UniFi WiFi Parental Control Guide
Complete multi-layer framework for screen time & content control. Five independent layers working together — if one fails, the others still protect.
Introduction: The Multi-Layer Approach
Parental controls aren't one-size-fits-all. A truly effective system requires five independent layers working together:
- DNS Filtering — blocks inappropriate content
- Network Isolation — separates kids from adult systems
- Time-Based Scheduling — enforces internet-free hours
- Bandwidth Limiting — prevents excessive streaming/gaming
- Device Monitoring — tracks usage patterns
If one layer fails, the others still protect. This redundancy is what makes UniFi powerful.
Setup Time: 2–3 hours (one weekend)
Monthly Maintenance: 30 minutes
Effectiveness: 85–95% (with family communication)
Quick Start (30 Minutes)
If you just want the basics up and running:
- Set DNS to Cloudflare Family (5 min)
UniFi Console → Settings → Internet → DNS
Add1.1.1.3(primary) and1.0.0.3(secondary). Save and reboot controller. - Create Kids WiFi SSID (10 min)
WiFi → Create New Network. Name:Family-WiFi-Kids. Security: WPA3. Strong password. - Enable WiFi Scheduling (10 min)
WiFi → Select Kids SSID → Edit → Advanced. Enable WiFi Schedule. Set hours: 7 AM – 10 PM on school days. - Monitor Usage (5 min)
Clients → Check connected devices. Track bandwidth via Insights → Traffic.
Result: Basic parental control is now active. For advanced features, continue reading.
Layer 1: DNS Filtering (Application Level)
DNS filtering is your first line of defense. When a child tries to access an inappropriate site, the DNS filter blocks the request before it even loads.
Option A: Cloudflare Family DNS (Free, Basic)
Best for: Parents who want a simple, set-and-forget solution.
UniFi Console → Settings → Internet → DNS. Replace default DNS with Cloudflare Family:
| Filter Level | Primary DNS | Secondary DNS | Best For |
|---|---|---|---|
| Malware Only | 1.1.1.2 | 1.0.0.2 | Teens (age 13+) |
| Malware + Adult | 1.1.1.3 | 1.0.0.3 | Younger kids (age 8–12) |
| No Filtering | 1.1.1.1 | 1.0.0.1 | Parents only |
Save and reboot UniFi controller. Test by visiting a blocked site — you'll see a Cloudflare block page.
Pros: Zero configuration, free, works instantly network-wide, no account required.
Cons: No scheduling, no per-device control, no allowlist/blocklist, limited reporting.
Option B: NextDNS (Recommended — Advanced Control)
Best for: Parents who want granular control, scheduling, and detailed analytics. NextDNS supports 95+ content categories, time-based scheduling, per-device rules, and a comprehensive dashboard.
Installation & Setup
Step 1: Create NextDNS Account
- Visit nextdns.io and sign up (free tier: 300,000 queries/month — enough for 3–5 devices)
- Create a "Security Profile" for kids
- Note your NextDNS ID (shown as
abc123in dashboard)
Step 2: Connect UniFi to NextDNS
- UniFi Console → Settings → Internet → DNS
- Set DNS: Primary
45.90.28.0, Secondary45.90.30.0 - Save and reboot controller
Step 3: Verify DNS is Working
- From any device on the network, open terminal
- Run:
nslookup google.com - Should resolve to NextDNS servers (not your ISP)
Configuring NextDNS for Kids
Content Filtering: In your Kids-Strict profile, enable these blocklist categories:
- Ads & Trackers
- Adult Content (pornography, gambling)
- Dating Apps (Tinder, Bumble, etc.)
- Malware (viruses, exploits)
- Streaming Services (optional: Netflix, YouTube, TikTok)
- Social Media (optional: Instagram, Snapchat)
- Gaming (optional: Steam, Roblox, Fortnite)
- VPN/Proxy Services (prevents bypass attempts)
Time-Based Scheduling: Profile → Schedule → Create rule: "Block internet 9 PM – 7 AM". Optional: different weekend schedule with later cutoff.
Per-Device Rules: Profile → Devices → Add each child's device by MAC address. Assign different profiles:
Kids-Strict— youngest, most restrictionsKids-Moderate— older kids, fewer blocksParent— no restrictions
Cost: $49.99/year (or $4.99/month) — includes unlimited profiles.
Free Tier: 300k queries/month (enough for most families).
Layer 2: Network Architecture (WiFi & VLAN)
Network isolation is crucial. You don't want kids accessing your home automation system, security cameras, NAS, or work devices. By creating a separate VLAN, kids are on a completely isolated network — they can only access the internet, not your internal systems.
Step 1: Create a Restricted VLAN
A VLAN is a separate virtual network inside your physical network. Devices on different VLANs can't talk to each other.
