Secure IoT Network Configuration

  Рет қаралды 409,575

Crosstalk Solutions

Crosstalk Solutions

Күн бұрын

▶ Check out my gear on Kit: kit.co/crosstalk
How to configure a network for segregating IoT devices.
Equipment used in this video (Amazon affiliate links):
EdgeRouter 4: geni.us/NuI6y
US-24-250W Switch: geni.us/8Be5
UAP-AC-PRO: geni.us/q8CLX
iClever smart plugs: geni.us/x6LnBB
Crosstalk Store on Amazon - RECOMMENDED PRODUCTS: www.amazon.com/shop/crosstalk...
Crosstalk Discord: / discord
Amazon Wish List: a.co/7dRXc67
Crosstalk Solutions offers best practice phone systems, network design and deployment, and UniFi Video camera systems. Visit CrosstalkSolutions.com for details.
Crosstalk Solutions is an authorized Sangoma partner and reseller.
Connect with Chris:
Twitter: @CrosstalkSol
LinkedIn: goo.gl/j2Ucgg
KZfaq: goo.gl/g4G58M

Пікірлер: 441
@jonathanleon-oakley6974
@jonathanleon-oakley6974 5 жыл бұрын
I can't thank you enough for all your super simple but through explanations of all the concepts that you teach. You are an absolute legend!
@CrosstalkSolutions
@CrosstalkSolutions 5 жыл бұрын
Cheers - thanks!
@tobyport5873
@tobyport5873 3 жыл бұрын
For those who have issues casting from Private to ioT network with Chromecast - you need one more rule. Add to the ioT Local Ruleset: allow UDP, destination port 5353(mDNS). [match the allow ioT DNS rule, just using port 5353]. You're welcome.
@joshmoore1292
@joshmoore1292 Жыл бұрын
I just started to setup my 1st iot network today. Literally. Then, I stumble on this video. Absolute gamechanger. You sir, are a gentleman and a scholar!
@patsjoholm
@patsjoholm 4 жыл бұрын
MQTT is used to broadcast JSON (or similar, i.e. YAML) requests. On IoT devices, this normally tells an MQTT server the status of that device (i.e. on or off, or temperature/humidity). It can also be used to turn the device on off, of course, via 2 way communication. It is highly efficient, as the packets are tiny, and is widely used in the Home Assistant environment, for example. P.S. Nice video. I am obviously here, as my weekend project, coming up, is to move onto a new router, switch, and AP, and implement VLANs for my IoT devices. Thanks for the share!
@ulkesh78
@ulkesh78 5 жыл бұрын
This is one of the best guides to this setup I've found. Excellent info and great presentation man!
@phoenix112308
@phoenix112308 Жыл бұрын
Your videos are great ! Straightforward and to the point while being clear and conveying information in a way that anyone can understand. LOVE your channel !
@RyanRath
@RyanRath 5 жыл бұрын
Ha! Crazy small world, I did this two weeks ago for my setup at home as well. Great content Chris, love the channel
@independentRestorationServices
@independentRestorationServices 5 жыл бұрын
Thanks for this! It’s such a pain trying to search 20 places to put all of this together is super convenient.
@zeeshanh8360
@zeeshanh8360 5 жыл бұрын
I hit like on this even before watching as this is something everybody should do - at least anyone with IoT devices. Before I made my first IoT purchase (t-stat & lights) I made sure to setup a separate SSID, vLAN & routing/firewall rules. This was early on & the devices used were not ideal, but I committed to not getting any IoT devices until this was at least somewhat segregated from my main LAN. I strongly recommend to any/everybody to setup vLAN or even subnet to isolate traffic (something's better than nothing). PS - SSID is excellent! Also like the 107.
@brooksdbetts
@brooksdbetts 5 жыл бұрын
Great video...been thinking of doing this at my house but just did not want to invest the time to research the firewall rules I needed. This is a great guide which gives me NO excuses now! ;)
@Ben-ld5lt
@Ben-ld5lt 2 жыл бұрын
Very well explained! I followed this comprehensive video today and set up an IoT network for my TP-Link smart plugs. Thank you Chris.
@Muttonbird
@Muttonbird 5 жыл бұрын
Great timing for a great video. Thanks Chris, very helpful indeed and was just wondering about setting all this up the other day so cheers! Looking forward to your next vid.
@kalbachekal
@kalbachekal 5 жыл бұрын
Hi Chris Please make a video for IoT devices again with USG router. From London with love
@ppi57
@ppi57 4 жыл бұрын
Yes please
@dacman61
@dacman61 5 жыл бұрын
I've been meaning to do this at my home. Looks like I got a project to do this weekend. Thanks for the video!
@lightrecordsentertainment9720
@lightrecordsentertainment9720 5 жыл бұрын
can you make a video or a article on your website for the USG? so we can follow along with the USG
@CodeMonkeX
@CodeMonkeX 5 жыл бұрын
I agree. It seems people with an edge router are already more experienced, so it would have been a better idea to demo this on a USG and then let the edge ruler folks fill in the blanks.
@epremsoft
@epremsoft 5 жыл бұрын
I totally agree!
