[1] https://sfconservancy.org/blog/2019/oct/02/cambium-ubiquiti-...
[2] https://news.ycombinator.com/item?id=9331512
[3] http://web.archive.org/web/20170317174847/http://libertybsd....
[1] https://sfconservancy.org/blog/2019/oct/02/cambium-ubiquiti-...
[2] https://news.ycombinator.com/item?id=9331512
[3] http://web.archive.org/web/20170317174847/http://libertybsd....
Wouldn't at this point a copyright holder (e.g. anyone who contributed to the kernel) + a donation campaign for legal costs be able to force them to either fix it within 30 days, or (once the legal process is over) to indefinitely maintain a patched version of the kernel removing that copyright holder's code?
https://www.mtin.net/blog/ubnt-vs-cambium/
https://www.courtlistener.com/docket/7616021/ubiquiti-networ...
D-Link comes to mind as a similar situation where GPL prevailed. Perhaps in this case nobody cares enough, either way doesn't mean GPL is useless and nobody should care about it.
the Linux Foundation has been notoriously anti-litigation, their corporate masters do not want any litigation at all, and more or less treat Linux as if it was BSD licensed instead of GPL
All kit has security issues but the important thing is how open the manufacturer is about the issues and how quickly they fix them, and Mikrotik have always been very good in this area, regularly releasing updates
Also, as all their devices run the same software, even devices that are years old will still be updated
I often see people saying “Mikrotik is insecure” but this seems to be based solely on the fact that there are published security issues which they have patched. In my opinion that is the opposite of insecure
Agree on the user friendliness though - I use them at home for personal stuff, but for work it is Unifi
I wouldn’t disagree that management ports should probably be locked down out of the box but I would expect anyone reading this to apply some basic lockdown when setting up any device
I just want to offer a counterpoint to an assertion that I often see here claiming they are insecure which I don’t think is justified
Certainly if you are not into networking and want something that just works then Unifi is great, but if you want something with bucketloads more functionality and don’t mind getting your hands dirty then don’t be put off Mikrotik due to security concerns
Only if you have exposed management port to the internet, which you should never do.
The Web UI seems to be a perfect equivalent if you want a GUI to manage your one box at home, and SSH should do the trick for automation. Is there any reason to use their proprietary (Windows-only) software to configure the router?
The user interface is beyond atrocious and even basic features you'd need in smaller/home setup need digging through Wikis to get the arcane settings you need to click. Basic things like NAT loopback or basic VPN setup. OpenVPN is still neutered and broken.
What's even worse - the defaults are all wrong. There's no simple "enable firewall" switch for basic use-cases like other equipment has. Instead you need to manually configure firewall rules in chains like working with raw IP tables and if you do a small misstep, you'll drill a hole in your network easily. Or make your internet horribly slow because you need to be careful about fasstrack rules and lack of NAT acceleration.
It's really about the most disappointing piece of hardware I bought in last few years and doesn't come close to niceness of Ubiquitis management. Sadly it's also the only company that makes a compact router with SFP and PoE+ to power Ubiquities.
ETA:
> What's even worse - the defaults are all wrong.
There is a new-ish thing in the web UI called "QuickSet" for these use cases.
But unfortunately I constantly see those admins recommend them for prosumer, unmanaged small business and home use-cases. In those cases they're horrible to manage and lack features users expect.
>horrible to manage and lack features users expect
Users expect WebUIs, and WebFig is horrible to manage.
MikroTik may well be better for you (I used it for 5km PTP links, but that's because it's cheap, if I had the budget I would've gotten LiteBeam or AirGrid), but that doesn't imply it's a suitable replacement for everyone. And it is most certainly not a suitable replacement of airOS for most people who use airOS.
Anyway, I wouldnt recomend ubiquiti as replacement for microtik. It is just too complex for most home users and even technical users (on the other side I wouldnt use ubiquity even if it is a giveaway).
