Live data from Hacker News

UniFi Express

ui.com

171–180 of 296 posts

Re: UniFi Express

#171

Earlier quoted context omitted.

That’s…Not an accurate description of how things work in the real world. There are large enterprises out there with NGFWs that aren’t doing much TLS inspection. Your average mom and pop business is more likely to have a wifi AP/router/NAT gateway combo from their ISP than something as feature rich as Unifi, let alone a real NGFW.

Every major company I’ve been at absolutely positively does NOT MitM their own traffic. They pay security people well enough to realize what a massive hole that creates in their security posture, and makes the intercepting appliance a cess pit of regulatory toxic waste. PCI, MNPI, even HIPPA from employees visiting their health insurance site? Check, check, check! All on a silver platter for insiders and hackers.

We MITM traffic at places I've been at, including government/charities. If you truly have a 'NGFW' then you can easily configure it to not MITM traffic based on categories, like healthcare.

It's pretty easy when you have your own PKI infrastructure. Which is surprisingly manageable if you have decent people running active directory services. Which is usually the single source of truth for LDAP integrations with NGFW anyway.

You can do cool things like having corporate devices have their own machine certificates that enable an always on VPN to access central resources (updates, AD, etc.) and switch to a user profile certificate as soon as a user logs into the device to get VPN/firewall access to resources that user needs.

It solves the pre-pipping problem of sending out devices to remote workers without them having to login before hand to load their profile on the same network as AD. And it's secure.

The alternative is to go cloud and in-tune everything and use Entra id, etc. which seems more popular but you lose a lot of control in my opinion and have a massive attack surface because unlike on-prem AD, the cloud is just some amorphous blob that you can't lock down using the usual things like firewalls.

Re: UniFi Express

#172
I want to like UI products, they seem to be the choice for prosumer equipment, but the lack of 10Gb networking is disappointing. WiFi 6/6e is multi-Gig but most devices only have the capacity to route/switch at the line rate of the physical ports.

This is probably asking for too much but I would a set-up that allows me to operate at home:

   - 10Gb router (packet switching to fully saturate the number of physical ports)
   - 10Gb switch
   - 6/6e AP
   - 10Gb firewall with IPS/IDS
Even just wanting a 10Gb switch for the home is nearly impossible, I doubt I will find a 10Gb router/ngfw that runs at line rate.

It seems strange that networking, outside of the data centre and WiFi, seems to be stuck in 2001.

Re: UniFi Express

#173

Earlier quoted context omitted.

It's not the cost of ports, but doing all the traffic processing for +500% of bandwith.

2.5G is absolutely nothing for modern chipsets and processors.

And do they cost the same?

I also wouldn't call it nothing, 2.5g switches have much higher consumption and get hotter, let alone 10g.

Re: UniFi Express

#174

Earlier quoted context omitted.

2.5G is absolutely nothing for modern chipsets and processors.

And do they cost the same? I also wouldn't call it nothing, 2.5g switches have much higher consumption and get hotter, let alone 10g.

I’ve got 2.5G switches at home and they easily run off 12V 0.8A power adapters (8 port 2.5G 1x 10g)

Re: UniFi Express

#175

I want to like UI products, they seem to be the choice for prosumer equipment, but the lack of 10Gb networking is disappointing. WiFi 6/6e is multi-Gig but most devices only have the capacity to route/switch at the line rate of the physical ports. This is probably asking for too much but I would a set-up that allows me to operate at home: - 10Gb router (packet switching to fully saturate the number of physical ports)…

The lack of 10G across the board in consumer devices is disappointing.

Somewhere in the early 00s computers started to come standard with gigabit. I think you could order a PowerMac G4 with gigabit in 2000. To put that in perspective, at that time VCRs were still the most popular way to watch a movie.

Re: UniFi Express

#178
My goto heuristic is: The slicker the presentation, the worse the actual product is. And this presentation is very slick. :)

Does it hold with this company?

Re: UniFi Express

#179
post #54

Earlier quoted context omitted.

Unifi AP for wifi, Unifi switches, Unifi security gateway of some kind, Unifi point to point for terrestrial wireless to share with another set of Unifi gear in a barn/shed/whatever down the road. All managed by UNMS.

Do the Unifi APs and other Unifi hardware still need a docker image or software installed that includes mongodb I think it was to manage devices?

All their dedicated hardware like APs do but the device in the link (as well as pretty much all their new gateway products - the "Dream" series) have a controller built-in

Re: UniFi Express

#180
post #178

My goto heuristic is: The slicker the presentation, the worse the actual product is. And this presentation is very slick. :) Does it hold with this company?

Fifty fifty.

Their hardware is quite good. Their consumer line (AmpliFi) is Solidly Okay.

From a management perspective, their UniFi system is bar none one of the better solutions for large deployments where you've bought into their whole stack: Routers, switches, Firewalls, APs, everything. There's some things it does OK with other vendors (particularly switches) but it's meant to be managed under their garden.

The nice part is that you can preconfigure hardware, chuck them into a bin, and make it Just Work on the other side. Deploying 100 APs to a new location? Ship 'em direct to the site, they'll just Show Up in the unifi interface. New deployment? Drop a few bits of hardware on a bench, set it up locally, yeet to new location, install the rest, configure over the 'net.

Some people have sworn off them for a lot of papercuts: There's a few points where their UI just Doesn't Work. There's occasional spots where if you preconfigure it manually then try to use the management interface, you might exhaust a DHCP pool in an hour.

But the hardware has, and continues to be, maybe not "cutting edge" but slightly behind it at a price point that makes enterprises salivate and Prosumers go "Hmmm I could probably swing that." And it works for a lot of people.

That isn't to say every product they've put out has been a Banger. The Dream Machine was, at first, very much a mixed bag (and took several YEARS of True Believers really working with Ubiquti to get it right) and this is absolutely them recouping some design loss from their Aplifi Instant product (the case, design, even the screen is Very Similar to it). There's been versions of the controller hardware (and software) that have been... let's put it: Enough to send some people selling all their gear and moving vendors.

Post reply on HN