Is there a better alternative? When I tested multiple routers mostly regarding low latency, network stability and reliability a few years ago nothing came close, especially when having multiple access points.
Is there a better alternative? When I tested multiple routers mostly regarding low latency, network stability and reliability a few years ago nothing came close, especially when having multiple access points.
My primary use case for their gear at home was to have a router that can handle a LACP WAN bond for my fancy cable modem as well as connecting to a 10G Ethernet switch via copper or direct-attached SFP+ to a CRS-305 10G switch. Their RB-4011 was a perfect fit, without any of the Ubiquiti SSO/controller stuff to worry about.
I haven’t explored their WiFi products yet (still using an old router as an AP) but their product range is pretty broad. Might look into it this year though.
Also interested in what access points (besides unifi) people pair with mikrotik routers. Any wifi 6 recommendations?
If you just need one AP you can set it up in standalone mode and forget about it. If you want more monitoring and control you'll need to have a Ubiquiti controller running to manage things. (can run one in docker, on a rasp pi, or just buy their "Cloud Key" product.)
unless you need any feature besides wifi at all. then you need a controller and usg at all times.
I’m still looking for a proper WiFi 6 replacement that can hook up to my 10G core, ideally via 2.5/5/10G copper or preferably SFP+ DAC. Nothing’s jumped out at me yet though.
I've had a UAP AC LR at home for a few years and we've got about 6 UAP AC HD at work. We used the phone app to provision and after that you can pretty much forget about it. Great for small startups that want great coverage and dont have someone who's supposed to mess around with it.
Up until around a year ago I was on adsl2 with a highly symmetrical connection. I work from home mostly as does my partner, with constant syncing to various cloud services plus large uploads and downloads for work.
Maxing out the puny 1Mb of upload would render the entire connection completely unusable. Yes, you can manually limit various apps but it so much easier just to throw an edgerouter x in front of everything running stock smart queue or cake.
I'm on a faster connection now so uploads are not so much an issue, but even still it works a treat for things like gaming / VOIP.
On my previous ISP latency would reach 2000+ ms when I let Dropbox sync or downloaded a huge file. Even web browsing would time out. I used Tomato to prioritize DNS, my VoIP analog telephone adapter, the first 256KB of any HTTP(S) connection, and some 27000+ ports used by games.
My current WAN connection reaches 300 ms without fq_codel enabled. With it enabled there's no jump in latency.
Because there are so many features the setup is not as easy as some alternatives I'm sure. But the value proposition is great.
Their "RouterOS" is standardised over pretty much all of their kit. So after you have worked it out once you should be set for anything else.
At this point there are probably 20+ home Unifi networks that i'm responsible for recommending or setting up, doing the same with MikroTik might turn me into a full time sysadmin :)
> RB-4011 was a perfect fit
Huh, isn't RB4011 the one with the very weird "you can't use a DAC in the SFP+ port" limitation?
> haven’t explored their WiFi products yet
They seem extremely underwhelming, especially in terms of software support :(
https://help.mikrotik.com/docs/display/ROS/WifiWave2 — they're finally barely rolling out WPA3, MU-MIMO/beamforming, 802.11w — in an optional beta package for a beta version of the OS, currently on 4 devices, breaking 2.4ghz on one of them, and breaking CAPsMAN (centralized management).
Thanks for the update on the WiFi side of things. Seems likely that I’ll be looking to another vendor for APs, but that’s fine.
That said, my next router/gateway won't be from Ubiquiti. Though I'll keep using UI access points for now.
[0] https://help.ui.com/hc/en-us/articles/115001529267-UniFi-Man...
[1] https://help.ui.com/hc/en-us/articles/115012664088-UniFi-Int...
Check https://mikrotik.com/software for some demos and stuff.
I'm still using Wi-Fi 5 because it's fast enough and cheaper. My central AP is a IAP-315, an IAP-305 in the garage, and another IAP-305 at the wall by the back yard. They're all PoE and linked with wired backbone to form a single big coverage area using a single elected IAP leader as controller for the rest.
