAL IPv4 rule: "Block IoT from UDM-Pro access"... this starts at 25:33 into the video

#3 rule above is what he deleted.  I'm guessing something in it was blocking access to the ratgdo on one of those ports or something like that.  I have not tested this yet, but if reconnect my PC to the IoT network, I'll see if I can access the UDM-Pro login screen, my guess is yes.




6/29/2025 4:12:30 PM EDT
[#9]
6/29/2025 6:56:56 PM EDT
[#10]
I've been reading and watching ZBF info and I'm glad I did.  I need to create some new VLAN's, clean up some wiring & assign some physical ports to VLAN's for cameras, AP's, etc. and revisit how I have my basic infrastrructure set up.  Shouldn't be a big deal and long overdue.   Then do the migration to ZBF and delete all of the old rules and set up everything from scratch with ZBF.  Those two new videos (have not watched all of both of them yet) are very good and while he talks alot it really helps someone like me who is all self taught about this stuff understand it all before moving on.  The series of videos he created is very good.. goes all the way back to very simple basics and builds on it each step of the way.  I need to revisit a few sections of it, but in general its pretty straight forward how he has the networks/wifi/vlans and existing rules set up....  and the rules don't really matter since you wipe them out and start over with zbf.

Sign up to continue the discussion

Create a free account to share your thoughts, follow topics, and connect with the AR15.COM community.

Already a member? Sign In