UniFi IoT Network & Wi-Fi Security Analysis#
VERDICT: [VERIFIED] SECURE AND ISOLATED SECURITY SCORE: 97 / 100 (Grade: A+) Live kernel firewall rules and DHCP configurations confirm that the marcoue - IoT Wi-Fi (
10.1.3.0/24, VLAN 13) has active inter-VLAN isolation, gateway management blocking, active honeypot detection, mDNS reflection, native Pi-hole DNS Option 6 (10.1.2.8), and local NTP gateway redirection (10.1.3.1:123).
1. Verified Infrastructure & Network Profile#
- Gateway Device: UniFi Dream Machine Special Edition (UDMPROSE / UDM-SE at 10.1.0.1)
- Wi-Fi SSID Name: marcoue - IoT
- Network Name: IoT
- VLAN ID: 13
- Subnet: 10.1.3.0/24 (Interface br13)
- Kernel IPSET Group: UBIOS_CUSTOM1_subnets
- Wireless Configuration: 2.4 GHz (ng protocol, 20 MHz channel width for stability)
- Active Devices Observed: Meross Dimmer Switches (10.1.3.178), Aqara Camera Hub G3 (10.1.3.222), smart plugs, smart lighting endpoints.
2. Empirical Firewall Rule Audit (Live Kernel Verification)#
Direct inspection of the UDM-SE Linux kernel firewall (iptables and ipset) verified the following active rule chains for VLAN 13 (UBIOS_CUSTOM1):