UniFi VPN Management

UniFi VPN Management#

1 OpenVPN#

1.1 Client Profile#

The verified iPhone client uses OpenVPN Connect with these settings:

  • Profile name: marcoue.ddns.net [OpenVPN Server]
  • Server hostname: marcoue.ddns.net
  • Username: marcoue
  • Password: Saved in the OpenVPN client; do not document it here.
  • DDNS provider: No-IP (ddns.net)

The profile uses the hostname rather than a fixed IP, so the iPhone profile normally does not need to be edited when the ISP address changes.

The OpenVPN listening port and the exact UniFi port-forward rule were not captured in the available documentation. Verify those values in the UniFi Network application if the VPN still fails after DNS is corrected.

Home Assistant & UniFi Device Management Standard

📱 Home Assistant & UniFi Device Management Standard#

1. Executive Summary & Architecture#

This document defines the Single Source of Truth (SSOT) Device Management Architecture for the Homelab environment.

To optimize speed, usability, and data integrity:

  1. Google Sheets serves as the Primary User Entry Interface. Adding or editing devices in the spreadsheet is fast, accessible on mobile/desktop, and requires zero complex IPAM UI navigation.
  2. NetBox (v4.2) serves as the Automated IPAM & DCIM System of Record. It is hosted on 10.1.2.202:8082 and reconciled directly from Google Sheets via terminal alias.
flowchart LR
    A["Google Sheets (User Entry)"] -->|Mac Studio Alias: netbox| B["sync_gsheets_to_netbox.py"]
    B -->|Non-Destructive Delta Sync| C["NetBox v4.2 (10.1.2.202:8082)"]
    C -->|API & Interoperability| D["UniFi UDM / Home Assistant / Pi-hole"]

2. Standard Operating Procedure (SOP) for Device Management#

A. Adding or Editing Devices#

  1. Open the Google Sheet inventory (Devices tab).
  2. Add or edit any row (Location, Name, Serial, MAC, IP, Type, Brand).
  3. Open your Mac Studio terminal and type:
    netbox
  4. Outcome: The script fetches your spreadsheet, securely sends the inventory to NetBox on 10.1.2.202:8082, and updates your network records in seconds.

B. Retiring or Deleting a Device#

  • Option 1 (Archive / Keep Record): Change the Location column in Google Sheets to Z-Inactive.
    • Behavior: The sync script automatically skips all Z-Inactive rows during import, removing the device from active NetBox IPAM while preserving historical records in your spreadsheet.
  • Option 2 (Permanent Delete): Delete the row from the Google Sheet and run netbox.

3. Work Completed#

During the system implementation, the following key engineering milestones were achieved:

Unifi UNAS-Pro Usage Inventory Plan

Master Plan: UNAS Pro SMB Usage Inventory#

This document outlines the proposed step-by-step strategy to perform a comprehensive audit and inventory of all workloads, computers, virtual machines, Docker stacks, and scripts utilizing SMB shares from the UNAS Pro (10.1.2.2) NAS.

Active Share Matrices#

Workstations & Computers#

Server / Machine Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
MacBook Air X X X X X X X X X X X X X X X X X
MacBook Pro 15 X X X X X X X X X X X X X X X X X
MacBook Pro 16 X X X X X X X X X X X X X X X X X
iMac (MO) X X X X X X X X X X X X X X X X X

Mac Studio (10.1.2.4)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
Mac Studio (Host) X - X X X X X X X X X X X X - - -
    └─ open-webui - - - - - - - - - - - - - - - - -
    └─ portainer-agent - - - - - - - - - - - - - - - - -
    └─ cloudflared - - - - - - - - - - - - - - - - -
    └─ dockge - - - - - - - - - - - - - - - - -

