💡

Key Points

Key Takeaways

  • 1

    Intrusion Detection

  • 2

    ISP Router: Router rented from provider has only 'minimum functions'. Security is porous, cannot see at all who is doing what (Black Box).

  • 3

    Ubiquiti UDM SE: Enterprise grade security gateway. UI is beautiful, obvious at a glance which device is using how much bandwidth and communicating with which country. Can instantly block 'Surveillance camera communicating with Chinese server'.

  • 4

    Firewalla Gold: Firewall usable just by inserting into existing router. 'Ad Block' and 'Child Smartphone Restriction' are powerful. Can be used even without network knowledge.

  • 5

    VLAN (Virtual LAN): Security of IoT devices (smart bulbs etc.) is weak. Must not place them on same network as main PC (for work). Segregating with VLAN is modern common sense.

Introduction: Invisible Intruder

How many devices are connected to your home Wi-Fi? Do you think “Just smartphone and PC”?

Actually, TV, refrigerator, Alexa, robot vacuum, and even neighbor’s smartphone might be connected. Visualizing (Visibility) and controlling (Control) these. That is role of “Network Guardian”.

1. The Enterprise Grade: Ubiquiti UDM SE

UniFi series combining beauty like Apple product and robustness for business use. Center of that is Dream Machine.

Ubiquiti Dream Machine Special Edition

Equipped with 8 PoE (Power over Ethernet) compatible ports. Can supply power to surveillance camera or Wi-Fi access point with single LAN cable. Joy of rack mounting.

Traffic Inspector

“What is this app doing behind scenes?” Identify content of communication by Deep Packet Inspection (DPI). If there is suspicious communication, IDS/IPS (Intrusion Detection/Prevention System) automatically blocks and notifies smartphone.

2. The Plug & Play: Firewalla Gold

UniFi is hard to build, but Firewalla is easy. Just plug into LAN port of router. With just that, communication in whole house is placed under surveillance.

Firewalla Gold

Ad block function (Ad Block) is excellent. Not only browser, advertising in app also disappears. Can wipe out unpleasant advertisements from smartphones of all family members.

3. Comparison: Build or Add

項目 Ubiquiti UDM SE Firewalla Gold
Form Router Itself Add to Router
VLAN Construction Good (Intuitive GUI) Possible (Setting Needed)
Camera Linkage UniFi Protect (God) None
Introduction Difficulty High (Rack Recommended) Low (Just Place)

4. The VLAN Strategy

This is most important. Segment network into 3.

  1. Trusted (Main): PC, smartphone, NAS. Area to protect most.
  2. IoT (Untrusted): Smart home appliances, TV. Connects to Internet but cannot access Main.
  3. Guest: For visitors. Only Internet allowed.

By this, even if cheap smart bulb is hacked, damage is limited only to that section (VLAN). Idea of “Compartmentalization” to minimize damage.

Conclusion: Hire Gatekeeper

Internet is dangerous place. Connecting without thinking is like sleeping with front door open.

Hire excellent Gatekeeper (Guardian). They continue to monitor packets 24 hours 365 days without sleeping. That sense of security supports your digital life.