You shouldn't have trouble buying grey-market ones as long as you are careful to stick to the same regulatory domain for all of them. Aruba gear is available as USA/FCC, Japan, Israel, and RW (Rest of World) versions. I have operated RW units in FCC territory (proooobably legally but probably not worth the risk) by setting them to "US Virgin Islands" so they match FCC-allowed frequencies and power limits, but linking more than one AP still requires the hardware to be same regulatory domain.
For mad scientists though, the very open software stack is a good friend to have when 11th hour Requirements® dictate you must produce a rabbit without a hat, or rewrite your own domain-specific implementation to replace the Avahi service.
No experience with Mikrotic.
_On topic_: With cloud news like this, it's nice to know about the availability of Ubiquitis' Network Management System[1] which you can host and run wherever.
[1]: https://unms.com/
Also RouterOS does not seem open source.
WireGuard isn’t supported on RouterOS 6, which is the current stable version, afaik. RouterOS 7 (currently available in beta) did support for WG in August though, as part of 7.1beta2 [1].
[1] https://mikrotik.com/download/changelogs/development-release...
It's great hardware but I'm no personal fan of RouterOS.
However, MikroTik seem to be making slow but steady progress with new features. Stability is still an issue to an extent, but for home use I could almost make the jump.
In fact, if I didn't use CAPsMAN to centrally control the multiple access points in my home, I would make the jump purely for fq_codel/cake AQM, Wireguard and WPA3.
Replace the US-24-250W PoE switch with an Aruba Networks S2500-24P (gigabit and PoE, 4x 10gig ports, quiet).
Replace the Cloud Key Gen 2 with BlueIris for camera controller. I expect this will be able to connect to the existing Ubiquiti cameras.
Possibly add one or more Ruckus R610 APs running in "Unleashed" mode to augment my Google WiFi. I'm happy with the Google WiFi, and in particular it has good tools for managing kids access to WiFi. But the Ruckus APs are quite good and so I may move parent and IoT access over to Ruckus, separate out IoT devices to their own network.
This is the end of phase 1. Then I plan to go on to:
Add an OPN-Sense router. Currently not using Ubiquiti for routing, the Google WiFi is our main router. Would like to gain additional capabilities like insight into what the kids are doing.
Replace the Ubiquiti Dome G3 with one of the less expensive 4K cameras if they seem to provide similar or better functionality. Also trying out the Wyse Cam v3, which seems ok and the price sure is right, but is more of an augment camera than a main camera, I prefer wired and PoE.
I've been doing some research and those are the options that seem attractive. In particular, going with old enterprise gear looks to be a huge win. You do lose that handy "single pane of glass" management. But considering the problems I'm having with Ubiquiti, and the upgrades I've already done to try to get past them, with only some success, I can't bring myself to go further in on Ubiquiti.
Can you get free firmware updates from Aruba or do you need a support contract?
Similarly for the Ruckus R610 AP I mentioned: Those APs were a grand new, but you can get them for a bit over $100 on ebay. Linus Tech Tips did a comparison of it with other consumer units, doing heavy multi-device streaming, and Ruckus was the clear winner.
Yes, Ubiquiti looks like a good value and they make some very interesting products. I've used some of them to great effect over the years. But my experience with the NVR and cameras and switch and Cloud Key has been relatively bumpy. Enough so that I'm ready to ditch the convenience for up-front loading and hopefully day-to-day more realible.
Have you looked at the power consumption of the switch? I've run some enterprise gear at home in the past (my favorite was the E-450 Sun server which an ex-employer gave me for free), but when I started paying for my own power, I found that even if the hardware is free, the power consumption makes it expensive.
Most recent version is a couple years old, but it was EOLed 3 years ago.
Ruckus firmware seems to be downloadable from their main product page for the R610, updated a month ago.