Managing more than that is crazy with the current software. Not to mention these are some of the cheapest and lowest build quality switches you will find with these insanely powerful features.
Unifi switches are a materially better build quality.
If you want great carrier grade look at Arista. You can even score a 10Gbit 48 port Arista switch off eBay used for about $700 last I checked.
Yes, you can set up simple things with Unifi in a simple way, but the more advanced ones are a tragedy, that you must also google around, dig wikies and forums for arcane incantations of the right json keys, so you can deploy your config in json, there are even no arcane settings to click.
However, the biggest and most major difference between the two lines of products is the requirement of the Controller to run the Unifi line of devices. For that simple fact I would pin the Unifi line as more 'advanced'.
They might share CLI, but that does not mean that your changes persist on USG. You can rely only on whatever you configured in GUI and half-rely on gateway.config.json; for example, they both have dnsmasq and I'm still figuring out how to configure it, so the changes persist. It would be otherwise trivial on edgemax or other pure dnsmasq-using system, like openwrt.
I run my VPN server on a different device, I can understand why you might want to run it in your router, but again this isn’t plug and play trivial networking gear and most administrators will be doing the same as me.
There are many companies selling what you want.
Which administrators? In what environments? Remember, the thread started with someone telling us that Mikrotik is a good replacement for Ubiquiti use-cases. Whose EdgeRouters and USGs have easily configurable VPNs with good defaults.
I'd also love to hear about any alternative products which support SFP for WAN and 802.3at PoE with ease of setup and use as Ubiquiti. Or even a SOHO ASUS router.
No no... It's way worse than that.
Linux / OpenBSD with open source wifi drivers, if that is even a thing. Snatch some Atheros or Realtek chips before they disappear.
https://en.wikipedia.org/wiki/Comparison_of_open-source_wire...
Edit: Also, Turris MOX or Turris Omnia [1] might be an alternative.
The APU works fine but after upgrading to a gigabit connection I’m a bit disappointed. It won’t saturate the connection on a single thread. (Yes over Ethernet) Maybe 400 Mbps max. Apparently it has something to do with pfSense not multithreading connections and the single cores of the CPU not being fast enough on their own. I can run 1 Gbps over multiple connections though so I suppose it mostly fulfills it’s purpose. I also want a WireGuard server but I might end up just deploying that in a VM. pfSense doesn’t currently have that option.
When I learned of these limitations I gave some consideration to the the Ubiquiti USG but found it isn’t exactly super beefy either and requires turning features off to get 1 Gbps. I’m debating building something similar to the ArsTechnica guide [0].
Overall, I’ve been satisfied with my setup and in particular the UAPs. I’ve deployed multiple UAPs and Edgerouter X’s at friends and family’s houses and have had essentially 0 support requests. The stuff just works and performs. I just had a party last night and even with 20+ clients, streaming music and YouTube TV for football, I had zero complaints or hiccups. All on a single UAP. I haven’t used any recent consumer gear but I know e consumer gear I used to buy would have definitely been choking on that kind of load.
I’m pretty disappointed to see this turn in events with UBNT. I’ve kinda seen it coming for awhile now since they’ve been moving towards these cloud services but I was really hoping they would resist the lures of Surveillance Capitalism.
[0] https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-bui...
[0]: https://teklager.se/en/products/routers/
[1]: https://teklager.se/en/products/routers/tlsense-i5-4lan
Edit: I noticed those thanks to link on PCEngines site, which is quite also amazing, knowing a fact TekLager and PCEngines are direct competitors.
[0]: https://teklager.se/en/knowledge-base/apu2c0-ipfire-throughp...
[1]: https://teklager.se/en/knowledge-base/apu2-1-gigabit-through...
Anyway, one of the GGP's (great grandparent's) links indicate the software freedom conservatory did open a lawsuit just last month. https://sfconservancy.org/blog/2019/oct/02/cambium-ubiquiti-...
that's a letter, not a lawsuit. not yet, anyway.