Re: [AFMUG] UBNT firewall

2015-01-20 Thread Jeremy
ub traffic? >>>>>> >>>>>> bp >>>>>> >>>>>> >>>>>> >>>>>> On 1/20/2015 10:05 AM, Josh Reynolds wrote: >>>>>> >>>>>> Management. VLAN. >>

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Brett A Mansfield
;>>>> you split management/sub traffic? >>>>>>>> >>>>>>>> bp >>>>>>>> >>>>>>>> >>>>>>>> On 1/20/2015 10:05 AM, Josh Reynolds wrote: >>>>>>&g

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Brett A Mansfield
2015 8:51:22 AM AKST, Bill Prince >>>>>>>> <mailto:part15...@gmail.com> wrote: >>>>>>>> Not the AP side, but the client side. We have traditionally NATted all >>>>>>>> residential subs on Canopy, and w

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Jeremy
client side. We have traditionally NATted all >>>>>> residential subs on Canopy, and were trying to do the same with UBNT. >>>>>> >>>>>> With Canopy it's easy, because the NATted TCP stack just passes through, >>>>>> and i

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Jeremy
orts are open, it goes to the sub's router (no impact on the >>>>> SM). >>>>> >>>>> Not so with UBNT, as the public IP for NAT is also the IP for the CPE. >>>>> >>>>> Just wondering if anyone else has tried the CPE firewall to pre

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Brett A Mansfield
1:22 AM AKST, Bill Prince >>>>>>>>>>> wrote: >>>>>>>>>>> Not the AP side, but the client side. We have traditionally NATted >>>>>>>>>>> all >>>>>>>>>>&

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Josh Reynolds
SSH ports are open, it goes to the sub's >router (no impact on the >>>>>>> SM). >>>>>>> >>>>>>> Not so with UBNT, as the public IP for NAT is also >the IP for the CPE. &

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Bill Prince
Behalf Of Bill Prince Sent: Monday, January 19, 2015 1:47 PM To: af@afmug.com Subject: Re: [AFMUG] UBNT firewall Nobody actually using the UBNT firewall? bp On 1/14/2015 11:25 AM, Bill Prince wrote: We

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Brett A Mansfield
;>> the >>>>>>>> SM). >>>>>>>> >>>>>>>> Not so with UBNT, as the public IP for NAT is also the IP for the CPE. >>>>>>>> >>>>>>>> Just wondering if anyone else has tried the CPE fire

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Bill Prince
, January 19, 2015 1:47 PM To: af@afmug.com Subject: Re: [AFMUG] UBNT firewall Nobody actually using the UBNT firewall? bp On 1/14/2015 11:25 AM, Bill Prince wrote: We notice that any time we use NAT on UBNT we

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Brett A Mansfield
enerally a bad idea to use that firewall (at least on the access point >>> side) as it supposedly cuts into your PPS capacity on the >>> radio. >>> >>> Peter Kranz >>> Founder/CEO - Unwired Ltd >>> www.UnwiredLtd.com <http://www.unwiredltd.

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Josh Reynolds
east on >>> the access point side) as it supposedly cuts into your >>> PPS capacity on the radio. Peter Kranz Founder/CEO - >>> Unwired Ltd www.UnwiredLtd.com >>> <http://www.UnwiredLtd.com> Desk: 510-868-16

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Bill Prince
Message- From: Af [mailto:af-boun...@afmug.com] On Behalf Of Bill Prince Sent: Monday, January 19, 2015 1:47 PM To: af@afmug.com Subject: Re: [AFMUG] UBNT firewall Nobody actually using the UBNT firewall? bp On 1/14/2015 11:25 AM, Bil

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Josh Reynolds
ide) as it supposedly cuts into your PPS >> capacity on the radio. Peter Kranz Founder/CEO - Unwired Ltd >> www.UnwiredLtd.com <http://www.UnwiredLtd.com> Desk: >> 510-868-1614 x100 Mobile: 510-207- pkr...@unwiredltd.com >> -Original Message

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Bill Prince
ile: 510-207- pkr...@unwiredltd.com -Original Message- From: Af [mailto:af-boun...@afmug.com] On Behalf Of Bill Prince Sent: Monday, January 19, 2015 1:47 PM To: af@afmug.com Subject: Re: [AFMUG] UBNT firewall Nobody actually using the UBNT firewall? bp

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Josh Reynolds
nto your PPS capacity on the radio. >> >> Peter Kranz >> Founder/CEO - Unwired Ltd >> www.UnwiredLtd.com >> Desk: 510-868-1614 x100 >> Mobile: 510-207- >> pkr...@unwiredltd.com >> >> -Original Message- >> From: Af [mailto:af-boun...@afmug.

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Bill Prince
al Message- From: Af [mailto:af-boun...@afmug.com] On Behalf Of Bill Prince Sent: Monday, January 19, 2015 1:47 PM To: af@afmug.com Subject: Re: [AFMUG] UBNT firewall Nobody actually using the UBNT firewall? bp On 1/14/2015 11:25 AM, Bill Prince wrote: We notice that any time we use NAT on UBNT we

Re: [AFMUG] UBNT firewall

2015-01-20 Thread Peter Kranz
: Af [mailto:af-boun...@afmug.com] On Behalf Of Bill Prince Sent: Monday, January 19, 2015 1:47 PM To: af@afmug.com Subject: Re: [AFMUG] UBNT firewall Nobody actually using the UBNT firewall? bp On 1/14/2015 11:25 AM, Bill Prince wrote: > > We notice that any time we use NAT on UBNT we get a

Re: [AFMUG] UBNT firewall

2015-01-19 Thread Bill Prince
Nobody actually using the UBNT firewall? bp On 1/14/2015 11:25 AM, Bill Prince wrote: We notice that any time we use NAT on UBNT we get a lot of login attempts via SSH. Are any of you using the firewall built in? It's not clear from the GUI interface whether this affects input or forwardi

[AFMUG] UBNT firewall

2015-01-14 Thread Bill Prince
We notice that any time we use NAT on UBNT we get a lot of login attempts via SSH. Are any of you using the firewall built in? It's not clear from the GUI interface whether this affects input or forwarding, or both. What I'd like to do is block any SSH logins that are not in one of our su