House Arrest
v1.13.0 adds House Arrest, a new tool for locking down a single device or a whole network using UniFi's zone-based firewall. Everything it does is something you could set up in UniFi yourself. House Arrest puts it in one place, shows you exactly what will change before anything is written, and tells you plainly what a lockdown does and does not cover.
Devices tab
- Four presets, from most to least permissive: Internet only, LAN only, No internet, and Quarantine. Each one is previewed before it is applied, with a picture and a plain list of what gets blocked.
- Block this device from the other devices on its network. Traffic between devices on the same network never passes through the gateway, so no firewall rule can stop it. House Arrest uses switch rules instead, on UniFi switches that support them, and tells you per device whether it will be fully blocked, partly blocked, or not blocked before you apply.
- See what each lockdown has actually stopped, counted from the gateway's own logs.
Networks tab
- One table of your networks against the settings that matter: network isolation, internet access, Device isolation, mDNS, and the DNS servers each network hands out. Every cell explains itself on hover, and the editable ones can be changed from there.
- Firewall rules that open a path through a network's isolation are listed, so an isolated network that isn't really isolated says so.
DNS Lockdown tab
- Force chosen networks onto the DNS servers you approve and block DNS to anywhere else, optionally including DNS-over-TLS. The rule order is checked after applying, and everything is rolled back if it came out wrong.
- Warns when UniFi's own Encrypted DNS, Content Filter, or Ad Blocking is handling DNS at the gateway.
Release is always safe. House Arrest only ever removes rules it created, and refuses anything else.
Full guide: docs/HOUSE-ARREST.md
Also in this release
- Webhooks to your own network. Set
WEBHOOK_ALLOW_PRIVATE_IPS=trueto send alerts to Home Assistant, n8n, ntfy, or Gotify on your LAN (#124). Off by default. - Need a hand with your network? A new "Get Help With Your Network" button links to Rogue Support for on-demand help, with 25% off your first session.
Upgrading
docker compose pull
docker compose up -d:latest now only moves when a release is tagged. If you want to try changes before they are released, use the :edge tag.
The full list of changes is in CHANGELOG.md.