Unifi / CyberSecure / NextDNS

Hello everyone, this is my first post here! So go easy on me…. :slight_smile: I have watched many of the Lawrence Systems videos over the years and learned many things, but I do have an issue I am trying to resolve and not sure how I should go about this…

ISP’s are set for WAN Failover
ISP1: Starlink (Residential Unlimited, no public IP)
ISP2: Windstream DSL (Static IP)

Unifi UDM Pro
Unifi Switches
Unifi AP’s

I have been using NextDNS for a number of years and it has worked great. I put the NextDNS IP’s under each of the network DHCP settings within Unifi so each of my devices uses NextDNS.

Now here’s my issue… I just signed up for the CyberSecure subscription and it looks awesome, but now I am not entirely sure how I should do my setup and worried NextDNS might be bypassing some of CyberSecure features. Should I even use both CyberSecure and NextDNS? If so, how do I go about properly setting this up so the two services are not conflicting with each other?

Should I ditch NextDNS in favor of CyberSecure as it is more robust and offers a deeper level protection? Any advice would be greatly appreciated!

Content filtering requires using the Unifi gateway for client DNS, and other features like IDS/IPS and Application Detection work better when the router sees the client DNS.

Right, so expanding my comment… Moving NextDNS IP’s up to the ISP level, meaning under Settings / Internet / and the ISP and changing the ISP DNS providers to NextDNS, and then each of the devices and DHCP scopes for the internal networks would point to my gateway address.

Unless that is a bad idea to use both, I could just go straight to CyberSecure. I am not sure what the best option is so please advise. Thank you in advance!

I’m not certain whether CyberSecure requires using any specific DNS - meaning that I think it would be fine to set the clients to use the gateway for DNS, and the gateway to use NextDNS if you want.

Okay sounds good. That’s what I figured but wanted to run it by other people to see if there was something I was missing or a better method for my configuration. Thank you!