Transcription
Hey everyone, Cody from Mac Telecom Networks. In this video, we're going to be doing something that has been requested a lot over the last year. This is going to be my complete UniFi network application setup of 2025. We're going to go over everything from the initial setup to adopting devices, creating Wi-Fi networks, creating networks, doing firewall rules, and we're going to also look at VPNs and our threat management.
Now, this video is going to be quite long, so I will put timestamps down below so you could just jump wherever you want to go, but this is just going to be a basic setup to get your home up and running or your business up and running. I know a lot of people want in-depth firewall rules. So, if you want to see more about the firewall, leave your comments down below. I'm going to do a separate video on all of those comments.
If you don't want to set up the UniFi Network application alone or you want me to do it, we do offer full remote support for anywhere in the world. Just visit our website at macktelecomnetworks.com if you're local. We also provide structured cabling. We do phone systems, camera systems, and unifi access. So visit our website and click the hire us button. Now let's jump right into it.
Before we get into the initial configuration, we're going to take a look at the topology of what I am using for this buildout of the video. We have two ISPs at the top, ISP1 and ISP2. And for our firewall, we're going to be using the cloud gateway fiber. This will do 5 Gbit per second IDs and IPS. That's why I chose it. And then down below we have the Pro HD 24 POE. This is a great switch for your home or business, but it may be a little bit overkill if you're just using it for your home. But this will provide PoE for all of our devices for our access points, cameras, or our telephones. The access points that I'm using is the U7XG and the U6 Enterprise. These both have 6 GHz and the U7XG has Wi-Fi 7. And then we will also have a NAS connected to it.
For our networks, we're going to have the default network at 10.10.1.1/24 with no Wi-Fi. This will be our management network that will be hosting all of our UniFi equipment. We're also going to have a staff network at 10.10.10.1/24 with Wi-Fi of staff 2025. We'll have an IoT network that could go out to the internet and it's going to have a Wi-Fi SSID of IoT 2025. We're also going to have an NOT which won't have internet access, but it will also have Wi-Fi. So, if you want any devices to be put on that, but you don't want it to be reaching out to the internet, that's the network you'll want to use. We're also going to have a guest and we're going to have a kids network, which we will put on a schedule, and we'll do some content filtering with that.
Before we do any of the network configuration, we need to get the initial setup done. And the easiest way to do it is by your phone using the UniFi network application. So, we're going to jump over to my phone and get the initial setup done.
We're now over on my phone on the UniFi Network application and we could see that a new cloud gateway fiber has been found. We need to get this set up. If you don't already have an account with Ubiquiti, you'll want to create one at account.ui.com. You can also set this up locally if you don't want to be tied to their account. So, we're going to press set up. It says, "Name your cloud gateway fiber. We're going to call it YouTube 2025." We can see that it's doing a speed test and we're getting about a,000 down and we should probably get about 40 up. That's what this coax connection does. Now, right from the top, it's going to tell us our ISP. It's going to show us the location and our IP address, but it also has this quality enhancement. So, if you have that turned on, it will have QoS for those following applications. And we'll press next. Now, it's going to be setting up our UniFi OS and we'll be doing any firmware upgrades. We will take a look to see if there's any other upgrades for our network application once this is done.
The console is now set up and we're on the cloud gateway fiber. I got here by going to unifi.ui.com through the Ubiquity site manager. Right now, we see my dashboard. There's not a whole lot to it. We could see all network health, Wi-Fi health, and then we could see the applications and the devices that are being most utilized. The first thing we're going to do though, we need to change our network. If we click on the unified devices, we could see that the YouTube 2025 is at 192.168.1.1. And if we go back to our drawing, we want it to be at 10.10.1.1. So before adopting all of these devices, we're going to click on our settings wheel. We're going to go over to networks, and then we're going to click on our default network. Here, we're going to change the host address to 10.10.1.1. And then we're going to press apply changes. Before I do this, I'm going to deselect autoscale because I don't want these networks scaling by themselves and then press apply changes.
The next thing I'm going to do before we get our devices into the UniFi network application is to check for updates. How we do that? We go over to our control plane. From the control plane, you can see our UniFi OS is up to date and we're under the official release channel. We can see that the UniFi Network application needs to be updated to 9.1.120. So, I'm going to do that right now. For all the other applications, they're not installed right now, and I'll leave them uninstalled until I actually need them. If I ever wanted to run some cameras on that, then I would install UniFi Protect.
