Live data from Hacker News

UniFi Express

ui.com

271–280 of 296 posts

Re: UniFi Express

#271
post #184

Earlier quoted context omitted.

There are still far more people below gigabit speeds than there are people hitting their gig. As more fiber is deployed that may change, but it's still a very functional device regardless.

it also means your home network is slower. Why should a backup from my laptop to my file server be limited to 1gbps? Has nothing to do with outside connection. Tehre are a lot of use cases for faster home networking irrelevant of network speed to the external world

Sure, but it's just a single port LAN router. If you have a 10G switch it's going to have a MAC table and let your laptop talk directly to your file server over Ethernet.

Otherwise the wireless throughput is nowhere near gigabit so you would be limited by that anyway.

Re: UniFi Express

#272
post #83

Earlier quoted context omitted.

That's with all the features on though right? I'm sure a lot of folks wouldn't be using VPN, deep packet inspection, ad blocking, a large number of routes and vlans, IDS, caching etc all at once, it hardly takes any CPU processing to simply route 2.5G (or hell, even 10G) through a firewall.

Solid points, but there’s a little bit of history (the details are fuzzy for me so apologies to anything I get wrong): When 1Gbps internet connections were starting to be widely available Unifi put out some “1Gbps” products that could only route 1Gbps with nothing turned on. It quickly dropped to 300Mbps if someone wanted to use any of the Unifi features and people called them out. If they are making it a point to ad…

This is surprisingly common, SonicWall devices are kind of market segmented by how much they can process with security services enabled. We installed 50/50 fiber at a customer location and their SonicWall had a gig WAN, but with the device set to "Maximum Security" it only got about 30-35 meg download speed. "Performance Optimized" let it hit the 50/50 lmao

Re: UniFi Express

#273
post #268

Earlier quoted context omitted.

Of course it will manage 15 access points, there is nothing to it.

Yeah it's not like it needs to talk to them constantly. Just push settings and updates periodically and retrieve some statistics.

Ubiquiti isn't convinced the hacky mess of MongoDB they run won't corrupt itself when it hits a resource constraint on this device, and they also want to avoid RMAs when the controller either wears out the small amount of our device storage from too many writes, or when the whole unit bogs down from too many paired devices.

The controller should really be off board, or the on-board controller should be tuned to communicate less with the devices it s and write significantly less often to storage.

Re: UniFi Express

#274

Earlier quoted context omitted.

That device is so suspect. Old, dual core processor, 1GB of DDR3 and, supposedly, "next-gen" security features including IPS. Riiiiiight.

Barely can break 350mbps with IDs and IPS enabled and starts getting buffer overload. I'm pretty sure Mikrotik had a faster router a few years before the usg4 hit the market for about the same price. what unifi sold people on was cloud managed easy config and it just started working somewhat in the last version for me. Really feels like they need to triple down on the software front and beef the midrange hardware. I…

Without necessarily defending Ubiquiti's oftentimes-weird product lineup, IDS/IPS are basically useless, so there's not much point worrying about what they do to raw WAN speed.

Re: UniFi Express

#275
post #189

Earlier quoted context omitted.

Every major company I’ve been at absolutely positively does NOT MitM their own traffic. They pay security people well enough to realize what a massive hole that creates in their security posture, and makes the intercepting appliance a cess pit of regulatory toxic waste. PCI, MNPI, even HIPPA from employees visiting their health insurance site? Check, check, check! All on a silver platter for insiders and hackers.

That’s simply not true. I can tell you for a fact basically every Fortune 500 is doing SSL inspection on at least a portion of their traffic. As for things like HIPPA - that’s why you do URL categorization and bypass those destinations.

I can tell you for a fact, having worked at them in a senior executive technical role with responsibility for security, that at least the top banks do not do this, and definitely not tech giants like Amazon. I am certain others do - but this doesn’t make it a good idea. There are a lot of bone headed things that networking hardware companies convince deep pocketed customers to do that they shouldn’t. Creating the ability to intercept traffic means none of your communications are secure within their TLS tunnels because there exists a well known and discoverable single point of failure for literally all traffic in the network.

Finally URL categorization isn’t perfect, and you end up with a leaky solution that is again, as I said, a giant cess pit of regulatory toxic waste.

Re: UniFi Express

#276

I was on unifi for a long time but I found it somewhat unreliable with a lot of issues. I switched over to TP-Link's Omada and now I never touch my network. I believe that TP-Link isn't as flashy, but they are rock solid. I prefer rock solid.

Went from unifi to Omada here as well. The APs have better specs for half the price. UI is comparable (at least for wireless, can't comment on their edge stuff but if you're familiar with the standard unifi controller setup you'll be comfortable with Omada).

Re: UniFi Express

#277
post #64

What would I get from this both hardware and software-wise that I don't get from ASUS routers?

OK, I've had several high-end ASUS routers and I know that your ASUS router is probably not stable and needs to be restarted all the time. At very least, Unifi is a huge step up from that and it will easily run at max performance for 3+ months at a time without a reboot.

I haven't experienced any instability with personal routers to be honest.

Re: UniFi Express

#278

Earlier quoted context omitted.

Isn't it normal that changing the destination of all of a system's network traffic would require admin permissions? Why does that make you think it's a hack?

It's completely reasonable that it requires admin permissions, but what I'm saying is that the other protocols (i.e. L2TP) that are built into macOS/Windows and mobile devices are integrated in such a way that they do not. Most businesses never give their users admin permissions because it's a security can-of-worms, so for Unifi to push Wireguard for business doesn't make much sense. Happy for someone to point me at…

There are many enterprises install Cisco AnyConnect or ZScaler

Re: UniFi Express

#279
post #236
post #234

Earlier quoted context omitted.

> I guarantee you approximately everyone that does not work in tech has one AP, the one provided by their ISP. Unifi already has a range of prosumer products, this is them moving into the consumer space. I'm not sure what are you trying to say with this - yes, obviously, people who don't buy extra APs don't have extra APs, but why are they relevant to conversation about UniFi prosumer products? It's not like UniFi cu…

This isn't a prosumer product. You aren't adding these to an existing Unifi install. The prosumer version of this device is the UDR. This is Unifi releasing a cheap consumer product so when you, as a person who knows their tech stack, need to suggest a all in one device for someone who would otherwise have just an ISP router, there is a product that costs in the same price range as the netgears and tp-link devices in…

This is prosumer. they have a consumer brand already: https://amplifi.com/

Re: UniFi Express

#280

Earlier quoted context omitted.

I wouldn't say they went to shit, but their products moved away from what I wanted. I had an ER-X and APs and they worked well. I'd like an upgraded ER-X, but don't need a UDM. I ended up continuing to use my ER-X and use Eeros for the APs - got them super cheap on some Amazon deal.

Same here. I have a ER-X deployed to provide internet acces to a bunch of servers. I don't need any cloud service and stuff, just a router with some firewall and NAT. My next product will be so ething else, because all the new stuff doesn't buy into the "KISS" anymore.

An updated ER-X with double the ports would be awesome. That's just not a market that ubnt seems to want to be in now. Cloud connected everything isn't something I want.
Post reply on HN