@CrosstalkSolutions
@CrosstalkSolutions 5 жыл бұрын
Maybe - but it would take a lot more setup on my side. I don't use a USG internally. Keep in mind though that it's *almost* the same...you just have to do Corporate LAN instead of VLAN-only when creating the IoT network in UniFi...and then just add the same firewall rules in UniFi instead of the EdgeRouter.
@madrian_hello
@madrian_hello 5 жыл бұрын
Agreed. I have full Unifi ecosystem.
@muflon2002
@muflon2002 5 жыл бұрын
+1
@KeyJayHD
@KeyJayHD 5 жыл бұрын
Excellent video dude! I just joined the Ubiquity family with two Pro AP's and an Edgerouter 4. I'll still be using my Netgear GS724T switch for the time being, but we also just put in a new security system and I'll soon be spinning up a Blue Iris camera system. I also have a media server on the network. I'm going to try and replicate this for my camera system. Essentially, I may create a total of 4 VLAN's which one will be for cams and another for my existing Smarthings IOT network. I'm still pretty new to all this level of control (I mean my old router did allow me to SSH into it and make a few changes), but I have high hopes. I'm liking the Ubiquity platform thus far (just started literally yesterday) and will start digging in deeper today as soon as my new router comes in. Thanks again for these detailed quality videos; it's really helping me get off my feet with this.
@Firespyer
@Firespyer 5 жыл бұрын
The S in 'IoT' is for Security
@svampebob007
@svampebob007 5 жыл бұрын
the IDIoT tag is hilariously ironic.
@markarca6360
@markarca6360 4 жыл бұрын
@@svampebob007 Hahaha... #lmao
@H0lyheath3n
@H0lyheath3n Жыл бұрын
this is a great tutorial. I used it to build by IOT network about 3 years ago, shortly after you posted it. I finally wised up and built a Pihole on an old PC since I can't find a Raspberry Pi anywhere for reasonable. I came back to this video to see what I was missing on my firewall. The rules you have, fixed me right up. Your Pihole video was really helpful as well. At the end of this video you talk about other firewall rules that could be setup. Any chance you have a blog or video talking about those other rules? Example blocking DHCP for anything other than the pihole.
@wrightpc1215
@wrightpc1215 5 жыл бұрын
This couldn't have come at a better time... Thanks Chris really appreciated 👍
@shadez7650
@shadez7650 4 жыл бұрын
Outstanding video. You make things very clear for even people who aren't the best or that knowledgable to do this stuff.
@M4l3k0
@M4l3k0 4 жыл бұрын
Finally picked up a managed switch to implement this and worked a dream! Thank you for such good videos explaining everything and making it straight forward. I came across one snag. I enabled mDNS but still couldn't see any Google Devices - other IOT devices worked and I could control etc. I found that adding a third rule to the IOT_LOCAL to accept port 5353 on UDP fixed the issue. Hopefully this was the right thing to do!
@crpledger
@crpledger 4 жыл бұрын
Thanks for the tip! Android devices found my Chromecasts fine but Apple ones didn't until I added the extra rule.
@aaronboggs5799
@aaronboggs5799 4 жыл бұрын
Thank you! This solved my issue with not being able to see Chromecasts in my IoT network on my trusted LAN. After doing lots of troubleshooting and config tweaks, this is the change that finally resolved it for me.
@mikecullen1181
@mikecullen1181 4 жыл бұрын
You rock. This allowed my private LN to talk to devices on my IDIoT LAN using the Apple Home app. What I'm not able to do is connect to these devices when I am outside the network, i.e. on LTE. Do you think that needs a similar 5353 entry on WAN_LOCAL?
@juanmanuelius
@juanmanuelius 3 жыл бұрын
Thanks for the tip!
@andrewslater6846
@andrewslater6846 5 жыл бұрын
I understand that by having your private network on a separate VLAN from your IoT devices you will save a lot of bandwidth on the private LAN. But, on average, how much bandwidth do the IoT devices eat up on your internet connection? You seemed to touch on internal traffic, but I would like to know how much traffic the devices have to the outside internet. This is a wonderful video explaining what the general public should for IoT setups. I haven't found anything else that covers this topic as simply nor as completely as you have. Thank you!
@kycsip3066
@kycsip3066 3 жыл бұрын
This is really great stuff. I have a UDMpro and I'm trying to setup a secure iot network, this is almost exactly what I need. I only say almost because I know next to nothing about networks so I'm making educated guesses as to how the edge router configuration translates to the UDM. It would be extra awesome to have this same video remade with the new unifi interface.
@6Wojcieech
@6Wojcieech 3 жыл бұрын
I think the interest in such material would be very high.
@CoFRHeLLsFuRy
@CoFRHeLLsFuRy 2 жыл бұрын
Agreed. A new video with all Unifi hardware would be awesome. Get why it wouldn't be a priority but sure would be nice.
