Ubiquiti UniFi Switch Port Security

Sdílet
Vložit
  • čas přidán 25. 08. 2024
  • UniFi does some port security -- but it's a little different than most vendors. With UniFi we don't get sticky addresses and we have to specify all the mac addresses that will traverse the port.
    Want to join us in learning how to deploy network services like this? Put your name on the training list now: williehowe.com...
    Hire us! williehowe.com
    Amazon Afflilate Links for Grandstream Gear:
    GWN7801P: amzn.to/3LyXkri
    Affiliate Links (I earn a small percentage of the sale if you use these links):
    My AmazonLink: www.amazon.com...
    Netool: netool.io use code WHT to save at least 10%!
    Digital Ocean Affiliate Link: m.do.co/c/39aa...
    Patreon Link: / williehowe
    Contact us for network consulting and best practices deployment today! We support all Grandstream, Synology, DrayTek, Obihai, Poly, Ubiquiti, MikroTik, Extreme, Palo Alto, and more!
    Come back for the next video!
    Twitter - @WillieHowe
    TikTok - @whowe82
    SUBSCRIBE! THUMBS-UP! Comment and Share!

Komentáře • 25

  • @awstott
    @awstott Před rokem +11

    Nothing in the logs seems like it would be a nightmare to troubleshoot 6 months down the road when you forget you restricted the port. As another commenter posted curious what 802.1X looks like - mind you I don't want that at home as I fight with ISE all day at work!

  • @waynewickens9074
    @waynewickens9074 Před rokem +9

    Hi Willie what about the Unifi's 802.1X control have you played with that yet. Would love to know more about that

  • @markalmada9662
    @markalmada9662 Před rokem +4

    Thanks Willie, sounds like you'd have to document it elsewhere or it could become tricky to diagnose later.

  • @techreviewsau
    @techreviewsau Před rokem +4

    Hi Willie, regarding the lack of anything in the Logs showing when you connected the GrandStream Phone to that Port - maybe there is something in Notifications you need to enable for it then to show up?

  • @lkfng
    @lkfng Před rokem +5

    Hi Willie, going forward can you use dark mode? The white mode is blinding ly bright.

  • @jamesbaldwin2650
    @jamesbaldwin2650 Před rokem +2

    That’s silly that PoE and DHCP still works on the port. This could put your switch over PoE budget causing other devices not to get correct power. If you had a laptop in that port can it still sniff traffic? I feel like they made a generic ACL that gets applied when the port isn’t on the MAC list. Who knows what all traffic that port can see!

  • @rogerjenson5689
    @rogerjenson5689 Před rokem +2

    I suspect that you have the Logging Levels (UniFi Network > Settings > Support > Logging Levels) set to Auto. Unchecking the Auto check box displays drop down lists to change the Device, Management, Remote Access, and System log levels to Normal, Verbose, and Debug. Setting the log level to verbose may give you log entries with more information on switch port. The Debug log level should only be used for short duration troubleshooting sessions due to the high number of log event entries generated.

  • @davidanderson2436
    @davidanderson2436 Před rokem +2

    That seems kinda goofy - if the mac address is wrong - why wouldn't it also stop power going to that device - great video thanks!

  • @TSSC
    @TSSC Před rokem +1

    Any plans to cover Edge-products? I hear you mentioning EdgeSwitch (3:15).

  • @stanleyleake7624
    @stanleyleake7624 Před rokem +3

    Hey Willie thanks for this! Slightly related, I missed your Synology Directory course Apr 28th. Will you be making any of it available for purchase in another way? Will be running a Synology with Directory Services with a few of these Unifi Switches.

    • @andyrandy0815
      @andyrandy0815 Před rokem +2

      Oh, no log entry when unwanted devices are plugged in is not so nice. Well, Vlan plus port security enabled should be a decent way to not let anyone onto your network or even access the infrastructure. MAC address cloning is not that difficult btw

    • @WillieHowe
      @WillieHowe  Před rokem +3

      Yes we are -- I posted the link here and on Twitter.

  • @JasonsLabVideos
    @JasonsLabVideos Před rokem +4

    Me first, I win a PA220 !!

  • @mayyam
    @mayyam Před rokem +1

    Look on that blocked port with old unifi interface ;)

    • @WillieHowe
      @WillieHowe  Před rokem +2

      Old interface doesn't exist on the UDR.

  • @syl764
    @syl764 Před rokem

    My USW-Lite-16 port settings look quite different. Bad luck they've changed it in an upgrade just after you made the video.

    • @WillieHowe
      @WillieHowe  Před rokem +1

      Hrm.. I check a couple different versions and they look the same. How is yours different?

    • @syl764
      @syl764 Před rokem +2

      @@WillieHowe No PORT: active / disabled / restricted for a start. My settings rows are Name, Port profile, MAC address list (empty), then a port profile override section. I'm on 6.5.32 - happy to send a screenshot if it helps.

  • @domadox
    @domadox Před rokem

    Hi Willie, I saw a Unifi Flex switch in you controller overview. Can you confirm that this switch is or is not capable to do MAC restrictions? Since I didn't found any information on that, I would like to verify this function before purchase it. Thanks in advance!

  • @bayarea757
    @bayarea757 Před rokem

    How can you possibly use tictok. Do you know anything about security?

  • @brycehall7300
    @brycehall7300 Před rokem

    Arp table

  • @brycehall7300
    @brycehall7300 Před rokem

    Ssh to logs

  • @brycehall7300
    @brycehall7300 Před rokem

    NAT