Unifi UNAS-Pro Backup Migration Plan

UNAS-Pro Backup Migration Plan: SMB (Push) to Native Rsync Daemon (Pull)#

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

This document is the complete master migration plan for transitioning the UNAS-Pro backup strategy from the UniFi Drive UI-managed SMB (Push) setup to a Native Rsync Daemon (Pull) model.

Because the UniFi Drive UI natively supports Rsync server settings and shared folder modules, migrating to Rsync requires configuring your TrueNAS SCALE servers (HP1, HP2, HP3, HP7, HP8) to pull the backups directly from the UNAS-Pro Rsync daemon over TCP port 873.

2026-07-22 - UniFi Firewall Rules Architecture & Security Audit

Complete UniFi Firewall Rules Architecture & Security Analysis#

VERDICT: [VERIFIED] EXCELLENT HARDENING & ZERO CONFLICTS FIREWALL AUDIT SCORE: 98 / 100 (Grade: A+) A comprehensive, empirical audit of all Linux kernel firewall chains (iptables and ipset) on the UniFi Dream Machine Special Edition (UDM-SE) confirms that your network firewall architecture is correctly ordered, free of logic errors or shadowed rules, and effectively enforces zero-trust boundaries between untrusted endpoints, corporate work devices, server clusters, and management interfaces.

2026-07-22 - UniFi iLO Security Analysis

HPE iLO Out-of-Band Server Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the dedicated HPE iLO Out-of-Band Management network (10.1.5.0/24, interface br15) confirms that all 7 HPE ProLiant iLO management controllers (HP1-iLO through HP8-iLO) are isolated in a dedicated VLAN protected by enforced Linux kernel firewall rules (iptables), gateway management blocking, active honeypot detection (10.1.5.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Lab-Servers Security Analysis

Lab-Servers Infrastructure & Virtualization Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Lab-Servers network (10.1.1.0/24, interface br11) confirms that all Proxmox VE hypervisor nodes, Proxmox Datacenter Manager (PDM), Proxmox Backup Servers (PBS), TrueNAS storage arrays, and virtual server infrastructure operate on a dedicated 10G SFP+ aggregated network protected by Linux kernel firewall rules (iptables), gateway management isolation, active honeypot monitoring (10.1.1.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Lab-VM Security Analysis

Lab-VM Virtual Machines & Container Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Lab-VM network (10.1.2.0/24, interface br12) confirms that your core application workloads — including the High Availability Pi-hole DNS cluster (10.1.2.8), Docker container hosts, Nextcloud/Owncloud private clouds, Synology DSM VMs, GPU compute nodes, LubeLogger, and virtual NAS appliances — operate on an isolated 10G SFP+ aggregated network (USW Aggregation 2) protected by Linux kernel firewall rules (iptables), gateway management isolation, active honeypot detection (10.1.2.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi LasikMD Security Analysis

LasikMD Work Network & Sandbox Security Analysis#

VERDICT: [VERIFIED] SECURE AND 100% ISOLATED SECURITY SCORE: 98 / 100 (Grade: A+) An empirical security audit of the LasikMD Work Laptop Network (10.1.8.0/24, interface br18) confirms that your primary security objective — ensuring company infrastructure and corporate IT monitoring software cannot see, scan, or discover any device on your personal homelab — is 100% fully achieved and enforced at the UDM-SE Linux kernel level (iptables).

2026-07-22 - UniFi Management LAN Network Security Analysis

UniFi Primary LAN & Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 96 / 100 (Grade: A+) An empirical audit of the primary Default LAN network (10.1.0.0/24, interface br0) confirms that all 21 UniFi infrastructure hardware devices (UDM-SE gateway, ProMax switches, 10G aggregation switches, wireless access points, building bridges, and smart UPS) operate on an isolated management subnet protected by enforced Linux kernel firewall rules (iptables), key-only SSH authentication, and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Protect Security Cameras Network Security Analysis

UniFi Protect Surveillance Camera Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Cameras network (10.1.4.0/24, interface br14) confirms that all 7 UniFi Protect HD/4K security cameras operate on a dedicated surveillance VLAN protected by Linux kernel firewall rules (iptables), local UniFi Protect NVR video recording, gateway management isolation, active honeypot detection (10.1.4.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi WAN2 Transit Security Analysis

WAN 2 Transit Secondary Internet Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 98 / 100 (Grade: A+) An empirical security audit of the WAN 2 Transit secondary internet interface (eth4, IP 100.107.0.252/10) confirms that your secondary failover ISP line is protected by strict Linux kernel firewall rules (UBIOS_WAN_IN_USER & UBIOS_WAN_LOCAL_USER), Carrier-Grade NAT (CGNAT) isolation, stateful packet inspection, dynamic outbound masquerading, and zero WAN administrative interface exposure.

2026-07-21 - UniFi IoT Network Security Analysis

UniFi IoT Network & Wi-Fi Security Analysis#

VERDICT: [VERIFIED] SECURE AND ISOLATED SECURITY SCORE: 97 / 100 (Grade: A+) Live kernel firewall rules and DHCP configurations confirm that the marcoue - IoT Wi-Fi (10.1.3.0/24, VLAN 13) has active inter-VLAN isolation, gateway management blocking, active honeypot detection, mDNS reflection, native Pi-hole DNS Option 6 (10.1.2.8), and local NTP gateway redirection (10.1.3.1:123).


1. Verified Infrastructure & Network Profile#

  • Gateway Device: UniFi Dream Machine Special Edition (UDMPROSE / UDM-SE at 10.1.0.1)
  • Wi-Fi SSID Name: marcoue - IoT
  • Network Name: IoT
  • VLAN ID: 13
  • Subnet: 10.1.3.0/24 (Interface br13)
  • Kernel IPSET Group: UBIOS_CUSTOM1_subnets
  • Wireless Configuration: 2.4 GHz (ng protocol, 20 MHz channel width for stability)
  • Active Devices Observed: Meross Dimmer Switches (10.1.3.178), Aqara Camera Hub G3 (10.1.3.222), smart plugs, smart lighting endpoints.

2. Empirical Firewall Rule Audit (Live Kernel Verification)#

Direct inspection of the UDM-SE Linux kernel firewall (iptables and ipset) verified the following active rule chains for VLAN 13 (UBIOS_CUSTOM1):