URL/Website filtering Ubiquiti

ohio_grad_06

Well-Known Member
Reaction score
581
So the title pretty much says it. I work for a Church organization in the USA and we support a Bible college as well. The college is asking for assistance with blocking websites so just trying to figure out the best option. Currently they use Ubiquiti. Which is to say we've got a Ubiquiti cloud key there that at the moment is handling DHCP iirc. I'm not the primary person there, usually once a week.

Anyway

1. Ubiquiti network with cloud key managing
2. Unifi Security Gateway behind the cloud key
3. Windows Domain server manages DNS.

So currently, staff systems get joined to the staff/internal Wifi.

There is student wifi, which is essentially a guest wifi network. There's not a portal per se, but they don't have internal access to the main network as they are segmented via a VLAN.

As far as antivirus, we are deploying Checkpoint antivirus that we purchased through a local vendor in our area to staff and public use systems that need to print etc.

However, the big concern is actually people for example who join the student wifi network primarily and may attempt access any plagarism websites. We realize that we won't be able to stop everyone as some enterprising kids will realize they can simply disconnect from wifi or change the dns on their local devices, but hoping to at least slow people down.

We are trying to look at services such as untangle or this other one, but I don't have as much experience on this personally.


One thing that did come to mind was that since we do have our domain controllers set a dns server, to use that to block some of the sites if possible. We found a guide here that describes this.


Just trying to think of something that is relatively easy to deply and at least will annoy people who want to plagarize. My understanding is the staff uses already a service that helps to check papers for plagarism but it seems there are many sites to try to block, so simply trying to figure out the best solution.
 
The Cloud Key wouldn't be handing out DHCP, it's just a wee tiny micro PC running linux which then runs the Unifi controller.
The USG would be doing DHCP.

Unifi itself has actually built up their content filtering quite a bit.
For a church (and the assumed size of concurrent users) I'd want a bit more horsepower than an old USG3p. Probably a Dream Machine Pro, or NextGen Gateway (and if the NextGen..set it up with Hostifi). the Dream Machine Pro has a built in Unifi controller...so that would replace the old Cloud Key.

But back to Unifi...yeah their threat protection and content filtering are evolving fairly well. However, DNS Filter, which we resell, is VERY good, love the product, and quite the low cost...with a super good discount for education.
 
Thanks for reaching out. You mentioned the dream machine pro. So the situation is we took over the network a couple of years ago and have been managing it. They were previously set up with Ubiquiti, we've kind of had to go with what they had so far based on budget. At the moment however, things are running on a Cloud Key Gen 2+.

We have 2 buildings at the moment, our Admin building runs off one cloud key, the dorm runs on a seperate one due to the wifi load as well as Cameras, we have close to 50 cameras also unifi, but we have to split them between 2 ubiquiti nvrs. We don't have the pro, we have the smaller rack mount models.

Before we took over the previous tech however did purchase the product below, but I suppose had issues putting it in service or never got time to configure it. We've not really done anything with it. Our thinking is eventually we'd like to get away from Ubiquiti however.

UAS-XG

 
Back
Top