Earlier quoted context omitted.
If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily. The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.
I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".
Ubiquiti Networks Breach
301–310 of 486 posts
Re: Ubiquiti Networks Breach
#302Earlier quoted context omitted.
I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…
Do you know how ubiquiti's "edge" line compares to mikrotik?
For mad scientists though, the very open software stack is a good friend to have when 11th hour Requirements® dictate you must produce a rabbit without a hat, or rewrite your own domain-specific implementation to replace the Avahi service.
No experience with Mikrotic.
_On topic_: With cloud news like this, it's nice to know about the availability of Ubiquitis' Network Management System[1] which you can host and run wherever.
[1]: https://unms.com/
Re: Ubiquiti Networks Breach
#303Earlier quoted context omitted.
Ubiquiti had a steady exodus of engineers in the past few years. It's a very different company now compared to the glory days of UniFi.
Doesn't it seem like one of the missing measurements for directors/VPs should be "amount of disappearing expertise"?
Re: Ubiquiti Networks Breach
#304Earlier quoted context omitted.
My primary use case for a home router is solid set and forget qos. fq_codel and cake were recently added to routeros v7 beta, which means I will be plugging in my hEX again after a few years of happy edgerouter x usage. Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?
I'm curious as to what you are doing with qos in a home setup.
On my previous ISP latency would reach 2000+ ms when I let Dropbox sync or downloaded a huge file. Even web browsing would time out. I used Tomato to prioritize DNS, my VoIP analog telephone adapter, the first 256KB of any HTTP(S) connection, and some 27000+ ports used by games.
My current WAN connection reaches 300 ms without fq_codel enabled. With it enabled there's no jump in latency.
Re: Ubiquiti Networks Breach
#305Earlier quoted context omitted.
I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…
Yes, I recommend MikroTik as well. Got two of their cAP wireless access points. All the features you would expect on enterprise level kit at 1/4 the price easily. Because there are so many features the setup is not as easy as some alternatives I'm sure. But the value proposition is great. Their "RouterOS" is standardised over pretty much all of their kit. So after you have worked it out once you should be set for any…
At this point there are probably 20+ home Unifi networks that i'm responsible for recommending or setting up, doing the same with MikroTik might turn me into a full time sysadmin :)
Re: Ubiquiti Networks Breach
#306Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
I’ve become a big fan of MikroTik routers and 10G/SFP+ router/switch hardware in the last few years. Their web UI and SSH console are a bit quirky but the performance is pretty great for the price. My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G sw…
Re: Ubiquiti Networks Breach
#307Argh, why do I learn about this from HN when they pretty much force me through the cloud login with UDM-Pro. Nothing in the dashboard. Also I think http://unifi/ is crap from a security standpoint. Their threat management also seems to be just some kind of a bad joke.They could for example do a nice hardware based honeypot that you have to untrigger with physical access. They could offer so much more for prosumers pr…
Re: Ubiquiti Networks Breach
#308Re: Ubiquiti Networks Breach
#309Earlier quoted context omitted.
I'm not clear what you were trying to achieve? You had unmanaged switches on your network, and were trying to manage thier downstream connections? What exactly do you mean by 'breach the firewall'?
It's a basic home network. I had a simple netgear unmanaged switch and an apple airport extreme in bridged mode. The equipment works and i didn't want to add more trash to the landfill and spend money i didn't need, so I wanted to continue to use them. There is no way to identify any clients on your network that are either behind the switch or behind the airport (even in bridged mode). I would expect at least some li…
The default logging may not capture the individual child clients, depending on your configuration (eg double nat), sure... but those child clients are still entirely at the mercy of your configuration otherwise. Saying that the clients are completely invisible/invincible, and that the fault is the Ubiquiti product, is not true.
Re: Ubiquiti Networks Breach
#310Earlier quoted context omitted.
If you only need to VLAN-tag the 4 ports on that one device, you can do it with like… about literally anything? e.g. an Archer C1750 with OpenWRT does that easily. The benefit of UniFi is that you can centrally control a bunch of switches. It's definitely overkill and overpriced if you just want an all-in-one.
I need to set up multiple wifi SSIDs, each on a distinct VLAN, and apply firewall rules to ensure things like: hosts in the "home" vlan can open connections to hosts in the "iot" vlan, but "iot" cannot open connections to "home".