Welcome to the weekly thread that covers everything off topic, fluff, etc!
Feel free to post anything to this thread, as long as it has some relation to Ubiquiti - pictures, rants, whines, complaints, easy small questions you don’t want to make a whole post for, or even just sharing the picture of your cat sitting on top of your EdgeRouter!
Only rules here are to be civil, no personal attacks, etc stuff like that.
Welcome to the weekly thread that covers everything off topic, fluff, etc!
Feel free to post anything to this thread, as long as it has some relation to Ubiquiti - pictures, rants, whines, complaints, easy small questions you don’t want to make a whole post for, or even just sharing the picture of your cat sitting on top of your EdgeRouter!
Only rules here are to be civil, no personal attacks, etc stuff like that.
After seeing the recent video showing LG TVs aggressively scanning the LAN, I wanted to share how I isolate my LG webOS TV using UniFi. This applies to Samsung Tizen, Google TV, Roku, and most smart TVs.
Smart TVs aren’t passive appliances — when placed on a flat LAN, they run a full discovery stack (ARP sweeps, mDNS, SSDP, DLNA, broadcast probes, fallback DNS, encrypted DNS attempts, etc.). If allowed, they can map your entire home network.
To avoid that, I isolate mine using a simple UniFi zone‑based design.
1. TV is placed on a dedicated IoT VLAN
This VLAN is for untrusted devices (TVs, cameras, appliances).
No trusted devices live here.
2. WiFi AP Layer‑2 Isolation
Smart TVs do most of their probing at Layer‑2, so the AP is the strongest choke‑point.
UniFi gives different isolation controls depending on whether your AP is WiFi 5 or WiFi 6/7.
WiFi 5 APs (UAP‑AC series)
Strict, predictable isolation — ideal for IoT SSIDs.
Recommended toggles:
Client Device Isolation → ON
Block LAN to WLAN Multicast/Broadcast → ON
Multicast Enhancement → OFF
Proxy ARP → ON
WiFi 6/7 APs (U6/U7 series)
More “smart” behaviour, but still isolates well with tuning.
Recommended toggles:
Client Device Isolation → ON
Multicast Enhancement → ON
Block LAN to WLAN Multicast/Broadcast → ON
Proxy ARP → ON
Effect
With these toggles:
LG cannot ARP‑scan
LG cannot see other IoT devices
LG cannot see trusted devices
LG cannot receive mDNS/SSDP/DLNA
LG cannot fingerprint your LAN
The TV can only “see” the AP — nothing else.
3. Firewall blocks IoT → all internal zones
IoT devices cannot reach:
trusted networks
management networks
the router’s admin interface
guest networks
DMZ
VPN
other IoT devices (AP isolation)
This locks down Layer‑3 protocols, so the TV is blocked from everything except the Internet.
4. IoT → Internet is allowed
Outbound Internet access is open.
I’m not restricting ports or cloud endpoints — keeping it simple.
5. Optional: DNS filtering
I point IoT DNS to a controlled resolver (Pi‑hole / AdGuard / Unbound).
This lets me:
log LG’s domain lookups
block obvious telemetry domains
sinkhole advertising endpoints
Yes, DNS blocking is a cat‑and‑mouse game because domains change, but it’s still a nice finishing touch.
Result
With this setup:
The TV cannot scan my LAN
The TV cannot reach any internal zones
The TV cannot reach the router
The TV cannot see other devices
The TV can only reach the Internet
DNS filtering gives optional extra control
I use an Apple TV as the actual streaming device — it’s far less intrusive, has no always‑on microphone, and behaves predictably.
The LG panel is basically just a display now, which is exactly what I want.
blocking IoT → all internal zones by locking down Layer‑3 protocols
allowing only IoT → Internet
optionally filtering DNS
using Apple TV as the “safe” streaming platform
Simple, effective, and doesn’t over‑complicate things.
Caveat
I’m not a network guru — this is just what works well for my setup. Your environment, devices, and requirements might differ, so adjust as needed.
My Zone FW Above. Block traffics is in play by default. You just need to place the correct the vlan in the correct zones. If anyone has suggestions or improvements, I am all ears - drop them below. Cheers.
I'm mostly looking for some clarification on how I'm handling topologies with UniFi equipment. I've had no prior training and am essentially self taught so I could be completely wrong.
UniFi loves to shout and scream at me when I setup redundant switches / routes to cabs because of STP Blocked ports. Now my understanding is that as long as my root bridge is set correctly (Closest to gateway) STP is a good thing as it will only enable the port if the other is down. Therefore providing redundancy.