@garygrobard4095
@garygrobard4095 5 жыл бұрын
Stuff to think about: 1. Remove/blackhole VLAN1 2. Add new default VLAN to replace VLAN1 3. Add a management VLAN 4a. DNS reflection rule. I use this to redirect all external DNS requests from internal clients to my DNS server from any incorrectly configured client. (I do this for NTP as well as some devices don't accept the DHCP NTP option). 4b. DNS block internal clients from using external DNS services. I've been thinking/working on blocking internal clients from using DNS over HTTPS and/or TLS..... 4c. Move internal DNS server to HTTPS or TLS Going down a rabbit hole. Stopping now. Keep up the good work. You not only need to have a grasp of the tech, but also the charisma to present it. Well done!
@CrosstalkSolutions
@CrosstalkSolutions 5 жыл бұрын
Good feedback - thanks!
@pauldean9671
@pauldean9671 5 жыл бұрын
Restricting access to external DNS servers is a good idea. How do you plan to block DNS over Https/TLS? I think it’s built into the browser so how would you be able to detect the DNS request? I’d like to do this also.
@jjrican72
@jjrican72 4 жыл бұрын
Hi Chris, Do you have a tutorial on how you setup the Pi-Hole you mention on your "Secure IoT Network Configuration" video?
@AlanW
@AlanW 3 жыл бұрын
Haven't finished watching yet, but let me say I love the names you gave things.
@DRUMSBH
@DRUMSBH 5 жыл бұрын
Thank you Chris for the tutorial! Note to others regarding mdns repeater; I had to reboot my Edge Router X before this would work.
@johnraahauge4552
@johnraahauge4552 5 жыл бұрын
Thank you, Thank you, Thank you!! Have been messing with this for hours until I decided to read the comments. Now it works!!
@johnraahauge4552
@johnraahauge4552 5 жыл бұрын
I also found that I had to make a rule in the IDIoT_Local ruleset to allow UDP 5353 or mDNS wouldn't work both ways
@AlexJustesen
@AlexJustesen 5 жыл бұрын
Perfect IoT ssid... perfect
@mattproto5486
@mattproto5486 3 жыл бұрын
Love to see this video updated for the UDM-Pro. Could you do this for both a main network and guest network setup (showing all three separate but showing the guest or main networks being able to access airplay, Chromcast, etc). I want to be able to access all networks from the main network, but have my iOT be separated off
@speedup070605
@speedup070605 5 жыл бұрын
Hi Chris thanks for the wonderful content, this help me a lot in setting up the firewall in my network. Also hope you don't mind if you can post a procedure on how we can forward UDP broadcast to certain VLAN. Again thank you so much for the content you have shared.
@MikeySoft
@MikeySoft 5 жыл бұрын
Thank you for the execulent video. I tested it on an old sonoff device flashed with tasmota. The only thing I had to do was add a rule for the IoT network for the MQTT server on my raspberry pi. I don't feel I need this for my tasmota devices but plan to use it for my IoT devices which use the cloud such as my thermostat and wyze cameras.
@packetguy42
@packetguy42 5 жыл бұрын
This is a nice first cut for improving IoT security, but you should really have separate VLANs for each unique type of IoT device or you'll be vulnerable to lateral attacks within the IoT domain: e.g., access control on one VLAN, video surveillance on another, home automation on a third, entertainment on a fourth, etc. For WiFi, put each device on a separate WLAN group, and use hidden SSIDs to eliminate unnecessary beaconing polluting WiFi spectrum, and then associate those WLANs with the corresponding IoT VLANs. Now you can control all communication between IoT realms and between IoT, the protected LAN, and the Internet. This last control is often overlooked: always filter Internet traffic from each IoT device to only permit addressing the public IPs they actually need, rather than the entire Internet. You can discover which destinations and protocols these are by initially denying all Internet traffic and checking the firewall logs to see what is getting denied.. This is the standard for enterprise IoT security, as implement by Cisco, Juniper, etc, and is also the approach used going forward in automobile and aircraft IoT networks. An interesting article on IoT enterprise deployment is www.networkworld.com/article/3213868/3-real-world-examples-of-iot-rolled-out-in-the-enterprise.html
@mechanix6191
@mechanix6191 4 жыл бұрын
Great video. Having a hard time translating the Edge Router firewall to the UniFi controller firewall. For example, I don't see a Interface option and I'm also unsure about setting the source versus destination.
@EmilianoSandler
@EmilianoSandler 5 жыл бұрын
Amazing video. Followed your config for my network and started transferring my IoT devices. I have an EdgeRouter 4, Cloud Key (Gen 1), US-8-150W, 2x UAP-AC-PRO, so the setup is pretty the same as yours. I have a streaming box with Kodi and it's configured to access my media library from my NAS using NFS. If I transfer my streaming box to the IOT VLAN, how do I allow it to connect with NFS to my NAS?
@zeddyorg
@zeddyorg 5 жыл бұрын
It would be good if you could show people how to handle devices like Phillips Hue, Sonos etc. that need an igmp proxy. I never got this working on my USG
@ChipLinck
@ChipLinck 5 жыл бұрын
I didn't set up a proxy and Hue works just fine for me. I put all of my IoT on a separate VLAN, and my firewall rules completely separate it from my other 3 VLANs. I control the Hue lights either through my Echo devices, IFTTT applets, or my phone app, which connects through the cloud rather than on the same network. Having said that, my Hue bridge was already set up before I created the IoT VLAN. This setup works for all of my devices except the Harmony hub. In that case I only need it to see my phone if I want to make changes, since I use a Harmony remote rather than the phone app to control my media devices with the hub. I'm using a USG.
