2026-07-23 - UniFi WAN Security Audit Report

UniFi UDM-SE WAN, Security & IPv6 Audit Report#

Date: July 23, 2026
Gateway Device: Ubiquiti UniFi Dream Machine Special Edition (UDM-SE)
Firmware Version: 5.1.19.33549
Primary ISP (WAN1): Cogeco Connexion (1000 Mbps Down / 30 Mbps Up)
Failover ISP (WAN2): Vidéotron (Currently Down - Offline)
Secondary Backup ISP (WAN3): Starlink (CGNAT)


1. Executive Summary#

An in-depth audit of the UniFi Dream Machine SE gateway was performed via the UniFi API. The assessment evaluated the primary WAN (WAN1 - Cogeco Connexion), secondary failover WAN (WAN2 - Vidéotron), and backup satellite WAN (WAN3 - Starlink).

2026-07-22 - UniFi Firewall Rules Architecture & Security Audit

Complete UniFi Firewall Rules Architecture & Security Analysis#

VERDICT: [VERIFIED] EXCELLENT HARDENING & ZERO CONFLICTS FIREWALL AUDIT SCORE: 98 / 100 (Grade: A+) A comprehensive, empirical audit of all Linux kernel firewall chains (iptables and ipset) on the UniFi Dream Machine Special Edition (UDM-SE) confirms that your network firewall architecture is correctly ordered, free of logic errors or shadowed rules, and effectively enforces zero-trust boundaries between untrusted endpoints, corporate work devices, server clusters, and management interfaces.

2026-07-22 - UniFi iLO Security Analysis

HPE iLO Out-of-Band Server Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the dedicated HPE iLO Out-of-Band Management network (10.1.5.0/24, interface br15) confirms that all 7 HPE ProLiant iLO management controllers (HP1-iLO through HP8-iLO) are isolated in a dedicated VLAN protected by enforced Linux kernel firewall rules (iptables), gateway management blocking, active honeypot detection (10.1.5.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Lab-Servers Security Analysis

Lab-Servers Infrastructure & Virtualization Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Lab-Servers network (10.1.1.0/24, interface br11) confirms that all Proxmox VE hypervisor nodes, Proxmox Datacenter Manager (PDM), Proxmox Backup Servers (PBS), TrueNAS storage arrays, and virtual server infrastructure operate on a dedicated 10G SFP+ aggregated network protected by Linux kernel firewall rules (iptables), gateway management isolation, active honeypot monitoring (10.1.1.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Lab-VM Security Analysis

Lab-VM Virtual Machines & Container Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Lab-VM network (10.1.2.0/24, interface br12) confirms that your core application workloads — including the High Availability Pi-hole DNS cluster (10.1.2.8), Docker container hosts, Nextcloud/Owncloud private clouds, Synology DSM VMs, GPU compute nodes, LubeLogger, and virtual NAS appliances — operate on an isolated 10G SFP+ aggregated network (USW Aggregation 2) protected by Linux kernel firewall rules (iptables), gateway management isolation, active honeypot detection (10.1.2.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi LasikMD Security Analysis

LasikMD Work Network & Sandbox Security Analysis#

VERDICT: [VERIFIED] SECURE AND 100% ISOLATED SECURITY SCORE: 98 / 100 (Grade: A+) An empirical security audit of the LasikMD Work Laptop Network (10.1.8.0/24, interface br18) confirms that your primary security objective — ensuring company infrastructure and corporate IT monitoring software cannot see, scan, or discover any device on your personal homelab — is 100% fully achieved and enforced at the UDM-SE Linux kernel level (iptables).

2026-07-22 - UniFi Management LAN Network Security Analysis

UniFi Primary LAN & Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 96 / 100 (Grade: A+) An empirical audit of the primary Default LAN network (10.1.0.0/24, interface br0) confirms that all 21 UniFi infrastructure hardware devices (UDM-SE gateway, ProMax switches, 10G aggregation switches, wireless access points, building bridges, and smart UPS) operate on an isolated management subnet protected by enforced Linux kernel firewall rules (iptables), key-only SSH authentication, and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Protect Security Cameras Network Security Analysis

UniFi Protect Surveillance Camera Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Cameras network (10.1.4.0/24, interface br14) confirms that all 7 UniFi Protect HD/4K security cameras operate on a dedicated surveillance VLAN protected by Linux kernel firewall rules (iptables), local UniFi Protect NVR video recording, gateway management isolation, active honeypot detection (10.1.4.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi WAN2 Transit Security Analysis

WAN 2 Transit Secondary Internet Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 98 / 100 (Grade: A+) An empirical security audit of the WAN 2 Transit secondary internet interface (eth4, IP 100.107.0.252/10) confirms that your secondary failover ISP line is protected by strict Linux kernel firewall rules (UBIOS_WAN_IN_USER & UBIOS_WAN_LOCAL_USER), Carrier-Grade NAT (CGNAT) isolation, stateful packet inspection, dynamic outbound masquerading, and zero WAN administrative interface exposure.

2026-07-21 - UniFi IoT Network Security Analysis

UniFi IoT Network & Wi-Fi Security Analysis#

VERDICT: [VERIFIED] SECURE AND ISOLATED SECURITY SCORE: 97 / 100 (Grade: A+) Live kernel firewall rules and DHCP configurations confirm that the marcoue - IoT Wi-Fi (10.1.3.0/24, VLAN 13) has active inter-VLAN isolation, gateway management blocking, active honeypot detection, mDNS reflection, native Pi-hole DNS Option 6 (10.1.2.8), and local NTP gateway redirection (10.1.3.1:123).


1. Verified Infrastructure & Network Profile#

  • Gateway Device: UniFi Dream Machine Special Edition (UDMPROSE / UDM-SE at 10.1.0.1)
  • Wi-Fi SSID Name: marcoue - IoT
  • Network Name: IoT
  • VLAN ID: 13
  • Subnet: 10.1.3.0/24 (Interface br13)
  • Kernel IPSET Group: UBIOS_CUSTOM1_subnets
  • Wireless Configuration: 2.4 GHz (ng protocol, 20 MHz channel width for stability)
  • Active Devices Observed: Meross Dimmer Switches (10.1.3.178), Aqara Camera Hub G3 (10.1.3.222), smart plugs, smart lighting endpoints.

2. Empirical Firewall Rule Audit (Live Kernel Verification)#

Direct inspection of the UDM-SE Linux kernel firewall (iptables and ipset) verified the following active rule chains for VLAN 13 (UBIOS_CUSTOM1):