Re power consumption, it looks like the Aruba pulls around 50W idle, and the Ubiquiti pulls 29W idle. Of course, if I can get rid of the second switch I've been running because the Ubiquiti keeps blocking the Google WiFi ports, that brings it even closer. :-)
With a male/male extension: http://amzn.com/B00QM8ZP5E
My current one I've nicknamed a "Pirate" R232 adapter because it has an unfortunate and hilarious effect of duplicate the lowercase 'r' character for some reason (so I see Arrrrrrrrchlinux).
I mostly administer via SSH so it's all good at the moment.
I don't usually run any services since I prefer to dedicate boxes to things, but I have in the past run a number of services, including minecraft and minetest on it and it flies. Really pleased with it.
There's Xeoma and Blue Cherry, neither of which I know very much about. Never heard anyone mention either of them. So I figured BlueIris was what I'd try. Seems to be what everyone on YouTube is using...
The other reason I decided to 'roll my own' was an in-line IDS. There seem to be 'hacky' ways to get Snort installed on the RouterOS platform, but the CPUs aren't really powerful enough to run DPI with a sufficiently large ruleset.
I also like the ability to use Ansible to manage my router/firewall. There are modules available to do this with RouterOS, but they don't seem nearly as robust and mature as the built-in Linux utilities.
I've had whatever routers before, but mostly when using some VPN to hide the traffic from your home network, and if having fast enough internet, a good CPU is a must.
Outside that, wifi part is hard to get right and smart switches are nice to have, but they are PITA if the firmware is never updated and there's no single place to nicely manage it all.
I don't think the distro was ever security audited.
Do you have some better suggestions for the router software? I'd love to run Opnsense, but a native Wireguard client is a must, and so is a good web interface for the setup.
These are available from Europe, but I've heard good things from US about similar boxes, when I searched with "best pfsense computer". Not the same brand, but similar hardware.
https://www.amazon.de/gp/product/B08JHKZMTN/ref=ppx_yo_dt_b_...
Let's see how it works, but I expect it to be much faster than my current ARMv7 box. Of course if you have space for a rack, go with something actively cooled. In our apartment, we expect the router to not make any noise.
That said, it also says 'Pfsense', so I suppose more likely it's a typical 'Chinesium' listing.
The current ARMv7 I have goes to about 100 degrees Celsius and loads in the level of 4 to 6 when downloading a bunch of data full speed.
https://www.raspberrypi.org/products/compute-module-4/?varia...
https://www.zahradnik.io/raspberry-pi-as-a-home-router
Edit: You would be better served by other boards from this benchmark repo for vpn usage: https://github.com/ThomasKaiser/sbc-bench/blob/master/Result...
While a Raspberry Pi might work for some folks, it's worth noting that these are two very different performance classes.
Ethernet adapter and USB speeds seem less than ideal.
It's definitely not for people like OP but may work for other people who don't want to pay much and still have something decent that they can hack themselves.
I have tried to flash open firmware on my router before but it didn't work out. I had a raspberry pi already so I decided to convert it into a router and use it.
I'm seriously thinking about pfSense or Opnsense, but FreeBSD still misses native Wireguard support, leaving the encryption to the go implementation, which is subpar for our use cases. But, I'd be happy to run Opnsense, with jails and all those goodies from FreeBSD.
You were probably thinking of OpenVPN? Wireguard is not based on AES and thus has no use for AES-NI.
The cons are that everything has one or more "mikrotik" way of doing things, and it may not be intuitive to the new user. Also, although everything is included, you have to set it all up yourself.
They’re still sending out the email. Mail chip will be rate-limiting the send rate to prevent email providers from block listing them.
Give it a couple of hours and no doubt you’ll have an email as well.
-edit- I just received it at 2:42 pm pst
Make sure you turn off Remote access in your device.
Probably can leave on local login (w/Ubiquiti acct) but should turn on 2FA
You do need a Ubiquiti account to setup the hardware in the first place, but you can turn off cloud access and login locally after that. And you should.
> can't see why disabling cloud login is a problem
:)
I do agree it is a big limitation, and I am looking for alternatives as Ubiquiti do not seem to be prioritizing getting their app to work without remote login which is truly unfortunate, since the predecessor, UniFi Video, supported this.