@chrisdvorak8180
@chrisdvorak8180 4 жыл бұрын
I'd also add Samsung SmartView App to this list to help with. I just started testing an IoT VLAN network. My Samsung Smart TV (8 series) is hard wired my my UniFi switch, so I changed the port on the switch to be connected to this VLAN network. This worked to assign an IP within the range of the VLAN. My problem now is that the app on my phone, in my primary LAN network can not connect to the TV. It can see it, but not connect. I have tried a bunch of different firewall rules based on your video, but have yet to be successful. Would also +1 doing this same video with a full UniFi system. Love your videos though!
@ppi57
@ppi57 4 жыл бұрын
Yes please
@TimCancila
@TimCancila 4 жыл бұрын
I was able to get Sonos talking from my secure IoT network to my LAN by following the steps from this post community.ui.com/questions/Yet-another-Unifi-and-Sonos-post/933bc98e-55b7-426a-a58b-8a4c6dc03f24#answer/1772e10a-e4b4-450b-a577-8bbbbfa39517
@notguiltystyle
@notguiltystyle 3 жыл бұрын
Thanks, works great for wireless devises. How would I allocate one of the Edgerouter ports for wired devices?
@j.j.6461
@j.j.6461 3 жыл бұрын
Chris, You do an outstanding job with the videos! Can you do a side-by-side comparison of EdgeMax vs USG? It would save time and effort for a USG focused. Thanks!
@sinterklaashoekschewaard
@sinterklaashoekschewaard 2 жыл бұрын
Great tutorial! Exactly what I was looking for. Only thing I had to do next to this tutorial is to allow UDP port 5353 in the IOT_local firewall rules. This made my Chromecasts visible again in my main LAN. Just MDNS did not do the trick for me.
@joepalovick1915
@joepalovick1915 5 жыл бұрын
Great video! Thanks for pulling it all together. My challenge has been trying to get Sonos speakers on an IoT network!
@CrosstalkSolutions
@CrosstalkSolutions 5 жыл бұрын
Not every IoT device is going to work on the IoT network. Some require local network access to function - such as Philips Hue. But, if you can get *mostly* everything over there, that's better than not having it at all.
@joepalovick1915
@joepalovick1915 5 жыл бұрын
Good point! It seems like cloud based devices like Smartthings, Ecobee, Echo etc adapt very easily to an IoT network. Local network centric devices especially like Sonos are much more difficult. Keep up the great work and thanks again.
@madrian_hello
@madrian_hello 5 жыл бұрын
en.community.sonos.com/advanced-setups-229000/access-sonos-from-a-different-wireless-network-6808767 this?
@craigcoffman69
@craigcoffman69 2 жыл бұрын
Solid information Thank You! Answered a LOT of questions but.... Now I have just as many new questions!!!
@XorgBot
@XorgBot 5 жыл бұрын
Great video! ... Talking about IoT, have you heard of anything Ubiquiti and 802.11ax (WiFi6) road map, rumors or other?
@DaniloFusco
@DaniloFusco 2 жыл бұрын
For anyone struggling with vlans and the dual wan feature you want to add the modify balance profile to the vif as per the parent eth interface.
@CodySuders
@CodySuders 3 жыл бұрын
I'd love to see an updated version of this. and using a separate security vlan for protect. +1 more for wanting to see this with UBNT gear, maybe a new dream machine pro.
@staaldak
@staaldak 3 жыл бұрын
Hey Chris! Thanks for the guide. Much appreciated. I followed the guide to the letter, including setting up an mdns repeater on my EdgeRouter 6P, but I still could not see my Chromecasts (on the IoT vlan) from devices running on my trusted vlan. I solved this by adding the following third rule to the IDIoT_LOCAL ruleset: rule 3 { action accept description "Allow MDNS" destination { port 5353 } log disable protocol udp } I can now stream to my Chromecasts and TV's on the IoT vlan from devices on the trusted vlan. I hope this helps someone!
@JJFlores197
@JJFlores197 4 жыл бұрын
Just wanted to say thanks for this awesome video! I'm planning on implementing a fair mount of this on my own home network as well. I'm having some issues in planning on how to do this, though. I'm using Ubiquiti for my networking equipment. I have a USG 3P router, 2x UniFi 8 switches and 1 UniFi AP Lite. I have my home and IOT networks configured and mostly working as I'd like. The issue is trying to figure out how to correctly work my ESXi server and VMs into the equation. As it stands, I have my Windows Server 2019 VM running DHCP and file storage, 2 Ubuntu servers: 1 for Pi-Hole and the other for the Ubiquiti controller. With the current setup, my home network gets ip address just fine. The thing I'm trying to figure out is how to get my Server 2019 to handle DHCP for the IOT network. I'm currently using the USG router as a DHCP server for that network, but my goal is to have the Server VM serve IPs for both my home and IOT network. If I recall from the couple of Cisco classes I took a few years ago, I need to have trunk ports on my switches in order for my VLANs to work correctly. I don't think Ubiquiti uses the term "trunk" in this use-case and I believe I have that configured correctly on my equipment. The problem I'm having is figuring out how to get my ESXi host and Windows Server VM to work across VLANs. If anyone has any suggestions or pointers, I'd greatly appreciate it.
