Live data from Hacker News

UniFi Express

ui.com

261–270 of 296 posts

Re: UniFi Express

#261
post #256

Earlier quoted context omitted.

I bought into their unifi ecosystem years ago. Separate devices, prosumer pricing, features and quality, single pane of glass. ... And I haven't upgraded anything since. Their new products are totally undirected, they aren't making items that are obvious and needed. Their software is falling behind and they just don't care. Case in point: the usg pro 4 is years old but they havent released an updated affordable just-…

I just upgraded my networking and wifi and had the intention of going with unifi equipment rather than the consumer grade stuff. I was shocked to see that they don't have 2.5GbE or Wifi 6E options for their equipment.

They do have 2.5GbE through the dream machine special edition, also anything that is an SFE port you can put in a 2.5 or 10gbit ethernet jack if you need it. I get the general impression that they just want to go straight to 10gbit and not do 2.5gbit much.

Re: UniFi Express

#262

Earlier quoted context omitted.

I don't disagree, but since buying the UDM-Pro years ago, I feel like the software has gotten great. And recently, they've baked in Wireguard replacing L2TP. Personally, I'd like to see more prosumer devices that support 2.5GbE/10GbE.

People always raise Wireguard as the end-all of VPN and yet its 2023 and there's virtually no way to deploy it in a business context. InTune doesn't even list it as a supported VPN, and everything I see to deploy it suggests some kind of hack to bypass UAC for one specific app because the end-user software requires Admin permissions to startup and hook. When we use L2TP with UDM Pro we get ~0.1Mbps across the wire fr…

Wireguard feels like the HDR of VPNs, adoption is slower than you'd think it would be.

Re: UniFi Express

#263

Earlier quoted context omitted.

Every major company I’ve been at absolutely positively does NOT MitM their own traffic. They pay security people well enough to realize what a massive hole that creates in their security posture, and makes the intercepting appliance a cess pit of regulatory toxic waste. PCI, MNPI, even HIPPA from employees visiting their health insurance site? Check, check, check! All on a silver platter for insiders and hackers.

I'd say, based on my experience, that if there's an 'average' big corp, they do targeted TLS proxy: on most or all of their inbound traffic to hosted services and limited category by category decryption outbound. Yes, they are absolutely concerned about legitimate regulatory and privacy concerns, but they are also concerned about data being exfiltrated, phishing attempts, identifying malicious payloads, etc.

Those companies tend to whitelist dropbox, one drive etc, the very places things are exfiltrated too.

Re: UniFi Express

#264

Earlier quoted context omitted.

We live in a 3 floor 1800 sq.ft. house, with have a garage that is 300 ft away. My single UAP-AC-LR manages to cover this quite nicely, only the far corner of the garage has poor connection, out in the garden it's excellent. Unless all the walls in your house are heavily reinforced concrete, I don't see how you need that many APs.

What is your house built of? In the UK, we’ve got houses with brick walls everywhere - it’s killer for signal.

I live in a wooden house, which is kind of ideal yes. You say brick, which isn't actually that bad, if you reference the classic NIST report [1].

And even in a brick house a lot of the interior walls are still just plywood or drywall, even in the UK AFAIK.

What is interesting though is that OP said it is sufficient with one AP per floor plus one outside. So apparently propagation within one floor is fine, but between floors or to the exterior is not. In that case, it has to be a building where the interior walls are mostly just drywall, and the exterior walls and floor slabs are reinforced concrete with little in terms of openings. Which sounds more like an apartment building than anything else?

[1] https://www.nist.gov/publications/electromagnetic-signal-att...

Re: UniFi Express

#265
post #198

Earlier quoted context omitted.

2 floor house + Outside is immediately 3 APs. You'll also need at least one PoE switch to power them. That's 4 devices already, without adding anything else like security cameras or similar.

We live in a 3 floor 1800 sq.ft. house, with have a garage that is 300 ft away. My single UAP-AC-LR manages to cover this quite nicely, only the far corner of the garage has poor connection, out in the garden it's excellent. Unless all the walls in your house are heavily reinforced concrete, I don't see how you need that many APs.

Over here houses typically are built with reinforced concrete floors, and double brick walls. Also, building up instead of out is normal, so many have a basement, ground floor and 2 upper levels.

