Earlier quoted context omitted.
Yes, it should. Assuming you're running your unifi controller on a public ipv4 /32 somewhere on the internet (at some commodity VM host), it's entirely up to you how you want to lock down access to it. Some people do leave the TLS1.2 web browser admin control panel login exposed, but on a non standard port, other people set up iptables ACLs to only allow traffic from a certain IP range, other people set it up so that…
>more in favor of having the unifi controller on the same premises as the APs But when your premise is MANY sites across the country, and you are using a single controller, only ONE site gets the controller on prem, OR you have many controllers running. >Big difference between like $700-900/year and $120/year. At the end of the day, it comes down to what my time is worth doing other things (not how much im paid, but…
yes, totally agree, in that sort of scenario with many premises you would set up your own internal L3 management of the APs, in your own management VRF, in RFC1918 IP space.