UniFi Security Gateway Pro

From Pumping Station: One Wiki
Jump to: navigation, search

UniFi Security Gateway Pro
Owner/Loaner PS:One
Make/Model UniFi Security Gateway Pro
Arrival Date 12/2017
Usability yes
Contact CTO
Where Dell PS 38S Server Rack
Authorization Needed yes
Hackable no
Estimated Value $300
Host Area CTO

UniFi Security Gateway Pro Area: CTO https://wiki.pumpingstationone.org/UniFi_Security_Gateway_Pro


Online as of 12/30/17

Device will be moved to the new infrastructure location with other PS:1 maintained equipment.


Configuration is backed up with the UniFi Controller.


Please see UniFi Controller for extended configuration information. USG is managed from controller interface.

Port configuration is as follows:

  • LAN Port 1
  • LAN Port 2
    • Disconnected. May be used in the future to service member rack.
  • WAN Port 1
    • Connected to primary internet connection, currently the Motorola SURFboard SB6120 on top of the Dell PS 38S Server Rack
  • WAN Port 2
    • Disconnected. Will be used in the future for a failover/backup internet connection.

Enable IPv6 Support

IPv6 support is in progress. Documentation to enable this is found here.

Initial Setup

Instructions for adpoting a USG Pro can be found here

Adpoting a USG Pro into an existing network

NOTE: This has been tailored for PS:1's existing network setup.

1. Connect a computer into the LAN NIC (LAN port 1) of the USG. It will obtain a 192.168.1.x IP from DHCP.

2. SSH into using username and password combination of ubnt / ubnt.

3. For this example, the controller is on, so let's change the USG’s LAN IP to Choose an available IP within the subnet of the local controller.

4. In the SSH session, run the following (Since this is a USG Pro, eth1 has been replaced with eth0 per Ubiquiti instructions):

  • configure
  • set interfaces ethernet eth0 address
  • delete interfaces ethernet eth0 address
  • commit

Now the USG’s LAN IP is The SSH session will drop.

Controller Configuration

In order for the USG to work properly, you must correctly configure the appropriate settings in the UniFi Controller GUI located at or via https://unifi.ubnt.com/

Under "Settings" > "Networks", select edit on the network named "LAN".

The following settings should be configured as such:

  • Name
    • LAN
  • Purpose
    • Corporate
  • Parent Interface
    • LAN
  • Gateway/Subnet
  • Domain Name
    • ad.pumpingstationone.org
  • IGMP SNooping
    • Disabled
  • DHCP Mode
    • DHCP Server
  • DHCP Range
    • -
    • Manual
  • DHCP WINS Server
    • Disabled
  • DHCP Lease Time
    • 86400 seconds
  • DHCP Gateway IP
    • Auto
  • DHCP UniFi Controller
  • DHCP Gaurding
    • Enabled
  • UPnP LAN
    • Disabled


  • DHCP NTP Server
    • Disabled
  • DHCP Network Boot
    • Enabled
      • /pxelinux.0
  • DHCP Time Offset
    • Disabled
    • Empty
  • DHCP TFTP Server
    • Empty