- UniFi Console → Settings → Networks → Create New Network
- Network Name:
Kids-Network, VLAN ID:100 - IPv4 Address:
192.168.100.1, Subnet:/24 - DHCP: Enabled, range
192.168.100.6–192.168.100.254 - DNS: Set to NextDNS servers (
45.90.28.0,45.90.30.0) - Disable UPnP (security), enable IGMP Snooping
Step 2: Create Kids WiFi SSID on the Restricted VLAN
- WiFi → Create New Network
- SSID:
Family-WiFi-Kids, Security: WPA2/WPA3, strong password (16+ characters) - Network: Select
Kids-Network— this locks WiFi to the restricted VLAN - Enable 802.11k/802.11r (fast roaming), disable WPS (security risk), enable band steering
Result: Devices connecting to Family-WiFi-Kids are on an isolated network with internet access and NextDNS filtering only.
Step 3: Create a Parent/Admin SSID (Recommended)
Create Family-WiFi-Main on your default LAN with a different password. Two networks in your home: Family-WiFi-Kids (isolated, filtered) and Family-WiFi-Main (full access, for parents/smart home).
Layer 3: Time-Based Scheduling
Even with content filters, kids can still browse all night. WiFi scheduling automatically disables internet access during specified hours.
- UniFi Console → WiFi → Edit
Family-WiFi-KidsSSID - Scroll to WiFi Schedule → Enable
- School days (Mon–Fri): 7:00 AM – 10:00 PM
- Weekends (Sat–Sun): 8:00 AM – 11:00 PM
Result: The Kids WiFi network automatically disappears from WiFi lists during blocked hours.
Advanced Scheduling (Using UniFi Automations)
Settings → Automations → Create time-based triggers to disable/enable WiFi SSIDs. This allows different schedules per device or profile.
Layer 4: Bandwidth Management
Bandwidth limiting prevents kids from monopolizing your internet with gaming or streaming.
Network-Level Bandwidth Limiting
- UniFi Console → Settings → Networks → Select
Kids-Network - Traffic Management → Enable
- Download Limit:
15 Mbps(enough for streaming, not gaming) - Upload Limit:
5 Mbps
Per-Device Bandwidth Limiting (Advanced)
Some UniFi controllers support per-device limits: Clients → Select Device → Traffic Control. Example: iPhone 10 Mbps, iPad 8 Mbps, Laptop 12 Mbps.
Layer 5: Device Monitoring & Analytics
NextDNS Analytics Dashboard
- Security → Queries: View every DNS request in real-time, see blocked attempts
- Insights → Top Blocked: Identify which categories are blocked most, spot false positives
- Reports: Weekly/monthly summaries, trend analysis, exportable reports
- Alerts: Notifications for specific site access, DNS changes, or unusual activity
UniFi Controller Monitoring
- Clients → Kids-Network: Connected devices, real-time bandwidth, signal strength
- Insights → Traffic: Total data, protocols, peak usage times
- Events → WiFi Events: Connection/disconnection logs, authentication failures
Red Flags to Monitor
| Warning | What It Means | Action |
|---|---|---|
| VPN connection attempts | Bypassing filters | Review allowed sites, block VPN DNS |
| DNS query spikes | Unusual activity | Check NextDNS logs for patterns |
| 4 AM internet usage | Sneaking access | Review bandwidth alerts, tighten scheduling |
| Frequent reconnections | Trying different networks | Check if connected to parent WiFi, review passwords |
| Large data transfers | Downloading restricted content | Check protocol logs, review blocklist |
Deployment Timeline (2–3 Hours)
Phase 1: DNS Foundation (30 min)
- Choose DNS: Cloudflare or NextDNS
- Configure DNS in UniFi Console
- Reboot controller
- Test DNS resolution on a device
- Verify blocking works (try adult site)
Phase 2: Network Isolation (45 min)
- Create Kids-Network VLAN (192.168.100.x)
- Create Kids-WiFi SSID on restricted VLAN
- Set strong WiFi password
- Create Parent-WiFi SSID on main network
- Test: Connect child device — should get 192.168.100.x IP
Phase 3: Scheduling & Limits (30 min)
- Enable WiFi Schedule on Kids SSID
- Set school day hours (7 AM – 10 PM)
- Set weekend hours (8 AM – 11 PM)
- Configure bandwidth limits (15 Mbps download)
- Test: Device should disconnect at cutoff time
Phase 4: Monitoring Setup (20 min)
- Create NextDNS account (if using)
- Add kids' devices to NextDNS profiles
- Test dashboard access
- Set up analytics notifications
- Document passwords securely
Phase 5: Family Meeting (10 min)
- Explain what's happening and why
- Review which sites are blocked and why
- Set expectations for acceptable use
- Establish process for requesting access to blocked sites
- Explain monitoring (transparency builds trust)
Best Practices & Security
Parental Security
- Controller Password: Change default, use 20+ character password
- UniFi Account: Enable 2FA (two-factor authentication)
- WiFi Passwords: Rotate Kids WiFi every 30 days. Admin WiFi: different, 20+ characters, never share
- DNS Service: Keep NextDNS account email secure
- Updates: Keep UniFi firmware current
Communication & Balance
- Be Transparent: Explain why you're monitoring (safety, not distrust). Show them the dashboard.