@igitrust6481
@igitrust6481 Жыл бұрын
Thank you for all your videos - I’m new to the home network world and set up my own thanks to you. Any place I can get this detailed info for TP Link short stack?
@quezad01
@quezad01 3 жыл бұрын
Great video explanation!!! One suggestion: You should do a video on how to connect to a SONOS speaker in the IoT VLAN from another VLAN.
@timon0x31
@timon0x31 4 жыл бұрын
OpenDNS is a very good backup for your IOT network. I also have my USG relay through it says I don’t have a piehole.
@cue03
@cue03 4 жыл бұрын
Great video. Do all your smart devices still have accessibility from your smartphone or tablet while outside of your house coverage area? If you have camera that has both a direct connection while on your network but web connection while not on your network is that also possible and able to be secure like you have isolated everything else? I don’t want to loose functionality or accessibility from anywhere of the “smart” items I am buying or have. Thanks
@SheldonMahase
@SheldonMahase 2 жыл бұрын
Great job. Clear clean instructions. I used it on a USG-Pro-4 , cloud key and a UniFi Switch 16 POE-150W. I have successfully blocked all internvlan communication and so on. I don’t have any Ubiquiti access points. I have 2 questions. 1. I wish to block internal communication between devices inside the guest network? 2. Is there a way to limit speeds via mac accress or IP without using a Ubiquiti AP? I know this can be handled on the Ubiquiti APs I am looking or a firewall rule or a setting without using ubiquity APs.
@fredriklundberg4161
@fredriklundberg4161 4 жыл бұрын
I followed the great video thanks but have a question. The rule to drop all local traffic on the IDIoT network; does that not mean they cannot talk to each other if needed? Love your videos!
@MShadowZero1
@MShadowZero1 5 жыл бұрын
hello i want ask how i can cast file like KZfaq from one vlan to another vlan ? thank you
@markdeejay7
@markdeejay7 5 жыл бұрын
Hi Chris....At 20.40 you explain that the "Allow Established/Related" rule is tied to the network group. This differs to the same stage in Willie Howes video on the same topic. Can you confirm that both the "Allow" and "Drop" rules on the "IN" ruleset are tied to the network group please? Thanks in advance.
@tedbeckwith2997
@tedbeckwith2997 4 жыл бұрын
I know it is asked a lot in the comments for a separate USG video but how about just a side by side comparison of the settings you use in the video for the ER with what/where/who they are in USG in a tabular form or graphically shown with screen grabs?
@Akbar_Friendly_in_Cherno
@Akbar_Friendly_in_Cherno 4 жыл бұрын
Chris, I thought that "Local" was traffic destined for the router itself. (router services etc) You are saying here that it's on the VLAN itself. And inter-VLAN. Can you elaborate on this please?
@MarkFern90
@MarkFern90 3 жыл бұрын
That's my understanding as well. Was about to comment that and saw your post. Any intra-VLAN communication wouldn't necessarily hit the firewall (i.e. it could just be directed by the switch), so firewall rules wouldn't apply. I'm no expert but I've used the local rule only to limit access to the management interface to the router itself from the unsecure network.
@gp5173
@gp5173 5 жыл бұрын
Great video and very timely with IoT growing in popularity. One question, will this still allow for HomeKit traffic / control from the outside. For example controlling a iDevices switch using Apple HomeKit while on the road ? My understanding is that mDNS responder ‘should’ allow that but if not can you mention here how you can enable that kind of remote access to control outside of the home ? Thanks
@jimnichols5584
@jimnichols5584 2 жыл бұрын
Great video. Would like to see this done with the UniFi controller instead of the Edgerouter. Similar concept but nice to see the exact screens
@danbrown586
@danbrown586 5 жыл бұрын
Thanks for this video; it's been something I've been wondering/concerned about for a while. I'm pretty sure I can translate the EdgeRouter setup to my pfSense box, and the Unifi controller instructions will transfer directly to my WLAN, but my main switch is a Dell PowerConnect 5524P. I don't suppose you'd have any suggestions on setting up the "untagged port" there? I'll look through the docs, of course, but the manual is 700+ pages and poorly organized. Thanks again for this one. Edit: OK, I think I have it sorted on the switch. First, the ports which feed your AP(s) and your router have the Port VLAN Mode set to "General". PVID is set to your default VLAN ID, VLAN list includes that ID as untagged, and 107 (or whichever ID you choose for the IoT net) as tagged. The port that feeds my Roku has Port VLAN Mode set to "Access" (which is the default mode), with the VLAN List containing only 107. I think my firewall rules still need a little work, but I'm getting there.
@Kryoxys
@Kryoxys 3 жыл бұрын
Chris, any chance you could do an updated version of this video using a UDM Pro?
