Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Earbanean

1110 posts

Uber Geek
+1 received by user: 377


#324382 2-Apr-2026 11:02
Send private message quote this post

I'm just migrating from an old Edgerouter Lite to a new Unifi UCG Ultra.  All setup config on the UCG Ultra was pretty quick and easy.  The last thing I need to do is the inter-VLAN firewall rules.  On the ERL, these were all interface based rules, but I see Unifi do zone based rules (and also interface based?).  Has anyone had experience with the Unifi ZBF?  Also, what are people's thoughts on the relative merits of the two approaches?


Create new topic
SpartanVXL
1498 posts

Uber Geek
+1 received by user: 666


  #3477206 2-Apr-2026 16:04
Send private message quote this post

It add another level for policy based approach. If you don’t need it then you don’t have to use it. Interface based can be sufficient for your needs.




fe31nz
1295 posts

Uber Geek
+1 received by user: 423


  #3477417 3-Apr-2026 01:54
Send private message quote this post

ERLs can do zone firewalls too.  I have always done my firewalls as zone firewalls in my ERLs and ER4 and my OpenWRT router as I have a relatively complicated network.  The tradeoff is that setting up a zone firewall system initially is a bit more work.  But later I was able to just add new vlans to the correct zone and that was all I needed to do for a firewall.  With per-interface firewalls, you have to do new firewall rules for each interface.


Earbanean

1110 posts

Uber Geek
+1 received by user: 377


  #3478391 6-Apr-2026 10:51
Send private message quote this post

Thanks for the replies.  I'd assumed that zone based were actually going to be easier - and thought that was one of the reasons they set them up.  I might have a play and see how they go.


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.