Live data from Hacker News

UniFi Express

ui.com

61–70 of 296 posts

Re: UniFi Express

#61

I love ubiquiti. My entire home network runs on their gear, with self-hosted management. I have infra deployed across the country in a remote office that runs their gear, with a cloud key. It's solid stuff all around. Don’t use any of their unifi routers tho, can’t speak to that. I have an ER-4 at home and the remote office has a pfsense 1U.

Same here, I love the UDM Pro SE. Blocking application layer stuff like QUIC is just a couple clicks away. It has decent intrusion detection and response alongside other easy to configure firewall settings.

Why and how do you block application layer stuff like quic?

Re: UniFi Express

#62
post #61

Earlier quoted context omitted.

Same here, I love the UDM Pro SE. Blocking application layer stuff like QUIC is just a couple clicks away. It has decent intrusion detection and response alongside other easy to configure firewall settings.

Why and how do you block application layer stuff like quic?

Tiny network tyrants gotta flex somehow.

Re: UniFi Express

#63
post #42
post #21

Weird that the ethernet ports are only 1GbE, that discounts everyone with a >1Gbit internet connection

This is to my massive irritation. I don't want to use the router built into my cable modem, but my Internet is 1.2gb and I feel like I'm throwing money away. Routers with 2.5gbe uplink are hard to find and even more expensive.

The Mikrotik RB5009 is very affordable and has both SFP+ and 1x 2.5G Ethernet. And you can use either port as WAN or LAN depending on your setup. Will still need a switch however if you have more 2.5G clients.

Re: UniFi Express

#65
post #54

Earlier quoted context omitted.

Unifi AP for wifi, Unifi switches, Unifi security gateway of some kind, Unifi point to point for terrestrial wireless to share with another set of Unifi gear in a barn/shed/whatever down the road. All managed by UNMS.

Do the Unifi APs and other Unifi hardware still need a docker image or software installed that includes mongodb I think it was to manage devices?

Most of their stuff can be set up without needing a Unifi Controller, but for configuring wifi and gathering stats the software is used. They make a device called a Cloud Key that has the controller built in that can then be used to manage the Unifi gear from the cloud. UNMS is used for more Terrestrial wireless ISP stuff but the switches and point to points can be added to UNMS or the Controller.

Re: UniFi Express

#66
post #7

Earlier quoted context omitted.

Right?! Who's buying? Big businesses or regular retail? Or are they limiting supply to keep prices high?

The second one. Businesses aren't buying this shit.

I see unifi APs everywhere in businesses.

Re: UniFi Express

#67
post #51

Earlier quoted context omitted.

I kinda hate Ubiquiti routers. My UDM Pro felt like a total scam, with the IDS/IPS being nowhere close to advertised. They promised but never introduced WireGuard. I also experienced strange bugs in the stack. I eventually moved to OPNSense but the router I bought from them died. The interface was too cumbersome anyways, from the perspective of someone that just wanted WireGuard server+client, IPS/IDS, and VLAN. I fi…

Do you think Ubiquiti APs are still good, I have not used them since 2018?

Love their AP’s.

Re: UniFi Express

#68

I love ubiquiti. My entire home network runs on their gear, with self-hosted management. I have infra deployed across the country in a remote office that runs their gear, with a cloud key. It's solid stuff all around. Don’t use any of their unifi routers tho, can’t speak to that. I have an ER-4 at home and the remote office has a pfsense 1U.

Same here, I love the UDM Pro SE. Blocking application layer stuff like QUIC is just a couple clicks away. It has decent intrusion detection and response alongside other easy to configure firewall settings.

Udm pro SE is the best thing I bought. 10g, protect for camera selfhosting which works great, new updates made wireguard first class citizen, and if you want anything more complicated it's just a dumb debian underneath (which I do a bunch of stuff).

I'm reallt happy with it.

Re: UniFi Express

#69
post #50

Earlier quoted context omitted.

Unifi is just their name for this series of products that all work together with their (free) controller. So you buy an AP, a switch, a router, all from the Unifi line of products and they all get setup from a single controller and work together pretty effortlessly

I see, thanks. So basically a suite of networking hardware solutions? What I found the most confusing is that they sort of differentiate UniFi from WiFi. E.g. "Instant WiFi for retail POS" - yes, like any other WiFi router? Or is this box going to connect to a global mesh that's called UniFi?..

For the "Instant WIFI for retail POS" it could be describing a meshed wifi solution, where it then acts as a wireless backhaul and bridges to the LAN port you can connect to the POS system that doesn't have wifi built in.

Re: UniFi Express

#70

Earlier quoted context omitted.

A business really shouldn't be running this. Anything that isn't basically your home office is running a solid NGFW with SSL interception.

That’s…Not an accurate description of how things work in the real world. There are large enterprises out there with NGFWs that aren’t doing much TLS inspection. Your average mom and pop business is more likely to have a wifi AP/router/NAT gateway combo from their ISP than something as feature rich as Unifi, let alone a real NGFW.

Every major company I’ve been at absolutely positively does NOT MitM their own traffic. They pay security people well enough to realize what a massive hole that creates in their security posture, and makes the intercepting appliance a cess pit of regulatory toxic waste. PCI, MNPI, even HIPPA from employees visiting their health insurance site? Check, check, check! All on a silver platter for insiders and hackers.
Post reply on HN