How Brocade missed the boat with Vyatta (2014)
dotbalm.org
dotbalm.org
Unlike Vyatta it lacks a strong command line management console but more than makes up for it with a best in class web GUI.
Unfortunately though Pfsense took a huge step backwards with its founder CMB moving over to Ubiquity to work on proprietary software/hardware. Hopefully Netgate the corporation behind the hardware and software for Pfsense will keep development moving forward without the founder.
[1] https://vyos.io/
I submitted a pull request this week, and they reviewed it within hours with informative feedback.
The most recent major release overhauled their UI to use bootstrap, which has enhanced usability. They plan a REST API in the next major version.
They've been presenting new work on L3 routing over netnap ("extremely fast and efficient packet I/O for both userspace and kernel clients") which can reach line rate on 10GB networks.
https://github.com/Netgate/netmap-fwd/blob/master/netmap-fwd...
I understand the concerns about loosing someone as talented as CMB, but the others at Netgate appear to be engaging, open and very talented.
There are any number of open source router distributions using kernel-based forwarding (e.g. not fast enough for high PPS/limited utility in carrier environments). When it was introduced Vyatta was trying to sell hardware to compete with Cisco branch/ISR routers using the FOSS & make money on hardware+services model. Thing is Cisco ISRs integrate a lot more than routing (to the point of being a branch office in a box) so there wasn't a ton of demand for pricy commodity hardware. Imagestream was another vendor trying to complete on that model that has faded.
Around that time NFV became the new hotness (moving services like NAT, VPN, firewall to VMs so big expensive routers can focus on just moving traffic). Now, kernel-based forwarding routers are glass cannons. They can achieve high data rates with large packet sizes but tend to fall over when exposed to high rates of small packets like you'd find in VoIP or DoS traffic. This limits their usefulness in environments where you need to handle and block a lot of bad traffic. Brocade acquires Vyatta and reworks it to use DPDK (userland forwarding) so it doesn't fall over. They aren't the only one: Juniper has vMX, Alcatel-Lucent has VSR. All router products designed to fit into a pretty specific niche--one where not selling hardware is the niche.
e.g. pfSense has Radius support, but no way to link users with firewall rules. IPsec cannot assign a unique IP address to an authenticated user, so it's not possible to use host-based firewall rules. One use case is to provide different groups of users with access to isolated networks or subsets of the public internet.
It's cheap hardware for small business. It isn't anywhere close to the level of quality required for a datacenter and it lacks basic features/protocol.
War story: If we change the wifi password, all our ubiquiti access point will reboot and the wifi will be unavailable for the next 10-30 minutes :D
"War story: If we change the wifi password, all our ubiquiti access point will reboot and the wifi will be unavailable for the next 10-30 minutes :D"
This is how it used to be. When I update firmware, all our Apps don't go down at once, they go down sequentially, one at a time.
I've never seen a reboot to change an SSID password.
I'd have a doubt about these features for instances: 802.1x, some VLAN stuff, rate limiting/traffic shaping, ACL, OSPF, BGP, LCAP.
And even if they're adversited as "present" in the datasheet, that doesn't necessarily mean that they are fully functional. Plus there is no CLI for the configuration.
---
"I've never seen a reboot to change an SSID password."
I've never seen that except with ubiquiti. And I guarantee you that ALL access points do reboot at the same time. To add to the pain, they take > 10 minutes to come back online so it's really painful.
There's no CLI for configuration? You really haven't done much research - there absolutely is, based off Vyatta/VyOS/JunOS.
In fact, most of the "advanced" functionality is CLI-only.
I use: VLANs, traffic shaping, ACLs, LACP. RIP and OSPF is supported but I don't use. 802.1x and BGP are not.
They're good solid devices, and excellent value.
The EdgeRouter line is probably more powerful - it's a full VyattaOS underneath.
The Unifi line is meant to be cloud-managed from a central web dashboard - it's...getting there. Still missing functionality - you can always drop to a shell and do things manually as it's also based on VyattaOS, but if you want full GUI control, you may want to stick to EdgeRouter for now (unless you don't mind tinkering with JSON files). However, it does give you a single pane view across all your APs, switches, routers etc.