Free AI web copilot to create summaries, insights and extended knowledge, download it at here
4844
Abstract
gure><p id="9cb9">I also found a lot of people attacking the idea from both sides. Why would you want a UDM at all? A UDM is fine by itself. Why would you need PFSense? I like the idea of separate devices for WiFi vs. my Internet-facing device. I like redundancy in my security controls in case one or the other is compromised. I like the WiFi capabilities and monitoring of the Ubiquiti devices.</p><p id="d183">Here is what I’m testing out:</p><ul><li>Separate Wifi, Modem, Switches, Firewall. If one device is compromised, hopefully, another will catch it.</li><li>Better segregation of IoT devices using VLANs, switches, etc.</li><li>Discreet LAN ports on PFSense.</li><li>Reduce network <a href="https://erg.abdn.ac.uk/users/gorry/course/intro-pages/uni-b-mcast.html">multicast/broadcast</a> network spam.</li><li>Separate admin network. Already have but making improvements.</li><li>Better visibility into wifi traffic.</li><li>More ports for hard-wired traffic. I like to hardwire sketchy devices like printers and monitor them.</li><li>Preserve the PFSense firewall rules I wrote about in <a href="https://readmedium.com/scanners-lead-to-scammers-2866d49886f">Scanners lead to Scammers</a>.</li><li>Apply additional security to other parts of my network that ends up taking down video streaming services. (I’m looking at you, <a href="https://suricata.io/">Suricata</a>.)</li><li>VPN to cloud for some work.</li><li>Ability to inspect the traffic coming out of the UDM (already wrote about that).</li></ul><p id="0486">Is Ubiquiti a good choice given that they had a recent data breach? Sometimes the companies that have had a breach better understand that they need to step up their security. I’ve been hired to do assessments of companies like that.</p><p id="5a04">Unfortunately, as I’m writing this, Ubiquiti is suing Brian Krebs for his report on their data breach a while back.</p><div id="ad28" class="link-block">
<a href="https://arstechnica.com/tech-policy/2022/03/ubiquiti-sues-journalist-alleging-defamation-in-coverage-of-data-breach/">
<div>
<div>
<h2>Ubiquiti sues journalist, alleging defamation in coverage of data breach</h2>
<div><h3>Journalist Brian Krebs is being sued by network-equipment maker Ubiquiti for defamation over his coverage of a data…</h3></div>
<div><p>arstechnica.com</p></div>
</div>
<div>
<div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*XI7SJapBdB-Q4Dlc)"></div>
</div>
</div>
</a>
</div><p id="c659">Not sure this is appropriate, but will have to see how it plays out. I am a fan of honest journalism on data breaches and not a fan of coverups or the inability to take responsibility. I am not judging in this case, just watching to see what happens. I hope that everyone did, and does, the right thing in this case.</p><p id="6d00">The reason I want to use the UDM is for segregation between my WiFi and other networks. Additionally, it seems like the UDM specializes in WiFi and hopefully will provide better performance. So far it has, but lately things have been cutting out on both pfSense and WiFi. Need to figure out if that is Comcast or something else. But so far it was easy to set up two separate WiFi networks using the UDM Pro behind a pfSense.</p><p id="e2d7">Meanwhile, stay tuned as I think I kind of got everything working, except the mobile app which refuses to work but I don’t need it. Perhaps because I’m blocking a stun port connecting to Digital Ocean, but I’m not sure. I’ll be writing about VLANs, switches, network interfaces, physical firewall ports, and firewall rules. You can follow me on <a href="https://readmedium.com/cybersecurity-author-teri-radichel-bea5f6c8452f">Medium</a>, <a href="https://twitter.com/teriradichel">Twitter</a>, and sign up for emails on Medium to get the stories in your inbox.</p><p id="a58b">Updates:</p><p id="02f3"><i>Update 4/12/24 — I finally figured out that I got a device shipped with out of date firmware after speaking to someone at Ubiqiti. That is why some of the functionality I wrote about initially is a little strange. I’m going to revise these posts based on getting a device with the proper firmware when I receive it. The fact that it required me to login on the Internet was one reason it was outdated. The other was some of the network functionality was not as expected. I recommend buying direct and, if you have questions as to whether the firmware is the latest version, consult the website and if needed, talk to the vendor, install the firmware from the vendor website if you really have concerns.</i></p><p id="5f58">The UDM Pro appears to expose far too much traffic and sends it to your ISP. I saw traff
