2026-07-22 - UniFi Lab-VM Security Analysis

Lab-VM Virtual Machines & Container Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Lab-VM network (10.1.2.0/24, interface br12) confirms that your core application workloads — including the High Availability Pi-hole DNS cluster (10.1.2.8), Docker container hosts, Nextcloud/Owncloud private clouds, Synology DSM VMs, GPU compute nodes, LubeLogger, and virtual NAS appliances — operate on an isolated 10G SFP+ aggregated network (USW Aggregation 2) protected by Linux kernel firewall rules (iptables), gateway management isolation, active honeypot detection (10.1.2.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi LasikMD Security Analysis

LasikMD Work Network & Sandbox Security Analysis#

VERDICT: [VERIFIED] SECURE AND 100% ISOLATED SECURITY SCORE: 98 / 100 (Grade: A+) An empirical security audit of the LasikMD Work Laptop Network (10.1.8.0/24, interface br18) confirms that your primary security objective — ensuring company infrastructure and corporate IT monitoring software cannot see, scan, or discover any device on your personal homelab — is 100% fully achieved and enforced at the UDM-SE Linux kernel level (iptables).

2026-07-22 - UniFi Management LAN Network Security Analysis

UniFi Primary LAN & Management Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 96 / 100 (Grade: A+) An empirical audit of the primary Default LAN network (10.1.0.0/24, interface br0) confirms that all 21 UniFi infrastructure hardware devices (UDM-SE gateway, ProMax switches, 10G aggregation switches, wireless access points, building bridges, and smart UPS) operate on an isolated management subnet protected by enforced Linux kernel firewall rules (iptables), key-only SSH authentication, and strict inter-VLAN boundary drops.

2026-07-22 - UniFi Protect Security Cameras Network Security Analysis

UniFi Protect Surveillance Camera Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 97 / 100 (Grade: A+) An empirical security audit of the Cameras network (10.1.4.0/24, interface br14) confirms that all 7 UniFi Protect HD/4K security cameras operate on a dedicated surveillance VLAN protected by Linux kernel firewall rules (iptables), local UniFi Protect NVR video recording, gateway management isolation, active honeypot detection (10.1.4.254), and strict inter-VLAN boundary drops.

2026-07-22 - UniFi WAN2 Transit Security Analysis

WAN 2 Transit Secondary Internet Network Security Analysis#

VERDICT: [VERIFIED] SECURE AND HARDENED SECURITY SCORE: 98 / 100 (Grade: A+) An empirical security audit of the WAN 2 Transit secondary internet interface (eth4, IP 100.107.0.252/10) confirms that your secondary failover ISP line is protected by strict Linux kernel firewall rules (UBIOS_WAN_IN_USER & UBIOS_WAN_LOCAL_USER), Carrier-Grade NAT (CGNAT) isolation, stateful packet inspection, dynamic outbound masquerading, and zero WAN administrative interface exposure.

2026-07-21 - UniFi IoT Network Security Analysis

UniFi IoT Network & Wi-Fi Security Analysis#

VERDICT: [VERIFIED] SECURE AND ISOLATED SECURITY SCORE: 97 / 100 (Grade: A+) Live kernel firewall rules and DHCP configurations confirm that the marcoue - IoT Wi-Fi (10.1.3.0/24, VLAN 13) has active inter-VLAN isolation, gateway management blocking, active honeypot detection, mDNS reflection, native Pi-hole DNS Option 6 (10.1.2.8), and local NTP gateway redirection (10.1.3.1:123).


1. Verified Infrastructure & Network Profile#

  • Gateway Device: UniFi Dream Machine Special Edition (UDMPROSE / UDM-SE at 10.1.0.1)
  • Wi-Fi SSID Name: marcoue - IoT
  • Network Name: IoT
  • VLAN ID: 13
  • Subnet: 10.1.3.0/24 (Interface br13)
  • Kernel IPSET Group: UBIOS_CUSTOM1_subnets
  • Wireless Configuration: 2.4 GHz (ng protocol, 20 MHz channel width for stability)
  • Active Devices Observed: Meross Dimmer Switches (10.1.3.178), Aqara Camera Hub G3 (10.1.3.222), smart plugs, smart lighting endpoints.

