I'd actually originally (and still at many sites) intended to hold off and wait for WiFi 7 gear, because at that point a bunch of clients (and myself for that matter) will be interested in replacing WAPs anyway which is a very natural point to consider changing manufacturer as well. But a breaking point has come at a few places with a final feature which is PPSK, allowing the system to have many different passwords for an SSID that can be assigned different tags. Basically it allows having many of the benefits of WPA-Enterprise in terms of segmenting different clients onto different VLANs and revoking credentials and the like with more security and less manual work than MAB (MAC bypass) while still looking like a normal PSK scheme, which means the vast universe of brand new stuff which doesn't support 802.1x and never will works with it happily (by the same token none of that is going to play directly with using a secure virtual network or other better systems either sadly). Lower overhead and better compatibility than captive portals for non or semi-interactive devices as well. Someone hacked together a demo showing this could work on UniFi WAPs like four freaking years ago and Ubiquiti never did anything with it in favor of endless bikeshedding GUI changes to add more white space and hide important features and information (yes I'm a touch bitter).
So I'm not in the position of wholeheartedly recommending Omada yet, I don't have years under my belt there and it's relatively speaking fairly new. It has its own warts and rough edges for sure, from the software to the hardware physical design. But it can be self-hosted and the trajectory looks massively better, has already had more meaningful improvement in months than UniFi has had in years, seems to perform much better so far as well.
Of course the Venn diagram of self-hosting, herding lots of hardware with single pane, fully networking features, ecosystem richness and so on is pretty minimal in the overlap. Take away any one or multiple of those and options expand a lot, Aruba InstantOn for example.
And welp, this didn't end up "basically" at all did it, sorry about that. I am bummed by the sheer wasted potential with Ubiquiti. So it goes in tech over and over again though, we've all seen this movie many, many times.
As far as tips, I would suggest if you plan to stay on the managing-your-own-networks route to very strongly consider having the router/gateway stuff be separate and fully open source as I ended up. Doesn't have to be OPNsense, could be VyOS or plain OpenBSD or whatever else you're most comfortable with and depending on how you want to manage stuff and what needs there are for others to take over. But it's very, very pleasant to have the full spectrum of quality PC hardware available, you can get far more power for less, and you're never stuck with a critical aspect. I'd still suggest generally running that on metal rather than virtualizing it in a (semi)production network, but opinions vary there.
----
I've also soured on UniFi a lot over the last few years. It's crazy. The SMB / MSP market is massively underserved and instead of staying focused and capturing it Unifi is trying to compete in the enterprise market where, IMHO, they aren't going to succeed.
If we try out Omada and feel like it gives us everything Unifi does without all the feature creep then we'll do the same thing as you; EoL sites will move from Unifi to Omada. I'll always take fewer features and stability over continuous new features.
> I would suggest if you plan to stay on the managing-your-own-networks route to very strongly consider having the router/gateway stuff be separate and fully open source as I ended up.
We've used pfSense forever and have been happy with it. However, 2.6.0 has some gateway/dpinger issues where the bug fixes are slotted for 2.7.0 on the CE side, so it feels like the inevitable neglect of the CE version might be starting to kick in there. I tried to explain to them the realities of the market we're in (small businesses) along with real numbers in terms of what kind of money they could extract from businesses like ours and all it got me was an offer to talk to someone in sales and we're not buying into subscriptions (ever).
It would cost us $15k+ / year to switch to pfSense+. The software only subscription is nearly 2x the cost of buying their entry level appliance (assuming a 5 year lifecycle). IMHO, that's an indicator they don't want to support 3rd party hardware and there's a risk they'll eventually drop it.
I wish VyOS had less crazy pricing because their stuff looks nice. They used to have a $600 / year professional subscription which they don't appear to offer anymore. I think the corporate subscription used to be <$4k / year and now it's $6k. I wonder why no one wants to commit to subscriptions. How can I sell anything to a customer when I can't give a predictable price for ongoing maintenance a year into the future?
Our customers will literally go back to using their ISP supplied modems instead of proper firewalls before they'll pay the prices everyone is asking for. I don't blame them either. They only need a fraction of the functionality being sold and all of the fancy, expensive features everyone is using to justify sky high pricing are simply bad value in that context because they'll basically unneeded bloat.
No problem, glad to chat about this and commiserate a bit with someone in a similar boat.
>I've also soured on UniFi a lot over the last few years. It's crazy. The SMB / MSP market is massively underserved and instead of staying focused and capturing it Unifi is trying to compete in the enterprise market where, IMHO, they aren't going to succeed.
Yeah, it's such a huge waste. But the CEO is a classic trouble case with near total control (owns majority of the stock and thus effectively owns the board, a few caveats in terms of protection for minority shareholders in public companies don't really stop the trend).
>If we try out Omada and feel like it gives us everything Unifi does without all the feature creep then we'll do the same thing as you; EoL sites will move from Unifi to Omada. I'll always take fewer features and stability over continuous new features.
