← Back to list

Routing Traffic from a UDM SE or UDM Pro through pfSense

Set up your gateway and route the traffic through it

Teri Radichel in Cloud Security · 2025-01-19 21:51 · 0 claps · 2.9 min read paywalled
#ubiquiti #udm-pro #udm-se #routing #pfsense
Open on Medium ↗
Wiki topics: 📊 · Economic Policy

Routing Traffic from a UDM SE or UDM Pro through pfSense

Set up your gateway and route the traffic through it


⚙️ Check out my series on [*Automating Cybersecurity Metrics](https://medium.com/cloud-security/automating-cybersecurity-metrics-890dfabb6198) | [Code](https://github.com/tradichel).*

🔒 Related Stories: [*pfSense](https://medium.com/cloud-security/configuring-pfsense-and-netgate-devices-b58fb6a1b078) | [Dream Machine Pro](https://medium.com/cloud-security/ubiquiti-dream-machine-pro-b9a4f68c254d) | [Ubiquiti](https://medium.com/cloud-security/ubiquiti-dream-machine-pro-b9a4f68c254d) | [Network Security](https://medium.com/cloud-security/network-security-68e1f26db9df)*

💻 Free Content on* [Jobs in Cybersecurity](https://medium.com/cloud-security/cybersecurity-careers-and-jobs-69c05616d2b4) | *✉️ Sign up for the [*Email List](https://2ndsightlab.medium.com/subscribe)*

In a prior post I explained how to route traffic from one pfSense device through another.

[embed]Setting Up One pfSense Behind Another Further segmenting networks with a firewall behind a firewallmedium.com

If you want to route the traffic from a UDM Pro through a pfSense the configuration on the pfSense side is pretty much the same as what I explained in the above post. So this is going to be a pretty short post.

I’ll remind you that the key is to understand routing:

[embed]Routing — in a nut shell What you need to know about network routingmedium.com

So you can resolve this asynchronous routing problem when you put one router behind another:

[embed]Resolving No Route To Host Routing traffic between routers such as pfSense and a UDM Promedium.com

There are just a couple of notes I wanted to add here about the Ubiquiti device.

One is this. Make sure you connect the WAN port to the upstream device. If you connect a LAN port, depending on your traffic rules and network configuration, your devices may end up sending adoption traffic to the Internet or expose ports that attackers will try to connect to directly. I see scanners looking for the Ubiquiti ports all the time — 8080 and 10001.

[embed]Troubleshooting Device Adoption on UDM SE or PRO Why won’t my devices adopt??medium.com

In addition I’m trying to figure out what some STUN traffic is coming from the Ubiquiti device and don’t want that somehow reaching the Internet either to bypass the Firewall and NATs (unless you know what you are doing and you need it.

[embed]How to Figure Out What’s Running On a Specific Port on Linux Some strange process is running on a particular port — what is that?medium.com

You configure your gateway on the pfSense and you connect your Ubiquiti WAN port to the pfSense port on which you configured the gateway. You set up the Ubiquiti device to use the gateway IP address on the pfSense for DHCP and as a gateway to the Internet.

You configure the route on the pfSense to send anything destined for the networks you have defined on the Ubiquiti device back to that gateway so responses can reach the UDM Pro or SE. For the details refer to the pfSense behind pfSense article above.

The other caveat I will make is that even if you have DHCP guarding turned on, make sure your clients on the Ubiquiti device cannot reach any DHCP server IP addresses on the pfSense or assign themselves an IP address belonging to a pfSense network unless you really want them doing that.

Make sure clients on the pfSense cannot reach the Ubiquiti console where they shouldn’t and vice versa (and anything else they should not be accessing).

As I like to say — if there’s a route, traffic will flow there unless you block it.

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2025

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab


메타데이터
post_id
d447802f60c4
slug
routing-traffic-from-a-udm-se-or-udm-pro-through-pfsense-d447802f60c4
url
https://medium.com/cloud-security/routing-traffic-from-a-udm-se-or-udm-pro-through-pfsense-d447802f60c4
canonical_url
https://medium.com/cloud-security/routing-traffic-from-a-udm-se-or-udm-pro-through-pfsense-d447802f60c4
author_url
https://medium.com/@2ndsightlab
status
ok
fetched_at
2026-07-21 06:49:12