Unifi Network - Block Internet Access for Specific Devices


I have a number of devices that I no longer want to give access to the internet. For example, the smart TV and a P1 reader that tries to call ‘home’ every second.
Fortunately, it is very easy to create a firewall rule within the Unifi Network Application (formerly called Unifi Controller).

Below is the setup for both the old (Unifi Network Application before version 6) and the new user interface.

Setup Unifi Network Application OLD User Interface (below version 6)

  1. Go to Settings and Routing & Firewall and then tab Firewall and finally choose Groups
  2. Add a Group with a name, for example Block Internet
  3. Add the IP addresses of the devices that are no longer allowed to access the internet
  4. Save the changes and go to IPv4 Rules and choose WAN OUT
  5. Create a new rule with a name, for example Group Block Internet
  6. Select the group previously created at IPv4 Address group and save the changes

Setup Unifi Network Application NEW User Interface (version 6 and higher)

  1. Go to Settings and Traffic & Security and Global Threat Management and expand Firewall and go to the Groups and click Create New Group:
    • Name: for example Block Internet
    • Type: IPv4 Address/Subnet
    • Address: add the IP addresses of the devices that are no longer allowed to access the internet
  2. Click Apply Changes
  3. Go to the Rules and choose Internet and click Create New Rule:
    • Type: Internet Out
    • Description: for example Group Block Internet
    • Enabled: On
    • Rule Applied: Before Predefined Rules
    • Action: Drop
    • IPv4 Protocol: All
  4. Expand Source:
    • Source Type: Address/Port Group
    • IPv4 Address Group: select the group previously created for example Block Internet
    • Port Group: Any
    • MAC Address: leave this empty
  5. Expand Destination:
    • Destination Type: Address/Port Group
    • IPv4 Address Group: Any
    • Port Group: Any
  6. Advanced settings are not necessary. Click Apply Changes

Testing

Test if it works, for example with your mobile phone by temporarily putting the IP address in the group.


Read other notes

Comments

    No comments found for this note.

    Join the discussion for this note on this ticket. Comments appear on this page instantly.

    Tags


    Notes mentioning this note


    Notes Graph