Protecting a Local LAN with a firewall

Discussion in 'Tips/Tricks/Mods' started by Michel-André, Dec 6, 2024.

  1. Michel-André

    Michel-André New Member

    Salut all,

    Cahier-02: UniFi Cloud Gateway Ultra as a Firewall from the course “UniFi-101”, describes the configuration and integration of the UniFi Gateway Ultra (UCG Ultra) router/firewall to our Local LAN network.
    https://www.micronator.org/affaires...ier-02_unifi-cloud-gateway-ultra-en-pare-feu/.

    PDF: 26 355 Ko/150 pages
    New: 2024/12/04
    Version: 0.0.3
    Level: advanced, intermediate
    System: UniFi: OS-4.0.20 Network-8.6.9
    Language: French

    High resolution zoomable images
    Initial Network
    =>https://www.micronator.org/affaires...-04/Diagrammes/Diagramme-1_Reseau_initial.pdf
    PPPoE by NethServer => https://www.micronator.org/affaires...4/Diagrammes/Diagramme-2_PPPoE_NethServer.pdf
    PPPoE by UCG-Ultra => https://www.micronator.org/affaires...04/Diagrammes/Diagramme-3_PPPoE_UCG-Ultra.pdf
    Final Network => https://www.micronator.org/affaires/PDF/UniFi-101/2024-12-04/Diagrammes/Diagramme-4_Reseau_final.pdf

    [​IMG]
    [​IMG]
    Canada => https://ca.store.ui.com/ca/en/products/ucg-ultra $169 CAD / $120 USD / €114
    Germany => https://www.alternate.de/Ubiquiti/Unifi-Cloud-Gateway-Ultra/html/product/100046357?sug=ucg ultra €112,90
    Europe =>: https://eu.store.ui.com/eu/en/products/ucg-ultra €90
    UK => https://uk.store.ui.com/uk/en/products/ucg-ultra £75.00
    Brazil => https://br.store.ui.com/br/pt/products/ucg-ultra R$ 789

    ISPconfig Project
    The ultimate goal of the ISPconfig project is to create its own ISPconfig server that can host an email service, one or more websites and even an e-commerce site.
    • The first step is the creation of a Proxmox VE server to facilitate the development of this project.
    • Next comes the creation of a virtual machine for the installation of a minimal Debian server.
    • The next step is the installation and configuration of the ISPconfig server running under the Debian server.
    • Adding a UCG Ultra firewall to protect the network.
    • Finishing by connecting everything directly to the Internet.

    Acknowledgments
    We sincerely thank Mr. Till Brehm for allowing us to use the description of various ISPconfig parameters contained in his book "ISPConfig 3.1 Manual".

    ISPConfig 3.1 Manual
    You can support the development of ISPConfig by purchasing the ISPConfig Manual for the modest sum of 5.0 €: https://www.ispconfig.org/documentation/.

    Michel-André
     

    Attached Files:

    Last edited: Dec 9, 2024
    till and ahrasis like this.
  2. ahrasis

    ahrasis Well-Known Member HowtoForge Supporter

    Thank you for sharing, again.

    As I understood from here and before that you relied on UCG Ultra box as the main firewall for your LAN but this, undeniably in my mind and others, may be replaced by any other firewall softwares, in any other suitable box.

    I also understood from links given from this and previous posts that it offers more than other opensource firewall softwares, but with less headache for software setup, management and maintenance, with the price is not bad as well.

    It is an interesting ready made and easy to use firewall box to be considered really.

    Thanks for the sharings, again.
     
    Michel-André likes this.
  3. Michel-André

    Michel-André New Member

    Salut ahrasis,

    Thank you for your comment.

    Yes, a good firewall will do the job.
    Yes, mainly it offers a DNS server, a reverse proxy for domains, ports forwarding, no contract, free updates, etc... but mainly ease of use.
    You don't have to create new firewall rules, the ones already there are all you need. Of course, you can add some.
    It also offer the possibility to manage your UCG Ultra, and any other UniFi devices, from anywhere and with PC, phone, tablet, etc... but you need an account (free) for that.
    Backups: it offers a free automatic backup of the network and system configs, once a week/month, in your UniFi account.
    Power: max 3A/5V, no noise because no fan.
    LCD: a small 1 inch wide.

    I had an exchange on UCG Ultra today @ https://community.nethserver.org/t/...l-friend-nethserver-7-9-with-a-firewall/25007
    Andy is the main source of information about UniFi. He has a lot of experience on all kind of systems and always give very good advices.
    Open an account in that forum and you can PM him for any questions.

    I am reviewing my DOC on Proxmox and should finish in a few days.
    I will post it here too.

    Michel-André
     

Share This Page