2. Empirical Firewall Rule Audit (Live Kernel Verification)#

Direct inspection of the UDM-SE Linux kernel firewall (iptables and ipset) verified the following active rule chains for VLAN 13 (UBIOS_CUSTOM1):

Starlink

Starlink Emergency Network Backup Playbook#

This document outlines the operational and financial strategy for utilizing a Starlink Mini hardware kit on a Roam subscription tier as an infrastructure-independent secondary WAN failover. This configuration completely bypasses local terrestrial infrastructure dependencies (cell towers and cable/fiber nodes) during extended power grid collapses.


1. Core Architecture Strategy#

  • Integrated Router: Router is built directly into the dish panel, featuring a native, weather-sealed RJ45 Ethernet port. No proprietary Ethernet adapters required.
  • Direct WAN Hand-off: Connects directly from the dish into the secondary WAN port of the local gateway/firewall (e.g., UniFi Gateway).
  • Power Efficiency: Draws 25–40 Watts. Capable of native DC power input, making it resilient when running off standard 100W USB-C PD power banks or 12V portable generator setups.

Plan Selection: Roam Tier#

  • Cell Congestion Immunity: Roam plans skip geographic cell capacity checks. If an emergency triggers a mass local reactivation event, the system will block standard Residential activations but will approve Roam activations instantly.
  • Mobility Option: Allows the hardware to be disconnected from the home mount and utilized remotely for off-grid operations or travel.

2. Financial Metrics (CAD)#

  • Standby Mode Base Rate: $15.00 / month
  • Roam 100GB Tier: $75.00 / month
  • Roam Unlimited Tier: $200.00 / month
  • Over-Cap Throttled Speed: 1.0 Mbps Download / 0.5 Mbps Upload
  • Annual Idle Maintenance: $180.00 / year

3. Operational Lifecycles & Playbooks#

Configuration A: Baseline Idle State#

  1. Connect the Starlink Mini to the secondary WAN port of the gateway.
  2. Place the Starlink subscription into Standby Mode via the account portal.
  3. Keep the unit powered on.
    • Result: The dish consumes minimal background data to maintain alignment, pull critical system firmware updates, and pass basic network pings.
    • Bandwidth Cap: Throughput is strictly capped at 500 Kbps in this state. The link remains live just enough to load the Starlink management portal and process two-factor authentication (2FA) emails.

Configuration B: Phase 1 Activation (Short-Term Outage)#

Execute this phase when local terrestrial links drop and an extended power grid outage is confirmed.

UniFi UDM Device SSH Configuration

UniFi Device SSH Configuration#

This guide covers hardening and configuring SSH access for UniFi consoles (UDM-SE, UNVR, UNAS-Pro) and management of secondary devices like Switches and Access Points.


1. Console Configuration (UDM-SE, UNVR, UNAS-Pro)#

SSH Key Setup#

  1. Edit the authorized keys file to add your public keys:
nano .ssh/authorized_keys
# Restart the service
systemctl restart sshd

Install Tailscale#

For complete subnet advertising (10.1.0.0/16), exit node setup, and route approval guidelines, see the Tailscale Guide.

Netgear Switch GS110TPv3

Netgear Switch GS110TPv3#

codex resume 019fe6f1-4f8a-7413-be32-70dd7a25a64f

How to reach the switch#

The Netgear GS110TPv3 is managed through the primary UniFi LAN.

  1. Connect the Netgear switch uplink to an available port on a UniFi network switch.

  2. Use the Netgear’s g1 port as the uplink. It carries the management LAN and tagged VLANs.

  3. In the UniFi Network application, configure the UniFi uplink port with:

    • Native Network: LAN (1)
    • Tagged VLAN Management: Allow All (or an equivalent trunk profile)
    • STP: enabled/Auto; BPDU Guard disabled
  4. From a device on the same LAN, browse to: