How to Use the New UniFi Policy Engine and Object Oriented Networking [YouTube Release]

Additional Resources:

The new UniFi Policy Engine introduced in UniFi Network 9.4 feature Object Oriented Networking for easier, more powerful network management. In this video I walk you through how to use the policy engine to easily create and manage the rules and how to use Object Oriented Networking to make managing groups of devices and networks easier.

UniFi Zone Firewall Rules Explained

Connect With Us

Lawrence Systems Shirts and Swag

►👕 Lawrence Systems

AFFILIATES & REFERRAL LINKS

Amazon Affiliate Store
:shopping_cart: Lawrence Systems's Amazon Page

UniFi Affiliate Link
:shopping_cart: Ubiquiti Store

All Of Our Affiliates help us out and can get you discounts!
:shopping_cart: Partners We Love – Lawrence Systems

Gear we use on Kit
:shopping_cart: Kit

Use OfferCode LTSERVICES to get 10% off your order at
:shopping_cart: Tech Supply Direct - Premium Refurbished Servers & Workstations at Unbeatable Prices

Digital Ocean Offer Code
:shopping_cart: DigitalOcean: AI-Powered Unified Inference Cloud Infrastructure

HostiFi UniFi Cloud Hosting Service
:shopping_cart: HostiFi - Fast and Reliable UniFi in the Cloud

Protect your privacy with a VPN from Private Internet Access
:shopping_cart: https://www.privateinternetaccess.com/pages/buy-vpn/LRNSYS

Patreon
:money_bag: https://www.patreon.com/lawrencesystems

Chapters
00:00 UniFi 9. 4 Policy Engine and Object Oriented Networking
01:10 Policy Table
02:45 Creating new Policies
04:00 Zone Based Firewall
04:16 What is UniFi Object Oriented Networking
04:42 Managing Device Groups
05:21 Using Object Oriented Networking
07:22 Managing Devices and Networks in Object Oriented Networking
08:30 Creating Network Restrictions

Hi @LTS_Tom ! This was a really helpful video— slowly considering moving off Pfsense.

Quick question— do these policies push down to Unifi switches too? For example do they tell the switch to prevent two servers from communicating on the same vlan without requiring a round trip to the router/firewall/controller?

I’ve wondered if this policy engine is just another way to create firewall rules. I guess my question is, why not create said rule like normal in the zone? Curious to know what everyone else things about that.

That would be layer 3 switch routing and some model switches do support that.

Zones are the essentially containers for the rules. You can still create firewall, NAT, QoS, DNS, and ACL rules under zones.The same rules appear both in the zone firewall and the policy table, giving you multiple ways to manage them.

1 Like