Having one AP per floor is normal for coverage, so that would be 4 to serve the inside.

Re: UniFi Express

#266

Earlier quoted context omitted.

Every major company I’ve been at absolutely positively does NOT MitM their own traffic. They pay security people well enough to realize what a massive hole that creates in their security posture, and makes the intercepting appliance a cess pit of regulatory toxic waste. PCI, MNPI, even HIPPA from employees visiting their health insurance site? Check, check, check! All on a silver platter for insiders and hackers.

Pretty sure that is not true, almost every major security vendors recommends Deep packet inspection of unknown traffic (which requires Decryption) Most of the time there are white lists that exempt huge amounts of known traffic to common SaaS services, and known company resources (like Health Insurance) traffic, but if it not a known service than that traffic should absolutely been decrypted and inspected. Cisco, Pal…

Company selling hammers recommends banging things in

Re: UniFi Express

#267

I want to like UI products, they seem to be the choice for prosumer equipment, but the lack of 10Gb networking is disappointing. WiFi 6/6e is multi-Gig but most devices only have the capacity to route/switch at the line rate of the physical ports. This is probably asking for too much but I would a set-up that allows me to operate at home: - 10Gb router (packet switching to fully saturate the number of physical ports)…

gbit speeds are usually good enough for the majority of applications. even your 6e ap will not archive more than a gbit in most real world scenarios (not testing). the tables turn slowly, but the mass market for 10gig is just not here yet besides all-10gig soho switches beeing available for some time now. major point: 10gig uses vastly more power than 1gig, making integration (esp. in laptops) challenging. other poin…

> even your 6e ap will not archive more than a gbit in most real world scenarios

au contraire; even for wifi 5 aps like original Turris Omnia (3x3 MIMO, 80 MHz) or Ubiquiti nanoHD (4x4 MIMO, 80 MHz), the gigabit uplink was the bottleneck.

> major point: 10gig uses vastly more power than 1gig, making integration (esp. in laptops) challenging.

Only 10GBase-T. For a networking equipment, you would want SFP+ anyway.

Laptops slowly are losing wired Ethernet entirely. Meanwhile, 2.5GBase-T is still good enough for laptops, and does not represent integration challenges.

Re: UniFi Express

#268
post #167

Earlier quoted context omitted.

> UniFi Express supports up to 5 connected UniFi Network devices, including other UniFi Express units, switches, and WiFi access points. What does that even mean? That it bundles a controller that is not "capable" of handling more than 5 unifi devices? Who comes up with shit like that? Lets punish people that get too dependent on us and tries to buy too many devices. Let's squeeze some more out of them and risk them…

Because someone will invariably buy this thing and then hang 15 access points off of it, and it won't be able to manage given build of materials this device has. And then they'll be pissed off because it doesn't "do" what they want it to. This thing is designed for what 95% of household's need. A router and one or two WAPs. That's really it.

Of course it will manage 15 access points, there is nothing to it.

Re: UniFi Express

#269
post #167

Earlier quoted context omitted.

It's $149. I think you're expecting more from it than what your more advanced home setup needs. Mind you it talks a big talk for that price.

> UniFi Express supports up to 5 connected UniFi Network devices, including other UniFi Express units, switches, and WiFi access points. What does that even mean? That it bundles a controller that is not "capable" of handling more than 5 unifi devices? Who comes up with shit like that? Lets punish people that get too dependent on us and tries to buy too many devices. Let's squeeze some more out of them and risk them…

Sadly the UXG lite lacks the second WAN port which i use for 4G failover. Otherwise id replace my USG.

What I miss the most in their offering is an affordable 6e AP though.

Re: UniFi Express

#270
post #268

Earlier quoted context omitted.

Because someone will invariably buy this thing and then hang 15 access points off of it, and it won't be able to manage given build of materials this device has. And then they'll be pissed off because it doesn't "do" what they want it to. This thing is designed for what 95% of household's need. A router and one or two WAPs. That's really it.

Of course it will manage 15 access points, there is nothing to it.

Yeah it's not like it needs to talk to them constantly. Just push settings and updates periodically and retrieve some statistics.
Post reply on HN