Overview
This guide provides step-by-step instructions to secure a small business network with:
- A single LAN
- Ubiquiti UniFi Ultra as the gateway
- No port forwarding or open inbound ports
Threat vectors addressed include phishing, lateral movement, internal misconfiguration, and remote exploitation.
๐ง 1. Edge Router & Firewall: Lock Down the Gateway
โ UniFi Ultra Firewall Rules
- Deny by default all inbound WAN traffic
- Allow only established/related connections
- Explicitly drop all other WAN IN traffic
Recommended Rules (WAN IN):
Rule 1: Accept ESTABLISHED,RELATED โ WAN IN
Rule 2: Drop All โ WAN IN
WAN LOCAL (UI & service protection):
Rule 1: Allow DNS, DHCP (if hosted here)
Rule 2: Drop All โ WAN LOCAL
Additional Router Hardening:
- โ Disable UPnP
- โ Disable IPv6 (unless used securely)
- โ Disable UniFi Cloud Access (or restrict to admin IPs)
- โ
Restrict GUI management access to VLAN 10 (trusted)
๐งฑ 2. LAN Segmentation (Minimal VLAN Strategy)
| VLAN | Purpose | Devices |
|---|---|---|
| 10 | Trusted LAN | Admin PCs, Servers |
| 20 | IoT / Untrusted | Smart TVs, IP Cams, Printers |
| 30 | Guest or BYOD | Visitors, Staff Personal Devices |
VLAN Rules:
- ๐ซ Block inter-VLAN by default
- โ Allow VLAN 10 โ VLAN 20/30 (if needed)
- โ VLAN 20/30 should not access VLAN 10
๐งโ๐ป 3. Endpoint Hardening
Workstations:
- โ OS auto-updates
- โ EDR/AV (e.g. Defender with ASR or CrowdStrike)
- โ No RDP unless secured internally
- ๐ค Daily users: non-admin accounts
Servers:
- ๐ฅ Local firewall enabled
- ๐งฑ Block all except trusted LAN IPs
- ๐ Scheduled, off-site backups
- โ Disable unused remote protocols (e.g. WinRM, RDP)
๐ 4. DNS & Outbound Filtering
DNS-Level Defence:
Use one of:
Features:
- ๐ซ Malware & phishing domain block
- ๐ DNS logging and analytics
Outbound Rules (LAN โ WAN):
- โ Block:
- TCP 445 (SMB)
- TCP 3389 (RDP)
- FTP, Telnet
- ๐ Optional: whitelist-only outbound for VLAN 20
๐ 5. Authentication & Monitoring
- ๐ Enable MFA on all admin accounts
- ๐ Enable UniFi Threat Management (IDS/IPS: Balanced mode)
- ๐ Log to Syslog or external collector
- ๐ฅ Disable unused users, rotate passwords periodically
๐ 6. Backup & Recovery
- ๐ง Immutable, versioned backups (on NAS, PBS, or cloud)
- ๐ Backup:
- Router config
- Servers & domain controller
- Business data
- ๐งช Test restores quarterly
๐ซ 7. Remote Access (Optional)
If required:
- โ Use Tailscale or WireGuard
- โ Do not expose RDP, UniFi GUI, NAS, or printers
- ๐ Device approval and 2FA for VPN accounts
๐งช 8. Security Audit Checklist
| Item | Frequency | Status |
|---|---|---|
| OS & firmware patched | Weekly | โ |
Open ports scan (nmap)
|
Monthly | โ |
| IDS/IPS alerts reviewed | Weekly | โ |
| Endpoint AV/EDR status | Weekly | โ |
| Backups tested | Quarterly | โ |
| VLAN rules audited | Quarterly | โ |
Tip: For central visibility, consider using a self-hosted Grafana + Loki + Promtail or Graylog stack to aggregate firewall, system, and DNS logs.
National Cyber Security Centre certificates