When it comes to software, I'm conflicted. I like pfsense, but Netgate has gone a bit sour with the FLOSS community. I'd also consider OpenWRT, FreeBSD, OpenBSD.
I had to do some work to get it to boot properly, and it worked great for a year or so, but then it just died one day, and I could never figure out what its problem was.
Out of warranty by the dead date, never bought another.
Been using a $100 HP 8300 SFF with an i7 since, it's a bit overkill, but the price was right.
Just purchased a Lenovo M90n iot when it was on sale for $215, will see how it works out once I get it.
I haven't kept up with pfsense. Any chance for a tl;dr?
I think for some use cases this setup could be a nice alternative (and cheaper) to ubiquiti.
This is not a common use case, I was not interested in high bandwidth. I did try to disable beamforming and all other fireworks when testing though (but did tests with default settings too)
Honestly, unifi is great for what it is. What kind of IPS do you expect for $100?
If you want less risk, you need to move up the $ ladder.
The only issue I have with Netgate is pricing!
We are just as susceptible to the stuff haha.
So basically all you need to do is plug a laptop into a non-Unifi switch on someone's Unifi network and are able to breach the firewall.
Needless to say I was flabbergasted at the vendor lock-in strategy worse than Apple, and asked for a refund. Thankfully they complied.
I now have a hand-rolled OPNsense router that does everything I need, and with MUCH more configurability.
As another comment said, your strategy about breaching the firewall is confusing but it sounds like a configuration issue. If your aim is to default deny outbound traffic, or traffic from or across the LANs except for approved devices, that’s an achievable aim regardless of what switches are in the mix. If you’re trying to do port level security, you’d need a managed switch, Ubiquiti or no.
You had unmanaged switches on your network, and were trying to manage thier downstream connections?
What exactly do you mean by 'breach the firewall'?
There is no way to identify any clients on your network that are either behind the switch or behind the airport (even in bridged mode). I would expect at least some list of clients based on DHCP leases or the ARP table, but they are not accessible through the UI.
I have a robotic vacuum from china, and i want to stop it from calling home. There's isn't even a way to find out the IP or what traffic it's sending through the UDM pro, and no way to set blocking rules from the UI.
I understand if they want to provide wifi mesh support and other special wifi features for unifi devices only, but the supposed "enterprise grade" router and FW functionality should support standard network setups, since all traffic goes through the UDM-Pro, and it is certainly aware of the clients since it gave them DHCP leases, and they are in the ARP table (which is only accesible through the SSH command line) and are on the same subnet. It's unacceptable in my opinion.
The default logging may not capture the individual child clients, depending on your configuration (eg double nat), sure... but those child clients are still entirely at the mercy of your configuration otherwise. Saying that the clients are completely invisible/invincible, and that the fault is the Ubiquiti product, is not true.
Furthermore I didn't say they were invincible. I just said they were invisible to the UDM-Pro's UI. Unless you have a blanket ban on outgoing LAN traffic, which would be absurd, there's no way to block access for a particular client or a particular destination address for that client.
In the case I gave, a Chinese robot vacuum with no on-device interface, please tell me how to find the IP of this robot, then block outgoing traffic from it, without SSH'ing into the UDM and running scripts. That's right, you can't, because the UDM-Pro doesn't support it.
> Unless you have a blanket ban on outgoing LAN traffic, which would be absurd, there's no way to block access for a particular client or a particular destination address for that client.
To the contrary; this is exactly what you should be doing. Isolated subnet for these untrusted devices. Block by default. (Whitelist only)
I used the word invisible to describe it missing in the ui. I used the word invincible to describe your lack of “management” (ie; blocking) of the device.
What I am trying to suggest, however, is that the UDM is likely not the root cause of these issues. I certainly don’t mean to suggest they are the best. The lack of compatibility of features between their product lines is a nightmare.
Could you elaborate a bit more about your previous network setup? This sounds awful.