- Allow Bypass Requests: Kids can request access to blocked sites. Review together, add to allowlist if legitimate.
- Progressive Relaxation: Age 10 → strict. Age 13 → moderate. Age 16 → light. Age 18 → trust-based.
- Regular Check-Ins: Monthly reviews, discuss patterns, adjust rules together.
VPN/Bypass Prevention
Kids often try VPNs or proxies to bypass filters. In NextDNS: enable VPN/Proxy blocking in the blocklist. Block DNS tunneling (DoT except to NextDNS). Monitor UniFi traffic for port 1194 (OpenVPN) and 443 (QUIC tunneling).
Note: No system is 100% bypass-proof. Communication and trust are ultimately more important than technical restrictions.
Troubleshooting
DNS Issues
Kids can still access blocked sites:
- Device has hardcoded DNS (8.8.8.8) → Create firewall rule blocking all DNS except NextDNS
- NextDNS not linked → Verify DNS servers in UniFi Console, run
nslookup google.com - Conditional forwarding overriding → Remove conditional forwarding in DNS settings
Legitimate sites blocked (false positives): Check NextDNS dashboard → Top Blocked → find site → add to Allowlist.
Network Issues
- Kids WiFi randomly disconnects: Check VLAN routing (
ping 192.168.100.1), change WiFi channel, check AP load - Devices can't connect: Verify VLAN status is "UP", ensure SSID is visible, try WPA2/WPA3 mixed mode
Scheduling Issues
- WiFi schedule not working: Check controller timezone (Settings → Localization), verify device isn't on parent SSID, recreate schedule
Performance Issues
- Internet very slow on Kids WiFi: Increase bandwidth limit, check device count, test with Cloudflare DNS temporarily
Cost Breakdown
| Component | Cost | Notes |
|---|---|---|
| UniFi Dream Machine SE | $300–400 | All-in-one controller + WiFi (if needed) |
| UniFi WiFi 6 AP (U6-Lite) | $80–150 | Additional APs for large homes |
| NextDNS | Free – $50/year | Free tier: 300k queries/month |
| Cloudflare Family | Free | No cost, more limited features |
| Total (Minimal) | $0 (if you have UniFi) | + $50/year if using NextDNS Pro |
Hardware & Environment
Minimum Setup
- UniFi Dream Machine or UDM Pro (or separate controller + AP)
- Stable internet connection (10+ Mbps recommended)
- WiFi 5 or WiFi 6 access point
Recommended for Better Results
- Multiple APs (mesh coverage for whole home)
- PoE injector for remote APs
- Wired connection for controller (more stable)
- Dedicated switch for VLAN isolation
Summary: What You've Built
Scenario: Child tries to visit adult site at 2 AM on a school night.
- Layer 1 (DNS): NextDNS blocks the domain — site doesn't load
- Layer 2 (Schedule): WiFi is disabled — can't connect anyway
- Layer 3 (Isolation): Kids VLAN can't access parent systems — safe
- Layer 4 (Bandwidth): Limits streaming quality — discourages binge
- Layer 5 (Monitoring): Parents see attempt in NextDNS dashboard — discuss
Result: Multiple overlapping protections, plus family conversation.
Monthly Maintenance Checklist
- Review NextDNS analytics — blocked sites, trends, usage patterns
- Update allowlist — add any false positive sites
- Check UniFi logs — look for anomalies or errors
- Rotate WiFi passwords — change Kids WiFi password
- Review bandwidth usage — check if limits need adjustment
- Family check-in — discuss any issues, request access to blocked sites
- Monitor for bypass attempts — check for VPN, unusual ports, DNS changes
- Test DNS filtering — verify blocking still working
- Update UniFi firmware — keep system patched
Common Mistakes to Avoid
- Not communicating: Kids resent secret monitoring → Explain the system, discuss rules
- Filters too strict: Blocks educational sites → Use allowlist, review blocks monthly
- Ignoring VLAN security: Kids can access home automation → Create proper isolated VLAN
- Relying on one layer: Single point of failure → Use all five layers (redundancy)
- Set and forget: Rules go stale → Monthly review and adjustment
- Forcing too much control: Creates distrust → Progressive relaxation as kids mature