UniFi hasn't even had "continuous new features" though! Or rather, their "features" have been stuff like reskinning the GUI or doing their own entire custom silly speedtest stack for a while, not "features" like PPSK, or for that matter just having normal DHCP and DNS management! Or any sort of certificate management or customization, or, like, anything of substance. Or on hardware, they didn't even bother to upgrade their UniFi Security Gateways literally ever, not once! The ones still selling now are the exact same hardware as 2014 launch, no new updates in forever. They intro new stuff without ever sunsetting older stuff in general really. Use "EA" as a popularity poll test. The dysfunction goes on and on.
I don't know if Omada will be the answer yet but worth a spin IMO. I'd definitely hate having to either go back to lots of individual management or something cloud-based. I am stick with UI for PtP/PtMP stuff for the time being though, even if some rot is creeping in there too.
>We've used pfSense forever and have been happy with it. However, 2.6.0 has some gateway/dpinger issues where the bug fixes are slotted for 2.7.0 on the CE side, so it feels like the inevitable neglect of the CE version might be starting to kick in there.
I'm afraid that company has a history of scummy behavior too :(. I think OPNsense is just plain better but ymmv. FWIW, while it's OSS there is at least one company (Deciso) that does a "Business Edition" at a relatively sane rate (~$150/yr, less for a 3 year) with no hardware reqs (they sell hardware too but I don't suggest getting it) and does business support contracts as well. And Sunny Valley Networks does an interesting little layer 7 inspector that can plugin to it. It conversely might not be good enough for your needs either, but it's not crazy. And the free version is still quite solid. As I said in another comment the docs are pretty decent so might be worth giving them a glance and firing up a system in a VM.
At any rate my clients are happy now. And despite rough edges I'm grateful there are a number of essentially decent options available.
But basically Ubiquiti has become a toxic dumpster fire of a company and their product lines (UniFi in particular) on a downward trajectory in terms of performance, features and stability for quite a while.
I can't remember a time when Ubiquiti wasn't a dumpster fire. They've always seemed like the MongoDB of network hardware. For basic stuff it was okay, but "advanced" features like RADIUS, hardware acceleration, etc. never worked well. Their stuff's worked okay enough for me in the past, but it's really flared up with Sonic's 10G gear. But it's very, very pleasant to have the full spectrum of quality PC hardware available, you can get far more power for less, and you're never stuck with a critical aspect.
Gotta disagree here. I went with Ubiquiti because I wanted purpose built network hardware. COTS hardware tends to be more expensive and power hungry. I'm cautiously optimistic about the new Marvell (ex-Cavium) stuff but it sounds like Mikrotik is having a hell of a time with that too.The big problem is that homelab/SOHO folks (myself included) don't want to pay the upfront cost of supporting or developing/testing modern hardware. At the price point Ubiquiti is targeting I think any entrant will be doomed to failure.
4-6 years ago things still looked quite promising, high energy great community and forums (gone now), a basic but workable issue/feature tracker (gone), lots of clearly talented engineers who were responsive and right there (gone), etc. Very good price/performance, quality and so on particularly compared to other stuff of the time. There was a reason it got a lot of recommendations. That was certainly a while ago now though.
They've always seemed like the MongoDB of network hardware.
Eh. Though a grim bit of irony is how old a version of MongoDB they've stuck on too amongst other things.
>COTS hardware tends to be more expensive and power hungry
Not enough to me to matter I guess. For applications like this one can find solid low power hardware, Xeon-Ds for example, that consume tens of watts at max load and idle plenty low. Or truly embedded stuff a single digits. There are enormous floods of stuff available that is a few years old for dimes or even pennies on the dollar. I replaced all my USG-4Ps with a few years old Supermicro Xeon-D front-network port systems I got for around $350. An extra 20W 24/7/365 is something like $20-30/year, for a device this important that's well worth it to me. And there's no comparison, it's a slaughter. Real systems have actual BMC/IPMI which is super handy if things go wrong. The performance is just ludicrously higher. It's trivial to have more RAM, the system runs off of mirrored ZFS drives I can count on, it can do HA, etc etc. All the normal tools are available.
I'd even take an old Celeron or Atom system over a USG though. Even without going to second hand market, something like Protectli's basic J3060 based FW2B would still be better IMO and has a max power of 12W, fanless. "Purpose built network hardware" doesn't mean much, hardware vlan filtering or offload for CRC/LRO/TSO are something a decent NIC can do, or even plenty of built-in stuff.
As for Ubiquiti, I remember them thumbing their noses at the GPL and introducing security bugs in u-boot or having no idea how to fix the issues with RADIUS. They had no clue how to work around Cavium bugs (or get support from Cavium). I remember a company that shipped products based on a lightly skinned Vyatta using an end-of-life'd version of Debian (note that Debian ended support specifically for MIPS). I remember a company that shipped products (ER-X, ER-L) that ran hot enough to reliably cook themselves. And, yeah, Mongo. It was just a mess top-to-bottom.
This is very true. However if you bypass the Dream Machine and just use some other router or an EdgeRouter it’s ridiculously reliable in the home setting.
There are a heap of nice features in the UDM line, but wow does it need polish and stability.
My wifi is the best I’ve every used by a million miles, but the UDMP crashes and has weird behaviour that requires heroics to repair.