Live data from Hacker News

UniFi Express

ui.com

191–200 of 296 posts

Re: UniFi Express

#191

Earlier quoted context omitted.

That’s…Not an accurate description of how things work in the real world. There are large enterprises out there with NGFWs that aren’t doing much TLS inspection. Your average mom and pop business is more likely to have a wifi AP/router/NAT gateway combo from their ISP than something as feature rich as Unifi, let alone a real NGFW.

Every major company I’ve been at absolutely positively does NOT MitM their own traffic. They pay security people well enough to realize what a massive hole that creates in their security posture, and makes the intercepting appliance a cess pit of regulatory toxic waste. PCI, MNPI, even HIPPA from employees visiting their health insurance site? Check, check, check! All on a silver platter for insiders and hackers.

I'd say, based on my experience, that if there's an 'average' big corp, they do targeted TLS proxy: on most or all of their inbound traffic to hosted services and limited category by category decryption outbound. Yes, they are absolutely concerned about legitimate regulatory and privacy concerns, but they are also concerned about data being exfiltrated, phishing attempts, identifying malicious payloads, etc.

Re: UniFi Express

#192

Earlier quoted context omitted.

Not to detract from an otherwise excellent comment but... product astronauts? Never heard that term before.

Never heard of it either but I like it. I assume their heads are up in the sky and coming up with product ideas that are very far out there.

The military uses the term Idea Fairies.

Re: UniFi Express

#193
I was on unifi for a long time but I found it somewhat unreliable with a lot of issues. I switched over to TP-Link's Omada and now I never touch my network. I believe that TP-Link isn't as flashy, but they are rock solid. I prefer rock solid.

Re: UniFi Express

#194
I am quite turned off after a short honeymoon with unifi. They push setup via their mobile apps to the point that connecting to a dreammachine and entering its ip adress just shows a download link to the app store. The app could not connect without any hint of reason so i just consider this bricket now. Even before there were many red flags such as login flows to a local device going via .com domains. Completely confusing architecture where it is not obvious to me what parts of the admin setup run on unifis servers vs on the device. Why do all companies selling great looking devices poison everything with their cloud crap.

Re: UniFi Express

#195

Another confused product from UniFi. Is it targeting home users or businesses? It looks like businesses from their web page yet feels very much like a better fit for home. It only runs UniFi Network, so you have to buy more things, that also run UniFi Network, to get into any of their other products like Protect. I like their stuff but lately a lot of their stuff feels just confused to me, like they don't know what t…

Work From Home.

The enterprise is coming to the home.

Re: UniFi Express

#196

Earlier quoted context omitted.

The 50 vlan limit on their top of line stuff is the only reason we don't deploy them exclusively across our biz.

Genuinely curious What do you need 50+ vlans for? It feels like you could have physical lans to separate or simply different subnets? It’s hard for me to imagine why you would want to aggregate so many vlans over a single physical connection?

In certain scenarios, it may be necessary to assign multiple VLAN tags to the same network port. This is particularly common in environments where devices connected to that port need access to different network segments simultaneously.

For example, a networked device in a conference room might require access to VLANs designated for both guest internet and internal company resources. In this case, the port would be configured as a 'trunk' port, allowing traffic from multiple VLANs (each identified by a unique tag) to pass through. This setup ensures that the device can communicate across different departmental or functional network segments, such as VLANs for e.g. IT, Marketing, or Sales, etc.

Using VLANs over physical LANs or different subnets is fundamentally about enhancing network management efficiency and flexibility. The core advantage of VLANs is that they allow network administrators to segment and manage the network logically without the need for physical rearrangements. This means an engineer can configure and reconfigure network segments without the need to physically move cables or hardware (or even be on-site).

Re: UniFi Express

#197
post #95

Earlier quoted context omitted.

> Case in point: the usg pro 4 is years old but they havent released an updated affordable just-the-border device. Isn't the UniFi Gateway Lite[1] just that? [1]: https://techspecs.ui.com/unifi/cloud-keys-gateways/uxg-lite

That device is so suspect. Old, dual core processor, 1GB of DDR3 and, supposedly, "next-gen" security features including IPS. Riiiiiight.

Barely can break 350mbps with IDs and IPS enabled and starts getting buffer overload. I'm pretty sure Mikrotik had a faster router a few years before the usg4 hit the market for about the same price.

what unifi sold people on was cloud managed easy config and it just started working somewhat in the last version for me. Really feels like they need to triple down on the software front and beef the midrange hardware.

I just looked the other day - as I'm getting symmetric 2gb fiber in a few months and unifi has some wild high end router but it seems like it needs more on the CPU and ram front still, too. OpenSense here I come?

Re: UniFi Express

#198
post #124

Earlier quoted context omitted.

Having a few APs to cover a house is far from"advanced" setup. We live in times where lawn movers need wifi.

If you need 6 or more unifi devices, that's quite advanced. And quite a large area. If you have such a big house and also need WiFi for your fancy lawn mower, I can't shed a tear for the 149 USD budget unifi decice not being adequate for you.

2 floor house + Outside is immediately 3 APs. You'll also need at least one PoE switch to power them. That's 4 devices already, without adding anything else like security cameras or similar.

Re: UniFi Express

#199

Earlier quoted context omitted.

Genuinely curious What do you need 50+ vlans for? It feels like you could have physical lans to separate or simply different subnets? It’s hard for me to imagine why you would want to aggregate so many vlans over a single physical connection?

In certain scenarios, it may be necessary to assign multiple VLAN tags to the same network port. This is particularly common in environments where devices connected to that port need access to different network segments simultaneously. For example, a networked device in a conference room might require access to VLANs designated for both guest internet and internal company resources. In this case, the port would be co…

This doesn’t answer the question about needing more than 50.

Even if there are 20 departments, a development, testing/qa, and production server environment, phones, printers, 12 conference rooms, a dmz, an IoT, staff, and guest wifi, backups on their own vlan, a management vlan, and multiple vpns, you would still come under 50 with a few more to spare.

If you have a network like this it might also behoove you to physically separate it out so guest infrastructure and production, and management interfaces are all on completely different devices and thus each network doesn’t need all vlans.

Unifi doesn’t sell the highest quality of equipment that could necessarily support more complex environments in the first place but needing more than 50 vlans on one physical network sounds almost unsustainable.

Re: UniFi Express

#200

I am quite turned off after a short honeymoon with unifi. They push setup via their mobile apps to the point that connecting to a dreammachine and entering its ip adress just shows a download link to the app store. The app could not connect without any hint of reason so i just consider this bricket now. Even before there were many red flags such as login flows to a local device going via .com domains. Completely conf…

Companies aren’t satisfied with selling a great product for a profit, they have to keep growing. Their view is that not doing things like cloud services, adverts, selling personal data, etc is “leaving money on the table”
Post reply on HN