Now, our OS and our application is all up to date. We're using OS version 4.2.12 and network version 9.1.120. These network versions change quite often. So if you're seeing your dashboard look a little bit different than mine, there's probably a new version out. Usually what I do when the new UniFi network application comes out, I release a new video based on what is there or what is new and in the improvements.
The next thing we need to do, we need to get our devices adopted into the UniFi Network application by going up to our left and clicking on UniFi devices. On the device page, we can see that we have three different devices that need to be adopted. My USW Pro HD 24 POE, the U6 Enterprise, and the U7 Pro XG. We could click each one of these individually, or at the top, we could adopt them all, which I'm going to do. We need to have these devices adopted within the UniFi Network application so that we can make changes to them. Once they're done, they're saying getting ready, we may have some updates that we need to push out to them, and we always want to make sure that our devices, our OS, and our application is up to date.
While we're waiting for the switch to update, we'll start creating our networks by going down to the settings wheel, clicking on networks. The only one that's currently in here is our default network at 10.10.1.0. But if we look over on our diagram, we still need the staff, IoT, NOT, guest, and the kids network.
The first network we need to create is our staff network. And we do that by clicking new virtual network. Here I'm going to give it a name of staff. We're going to deselect autoscale. And then we're going to change the host address to 10.10.10.1. And we're also going to do it a /24. Looking down below, I'm going to click on manual. And then I'm going to give it a VLAN ID of 10. You could have this VLAN ID to whatever you want, but I like to match my third octet to the VLAN ID. The rest of these settings we're not going to need. So, we don't need this as a guest network or we're not isolating the network. And it's going to have internet access. We will create firewall rules around this later on in the video. And then we need to press add.
Our next network is our IoT network. We're going to deselect autoscale and it's going to be 10.10.20.1. We're going to click on manual. And then we're going to set the VLAN ID to 20. And then we're going to add.
We have another one that is going to be our note. And for the NOT, we're not going to have internet access. We're going to unselect autoscale. It's going to be 10.10.30.1. We'll click on manual. The VLAN will be 30, but this time we're not going to allow internet access. So, we're going to uncheck this box. So, it will only be able to work locally. And then we're going to add it.
We have two more networks that we need to do. And this next one is our guest network. And this is going to be on 10.10.40.1. We'll go to manual. The VLAN ID will be 40. And we're going to select guest network this time. And what the guest networks does, it isolates it from any other virtual network or VLAN that you have within your UniFi network application. If you want to have a splash page or a landing page, you could also enable that when we do our Wi-Fi networks.
The last network that we're going to create is our kids network. We're going to deselect autoscale. It's going to be 10.10.50.1 and we're going to select on manual and give it a VLAN ID of 50. For this network, we're going to put content filtering on and we're going to select that as family. So, it blocks VPNs, explicit, pornographic, and malicious domains, search engines, and YouTube set to safe mode. We can do more content filtering than this, and we will do that later on in the video, but for now, that is good enough. And we're going to press add.
We have all of our networks created. We now need to create our Wi-Fi networks. And we just need to select Wi-Fi above the networks. From here, we need to create a new Wi-Fi network. The first one is going to be called staff 2025. For our password, we have to have at least eight characters. And for this video, I'm just going to do test 1 2 3 4 for all of them. But you want to make sure it's a strong password. Below the password, we have our network. And this tells us where this Wi-Fi SSID lives on. So, if we click on the drop-down menu, I'm going to click on staff. When we connect to this Wi-Fi SSID, we're going to get an IP from 10.10.10.1, which is that staff network. We do have a bunch of different options. So, broadcasting APs, we're going to leave it to all. But if you want specific or you want to set up a group, you could do that. We also have advanced. So, if we click on manual, you could see private pre-shared keys, which we will go over here shortly. We have hotspot, which is your captive portal or your passport. And then we have enhanced IoT connectivity. With enhanced IoT connectivity, this makes it do only 2.4 GHz and turns off the 5 GHz and the six. So, we will turn that on for our IoT network. I'm also going to select multi-link operations for every network except our IoT network. It says right here, enabling multi-link operation enforces WPA3, which may disconnect legacy or IoT clients. So, we're not going to have that on for our IoT network. And then we're going to add this Wi-Fi network because everything else I'm going to want at default.