@richarddinges
@richarddinges 3 жыл бұрын
Hi Chris, thanks for this clear tutorial! I take the first steps in the edgerouter and to increase knowledge I did set this configuration up... But when I connect to the IOT wifi and go to the internet, I get no response. Looking at the statistics of the firewall, it is all blocked by the local default action.. drop.. For internet access on the IOT network, do you need to add a firewall rule to allow new traffic? Or do I do something wrong elsewhere?
@therandomking1265
@therandomking1265 4 жыл бұрын
Where do you get all the Ubiquiti Visio stencils from that you use in all of these videos?
@baldknobby
@baldknobby 5 жыл бұрын
Would like to see similar video with USG instead of Edge Router. Thanks.
@kevin973
@kevin973 4 жыл бұрын
Would be great to have a video for the Secure VLAN and firewall rules !
@myatix1
@myatix1 4 жыл бұрын
Great video Chris... Thanks! :) How do the EdgeRouter clans work with a Unifi Switch? Do you have to duplicate the same vLans on the Unifi Switch? IE: Configure a vLan on the EdgeRouter and then the same vLan in Unifi?
@stevenmorris5546
@stevenmorris5546 2 жыл бұрын
Great video"s nicely explained, getting my Dream Machine Pro in a few day so will be using you videos to help me set it up me being a network novice, I have one question, Seri needs to be on the same network has you iPhone or so it keeps telling me 🙂 so if you put your iPhone on the main network and Seri on the IOT network would this work? Thanks again for the great content 👍🏻
@erikmarschang2245
@erikmarschang2245 5 жыл бұрын
Trying to follow along but USG, I think I got most of it figured out. When it comes to your IDIot_Local, would this be the same as LAN_Local on the usg?
@invictuslegend4405
@invictuslegend4405 4 жыл бұрын
Great video. I tried this, but from my main LAN, I am unable to get to the AP connected to the IOT port. To access the AP, I had to be on the IOT network. What firewall rule should I add or reconfigure so that I can get to the AP @10.0.0.40? I can ping 10.0.0.1 from Main LAN, but no other leases.
@johnraahauge4552
@johnraahauge4552 4 жыл бұрын
Chris.how do I clear the routing tables? I have an EdgeRouter with VLANs set up folllowing your guide. I have some Cameras that after a power surge can’t be accessed across VLANs. Only if I give them new IPs are they accessible again. This has happened a couple of times and I’m getting tired of changing IPs.
@Lee-qy3bc
@Lee-qy3bc 5 жыл бұрын
Were you able to use the Roku remote app from your phone on the trusted VLAN to the Roku on the IoT vlan? I could not get it to work, I think it had something to do with SSDP as well as mdns. But couldn't narrow it down with wire shark. I installed avahi for pfsense.
@mikeennis8820
@mikeennis8820 5 жыл бұрын
Chris, have you done a pi-hole configuration video in other words what you're blocking, allowing or what you're monitoring, how aggressive is your pihole set up? Simply curious if it affects your internet experience, do you allow your IoT devices, thermo's, amazon devices etc to send any data back to their respective companies? Thanks
@Martin-ot7xj
@Martin-ot7xj 4 жыл бұрын
Hi there, i have a question as far as i can understand, we have to make 2 vlan and 2 dhcp server and 2 wireless access point, for our private network and Iot, for isolate every things right? Im waiting for your answer. Thnx
@constantelev8tion1
@constantelev8tion1 2 жыл бұрын
How would you set up the last rule you talked about at the end of the video about port 53?
@bumgarb42
@bumgarb42 4 жыл бұрын
Is it possible to do this same level of configuration on a UniFi USG Pro 4? If so, could you do a video showing that? I get lost trying to translate the Edge interface to UniFi for DHCP and DNS configuration you do around the 9 minute mark.
@Bostonaholic
@Bostonaholic 4 жыл бұрын
Great stuff! I'm putting together a UniFi network for my home and I'll be following this.👏 I'm curious as to why the Plex server should be in the IoT network. How would I even do that? My Plex server is embedded in my Synology NAS which I would think I'd want to keep in the Secure LAN. Do you have a video about this?
@marito158
@marito158 Жыл бұрын
Thank you for the video, should I still be available to ping from IoT network to the protected network?
@coolcatdom
@coolcatdom 4 жыл бұрын
Hi Chris, thanks for this video. I'm trying to do a similar setup using the OPNsense firewall. I don't see a similar setting in OPNsense for the advanced rule configuration (20:38). A few posts I read around the Internet suggest that those two options are the default for OPNsense. Is my understanding correct?
@rawshou136
@rawshou136 4 жыл бұрын
You saved me a lot of time! Thank you so much! It works perfectly :-)
@genericcommenter2676
@genericcommenter2676 3 жыл бұрын
Hi, how does it affect the auto discovery features IE, Apple Bonjour, between mobile devices on secure LAN and the IOT devices on a separate broadcast domain.
@kk1l
@kk1l 3 жыл бұрын
Thank you. This was informative. About the final statement to block DNS from any other lookups than the PiHole...My rules for DNS and DHCP are on the local interface. If I drop all DNS on the IOT_IN interface the lookups should still flow on the local...right?
@berndeckenfels
@berndeckenfels 4 жыл бұрын
In close neighbour ship I would not run hidden SSID, it makes channel conflict detection less functional.
@jean-lucward6587
@jean-lucward6587 4 жыл бұрын
Hi Chris Please make a video for IoT devices again with USG router. please please please, BTW thanks for everything, my Unifi network rock because of your guidance. you da man
@americus182
@americus182 4 жыл бұрын
Just a beginner here, would really like to see this with a USG. I found some other resources online to set the firewall up but doesn't provided details about who to add exceptions from the IoT to private networks.
@goddrago
@goddrago 2 жыл бұрын
Hello Chris, I'm about to setup this solution you made, but I want to be sure to have all the equipment. Right now I have a EdgeRouter X, and I'm about to buy a USW-Flex-Mini and 1 UAP-AC-LR. I want to know if I can do all this with this equipments. Look like I can do it, but I just want to be sure. Thanks for all your help.
@DLong-wp8su
@DLong-wp8su 7 ай бұрын
I have RT-AC88U main router and an old RT-68U as AiMesh. My thought for security stuff (PC, phone, Ipad, etc..) are on the main router and IoT (doorbell camera, light, TV, etc..) will be on the the RT-AC68U. I can also set IoT on the main router under "Guest". Which option is best and safe to protect the main router access?
@heywood62
@heywood62 5 жыл бұрын
Thanks for this video, I am moving toward Ubiquiti as I can afford it. I would like to add that Chris did a video on why he does not recommend the USG, it's definately worth looking up. From watiching that video I have decided on the Edge Router instead. Look it up and you'll see why.
@tornadotj2059
@tornadotj2059 5 жыл бұрын
He prefers using the EdgeRouter. He does also sell and support the USG, depends on what the right tool is for the job. If this were done using a USG, he'd be using all one interface and setting up the VLANs would have gone a bit quicker.
@TheRicosauve
@TheRicosauve 5 жыл бұрын
You could also go with pfsense box...much more robust and comprehensive FW/RTR. If you stay the Ubiquity route, get an edge router and leave the USG alone.
@tornadotj2059
@tornadotj2059 5 жыл бұрын
@@TheRicosauve USG can be the right tool for the job. It just depends. I've been running a USG here at my house for over a year and had zero issues. Even the failover feature works great for me.
@RAKRail
@RAKRail 5 жыл бұрын
An informative video Chris... Thanks
@ivanstefko
@ivanstefko 3 жыл бұрын
Hi Chris, how did you associated IDIoT network with IoT SSID? It's done automatically by set VLAN ID? Another thing is why is necessary create new network for IoT? Is it not enough to use default one? I'm able to obtain correct IP for VLAN 107 if I have corrected setup on EdgeRouter and EdgeSwitch for that VLAN (without any other network on uap).
@islandsnow
@islandsnow 4 жыл бұрын
Is the edge router required? Can I do all this with a USG, cloud key, ubiquity switch and ubiquity AP?
@lemming622
@lemming622 3 жыл бұрын
@Crosstalk Solutions Is it possible to have this or an updated version of this documented on the Crosstalk blog, in a similar fashion as the Definitive Guide To Hosted UniFi? I'm following along as best as I can and having to pause quite a bit to make sure you don't get too far ahead of me.
@HaouasLeDocteur
@HaouasLeDocteur 3 жыл бұрын
It is necessary to add an ‘allow’ rule for address 224.0.0.251 and UDP port 5353 in IDIoT_LOCAL otherwise mDNS will not work (devices inside the IoT VLAN will not be able to broadcast). This gave me problems with Homekit accessories being unresponsive without adding this rule. Homekit accessories will also fail to set up with these rules and I’m still trying to figure out how to overcome this.
@johnemerson3674
@johnemerson3674 3 жыл бұрын
Your diagram shows an AP for the secure network and a 2nd AP for the IoT network. Are there two APs for security reasons? If not, would it be a good idea to configure one UAP-AC-PRO to broadcast SSIDs for the secure network, the IoT network and a guest network?
@markarca6360
@markarca6360 4 жыл бұрын
It is applicable to the following: pfSense OPNSense Untangle IPFire Ubiquiti EdgeOS/UniFi Mikrotik RouterOS/SwOS
@it.gayndah
@it.gayndah 4 жыл бұрын
Hi, I'm Brad from Outback Rural QLD Australia. I strongly believe that all IOT must be it's separate vLAN. I have gone a little further by creating 2 IoT vLans - IoT & NoT. The second has basically the same rules as IoT as you shown with a few more including "preferred DNS" and blockling all other DNS servers (I have a standard DNS Drop rule on Google IPv4 & 6). Unlike Iot that can get out to the Internet under special ruleset, NoT can't get out and can't get to other vLans too, however Management vLan can access both IoT, NoT and Cameras vLans one way using "New/Est/Related". My Camera vLan is a bit like the NOT network too but with the NVR also residing in this vLan. I have gone a little further by making my Management vLAN (primary Corporate LAN) having its own vLan number. I have a separate TRUNK vLan that interconnects from USGPRO4 to all my 4 switches and 8 APs etc., for some extra securty. I feel this network design gives a little more security. Yes the security is only as good as the Firewall Rules! I just learning all this stuff, and taking it slowly and building my IoT devices which will basically connect to everything in the home and farm. Any constructive comments most welcome.
@Sir-Fix-a-Lot
@Sir-Fix-a-Lot 4 жыл бұрын
Also there is quite a bit of fiddling involved in getting Sonos to work in these setups - took me a good evening of googling to find the right recipe to get the Sonos Controller application on the secure nw PC to actually be able to communicate with the Sonos Bridge in the IoT network.
@sebdl1286
@sebdl1286 4 жыл бұрын
I am just about to set up Sonos on a newly created IoT VLAN, as per this Video... Would you mind sharing that "right recipe"?
@Sir-Fix-a-Lot
@Sir-Fix-a-Lot 4 жыл бұрын
@@sebdl1286 Well, the end result wasn't a simple recipe, but I'll put the source article links here for your reference - hope they are still valid. I composited my config from these articles after a painful night of googling: en.community.sonos.com/advanced-setups-229000/access-sonos-from-a-different-wireless-network-6808767 help.ubnt.com/hc/en-us/articles/215458888-UniFi-How-to-further-customize-USG-configuration-with-config-gateway-json community.ubnt.com/t5/UniFi-Routing-Switching/Cloud-Key-config-gateway-json-file/td-p/1553060 blog.awelswynol.co.uk/2017/11/unifi-sonos-and-vlans community.ubnt.com/t5/UniFi-Routing-Switching/Configure-Sonos-across-subnets-on-USG/m-p/1982496#M49654 I hope you can figure it out!
@antonlamers5913
@antonlamers5913 4 жыл бұрын
Hi, i have this error: "Error using vlan on switch-port interface interfaces ethernet eth1 vif 107" when i want to add a vlan
@brianmost311
@brianmost311 4 жыл бұрын
I did too! I'm a n00b so take my advice with a grain of salt, but if you click on Actions for your swtich0 interface, click Config, click the Vlan tab, and check the box for VLAN Aware Enabled. Hope this helps.
@jonstrongman3292
@jonstrongman3292 4 жыл бұрын
So I have an Apple TV an old WD media player and a Sonos system, should these devices be in a IOT VLan?
@madrian_hello
@madrian_hello 5 жыл бұрын
I just wanted to setup on USG, but settings are so much different. I wait for a video for USG.
@Eric-vw6kb
@Eric-vw6kb 3 жыл бұрын
Superbe Vidéo, et super canal, Vous devriez nous faire une vidéo de la même configuration mais dans le UNIFI. Ce serait très apprécié.
@HarshGupta-yo2rw
@HarshGupta-yo2rw 5 жыл бұрын
Plus one can use Raspbeery pi's "PI-HOLE" as a DNS for IOT Devices , so that we can see and block iot's dns resolution to unsuspected webapi's
@a.j.8926
@a.j.8926 4 жыл бұрын
This is on my to-do-list for sure. I have an edge router Max, close enough. What about my NAS? Will my IOT devices be able to see my NAS? Say if I want to stream a video on my raspberry pi? I think the firewall rules allow that. Thanks. great video!
VLANs Made Easy: Learn This Today!
41:08
Crosstalk Solutions
Рет қаралды 230 М.
UniFi Network BEGINNERS Configuration Guide | 2024
46:14
Unified IT
Рет қаралды 136 М.
Самый Молодой Актёр Без Оскара 😂
00:13
Глеб Рандалайнен
Рет қаралды 10 МЛН
Clown takes blame for missing candy 🍬🤣 #shorts
00:49
Yoeslan
Рет қаралды 39 МЛН
Amazing weight loss transformation !! 😱😱
00:24
Tibo InShape
Рет қаралды 53 МЛН
WHAT’S THAT?
00:27
Natan por Aí
Рет қаралды 13 МЛН
Securing Your IoT Devices
13:55
IBM Technology
Рет қаралды 27 М.
BEST WiFi Optimization Settings!
20:25
Crosstalk Solutions
Рет қаралды 329 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,2 МЛН
Ubiquiti Edge Full Setup and Configuration For Home Or Small Business
18:45
Mactelecom Networks
Рет қаралды 60 М.
UniFi Basics: Start the Right Way Without Breaking the Bank!
14:52
Crosstalk Solutions
Рет қаралды 130 М.
UniFi Basics: Initial Setup Made Easy
28:27
Crosstalk Solutions
Рет қаралды 42 М.
7 Steps to SECURE Your Network | E06
10:37
Steve DOES
Рет қаралды 42 М.
Securing your network from IOT devices using the EdgeRouter X
28:19
Rate This Smartphone Cooler Set-up ⭐
0:10
Shakeuptech
Рет қаралды 2,7 МЛН
Какой ноутбук взять для учёбы? #msi #rtx4090 #laptop #юмор #игровой #apple #shorts
0:18
Battery  low 🔋 🪫
0:10
dednahype
Рет қаралды 13 МЛН
Сколько реально стоит ПК Величайшего?
0:37
$1 vs $100,000 Slow Motion Camera!
0:44
Hafu Go
Рет қаралды 27 МЛН
Это Xiaomi Su7 Max 🤯 #xiaomi #su7max
1:01
Tynalieff Shorts
Рет қаралды 1,9 МЛН