MMProxmox (10.1.1.10)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
MMProxmox (Host) X - - - - - - - - - - - - - - - -
Pi-Hole (LXC 100) - - - - - - - - - - - - - - - - -
HomeAssistant (VM 200) - - - - - - - - - - - - - - - - -
MMDocker (VM 230) - OS Mounts X X - - X X X - X X X X X X - - -
    └─ Radarr - - - - - - X - - - - - - - - - -
    └─ Sonarr - - - - - - X - - - - - - - - - -
    └─ Lidarr - - - - - - X - - - - - - - - - -
    └─ qBittorrent - - - - - - X - - - - - - - - - -
    └─ Backup Sync - X - - - - - - - - - - - - - - -

HP1 Proxmox (10.1.1.11)#

Server / Machine / VM / Service Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
HP1 Proxmox (Host) X - - - - - - - - - - - - - - - -
Pi-Hole-2 (LXC 101) - - - - - - - - - - - - - - - - -
VPSBackups (LXC 102) - - - - - - - - - - - - - - - - -
DatacenterManager (LXC 105) - - - - - - - - - - - - - - - - -
HP1TrueNAS (VM 201) - - - - - - - - - - - - - - - - -
HP1Docker (VM 202) - OS Mounts X - - X X X X - X X X X X X - - X
    └─ Backrest X - - - X X - - X X X X - - - - X
    └─ Paperless - - - X - - - - - - - - - - - - -
    └─ Paperless Sync (Cron) - - - - - X - - - - - - - - - - -
    └─ Hugo Publish (Cron) X - - - - - - - - - - - - - - - -
HP1BackupServer (VM 211) - OS Mounts X X - - - - - - - - - - - - - - -
    └─ PBS Daemon X X - - - - - - - - - - - - - - -
HP1Clouds (VM 217) - OS Mounts X - - X X X X - X X X X X X - - -
    └─ Nextcloud AIO X - - X X X X - X X X X X X - - -
    └─ Owncloud Server X - - X X X X - X X X X X X - - -
    └─ File Indexer (Cron) X - - X X X X - X X X X X X - - -
HP1SynologyDSM (VM 221) - - - - - - - - - - - - - - - - -
HP1GPU (VM 231) - OS Mounts X - - - X X X - X X X X X X - - -
    └─ Immich Server - - - - - - - - X - - X - - - - -
    └─ Emby - - - - - - X - - X - - X X - - -
    └─ Plex - - - - - - X - - X - X X X - - -
    └─ Navidrome - - - - - - - - - X - - - - - - -

Scripts & Automations#

Script / Automation Hook Software ProxmoxBackups TimeMachine Paperless_consume Books Documents Downloads GoogleCloudSync Immich Musique Nadine Photos Films TVSeries Personal-Drive UNVR HomesDSM
Git Hook: post-commit X - - - - - - - - - - - - - - - -
proxmox_backup.sh X - - - - - - - - - - - - - - - -
HP1_UNAS_Pull_Backup.sh X - - - X X X X X X X X - - - - X
HP2_UNAS_Pull_Backup.sh X - - - X X - - X X X X - - - - X
HP3_UNAS_Pull_Backup.sh - - - - - - - - - - - - X X - - -
HP7_UNAS_Pull_Backup.sh X - - - X X - X X X X X - - - - X
HP8_UNAS_Pull_Backup.sh X - - - X X - X X X X X X X - - X

Target Inventory Scope#

The inventory will discover and map every dependency on the UNAS Pro SMB shares across four distinct layers:

UniFi UNAS-Pro Pool Migration Strategy

UniFi UNAS-Pro Pool Migration Strategy: Pool 1 (SSD) to Pool 2 (HDD)#

This document defines the operational plan, safety protocols, database update queries, and verification steps to migrate all shared folders from Storage Pool 1 (SSD - Degraded RAID5) to Storage Pool 2 (HDD - Healthy RAID5) on the master UniFi UNAS-Pro NAS (10.1.2.2) while preserving all access rights, Samba configurations, and TrueNAS backup operations.

Antigravity chat: agy –conversation=3dd15667-3c79-485d-af10-ebb5c4f9cc01


1. Executive Summary & Objective#

Due to hardware failures on Pool 1 (Slot 2 pulled, Slot 3 accumulating 75,000+ write failures), Pool 1 is operating with zero fault tolerance. To prevent data loss prior to receiving warranty replacement drives, all active shares on Pool 1 will be migrated to Pool 2.

