Earlier quoted context omitted.
I bought into their unifi ecosystem years ago. Separate devices, prosumer pricing, features and quality, single pane of glass. ... And I haven't upgraded anything since. Their new products are totally undirected, they aren't making items that are obvious and needed. Their software is falling behind and they just don't care. Case in point: the usg pro 4 is years old but they havent released an updated affordable just-…
Not to detract from an otherwise excellent comment but... product astronauts? Never heard that term before.
UniFi Express
101–110 of 296 posts
Re: UniFi Express
#102Earlier quoted context omitted.
Isn't it normal that changing the destination of all of a system's network traffic would require admin permissions? Why does that make you think it's a hack?
It's completely reasonable that it requires admin permissions, but what I'm saying is that the other protocols (i.e. L2TP) that are built into macOS/Windows and mobile devices are integrated in such a way that they do not. Most businesses never give their users admin permissions because it's a security can-of-worms, so for Unifi to push Wireguard for business doesn't make much sense. Happy for someone to point me at…
> Fixed the issue where WireGuard VPN could not be used through Intune-deployed MSI installation.
Source: https://wiki.ui.com/docs/identity-enterprise-endpoints-0671
Re: UniFi Express
#103I love ubiquiti. My entire home network runs on their gear, with self-hosted management. I have infra deployed across the country in a remote office that runs their gear, with a cloud key. It's solid stuff all around. Don’t use any of their unifi routers tho, can’t speak to that. I have an ER-4 at home and the remote office has a pfsense 1U.
Re: UniFi Express
#104Earlier quoted context omitted.
> What is UniFi Express? > UniFi Express is a complete UniFi Networking stack in an ultra-compact, plug-and-play form factor. It runs UniFi Network and features a powerful gateway engine and built-in WiFi 6 with seamless meshing.
Read this several times. Still don't know what I am looking at. What is "UniFi Networking stack", what is "UniFi Network"? Is it a WiFi router? I use a TP-Link router at home, and they don't sell it as "TP-Link Networking stack".
In a wifi router like your TP-Link, the control plane software is running on the box with the the switching hardware and wifi ap, so you've got a little single board computer running web server for the UI, and all the random dhcp/dns/etc and other doodads that can run on them.
In the Unifi world, you've got all the same functions, routing/switching/wifi etc, but instead of sharing one box, the functions are spread across a number of different devices.
As with a combination router/wifi/switch, the important part to a user like you or me is that control plane software- you plug the thing in, point your browser to 192.168.1.1 or whatever, and set things up. The Unifi world has this too, but that software component doesn't need to run in any specific place in your network. So for example, you could buy two Unifi Access Points which do nothing but talk to wifi clients, then you would need some kind of device capable of going your routing, and you might need a switch as well.
Ubiquiti sells a variety of little routers and switches that can perform those network functions, but which don't have any compute or storage resources that would be necessary to run the control plane software. However, they also sell little gizmos like the Cloud Key which can run the control plane software- it's just a tiny server with some flash storage and an ethernet port. I'll refer to that thing as The Controller.
When you change some settings on your TP-Link, the web UI app is twiddling with the the routing/switching/wifi/etc hardware or software on the device. In the Unifi world there's a web ui as well, running on the controller, but when you change a setting in the web ui, the controller decides which devices need to have their configuration updated, and sends out new configuration to them over the network.
Here's where I think things get confusing. The Controller software package can run on a wide variety of devices which are so different that the whole thing will seem nonsensical if you're used to regular wireless routers. You can buy a CloudKey and connect it to your network. You can download a copy of the Controller that will run on a Linux box on your network. Or you could do the same thing but have the Controller running on a machine that isn't on your network at all, like an EC2 vm. Or, Ubiquiti also sell some devices which combine two or more functions into a single device, like some of the "UDM" family of devices have compute and storage resources in addition to the switching/routing/wifi hardware, and have The Controller software installed in advance.
