Jay-Dee Posted March 28, 2022 Posted March 28, 2022 Good morning all, We are currently in the process of replacing our wireless, and going from a Ruckus management wireless network to a Unifi, as it was a third of the price. I have done most of the setup but looking at setting up ACLs to block particular port traffic between different VLANs. On a Ruckus controller this is all built-in and easy to use, but unsure as to whether this is possible on a Unifi Cloud Key 2. Could anyone advice on this, as I have tried using the 'Firewall and security' section, but it doesn't do anything? Looking online, I have a feeling you need a dream machine or secure gateway to use the firewall features, but any help would be great? Worse case scenario I guess I will have to attempt this on our core switch. Many thanks
CrootUK Posted March 28, 2022 Posted March 28, 2022 You are correct, firewall rules only apply to there security gateways.. the new Gen2 pro switches can apparently do this too. ACLs aren’t possible AP end using UniFi. I would recommend doing this on core switch anyway.
Davit2005 Posted March 28, 2022 Posted March 28, 2022 (edited) I would check out that Unifi Dream Machine Pro is suitable and does what you need (or may need in the near future). I'd even go for a slightly more expensive pfsense box or Sophos etc. As for ACLs, yes they can be done on a core switch or a firewall. Personally if possible I'd keep WiFi separate and route/ACL on your firewall allowing only traffic needed to be routed back to you core switch/servers etc. You will generally find firewall rules are easier to work with than ACLs on a core switch and I have done a fair bit of both in the past. Edited March 28, 2022 by Davit2005
Jay-Dee Posted March 30, 2022 Author Posted March 30, 2022 You are correct, firewall rules only apply to there security gateways.. the new Gen2 pro switches can apparently do this too. ACLs aren’t possible AP end using UniFi. I would recommend doing this on core switch anyway. Thanks for the response here, core switch it is then. Cheers
chazzy2501 Posted March 30, 2022 Posted March 30, 2022 if you setup a vlan as a guest network the clients are limited to only the gateway (not even each other), if that helps.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now