Live data from Hacker News

Unifi Travel Router

blog.ui.com

281–290 of 437 posts

Re: Unifi Travel Router

#281
post #269

Earlier quoted context omitted.

Sign up for free using Google Sign In. Install the tailscale client on each of your devices. Each device will get an IP address from Tailscale. Think about that like a new LAN address. When you're away from home, you can access your home devices using the Tailscale IP addresses.

So basically wireguard, but you have to pay for it, and you have create an account through Google/Apple/Microsoft/whatever. Wireguard is not that hard to set up manually. If you've added SSH keys to your Github account, it's pretty much the same thing. Find a youtube video or something, and you're good. You might not even need to install a wireguard server yourself, as some routers have that built in (like my Ubiquit…

It's not really "basically wireguard" and you don't have to pay for it for personal use. Wireguard is indeed pretty easy to set up, but basic Wireguard doesn't get you the two most significant features of Tailscale, mesh connections and access controls.

Tailscale does use Wireguard, but it establishes connections between each of your devices, in many cases these will be direct connections even if the devices in question are behind NAT or firewalls. Not every use-case benefits from this over a more traditional hub and spoke VPN model, but for those that do, it would be much more complicated to roll your own version of this. The built-in access controls are also something you could roll your own version of on top of Wireguard, but certainly not as easily as Tailscale makes it.

There's also a third major "feature" that is really just an amalgamation of everything Tailscale builds in and how it's intended to be used, which is that your network works and looks the same even as devices move around if you fully set up your environment to be Tailscale based. Again not everyone needs this, but it can be useful for those that do, and it's not something you get from vanilla Wireguard without additional effort.

Re: Unifi Travel Router

#282

Earlier quoted context omitted.

Same! And the best thing is that you can install Tailscale, so you can connect to your tailnet, and exit all traffic through one of your nodes (e.g., your home/office network). It's incredibly useful, with the added bonus that you don't need to install tailscale client in any of your travel devices (phone, tablet, work computer, etc).

> with the added bonus that you don't need to install tailscale client in any of your travel devices (phone, tablet, work computer, etc). I am sorry, this confuses me. If I don't have a lclient, for example in my laptop, how does my laptop uses Tailscale then? Also, TailScale Personal says 3 users. Is that a problem for as we are 4? (me, wife, son, doughter).

If Tailscale is installed on your router, then any client will also be able to connect to Tailscale networks.

Fo example, if you have a default route back to your home network on the router, any client will also connect through that tunnel back through your home. This assumes you are using your travel router to connect your laptop as opposed to say the hotel wifi. (In this scenario, your travel router is connected to both the hotel wifi as an uplink and Tailscale.)

Re: Unifi Travel Router

#283

Have Ubiquiti/Unifi firmware/devices ever been subject to independent, third-party security testing? Surely a company charging such a premium for high-end devices has invested in such processes and is proud to showcase them ...

As much I love Unifi products I dislike their privacy policy: > Usage Data. We may collect certain information about your devices, your network, your system and third party devices connected to your network or system when you use the Services ("Usage Data"), including but not limited to device data, performance data, sensor data, motion data, temperature data, power usage data, device signals, device parameters, devi…

you can disable it in settings https://help.ui.com/hc/en-us/articles/360042384093-Analytics...

Re: Unifi Travel Router

#284
post #253

Earlier quoted context omitted.

I don't think you need to pay $6 a month to try it out. Install it on all the machines you want. When you are running it on the machine, it is networked to the other machines that are running it. Now make an 'exit node' on one of those machines by selecting it in the UI, and all your gear can access the internet via that exit node. Your phone can run it. Your apple tv can run it. You can have multiple exit nodes. So…

How does it compare to Zerotier? The way I understand it it's kind of overlapping functionality but not necessarily everything. What I want from Zerotier is basically what you described about Tailscale. The two problems I have with zerotier are: 1) It's supposed to let a mobile device like an Android tablet route its traffic through zerotier (functioning as a VPN to my home site, in this case). However, I've never go…

Having tried both Zerotier and Tailscale, I found Tailscale to be a significant improvement. Tailscale uses Wireguard as the base encrypted protocol instead of a semi-homebrew protocol Zerotier came up with that notably lacks things like ephemeral keys/perfect forward secrecy. Tailscale also has a faster pace of improvement and is responsive to customer asks, regularly rolling out new features, improving performance, or fixing bugs. Zerotier by contrast seems to move slower, regularly promising improvements for years that never materialize (e.g. fixing the lack of PFS).