To give you an example of how flexible the controller placement is, I have a little Synology NAS that is able to run Docker, and on it I have an image that contains the Unifi Controller, so when I go the web ui for my network, I'm talking to a containerized web server on the NAS, which is managing the configuration of my devices, which are a router (I just replaced my USG 3P with a UXG-Lite yesterday), a couple of their little inexpensive switches, and a pair of Wireless Access Points.
What I like about this model is that I'm able to update pieces of it as I need to, and usually the individual pieces are fairly inexpensive. But what I dislike about it, as some other respondents on this thread have complained, choosing which devices you need is confusing as hell. They sell at least one machine which has a wifi AP, switch, router, and controller all in one box. Why not get that? The reason, I believe, is that many of the people who use this Unifi stuff are managing a bunch of networks at a bunch of different sites, like maybe at a bunch of retail locations or restaurants, where its way more convenient to have the controller running offsite, but then they decide to install some stuff at home and need a Controller which needs fewer resources so a Cloud Key or just running the stuff on your desktop would be ok.
This flexibility means that there's no single right set of hardware, no single best product, etc. Especially if you don't need multiple APs, I think a single-box wifi router will provide equal or superior performance with much less trouble, but once you need multiple APs, the Unifi stuff can be compelling if you're comfortable with the architecture, but I think it's difficult to decide which hardware bits to choose and what the best place to run the controller will be.
anyway apologies for the length- I found all this very confusing initially as well although I've grown fond of the Unifi stuff and thought it might be worth writing the whole thing out in case its useful to somebody considering this stuff.
Re: UniFi Express
#105I love ubiquiti. My entire home network runs on their gear, with self-hosted management. I have infra deployed across the country in a remote office that runs their gear, with a cloud key. It's solid stuff all around. Don’t use any of their unifi routers tho, can’t speak to that. I have an ER-4 at home and the remote office has a pfsense 1U.
I kinda hate Ubiquiti routers. My UDM Pro felt like a total scam, with the IDS/IPS being nowhere close to advertised. They promised but never introduced WireGuard. I also experienced strange bugs in the stack. I eventually moved to OPNSense but the router I bought from them died. The interface was too cumbersome anyways, from the perspective of someone that just wanted WireGuard server+client, IPS/IDS, and VLAN. I fi…
Can’t believe I spent $300 + on the Netgate that couldn’t handle 1 Gbps traffic WITHOUT IDS/IPS turned on. Even a $50 EdgeRouter X can do gigabit WAN!
Re: UniFi Express
#106I love ubiquiti. My entire home network runs on their gear, with self-hosted management. I have infra deployed across the country in a remote office that runs their gear, with a cloud key. It's solid stuff all around. Don’t use any of their unifi routers tho, can’t speak to that. I have an ER-4 at home and the remote office has a pfsense 1U.
I kinda hate Ubiquiti routers. My UDM Pro felt like a total scam, with the IDS/IPS being nowhere close to advertised. They promised but never introduced WireGuard. I also experienced strange bugs in the stack. I eventually moved to OPNSense but the router I bought from them died. The interface was too cumbersome anyways, from the perspective of someone that just wanted WireGuard server+client, IPS/IDS, and VLAN. I fi…
Seems like all you can do I hope they do not spy on your traffic and sell data. I run a reputable VPN for that very reason I don’t trust even my publically traded ISP.
IDK, seems suspect. Or at least requires more trust than I am willing to hand out.
Re: UniFi Express
#107I am lucky enough to have FTTH service where the provider furnishes me with an SFP stick with simple DHCP (no PPPoE). Beyond UniFi, Microtik, and rolling your own, there’s very little option in consumer routers.
Re: UniFi Express
#108Re: UniFi Express
#109Earlier quoted context omitted.
Right?! Who's buying? Big businesses or regular retail? Or are they limiting supply to keep prices high?
The second one. Businesses aren't buying this shit.
Remote access, decent ecosystem, reliable. What's not to like?
The only problem I have on occasion is stock.