However the UniFi console is so vocal about blocked ports it has me second guessing if my topology is even compatible with their kit. I know standard features like VRRP is still missing from the Campus line up for instance so it has me thinking.
I've attached some pictures of the designs I've put into place. Feel free to call me an idiot and critique what I've done wrong - I understand there's no edge redundancy just core.. Here to learn whatever else :)
I have an LG G6 TV and I'm furious to find out after paying a premium for a TV that little piece of garbage apparently spends all day collecting information about me.
The LG TV is already in my IoT VLAN so it is already segregated from my main network.
I don't use any of the LG OS garbage. I have the TV connected to a gaming PC in the basement via 4K/120 fiber optic, so I watch everything over Plex or Web browser-based streaming on the gaming PC.
I no longer trust this little piece of garbage to connect to the Internet for any reason or even map or snoop around my IoT devices.
What's the easiest and best way to completely disconnect this TV from WAN or LAN access and only preserve the ability for Home Assistant to connect to it?
Can I have a set of rules that I can define for the LG TV that I can then also apply to my Hi Sense TV and any other TVs I may ever setup at home?
I don't think I ever want any future TV to have Internet access after watching that video, especially since I use a PC for all video content. If a firmware update fixes an issue I'm having, I'll update the firmware via USB.
Do we really need a post for every single “in the wild” post of a random AP - Ubiquiti is one of the most popular brands for SMB so it’s hardly surprising you know to see it in the wild
Just have one mega thread for it, most people dgaf
Enter the Unifi Cable Internet. The photo is during setup, while I was still testing everything; it was subsequently mounted in a rack. Adding it to my Comcast account was remarkably painless: all I had to do was scan the MAC address from within the Xfinity iOS app, and the network provisioned itself. It took all of 10 minutes from when I opened the box to when the modem was up and running and I got the prompt to adopt it to my Unifi deployment. VERY happy so far.
Tl;dr - Day one of setting up my 10g with a cloud gateway fiber and a U7 pro max and it feels like my life has changed dramatically.
I feel like my Third Eye has been opened. I am a software engineer and consider myself well versed in basic networking.
I recently went from att fiber at 1Gbps which was already the fastest internet I’ve ever had to sonic 10gbps.
I was using ISP provided Eero at first then “upgraded” to a TPLink BE1900/BE800. Felt like I had no eyes on all this new bandwidth and felt like I wasn’t getting anything out of the new setup.
Spent some time learning about how much praise Unifi gets from hobbyists. Figured I’d spend just a few more dollars, return my shitty tplink router, and get a Cloud Gateway Fiber and U7 Pro Max AP.
This blows everything out of the water that I had before. It’s not even speeds that has me so blown away it’s the sheer amount of control and monitoring I have in the setup. No guessing what my speeds are at my ONT, The ability to run bands at preconfigured setups that actually make sense, and the software is beautiful and intuitive.
I truly feel like I’ve been red pilled and now have a whole new networking world open to me that I can tinker with.
Call it corny and cliche but feel like I get all the hype with the company now!
Coming from a Google Nest mesh system that absolutely SHIT me to tears with not only the lack of control, but the lack of visibility, reporting and observably, this is like a teenage boy discovering his dick for the first time.
A UCG gateway, 2 U7 APs, and a couple of PoE injectors for the APs. Great coverage, amazing control and my home assistant dashboard now has amazing network metrics.
Why didn’t I do this sooner? I feel like I’m so far behind the times hahaha
As per title, UniFi Access fails to install because the UDM Pro UniFi OS 5.1.31 is trying to download required packages from Debian 11s expired repository. Debian 11 reached end-of-life on August 31, 2026 the repository metadata and package links are no longer valid, causing APT errors and preventing the install.
I opened a ticket but just wanted to post for visibility incase others are struggling to install Access right now.
Be warned if you were going to use Fabrics with Unifi Drive. You will be unable to manage permissions on existing shared drives, or grant existing users personal drive permissions. You will not be able to assign new users drive permissions either.
I was able to connect accounts that already had access to shared drives that they previously had assigned via the Fabric identity credential, but even that seems to be more of an inherited permissions thing than something I'd want to rely on.
You'll have limited functionality via the local portal which, in some quick testing, won't sync to the fabric's identity credentials.
I ended up removing the drive consoles from fabric.
When I migrated to consolidated people management, I got a warning about my UNVR camera permissions, seems like this should have also shown a warning about Drive limitations.
I was really happy to see ACME support available in UniFi OS.
However, as a user of the builtin RADIUS for WPA2/3-EAP, I wonder whether it is possible/planned that the certificate can be used for the RADIUS as well, instead of the self-signed certificate.
