Met het uitbrengen van UniFi Netwerk 9.4 komen er weer een aantal interessante nieuwe functies bij in het UniFi systeem. 9.4 brengt oa Object Oriented Networking, Policy Tabellen, IPv6 updates en meer. Volledige details in het Engels hieronder;
Object Oriented Networking
A new and powerful way to streamline the creation of multiple dynamic policies.
- Apply complete policy sets (Security, Routing, and QoS) from a single screen.
- Match on specific clients, client groups, or networks.
- Configures multiple Firewall Rules, ACLs, Policy-Based Routes, and QoS Rules at once.
- Requires Full UniFi stack and Zone Based Firewall to be active.
Master Policy Table
The single source of truth containing all policies.
- Create and manage Firewall, ACL, DNS, NAT, QoS, Routing, and Port Forwarding policies from a single screen.
- Apply intelligent filters and customize columns to focus on specific policies.
- Set up OSPF and BGP Dynamic Routing.
Verbeteringen
IPv6
- Added support for IPv6 NAT66 rules to the Policy Table.
- Added support for MAP-E IPv4 over IPv6 internet connection type in Japan.
- Supported access services are JPIX v6 Plus and NTT OCN Virtual Connect.
- Requires UniFi OS 4.4 or newer.
- Added DHCPv6 client options to WAN settings for increased compatibility with select ISPs.
- Requires UniFi OS 4.4 or newer.
- Added DHCPv6 CoS to WAN settings.
- Improved IPv6 validation.
- Improved IPv6 subnet validation to block use of reserved ranges, including 2001:db8::/32, multicast, link-local, and IPv6-mapped IPv4 addresses.
- Improved IPv6 Static Route validation.
- Blocked IPv4-mapped IPv6 addresses from all input fields.
- Disallowed documentation-only CIDRs such as 2001:db8::/32.
- Restricted Multicast IPv6 addresses to Firewall rules only.
Dashboard
- Added the Most Common Devices widget for visibility of top device types.
- Added WiFi graph filtering by WiFi Broadcasts.
- Improved WAN monitoring and traffic flow graphs for greater detail.
- Improved performance on sites with active CyberSecure subscriptions.
Routing & Policy
- Added Source and Destination Networks for Destination NAT.
- Added Destination IP List option for Destination NAT.
- Moved Dynamic Routing (BGP, OSPF) to Policy Table > Dynamic Routing for unified management.
- Changed VLAN Groups on EFG and UXG-Enterprise to Native and Tagged VLAN Management settings.
- Requires UniFi OS 4.3 or newer.
Content Filtering
- Added a user-facing Block Page to indicate why a website’s access is denied.
- UniFi intercepts HTTPS traffic to display this page, which may trigger browser security warnings if the gateway’s certificate is not installed and trusted on the client.
- Enable UniFi Identity Certificate Distribution or manually download the certificate from the Protection page.
- When UniFi Identity is deployed, the gateway certificate is automatically distributed via the Identity Endpoint Agent, allowing supported client devices to bypass browser warnings and display the block page securely and seamlessly.
- Requires UniFi OS 4.4 or newer.
Others
- Added filtering by installed date, uptime, and model on the Devices page.
- Added option to toggle All Clients On/Off on the Topology page.
- Added Signal filtering to the Clients page.
- Added Counters to the System Logs Filter.
- Added the last connected uplink for non-network UniFi Devices and Clients.
- Improved filtering and navigation experience across Port Manager, Device page, and System Logs & Insights for smoother and more consistent usability.
- Improved DHCP Manager user experience with direct access from the Clients page and better filtering options.
- Moved MC-LAG to the Network settings.
Bugfixes
- Fixed an issue where the WiFi Channel Plan was only being applied to the 5GHz band in some cases.
- Fixed an issue where creating VLANs failed in rare cases.
- Fixed an issue where an incorrect subnet could be generated in Auto mode for VPN servers in rare cases.
- Fixed an issue where the All Traffic Flows option was not working for the UXG-Max.
- Fixed an issue where creating IPv6 Static Routes could fail in rare cases.
- Fixed issue where Zone-Based Firewall did not correctly match traffic from IPv6 clients.
- Fixed an issue where the VLAN 4040 IP was incorrectly assigned to L3 switches in rare cases, potentially causing routing conflicts.
- Fixed an issue where multicast traffic was incorrectly reported as 100% in AirView when no clients were connected to the radio.
- Fixed an issue where the Isolate Spokes option within Site Magic SD-WAN was not working in rare cases.
- Fixed an issue where invalid Blackhole Static Routes could cause Gateway configuration issues.
- Fixed an issue where the Traffic Flows could incorrectly list the Allow action instead of Block.
- Fixed an issue where creating a Third-party Gateway network on the UDR7 resulted in a gateway configuration error.
- Fixed an issue where Speed Limits could be configured on the UX7 when connected via a Wireless Uplink.
- Fixed an issue where Switch ACL was unavailable when a UniFi Gateway was not adopted.
- Fixed an issue where IP conflicts could occur when cloning configurations from another device with a Fixed IP configured.
- Fixed an issue where WAN failover system logs would be shown after Console setup.
- Fixed an issue where VLAN tagging did not work correctly when all ports are set to allow all on InWall APs.
- Fixed an issue where AP/WiFi client selection was missing in AirView.
- Fixed an issue where Content Filtering settings were being removed when removing networks in rare cases.
- Fixed an issue where the Jumbo Frames setting was missing for the EFG and UXG-Enterprise.
- Fixed an issue where flows from the built-in Firewall Policies were incorrectly shown as Blocked.