Options
ic out of the box that should have been confined to the LAN. Is this because I’m using two local IP addresses? But why is that traffic crossing the gateway from the UDM to the other device such as traffic for port 10101 and other UDM specific ports? I am not sure if that’s how it is suppposed to work but I blocked the traffic.</p><p id="0566">On a related note, I’ve been having issues with LLDP using WiFi to cut out and there are no simple, documented instructions to turn that off at that time of this writing. LLDP has been used to scan networks and spoof devices on the network as explained this post. Not sure if I’m doing something wrong but I have pinpointed that traffic caused my network glitches as the timing was consistent.</p><p id="b09c">4/24/2024 — this has stopped happening. I don’t know if it was an update to the devices or my laptop. Never had time to investigate further. Still want to turn this off and would like to knwo how.</p><div id="7c7d" class="link-block">
<a href="https://readmedium.com/lldp-on-ubiquiti-udm-pro-causing-network-glitches-38d59637054c">
<div>
<div>
<h2>LLDP on Ubiquiti UDM Pro Causing Network Glitches?</h2>
<div><h3>Random issues with network cutting out</h3></div>
<div><p>medium.com</p></div>
</div>
<div>
<div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*aUAASXkElgHq2L8VhiKrFw.png)"></div>
</div>
</div>
</a>
</div><p id="4848">It seems that you can’t run a full IDS/IPs on the UDM Pro like you can on pfSense but I need to look into this a bit further. This would be another difference and a reason why you might want the pfSense in front of the UDM Pro.</p><div id="1f21" class="link-block">
<a href="https://readmedium.com/suricata-on-pfsense-ec73761ac969">
<div>
<div>
<h2>Suricata on pfSense</h2>
<div><h3>Detecting the attacks (like bit torrent) that aren’t in your flow logs</h3></div>
<div><p>medium.com</p></div>
</div>
<div>
<div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*EbNHN3BLiHQmeQlQc0Ollg.png)"></div>
</div>
</div>
</a>
</div><p id="344c">That said, there’s a problem with the Suricata implementation on pfSense that breaks some of the rules.</p><div id="2131" class="link-block">
<a href="https://readmedium.com/why-the-stream-rules-dont-work-in-suricata-on-pfsense-599389f7fbd">
<div>
<div>
<h2>Why The Stream Rules Don’t Work in Suricata on pfSense</h2>
<div><h3>Vendors not following specifications, misconfigured devices, false positives, and rule implementation issues</h3></div>
<div><p>medium.com</p></div>
</div>
<div>
<div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*hYladLV4_UjMI012HnX-hg.png)"></div>
</div>
</div>
</a>
</div><p id="b45d">Follow for updates.</p><p id="4a3a">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2022</i></p><div id="8b5f"><pre><span class="hljs-section">About Teri Radichel:
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab</pre></div><div id="caae"><pre><span class="hljs-section">Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation</pre></div><div id="5a42"><pre>Follow <span class="hljs-keyword">for</span> more stories like <span class="hljs-keyword">this</span>:
❤️ Sign Up my Medium Email List
❤️ Twitter: <span class="hljs-meta">@teriradichel</span>
❤️ LinkedIn: https:<span class="hljs-comment">//www.linkedin.com/in/teriradichel</span>
❤️ Mastodon: <span class="hljs-meta">@teriradichel</span><span class="hljs-meta">@infosec</span>.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab</pre></div><figure id="faf5"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*H9Ew1KCl-29nZiPR.jpeg"><figcaption></figcaption></figure></article></body>