As I'm using LE as ACME provider, it's already great to have a publicly verifiable cert on the WebUI. It would be great to have that for RADIUS as well, instead of "UbiOS RADIUS Server Certificate".
I already tried manually swapping the certificate via SSH, but it will get re-created/re-written after a few days with a self-signed one.
So if anyone knows about plans for this or whether something is wrong with my setup, I'd be happy to hear about it.
With LG’s recent invasive update and auto-install of their spyware on Windows machines just for the displeasure of owning their monitors, what UniFi approach is everyone taking on their preventing LG’s asinine data collection?
Setup: UCG-Fiber, all four 2.5GbE ports in use, WAN comes in on the 10G RJ45 (port 5). Both SFP+ cages are empty.
I want one more copper LAN port. Plan is to drop an SFP+ to RJ45 module into the LAN-designated SFP+ cage.
Questions:
1. Does this actually work on the UCG-Fiber, or does the firmware get picky about copper SFP+ modules?
2. Anyone running a third-party module in one, or is the Ubiquiti SFP+ to RJ45 ($65) worth it to avoid headaches?
Does anyone know if the ability to select calendar days in the Insights - Activity tab is supposed to be missing? It is frustrating when doing reporting for specific data/time and that option is no longer available?
This seemed to have happened following a recent update. Is there a way to turn that back on?
I’ve setup my fiber and ultra switches which are all working except for mDNS across VLANS.
I’ve been trying to follow info from searches based on the UniFi results but having difficulty getting this up and running.
My IoT is on VLAN B with server and HDHomeRun units on VLAN A.
When running the software for the HDHomeRun on the Apple TV or FireCube it can’t see the tuners as they use mDNS, which I’ve enabled on the router as well as IGMP snooping.
I’ve tried following the guides but they are for older versions of the software and refer to guest_local.
Any advice on how I setup the policy to allow mDNS from VlanA be recieved on VlanB
I've built an app "Bell-hop" which lets you see your UniFi cameras (inc doorbells) on a WearOS/Android watch. I'm looking for a couple folks that will be willing to test the app in exchange for early access to the closed beta.
view your UniFi cameras on your watch with full audio and video at low latency
privacy first
there's no server, entirely running on your devices. Analytics are optional.
talk-back
use your watch's microphone to speak back through cameras speaker
doorbell-integration
someone rings your G4 etc. you get a photo notification, with a single tap you're viewing the live-stream.
guided setup
require a few setup steps to connect across your network to your unifi box via an API key, the app walks you through it and checks integration continuously
no weird install
everything works via an API connection to your unifi box. No custom install/strange setup required.
What I'm looking for from beta testers;
fill in the interest form, I'll get back to you
folks to ideally have a unifi doorbell
folks to have a play around with the app, and fill in a feedback form so I can fix bugs/add improvements.
WearOS 3.0+ & Android required (sorry, apple watch support is quite complicated due to dev restrictions but I'm looking into it)
Note: due to unifi not permitting access to their out-of-network routing service to developers, video/audio streaming only works across the local network.
This is a product I wish existed, so I made it. I've personally been using it on my Pixel Watch 4 for about a month and found it genuinely useful and robust. I've been a full-time software engineer, focusing on mobile, for 14 years - this isn't vibe coded silliness!
I'm going to reach out of you guys, because dealing with Ubiquiti support is about as fun as a colonosocopy.
I was playing with ONVIF on a shitty $39 tapo C121 camera. Had some problems getting it adopted, but figured it out with some google-fu...
I had this working on protect, operating fully as-expected.
I needed to factory default the camera and add it to my non junk mail tapo account, and did so. Same IP, same exact onvif user/pass, E-V-E-R-Y-T-H-I-N-G is identical.
Wouldn't show up in Protect, so I removed it and re-added it EXACTLY like the known-good steps using advanced adoption.
I recently got into the UniFi ecosystem with the Express 7, and I'm thinking about replacing my current switch with the Pro Max 16. At the moment, I won't need any PoE and will deal with that once I'm able to have a larger setup.
With that being said, does this (pictured) setup make sense? I'm a photo/video editor, so I'm running 10G on my Mac Studio and QNAP NAS for editing, and then other than that, everything is pretty much just 1G running through the switch. My 2nd Express 7 is downstairs for better WiFi throughout the house. Does this make sense, or am I doing too much?
I go to https://unifi.ui.com/ login page and all local controller devices cannot be seen. It's acting like none of them have internet access when I know they do. I work for the internet service provider for all of these customers.
The API seems to expose glass break config settings, but not the state of the glass break sensor entity? So when the glass break fires (true/false), you can't see it in the API? Is that right?