Тёмный

Ubiquiti UniFi Layer 3 Switches and pfSense Revisited - One L3 Switch 

777 or 404
Подписаться 3,7 тыс.
Просмотров 6 тыс.
50% 1

Опубликовано:

 

5 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 50   
@marc3793
@marc3793 Год назад
Your videos are really useful and give all the required information on the topic you're discussing. Thanks.
@RifatNabi
@RifatNabi 10 месяцев назад
Thanks! Have a coffee on me. You are probably one of the most underrated content creator I watch. Keep up the good work 👍.
@nightfallen0420
@nightfallen0420 Год назад
Amazing, dude! Thank you so much for doing these series and everything else you've done on your channel! 🙏🏻
@Sommyie
@Sommyie 2 месяца назад
:facepalm: I forgot about vlan 4040! Derp! As of writing, my USW Pro Max 16 didn't show it's IP information for the VLAN4040 setup, but manually setting the values like yours totally allowed everything to work finally. I'll have a stiff one for you later.
@psycl0ptic
@psycl0ptic Год назад
great info. Looking forward to the next video.
@stevenmishos
@stevenmishos Год назад
Thanks for the video! A speed test of layer 3 routing within the switch might be interesting.
@hz777
@hz777 Год назад
I did think of speed testing initially, then decide not to include it in the series, because it seems L3 inter vlan routing can be handled by the pro switches effortlessly, especially if we are just talking about 1GbE ports.
@blahrvp
@blahrvp Год назад
Great work, dude! I was stuck and you just showed me the way! Thanks a lot!
@ryanbuster4626
@ryanbuster4626 8 месяцев назад
First off my network skills are poor and introducing L3 into *sense* firewalls was breaking my brain. These videos are absolutely INCREDIBLE as I've been debating whether or not to use the L3 functions of my switch for cross vlan routing and being able to isolate my servers. You even started from a scratch config on all devices, this is SO WELL DONE my friend. However I keep hearing of ACL dropping config on reboot. I haven't even looked into the ACL portion to see what parameters are possible to block vlans from communicating with each other but if the config does not come back up....is there even a point to using L3? I'm so excited for these videos and yet so dismayed at the same time. Please tell me we can use ACL between vlans and the settings will keep after a reboot? This has to be a bug and priority number one for Ubiquity right? It makes no sense. Can we just load config from backup if the switch goes down?
@hz777
@hz777 8 месяцев назад
Unfortunately nothing has changed about ACL: your config will be lost after reboot. Ubiquiti never publish their roadmaps so I have no idea whether ACL will be supported at all in the future.
@ryanbuster4626
@ryanbuster4626 8 месяцев назад
@hz777 Well I'm going to use L2 for now then. When ACL are implemented I am coming back to this video and I will leave some $ for a coffee. Thank you so much for such a well thought out video series.
@NiklasRooms
@NiklasRooms Год назад
Thank you for the video! I finally understood UniFi‘s implementation of L3 routing. One question: do you know, if the switches support some kind of ACL‘s? Of course, when traffic is being routed by pfSense, I can apply firewall rules there. But what I want to know: when I’m creating 2 VLAN‘s on the switch, can I create firewall rules between those? Can I restrict traffic between those VLAN‘s?
@hz777
@hz777 Год назад
Yes. Just search acl in my channel. But don’t raise your hope too high, because the settings won’t survive reboot.
@marc3793
@marc3793 Год назад
Yeah also a good a video. But sadly just highlights that UniFi L3 switches are pretty much pointless. The main reason you create VLANs is to restrict traffic between them 😂
@zdhughes
@zdhughes Год назад
Very Well done, saved my deployment.
@olavl8919
@olavl8919 4 месяца назад
@RifatNabi Thanks a lot for alls the work you put in your videos. Especially the L3 Switching is of great interest for me. What I have not understood so far is how the Unifi Controller is connected to your switch? Is it a cloud controller, or hosted as vm on the same device as the PF Sense?
@hz777
@hz777 4 месяца назад
Either way you described works. There is no special requirement when it comes to network controllers.
@olavl8919
@olavl8919 4 месяца назад
ok, thanks! Could it also be achieved with a local controller? I do use an express and in the moment it is situated between Firewall and USW-Pro-May-16 PoE. Default and Inter Clan 4040 networks reside on Unify express whereas the other VPNs I manage to setup on the usw.
@hz777
@hz777 4 месяца назад
This series of videos is about pfSense. If you use Unifi gateways which come with unifi controllers, the situation will be different and much more simpler. Everything is simply supported out of box. Having said that, I don't own an express so not sure where anything will be special.
@naterevo
@naterevo Год назад