Unifi UNAS-Pro Backup Strategy

UniFi UNAS-Pro Master Backup Strategy: Native Rsync Daemon (Pull) Architecture#

This document defines the complete operational standard, architecture, schedule matrix, node-by-node configuration reference, and disaster recovery procedures for backing up all shared data from the master UniFi UNAS-Pro NAS (10.1.2.2) across the fleet of 5 TrueNAS SCALE storage nodes (HP1, HP2, HP3, HP7, HP8). It is designed to be sufficient to fully reconstruct the entire setup from scratch.

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

Unifi UNAS-Pro Backup Migration Plan

UNAS-Pro Backup Migration Plan: SMB (Push) to Native Rsync Daemon (Pull)#

Antigravity Chat: agy –conversation=4c0c9b6d-2722-4fd6-a4aa-638c75ab46f4

This document is the complete master migration plan for transitioning the UNAS-Pro backup strategy from the UniFi Drive UI-managed SMB (Push) setup to a Native Rsync Daemon (Pull) model.

Because the UniFi Drive UI natively supports Rsync server settings and shared folder modules, migrating to Rsync requires configuring your TrueNAS SCALE servers (HP1, HP2, HP3, HP7, HP8) to pull the backups directly from the UNAS-Pro Rsync daemon over TCP port 873.

2026-07-23 - UniFi WAN Security Audit Report

UniFi UDM-SE WAN, Security & IPv6 Audit Report#

Date: July 23, 2026
Gateway Device: Ubiquiti UniFi Dream Machine Special Edition (UDM-SE)
Firmware Version: 5.1.19.33549
Primary ISP (WAN1): Cogeco Connexion (1000 Mbps Down / 30 Mbps Up)
Failover ISP (WAN2): Vidéotron (Currently Down - Offline)
Secondary Backup ISP (WAN3): Starlink (CGNAT)


1. Executive Summary#

An in-depth audit of the UniFi Dream Machine SE gateway was performed via the UniFi API. The assessment evaluated the primary WAN (WAN1 - Cogeco Connexion), secondary failover WAN (WAN2 - Vidéotron), and backup satellite WAN (WAN3 - Starlink).

2026-07-22 - UniFi Firewall Rules Architecture & Security Audit

Complete UniFi Firewall Rules Architecture & Security Analysis#

VERDICT: [VERIFIED] EXCELLENT HARDENING & ZERO CONFLICTS FIREWALL AUDIT SCORE: 98 / 100 (Grade: A+) A comprehensive, empirical audit of all Linux kernel firewall chains (iptables and ipset) on the UniFi Dream Machine Special Edition (UDM-SE) confirms that your network firewall architecture is correctly ordered, free of logic errors or shadowed rules, and effectively enforces zero-trust boundaries between untrusted endpoints, corporate work devices, server clusters, and management interfaces.

2026-07-22 - UniFi iLO Security Analysis

HPE iLO Out-of-Band Server Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the dedicated HPE iLO Out-of-Band Management network (10.1.5.0/24, interface br15) confirms that all 7 HPE ProLiant iLO management controllers (HP1-iLO through HP8-iLO) are isolated in a dedicated VLAN protected by enforced Linux kernel firewall rules (iptables), gateway management blocking, active honeypot detection (10.1.5.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Lab-Servers Security Analysis

Lab-Servers Infrastructure & Virtualization Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Lab-Servers network (10.1.1.0/24, interface br11) confirms that all Proxmox VE hypervisor nodes, Proxmox Datacenter Manager (PDM), Proxmox Backup Servers (PBS), TrueNAS storage arrays, and virtual server infrastructure operate on a dedicated 10G SFP+ aggregated network protected by Linux kernel firewall rules (iptables), gateway management isolation, active honeypot monitoring (10.1.1.254), and strict inter-VLAN boundary drops.