My last gripe is more niche, but I found Zerotier's single threaded performance to be abysmal, making it basically unusable for small single core VMs. My searching at the time suggested this was a known bug, but not one that was fixed before I switched to Tailscale. Not impossible to work around, but also the kind of issue that didn't endear the product to me or inspire confidence.

Re: Unifi Travel Router

#285

Earlier quoted context omitted.

> with the added bonus that you don't need to install tailscale client in any of your travel devices (phone, tablet, work computer, etc). I am sorry, this confuses me. If I don't have a lclient, for example in my laptop, how does my laptop uses Tailscale then? Also, TailScale Personal says 3 users. Is that a problem for as we are 4? (me, wife, son, doughter).

If Tailscale is installed on your router, then any client will also be able to connect to Tailscale networks. Fo example, if you have a default route back to your home network on the router, any client will also connect through that tunnel back through your home. This assumes you are using your travel router to connect your laptop as opposed to say the hotel wifi. (In this scenario, your travel router is connected to…

Oh, got it.

What about the users? Do I need 4 for my family of 4? Or are the 3 users included in the free plan just admin users?

Re: Unifi Travel Router

#286

I never travel without my GL-AXT1800. Saved me so many times: https://www.gl-inet.com/products/gl-axt1800/ I’m actually on it right now.

Same! And the best thing is that you can install Tailscale, so you can connect to your tailnet, and exit all traffic through one of your nodes (e.g., your home/office network). It's incredibly useful, with the added bonus that you don't need to install tailscale client in any of your travel devices (phone, tablet, work computer, etc).

I do want to point out that dumping all of your traffic through a home/office network is not always a good idea. YMMV, but if you are in, say, LA, and pushed your 0.0.0.0 traffic through your home in NY, you just added quite a bit of latency.

This is great for keeping things in a LAN, but make sure you use your network rules correctly and don’t dump everything to your home network unless you need to.

(I too have a gli slate, but I use UI at home so will consider this when it comes out)

Re: Unifi Travel Router

#287

Earlier quoted context omitted.

Have you tried hooking it up to an Ethernet port in a hotel room like the one that the TV uses?

This rarely works. The TV network is usually access controlled, so you either won't get an IP or you simply won't have internet access. Some hotel rooms (particularly older business hotels) will have an ethernet port for the guest. These work maybe 50% of the time these days. Sometimes you can find a Ruckus AP in your room at outlet level, and these usually have several ethernet ports on the bottom. These also have a…

I've read the GL.inet can easily clone the TV Mac, pretty cool.

Re: Unifi Travel Router

#288
When I travel, I like carrying as little as possible. These comments are fascinating to me, people are brining more devices than I have in my whole house and needing to make a LAN for them.

Personally I just connect my phone to WiFi and then use Tailscale and call it a day.

Re: Unifi Travel Router

#289
post #288

When I travel, I like carrying as little as possible. These comments are fascinating to me, people are brining more devices than I have in my whole house and needing to make a LAN for them. Personally I just connect my phone to WiFi and then use Tailscale and call it a day.

Some people spend 100+ days a year in hotels.

Re: Unifi Travel Router

#290

Earlier quoted context omitted.

Same! And the best thing is that you can install Tailscale, so you can connect to your tailnet, and exit all traffic through one of your nodes (e.g., your home/office network). It's incredibly useful, with the added bonus that you don't need to install tailscale client in any of your travel devices (phone, tablet, work computer, etc).

I do want to point out that dumping all of your traffic through a home/office network is not always a good idea. YMMV, but if you are in, say, LA, and pushed your 0.0.0.0 traffic through your home in NY, you just added quite a bit of latency. This is great for keeping things in a LAN, but make sure you use your network rules correctly and don’t dump everything to your home network unless you need to. (I too have a gl…

I disagree. DNS is generally unencrypted and leaking that over whatever open wifi you're on is generally worse from a privacy perspective than the latency you add bouncing through your home where you probably have encrypted DNS setup.

Even if you don't visit any http sites, you never know what might phone home over http, so an OS level VPN provides foolproof privacy at the cost of a tiny bit of latency.

Post reply on HN