In https://unifi.ui.com/device/xxx/settings/advanced
- Advanced
- SSH: On / Password: S1…
- Device Name: CustName UDM-Pro
- Automatic Firmware Updates: Disabled
- Applications
- Network
- Check for updates.
- Network
- General
- Firmware: Update
- Location
- Set manually.
In https://unifi.ui.com/device/xxx/network/site/default/v2/dashboard
- Settings
- WiFi
- Create a lan/wan Wifi Network called xxx_lan (or match old SSID)
- You can have up to 4 SSIDs in a WiFi group
- Speed restrictions are applied using client groups – see advanced features.
- Create a Guest Hotspot for Guests called xxx_guest (or match old SSID)
- Optional – Set to be available during work hours only.
- Create a lan/wan Wifi Network called xxx_lan (or match old SSID)
- Networks
- Create a LAN for each virtual LAN as required (you need at least one (main one))
- Lan (Main)
- Content Filter: Work
- Advanced:
- IP – 192.168.1.254 - or as required
- DHCP – 192.168.x.30-192.168.x.249
- Lan (Main)
- Create a LAN for outgoing VPNs (site to site) as required.
- Create a LAN for each virtual LAN as required (you need at least one (main one))
- Security
- Internet Threat Management
- Enabled
- Intrusion Detection System then later change to Intrusion Prevention System
- Level 3
- Customize Threat Management
- Pick what makes sense in the environment you are working in. Level 3 will pre-set most of these.
- Network Scanners
- Threat: Yes
- Honeyport: Optional (Enable & create if you plan to monitor)
- Firewall
- Add port forwards and rules.
- Advanced
- Restrict Access to Malicious IP Addresses = Yes
- Restrict Access to Tor = Yes
- Traffic & Device Identification
- Enable Deep Packet Inspection = On
- Device Fingerprinting = On
- Internet Threat Management
- Internet
- Setup WAN connections
- WAN – Next hop
- For initial setup at Scottronic use DHCP
- For onsite use net hop settings or internet provider settings
- VLAN ID: blank / 10 / other
- WAN2 – Alternate hop or Failover for WAN
- System Settings
- NZ / English / 24 hr
- Automatic Firmware Upgrades = Off
- Schedule Firmware Upgrades = Off (For now)
- WiFi AI = On
- Device SSH Authentication = Yes, Scottronic, S1…1
- Advanced Features
- Leave unless required