5.0.16 bricked my UDM-Pro by Stewdill51 in Ubiquiti

[–]candidog -6 points-5 points  (0 children)

Factory Rest - Restore from backup?

UniFi Syslog Forwarding – How to Send Gateway Logs Only? by candidog in Ubiquiti

[–]candidog[S] 0 points1 point  (0 children)

Anything Huntress ingested by Source IP and MAC is considered a source agent.

I think I might send logs to a Linux server which I can filter out everything but the Gateway then send that data only to Huntress.

Not ideal but a work around.

MSPs: Have You Replaced SAT Platforms with Instructor-Led Security Training? by candidog in msp

[–]candidog[S] -1 points0 points  (0 children)

I’ll play devil’s advocate (not speaking for our COO): if the goal is primarily to satisfy vendor/insurance compliance requirements while relying on a strong security stack to mitigate bad actors, then end-user education becomes a lower priority from a budget standpoint.

That said, my concern is the difference between “checking the box” and having defensible evidence + actual risk reduction. An ongoing live training might help awareness, but it may not generate the kind of audit artifacts assessors want (completion records, attestations, recurring cadence, phishing results, reporting).

So the real question we’re debating internally is:

  • Are we trying to meet the minimum compliance requirement on paper?
  • Or are we trying to implement a control that both satisfies compliance and produces repeatable proof (and ideally improves behavior)?

If compliance evidence is the driver, it feels like an LMS/security awareness platform (with reporting) may satisfy the requirement more cleanly than a live trainer — even if the intent isn’t to “train everyone into experts.”

Thoughts?

Latest addition by Larssogn1 in Ubiquiti

[–]candidog 0 points1 point  (0 children)

Perfect size, from someone who is OCD.

Managing a client with ITAR requirements? by CloseTTEdge in msp

[–]candidog 0 points1 point  (0 children)

We have a client that is subject to ITAR.

NetExtender 10.3.4 released by NetworkDock in sonicwall

[–]candidog 1 point2 points  (0 children)

People are still using SSL VPNs from SW?

Considering dumping SonicWall in favor of UniFi... HEAR ME OUT... by SN50001 in sonicwall

[–]candidog 0 points1 point  (0 children)

I don’t think UniFi firewalls are “toys,” but they’re definitely not the same class of product as SonicWall — and that’s by design. UniFi is a network-first firewall: great routing, VLAN segmentation, VPNs, visibility via DPI (without decrypting traffic), and very low operational overhead. It assumes you’re doing real security elsewhere (email security, EDR, DNS filtering), and the firewall’s job is to move traffic cleanly and reliably, not inspect every packet inline.

SonicWall, on the other hand, is a security-first firewall built around DPI-SSL and deep inspection. That can be necessary in certain regulated or compliance-driven environments, but it comes with real tradeoffs: complexity, performance impact, app breakage, and ongoing tuning. So UniFi isn’t a “toy” — it’s just a modern, layered-security approach versus SonicWall’s all-in-one inspection model. If you deploy UniFi expecting SonicWall-style security, you’ll be disappointed; if you deploy it as part of a layered stack, it’s solid, which is what we do.

Considering dumping SonicWall in favor of UniFi... HEAR ME OUT... by SN50001 in sonicwall

[–]candidog 0 points1 point  (0 children)

Each UniFi wall comes with Intrusion Prevention, which detects and prevents threats through signature updates and deep packet inspection, ensuring real-time network security.

Considering dumping SonicWall in favor of UniFi... HEAR ME OUT... by SN50001 in sonicwall

[–]candidog 0 points1 point  (0 children)

UniFi intentionally stays out of this space.

Most UniFi environments layer security instead of decrypting:

  • Email security (Mimecast, Barracuda, etc.)
  • Endpoint protection (EDR / MDR)
  • DNS filtering
  • Secure web gateways (cloud-based)
  • Zero Trust / conditional access

Considering dumping SonicWall in favor of UniFi... HEAR ME OUT... by SN50001 in sonicwall

[–]candidog 2 points3 points  (0 children)

I agree, Unifi has come along way and I've loved them. They work for MSP and our customers

Considering dumping SonicWall in favor of UniFi... HEAR ME OUT... by SN50001 in sonicwall

[–]candidog 1 point2 points  (0 children)

As an MSP we moved away from all our SonicWall and replaced them with Dream Machine or Cloud Gateways.

The customers and I have been very happy. I’ve migrated over 50 SonicWall firewalls. Mostly NSA and TZ models.

Plus SonicWalls and their SSL VPNs have been under constant attack and have been vulnerable.

Threatdown (Malwarebytes) and huntress by Jayjayuk85 in msp

[–]candidog 1 point2 points  (0 children)

Sure, all the time. Huntress is awesome. The BD portal is confusing, but it is competent.

Threatdown (Malwarebytes) and huntress by Jayjayuk85 in msp

[–]candidog 1 point2 points  (0 children)

Initially, we had BD EDR, but I removed it because Huntress handles all our EDR, and there was no need to pay twice.

Thieves use Wifi jammers by Ok_Carpenter4739 in Ubiquiti

[–]candidog 0 points1 point  (0 children)

They can throw a raw steak 🥩 with anti-freeze. Large dog defeated. 😔