The next Wi-Fi network we need is my IoT. So, IoT 2025. We'll give it a password and then this time the network is going to be IoT. Clicking on advanced and then manual, we're going to go over to the enhanced IoT and it shows you right here. It limits this Wi-Fi network to 2.4 only. So, we'll check that off. And you can see that the 5 GHz and the 6 GHz are deselected.
The next one we have is our NOT 2025. And remember that this network doesn't actually have internet access. It's just going to be a local Wi-Fi. We need to give it a password and then we need to select the network of NOT. We click on manual and then for this I'm going to also have that an enhanced IoT connectivity. And the reason for that is because we don't want the 5 GHz or the 6 GHz turned on.
And the last Wi-Fi network that we're going to create is our kids network. So I'm going to call it kids 2025. We'll give it a password. And then we're going to select the network of kids. One thing that I didn't mention for multilink operations, it will only work on some access points that support Wi-Fi 7, just so you know. So, I'm going to click on manual and then we're going to go down and I'm going to select multilink operations and we're going to add this Wi-Fi network.
We're going to do two more things with the kids network. We're going to have them on a schedule so they could only use Wi-Fi between 8:00 a.m. and 8:00 p.m. Monday to Friday. And then on the weekends, they could do whatever they want. We're also going to limit their Wi-Fi bandwidth. So, scrolling down to the bottom, we have this Wi-Fi blackouter. I currently have it turned on. But if we look at it, it says specified times when this Wi-Fi should be disabled. So, I'm going to go right to 8:00 p.m. And I'm just going to go ahead and drag it over. And then we're going to go to 12:00 a.m. And I'm going to drag this over to 8:00 a.m. These times right here will be disabled. And I'm going to do the same thing all the way down to Friday. Once that's done, I'm going to press apply the changes. Going back to the kids, you could see that they're only going to be able to use the Wi-Fi between 8 a.m. and 8:00 p.m. Well, what if we want to limit them in bandwidth? Well, I'm going to scroll up a little bit and we're going to see right here Wi-Fi speed limit. I'm going to check it off and we're going to create a new profile. This profile, I'm going to call it kids Wi-Fi. I'm going to give them 40 down by 40 up. And we're going to add that. Now, we need to go back to our Wi-Fi, click on kids, scroll down, and then we need to find that Wi-Fi speed limit. From here, we could select that new profile that we just created, and apply the changes.
We have all of our Wi-Fi networks created, but what does private pre-shared keys do, and where do you want to use it? So, typically when we do private pre-shared keys, it's for multi-dwelling units. And what this does, it makes it so you only broadcast one wireless SSID, but you have different passwords to route you to different networks. And I'll show you that right now. If we click on my networks, I created PPSK1, 2, and 3. The Wi-Fi name that we'll give for this is PPSK. We're not going to give it a password because we're going to do that under the private pre-shared keys. We'll select manual and then go private pre-shared keys. But it shows something right here. DPSK only works with WPA2 security at this time and only on the 2.4 and the 5 GHz. You can't have 6 GHz. So, scrolling down, we're going to want to change this to WPA2 and then we could check off that box for private pre-shared keys. Now, with the private pre-shared keys, we have our native network. So if I put a password of test 1 2 3 4 here and then we add it in and then we select another network say our staff network and I call it staff 1 2 3 and we add that in and then we go ahead and we do our private pre-shared key 1 and I go PPSK12 34 and then we'll do one last one and it will be our private pre-shared key 2 and we go PPSK12 345 and we add that in whatever password we put in for our Wi-Fi it's going to route to these different networks. So, I'm going to add the Wi-Fi network. I will join it with one of these passwords. And you'll see that it routes us to different networks.
As you can see, I'm not connected to the network at all. If we go down to the bottom right and we see our wireless networks, we could see this PPSK. Bringing this up. If we connect to it, we're going to connect to the native network first using the password of test 1234. Now, we can see that we're connected. If I bring up a command line and I do IP config, we can see that I have an IP of 10.10.1.154. I've completely forgotten that Wi-Fi network. So, let's try connecting to another one. So, if we click on PPSK and go connect, we're going to do PPSK12345. So, PPSK12 345 and we'll press next. This time, we should get another IP address. So, we'll bring up a different command line. We'll go IP config and we're getting out of 192.168.4.54. So this is really great if you don't want to create 20 different Wi-Fi SSIDs for different units. You could just have one Wi-Fi SSID and different passwords to direct you to the network that they go on. You could also generate different passwords, download passwords, or you could upload passwords.
Our networks are done. Our Wi-Fi networks are done. The next thing we're going to look at is our internet and adding a secondary ISP. You'll see that my Bell is my primary WAN, but we don't have a secondary plugged in right now. The secondary port currently or the default is port 7. So that is going to be your SFP+. I don't have an SFP+ module, so I'm just going to reorder it. Clicking on the settings wheel, you could assign it to whatever port you want. So I'm going to say on port two, and then we're going to apply the changes. I'm going to grab a cable and I'm going to plug it into my secondary ISP on port two and we should see that liveen up.
Our secondary WAN is now connected. But say we wanted more than two WANs. Well, how can we do that and is it possible within the UniFi network application? Well, it is. You could see right here add WAN. I'm just going to call this WAN 3. We could select the port that we want this to be on. And I believe we could do up to eight different WAN connections. Now, most people won't need that, but if you do, that option is there. We're going to go ahead and cancel, and we're going to go back. You'd see that WAN one is the Bell connection and WAN 2 is our Rogers. But say we wanted those flipped around cuz WAN one is primary and WAN 2 is secondary. Well, it's really, really easy to do. Now, all we need to do, we just need to grab this and bring it to the top. Now, our WAN 2 is our primary and our WAN one is the secondary. A couple other things you could do. I have it set to failover right now, but you could have it doing load balancing and you could say which percentage you want it to be at. I typically don't do load balancing unless both WANs have the same upload and they both have the same download. We could also go into our WAN connections and we could modify that. Both of my WAN connections are DHCP, but if we need a VLAN ID, we need to do MAC cloning. Or if you need to set it to static or PPP POE, you could do that.
With our Wi-Fi networks, when we connect to the SSID, it knows which network to bring us on. But how do we do that for physically connected devices? If we click over on our UniFi devices and then my switch and then port manager, we could see on port 8, I have a camera sitting there right now. By default, all of these ports are in VLAN 1 or our default network. So, if we click on port 8, you could see that it's currently in default. But say we wanted this device into our IoT. All we need to do is click the dropdown and go to IoT. And then we want to select block all. After we apply the changes, I'm going to do a little power cycle on this. That camera should get an IP from our IoT network.
Now from our firewall down to our switch, from switch to switch, and then switch to access point, we want to have it like this. The port to be active, our native VLAN to be default, and then we want to allow all so that our VLANs could go across all of our switches as well to our access points. And once that camera restarted, you could see it's getting an IP of 10.10.20.137, which is out of our IoT network. For each physical device that you have, you're going to have to select the port, and then you're going to have to select the network you want it to be on.
The next thing we're going to look at is our security. And this isn't going to be a full-fledged firewall video as everybody's network is different. I'm going to do a base setup of the firewall. Like I said at the beginning, leave your comments below what you want to see for firewall rules and I'll compile a full video with all those comments. But what we're going to do, we're going to click over on security. And right now, this was defaulted and we don't have zone-based firewall. So what we're going to do, we're going to click to upgrade. We currently have no firewall rules in place. It tells us a bunch about the zone-based firewalls and we're going to select upgrade.
Now, each one of the networks that we created went into the internal zone. The only one that didn't go into internal was our guests that went to our hotspot. The reason for that, if we click on networks and then go to guest is because we specified it originally as a guest network. So, going back to security, our default or anything internally could see everything else. Your IoT could see default, staff could see IoT, so on and so forth. And we don't want that. We want to have our default be able to see everything and then all of our other networks being blocked off from each other.
What we're going to do, we're going to create a new zone. So to create a new zone, that's all we need to do. Click this link here. I'm going to call this zone untrusted. In this zone, we need to select the network interfaces that we want. So I'm going to select the IoT, the NOT, and the kids. I'm not going to select the staff because that's going to be in a trusted zone or the guest. The guests are already in the hotspot zone. And we're going to press save and then we're going to add the entry. It does come up with a warning. Please proceed with caution and view the policies applied to this zone to ensure traffic from device is not accidentally blocked. And we're going to proceed. Now going to this untrusted zone that we just created. It blocks all internally. So what this means inner VLAN routing is blocked. I can't get from the IoT to the NOT or from the IoT to the kids and vice versa.
Now, we're going to create another zone and this is going to be our trusted zone. The network interface we're going to put in this one is our staff and we're going to save that and then we're going to add the entry. The same popup will come up as it does block all as well within the internal zone until we start putting some rules in place.
This computer is currently within the default network and if we do a ping of 10.10.20.137. That's a device within my IoT network. We aren't able to hit it. But for my rule set, I want the default network to be able to hit everything. So, we need to scroll down when we're within the internal zone and we need to create a policy. This policy I'll call allow default to all untrusted networks. The source zone will be internal and it will be of network and this network will be our default. And then scrolling down from that, our action is going to be to allow the destination zone. This is going to be our untrusted and we're going to add that policy.
Now, we're going to have to create another policy to allow us to go to the staff. So, we'll say allow default to staff. It's going to be an internal zone of a network of default. The action is going to be to allow and we're going to autoallow return traffic. And the reason for this, it creates a built-in policy for the opposite zone pair to automatically allow the return traffic. If disabled, return traffic must be manually allowed. And then our destination, this is going to be the trusted zone. And we're going to do any any and we're going to add that policy.
Now, bringing up a command prompt again and pinging that device that's in IoT, we could see that we are able to talk to it. And the IoT device is now allowed to talk back to the default device that was talking to it in the first place.
We're going to do a couple other firewall rules. This computer is sitting in the IoT network, and if we ping 10.10.1.1, which is our default networks gateway, we're able to hit it. If we open up a browser and we go to 10.10.1.1, we're able to get to the web interface of it. So, you can see right here, if we click on advance and we proceed, they are able to get to the UniFi OS, which we definitely don't want. SSH by default it is disabled but if you enable it they may be able to bring up an SSH session under the untrusted network we're going to create a policy. This policy is going to deny untrusted to gateways. What we're going to do the source zone is going to be our untrusted network. We're going to block and then our destination is going to be our gateways. But we don't want to stop there. We want it on a specific port. So this what we're going to do is going to be HTTPS or you could create an object. So I'm going to do that. I'm going to create a new object. This will be called HTTP HTTPS and SSH. We're going to put all of those ports in. So 80, 443, and 22. So if we ever enable SSH within our console, these untrusted networks will never be able to get to it through something like Putty. Now, if we add this policy in and we go on and proceed, we shouldn't be able to get to the web interface.
Now, clicking on the browser, we're going to go 10.10.1.1 and this should time out and not allow us to get there. But if we go over to something like ui.com, we should be able to get there and we still have internet access.
We're going to add another rule to our untrusted zone. I'm going to go ahead and create a policy. The name will be block to gateways. The source zone is going to be our untrusted. The action is going to be to block. And then the destination zone is going to be our gateways. Scrolling down, we're going to want to select IPv4. And then we're going to do a custom protocol. This protocol is going to be ICMP. From here, we have the MP type name, and we're just going to select any, and we're going to add the policy. Now bringing up the command prompt. I'm trying to hit one of the gateway IPs and this is going to time out for us as we have that blocking rule. Let's go ahead and we'll try to hit the uh default gateway as well and we're not able to hit that. But we still do have internet access.
Let's say for whatever reason we want the IoT network to be able to talk to our NAS that's sitting on our default network. We'll create a new policy and call it allow IoT to NAS. The source zone will be the untrusted, but we only want to do the IoT network. Scrolling down, the action will be allow. And then our destination zone is going to be the internal network. And we're just going to add the IP of our NAS. So it will be 10.10.1.173. But before I add this policy, let's try to ping it right now. So I'm going to ping 10.10.1.173. And we're just going to do a -ash d. So, it's persistent and you could see that it is timing out. I'm going to go ahead. We're going to add this policy once a few timeouts go through and we should see the MP replies coming through in a second. And there you go. Now, our IoT network is able to talk to our NAS and access those resources.
That's going to be it for the firewall. Like I said, leave your comments down below what you want to see with it. If you're trying to cast between networks, you're going to want to go over to your network and make sure that all the networks you want to cast between are in the MDNS.
The next thing that we're going to look at is protection. At the top, it says upgrade to cyber seccure by proof point. And this will give you extra signatures. We're not going to go into that, but you could look at help.ui.com and you could see things about that. But below here, we have simple app blocking, content filtering, ad blocking, region blocking. So, I'm going to select region blocking. And typically, I just do like China and Russia. You could do whoever you feel comfortable doing. We're also going to do encrypted DNS. And I always put mine to auto. It just uses Cloudflare or Google, but you could do predefined or you could do custom. Under identification, we're going to do device and traffic. And then we want to have on our intrusion prevention. This is our IDS and our IPS system. And we want to cover all of our networks. I never have it set to notify. I always have it on notify and block because if it notices a threat, I want that to be blocked, not just notified. And I'm going to turn on all the threat categories. You'd see here that one of them aren't checked on. And then on the bottom one, we have one more to put on as well. Now, if you want detection exclusions, you could also add that in. In this video, I'm not going to cover access list. I did a full separate video on access list. I don't use it a whole ton with the layer 3 switching, but I will put that access list video down in the description below.
Next, we have our VPNs. And I don't have a public IP exposed to this gateway. We're just going to use Teleport because it breaks through Douen. But you could always use a VPN server like WireGuard or OpenVPN. If you want to route all your traffic through something like NordVPN, I you would have to use the VPN client, which I have a full video on that will be in the description. Then we have site-to-site VPNs and we also have site magic. Those will be left out from this video as I've just done them recently. But clicking on teleport, this is the easiest way to do it. We need to make sure that it's enabled. And then we need to just generate a new guest invite. With this invite, we could just copy the link to somebody who we want to be able to VPN remotely and they'll be able to access it. You could have the Wi-Fi man client on your Windows, which I currently have. So, I'm just going to copy this. I'm going to open up Wi-Fi Man, and I'm going to connect to a different network that's separate from this. I have the Wi-Fi Man application running on my Windows, but before we do that, we're going to try to hit that NAS that I currently have sitting on 10.10.1.173. We shouldn't be able to hit it because we're on a completely separate network now. But if we want to have remote workers or you want to access your files remotely when you're on vacation, this is how you do it. I'm going to copy this link again. We'll go to Wi-Fi man and then I'm going to paste it. Once I paste it, all I need to do is press connect. You now see that I'm connected a few seconds ago to YouTube 2025. So, let's bring that command prompt back up, hit the up arrow, and we should be able to hit this. And we can.
The issue with this with any of the VPNs, it allows us access to everything. So, all of the networks. So, if I went to ping 10.10.20.1, I'm going to be able to do that. And we probably don't want that. We just want our workers to be able to access specific things like this NAS. So, I need to create some firewall rules. Back at our firewall, we need to create a firewall rule or a policy for our VPN. Currently, you could see that it allows all traffic. We're going to create the policy and we're going to say block VPN to internal zone. The source zone is going to be our VPN and our action will be to block. Our destination will be internal and we'll add that policy. If we bring up a command line and we ping 10.10.1.173, which is that NAS, we shouldn't be able to get through to it. And we can't. But we do want this VPN to be able to go to it, but no other devices. So, we're going to create one more policy. This policy will be allow VPN to NAS. The source will be VPN. The action this time will be to allow and it will be internal to an IP of 10.10.1.173. And we're going to add the policy. Now, I'm going to do a consistent ping here, but you're going to see that we're still not able to do it. And the reason for that is our firewall rules are still in order. So, under the VPN, you could see block VPN is on top. Well, we need to make the allow on top. So, we need to reorder and drag and drop and then press done. Once it configures, you should see these ping replies going through. And there you go. The ping replies are going through and our remote workers are able to hit our NAS resources.
This next section we're going to take a look at policy-based routes and also QoS. So if you have multiple WAN connections, you could route different networks or different devices through those connections. So for this policy-based route, I'm going to see staff out WAN 2. If you have a client set up, a VPN client like NordVPN, you could also route that full network through it, but we don't have that set up. So, staff out WAN 2 and we're going to select the staff network. From here, we're going to go with the interface or VPN tunnel. And I'm going to select my WAN 2. We have this kill switch, and the kill switch prevents the client's device from connecting to the internet if the interface is not available. For us, for the staff network, we don't want that checked off. If WAN two goes down, we want them to fail over to WAN one.
QoS was recently added and what we could do with that, we could prioritize critical traffic. You could see here ensure optimal performance for voice and video calls. And if we configure this, it will say the name, which is critical applications, and we want to prioritize. The source could be any, but for this, we just want to do it for a VOIPE network that I just created. So, I'm going to click on VOIPE and then press save. So we will prioritize all of our VOIPE and our video feeds. We could also do a device or we could do a target. The targets that they have currently selected is Google Meets, Microsoft Teams, Zoom, WebEx, and FaceTime. One other protocol that I'm going to add is the SIP protocol. We're going to have this going down the primary WAN one. And we're always going to have this scheduled, and we're going to add that to the network. You could also manage multiple different QoS profiles. If we want to do it to prioritize or limit or prioritize and limit, we can do that.
We've gone over quite a lot for this video, and we're only going to touch on a couple more things. So, I'm clicked over on my Wi-Fi. And if we scroll down to the bottom, Ubiquiti does a really good job with this. We have our default Wi-Fi settings. We have maximum speed, conservative, or we could do custom. And that will apply to all the APs. On conservative on the 2.4, 4, it's on 20. You should always set the channel width for the 2.4 to 20. Don't go up to 40. On our 5 GHz, it's set to 80, which will give you quite a bit more speed. If you're looking for more reliability and you're in a very dense area, I would say put the 5 GHz on your 40. And for 6 GHz, we could go all the way up to 320 because the spectrum is so wide open. For our maximum speed. This is going to just push the 6 GHz up to 320.
When we're doing deployments at sites, we typically hardcode the channels that these are set to. As I only have two access points in here, we're not going to have too many conflicting. But if I click on the AP and then go to settings, we could see that it's on channel width of 20. And then I'm going to select the channel to be on channel one. And then for the 5 GHz, I'll be on channel 36. For my second AP, I'll go to the settings as well. And this time I'll have this on channel 11 for our 2.4. And for our 5 GHz, I'll set it to 157 so that they're not conflicting at all. There are tools out there like the Wi-Fi man wizard that could help you with this. And for designing your network, I would use design.ui.com. It really does help with your house or your business planning.
Another thing that's good for troubleshooting is our air view. We're going to be able to see what air time we have, interference, or TX retries. We could also look at our control and this is going to tell us our signal strength and then we could see our environment of things that are around us. We could see that the 2.4 is pretty congested. If we click on the 5 GHz, there's not much on it. And then the 6 GHz, there really isn't much there.
Looking at our logging, we have our critical alerts, device admin updates. We have our threats and our triggers. Let's look at the trigger. We could see right at the top at today at 12:19 that Mac Telecom was blocked from accessing 10.10.30.1 by this firewall policy which was block ICMP. If you have any IDS or IPS threats, this is where they'll show up. And we could also look at the VPN logs. You can see that Mac Telecom connected and disconnected from teleport.
The last two things we're going to look at for this video is our updates. You always want to make sure that your console is updated and your applications are updated. I typically turn auto updates off. I don't want to have auto updates on. I will push them out myself when I know the firmware is good. But if you're not within your UniFi OS at least once a month, I would leave auto updates on. Now, for our backups, if you have your account tied to the cloud, you could push out backups to the cloud. So, I'll back up now. And this will go up to account.ui.com. If my cloud gateway fiber ever dies, I'm just going to buy a new one, log in with my single sign on, and then I will load that backup that's in the cloud, and it will take about 5 minutes if there aren't many major firmware updates.
I know that was a ton to go through, and I'm sure I missed quite a bit because the UniFi network application is pretty big, and it is always changing. So, when changes do come in new firmware updates, watch out for those releases. If I did miss anything and you want to see it, let me know in the comments below. I will be doing a follow-up video to this. If you like this video, hit the thumbs up button. If you're new here, please subscribe and hit the bell icon.