4 ms·
I'm not clear what you were trying to achieve? You had unmanaged switches on your network, and were trying to manage thier downstream connections? What exactl
by NickNameNick 6y ago
I'm not clear what you were trying to achieve?
You had unmanaged switches on your network, and were trying to manage thier downstream connections?
What exactly do you mean by 'breach the firewall'?
- colordrops 6y agoIt's a basic home network. I had a simple netgear unmanaged switch and an apple airport extreme in bridged mode. The equipment works and i didn't want to add more trash to the landfill and spend money i didn't need, so I wanted to continue to use them. There is no way to identify any clients on your network that are either behind the switch or behind the airport (even in bridged mode). I would expect at least some list of clients based on DHCP leases or the ARP table, but they are not accessible through the UI. I have a robotic vacuum from china, and i want to stop it from calling home. There's isn't even a way to find out the IP or what traffic it's sending through the UDM pro, and no way to set blocking rules from the UI. I understand if they want to provide wifi mesh support and other special wifi features for unifi devices only, but the supposed "enterprise grade" router and FW functionality should support standard network setups, since all traffic goes through the UDM-Pro, and it is certainly aware of the clients since it gave them DHCP leases, and they are in the ARP table (which is only accesible through the SSH command line) and are on the same subnet. It's unacceptable in my opinion.
- gU9x3u8XmQNG 6y agoThis is not entirely accurate. The default logging may not capture the individual child clients, depending on your configuration (eg double nat), sure... but those child clients are still entirely at the mercy of your configuration otherwise. Saying that the clients are completely invisible/invincible, and that the fault is the Ubiquiti product, is not true.
- colordrops 6y agoYou need to read my comment again. The clients are behind either a bridged AP or a switch, i.e. all on the same subnet, all getting their DHCP addresses from the UDM-Pro, all in the UDM-Pro's ARP table. There is NO double NAT happening here. Furthermore I didn't say they were invincible. I just said they were invisible to the UDM-Pro's UI. Unless you have a blanket ban on outgoing LAN traffic, which would be absurd, there's no way to block access for a particular client or a particular destination address for that client. In the case I gave, a Chinese robot vacuum with no on-device interface, please tell me how to find the IP of this robot, then block outgoing traffic from it, without SSH'ing into the UDM and running scripts. That's right, you can't, because the UDM-Pro doesn't support it.
- gU9x3u8XmQNG 6y agoI never said you were using double nat, but noted it as an example in which you may have these issues. > Unless you have a blanket ban on outgoing LAN traffic, which would be absurd, there's no way to block access for a particular client or a particular destination address for that client. To the contrary; this is exactly what you should be doing. Isolated subnet for these untrusted devices. Block by default. (Whitelist only) I used the word invisible to describe it missing in the ui. I used the word invincible to describe your lack of “management” (ie; blocking) of the device. What I am trying to suggest, however, is that the UDM is likely not the root cause of these issues. I certainly don’t mean to suggest they are the best. The lack of compatibility of features between their product lines is a nightmare.
- colordrops 6y agoIt's not just compatibility features. They are missing features that low end consumer grade hardware have, and I'll say what I was implying: It's because it's a vendor lock-in strategy, and they want you to replace ALL your equipment with theirs. Explain to me why I shouldn't be able to manage a list of DHCP clients in a piece of "enterprise grade" hardware.