Thank you so much for this!!!! Why can't pfsense manage DHCP with L3 routing? oh, that might be in the last video. :D
@TangDynasty1983
@TangDynasty1983 10 месяцев назад
Thank you for another great video. Could you please share where we can learn those CLI commands from Unifi gears? They look very similar to Cisco commands. Thanks again.
@hz777
@hz777 10 месяцев назад
google "ubiquiti edge cli pdf", you should be able to find the official document from Ubiquiti about CLI for the edge switches (the old versions, before unifi switches). Please note it seems Ubiquiti never officially mentioned the existence of those CLI commands in UniFi switches, which means they not really officially supported and may change any time in the future.
@christopherogle5403
@christopherogle5403 25 дней назад
Besides your videos what additional resources would you recommend to learn more about networking?
@hz777
@hz777 23 дня назад
I am not a professional, and I have not taken any training, so I am not a person to provide such type of advice.
@ess2k456
@ess2k456 9 месяцев назад
Excellent video !!!
@toddshreve
@toddshreve Год назад
Verrrrrrrry well done!
@recalion
@recalion 8 месяцев назад
Thx for sharing. Liked + Abo
@mcury85
@mcury85 Год назад
Man, this config save problem is a show stopper. With no ACLs working, why should I use the L3 functions? Better to leave devices on same VLAN or use pfsense as the router on a spoke...
@khanh8524
@khanh8524 Год назад
for pfsense to l3 switch port config what is it set to? All or a custom profile with all the tag vlans? For some reason I don't have the all profile anymore
@hz777
@hz777 Год назад
Yeah, not too long ago Ubiquiti changed the port profile part in network controller. "Default" works for me.
@khanh8524
@khanh8524 Год назад
@@hz777 Thanks, for some reason when I us default it stops routing ai had to create a profile and add the networks
@cmoraes06
@cmoraes06 2 месяца назад
Thanks for the video!! Can we run L3 switching with 2 Aggregations together? One the main one and the other the secondary (for redundancy)?
@hz777
@hz777 2 месяца назад
They will be equal: no master-slave, no primary-secibdary, no main-backup.
@cmoraes06
@cmoraes06 2 месяца назад
@@hz777 but how the DHCP-SERVER will work on both?
@hz777
@hz777 2 месяца назад
Each L3 Switch runs its own DHCP server
@TangDynasty1983
@TangDynasty1983 10 месяцев назад
The default gateway for vlan4040 is 10.255.253.1, what about 10.255.253.2?
@hz777
@hz777 9 месяцев назад
2 is for the UniFi switch, 1 is for pfsense.
@psycl0ptic
@psycl0ptic Год назад
Do we still have no ACL support (official) between two vlans on unifi? so even in the case of a guest network, how to prevent all vlan to vlan traffic in unifi?
@seanwoods1526
@seanwoods1526 10 месяцев назад
Nope! Still not there.
@ChasePalsson
@ChasePalsson Год назад
I remember looking at doing this a year or two ago and people were saying that Ubnt Level 3 switching wasn't persistent across switch reboots, so if you rebooted the switch it would undo all the configuration. Has this been fixed?
@hz777
@hz777 Год назад
Not aware of such thing. If the changes are done through UniFi controller, how can they not be persistent?
@SanFable
@SanFable Месяц назад
Thanks for very nice guide, but I'm confused I have usw enterprise 8 poe and opnsense as a dns, dhcp server. And I was thinking that I can: optimize network communication between devices using L3, don't stress the opnsense server and play around these Vlans, separate things etc... but before doing anything, my traceroutes are direct to any LAN/WLAN device. I know that with Vlans I could isolate IoT devices etc (which to be honest could be already filtered on unbound dns blacklist) What I'm missing/not understanding there? tracert 192.168.1.239 Tracing route to 192.168.1.239 over a maximum of 30 hops 1
@hz777
@hz777 Месяц назад
Are your devices in the same VLAN?
@SanFable
@SanFable Месяц назад
@@hz777 yes, they are in same VLAN, but it doesnt matter. I mean if I don't touch any network/vlan settings anyway I get direct tracert
@hz777
@hz777 Месяц назад
If they are in the same VLAN, the traffic won't go to the router. Yes, it matters in fact.
@SanFable
@SanFable Месяц назад
@@hz777 But when I haven't configured anything yet, they are in same (default) network and I get direct connection without router
@hz777
@hz777 Месяц назад
The default network is just a special VLAN. As long as the devices are in the same VLAN, their communications won't go via router.
@Chromatic3000
@Chromatic3000 Год назад
Can you setup traffic rules between the vlans on the unifi ?
@hz777
@hz777 Год назад
You mean pfsense firewall rules for the unifi vlans? No, because pfsense is not aware of their existence.
Далее
这位大哥以后恐怕都不敢再插队了吧…
00:16
ЛЮБИТЕ ШКОЛУ?😁​⁠​⁠@osssadchiy
00:20
Layer 2 vs Layer 3 Switches
6:02
Просмотров 757 тыс.
pfsense and Unifi VLANs , Securing VLANS
12:32
Просмотров 24 тыс.