*** Official Ubiquiti Discussion Thread ***

TJM

TJM

Associate
Joined
10 Jun 2007
Posts
2,378
My Netgear R7800 is going on the fritz (random drops of all ethernet connections; cannot be resolved through wipes or updates) so I'm either going to replace it with an AC-86U or something else. Which Ubiqiuiti gear would suit a 1Gbps symmetrical connection? I don't need any fancy features.
 
Soldato
Joined
18 Oct 2002
Posts
5,983
Location
N.Devon
My Netgear R7800 is going on the fritz (random drops of all ethernet connections; cannot be resolved through wipes or updates) so I'm either going to replace it with an AC-86U or something else. Which Ubiqiuiti gear would suit a 1Gbps symmetrical connection? I don't need any fancy features.
As Chris stated i guess you just want a WiFi access point? Since you mentioned you're getting a new Router.
 

TJM

TJM

Associate
Joined
10 Jun 2007
Posts
2,378
As Chris stated i guess you just want a WiFi access point? Since you mentioned you're getting a new Router.
Sorry, I wasn't clear - I'll either get an all-in-one like the AC-86U or a separate router and wireless access point if it the kit is more stable and in the same price range.
 

Kol

Kol

Man of Honour
Joined
8 Jan 2003
Posts
14,219
Location
Ashby-de-la-Zouch
Chaps - vlans. Can I request some assistance? So, my set up is current USG>US8, off which is an AC-lite and a US8-60w in at the back of the house which feeds another AC-lite.

I was reading about vlans a while back, so decided I'd like to segregate my smart switches/plugs. So I thought I'd followed the guides on the ubnt and got everything nicely.

My main network is running perfectly (192.168.0.x) so I then proceeded with the following:

- Create a new network, set the vlan to 20, set the dhcp server to 192.168.20.6 > 192.168.20.254 and saved it.
- Create a new wireless network, ticked use vlan, 20 and saved that.

I connected the smart switches to that ssid and they've resolved with ips in the .20.x range. So seems to be working.

The problem is, the devices on .0.x can see .20.x devices. I've not yet touched the firewall, it's all as default out of the box/reset a while back when I decided to start from scratch.

I'm guessing I've missed an obvious setting somewhere or do I need to create a firewall rule which blocks cross communication? I assumed that was automatic.

Without looking like a complete amateur, is it solved by simply going into Routing & Firewall > Firewall > Action = Drop > Source = Network (IoT) > Destination = Network (LAN)?

EDIT - tried the above under LAN IN and it seems to have worked.
 
Last edited:
Soldato
Joined
29 Sep 2004
Posts
3,105
Location
Wilt of the Shire
I have the Edgerouter X and have just been to the Shields Up site to check it's security. It shows ports 80 and 443 as open, I followed the wizard setup and I thought that incoming on these ports would have been blocked. Have I set the firewall up incorrectly? I seem to be forgetting more about networking each day :(
 
Man of Honour
Joined
20 Sep 2006
Posts
34,046
My USG also has 80 and 443 and I'm not sure why, there's no port forwarding.

Edit, it's the network, LAN, UPnP LAN setting. If it's on both 80 and 443 are open. If it's off, Plex complains, so I will manually put in a rule for Plex port forward.
 
Last edited:
Man of Honour
Joined
20 Sep 2006
Posts
34,046
My USG also has 80 and 443 and I'm not sure why, there's no port forwarding.

Edit, it's the network, LAN, UPnP LAN setting. If it's on both 80 and 443 are open. If it's off, Plex complains, so I will manually put in a rule for Plex port forward.
Found the culprit, it was my QNAP NAS. Settings now adjusted.

You can see port forwarding statistics under insights.
 

Kol

Kol

Man of Honour
Joined
8 Jan 2003
Posts
14,219
Location
Ashby-de-la-Zouch
Yep, that'll do it.

I've added an additional rule in my setup so that nothing in VLAN2 can reach anything in VLAN1 but I've allowed VLAN1 to reach VLAN2 so that I can ping devices in VLAN2 to check if they're up.

Awesome - thanks. So the second rule, LAN in and simply reverse everything (so LAN > IoT) and instead of drop that should be accept?

Cheers!
 
Soldato
Joined
24 Sep 2015
Posts
3,674
That's what I thought it would be, but no. You need to create a rule that's above the drop rule that has the following settings - accept, all protocols, states - established & related. Source & destination - any.
 
Soldato
Joined
6 Jan 2006
Posts
3,372
Location
Newcastle upon Tyne
Chaps - vlans. Can I request some assistance? So, my set up is current USG>US8, off which is an AC-lite and a US8-60w in at the back of the house which feeds another AC-lite.

I was reading about vlans a while back, so decided I'd like to segregate my smart switches/plugs. So I thought I'd followed the guides on the ubnt and got everything nicely.

My main network is running perfectly (192.168.0.x) so I then proceeded with the following:

- Create a new network, set the vlan to 20, set the dhcp server to 192.168.20.6 > 192.168.20.254 and saved it.
- Create a new wireless network, ticked use vlan, 20 and saved that.

I connected the smart switches to that ssid and they've resolved with ips in the .20.x range. So seems to be working.

The problem is, the devices on .0.x can see .20.x devices. I've not yet touched the firewall, it's all as default out of the box/reset a while back when I decided to start from scratch.

I'm guessing I've missed an obvious setting somewhere or do I need to create a firewall rule which blocks cross communication? I assumed that was automatic.

Without looking like a complete amateur, is it solved by simply going into Routing & Firewall > Firewall > Action = Drop > Source = Network (IoT) > Destination = Network (LAN)?

EDIT - tried the above under LAN IN and it seems to have worked.

Great timing thanks as I need to do this next week.
 
Soldato
Joined
10 Apr 2013
Posts
3,747
I have an old ISP fibre hub (802.11n) and I'm considering buying a Ubiquiti access point in order to upgrade to 802.11ac and improve my wireless signal. Which would be the best access point for me?

Would your recommend either of these?

Ubiquiti Networks UAP-AC-LITE WLAN Access Point

Ubiquiti Networks UAP-AC-LR 2.4-5 GHz 802.11ac Dual-Radio Long Range Access Point


Is it worth the extra for the UAP-AC-LR? Any gotchas or other things I should bear in mind?
 
Last edited:
Back
Top Bottom