UniFi Express
ui.com
ui.com
> UniFi Express supports up to 5 connected UniFi Network devices, including other UniFi Express units, switches, and WiFi access points.
Even my home has one AP per floor (3x) and 3x Unifi switches. This is clearly an artificial limitation for market segmentation reasons. I'm not going to rip out Unifi switches to go unmanaged, just for the pleasure of using Express. Hopefully nobody buys it without reading the small print.
I feel like the lack of Protect and the 5 UniFi device limit are going to really limit who will buy this even at this price.
What does that even mean?
That it bundles a controller that is not "capable" of handling more than 5 unifi devices? Who comes up with shit like that? Lets punish people that get too dependent on us and tries to buy too many devices. Let's squeeze some more out of them and risk them switching to a competitor instead rather than build a relationship with us.
I've been worried about the future of unifi for my needs. The USG was a good deal. A bit slow (not gbit in routing but decent enough for most, not great VPN performance) but we have been waiting for an upgrade that surely was just around the corner for well over 6 years now YIKES! Feels like it has been out of stock for many years as well so hard to get replacements. The power bricks are starting to die, easy enough to get third party for that but feels like a dead end.
The nicer units are just overkill for most, and are quite hard to justify the cost. The ones targeted for the home do too much.
And just like that, I've missed the replacment(?!): UXG-lite
https://eu.store.ui.com/eu/en/pro/category/all-cloud-keys-ga...
First glance, seems like it is a direct replacement, perfect! Exact same thing but newer and faster. And you get to host your own controller, that is a relief.
These are cheap enough that you can recommend your immediate family to get and then manage centrally in your own network.
Need to do some more research but for once I'm hopeful about ui.
And then they'll be pissed off because it doesn't "do" what they want it to.
This thing is designed for what 95% of household's need. A router and one or two WAPs. That's really it.
The controller should really be off board, or the on-board controller should be tuned to communicate less with the devices it s and write significantly less often to storage.
What I miss the most in their offering is an affordable 6e AP though.
We live in times where lawn movers need wifi.
isn’t that typically the implicit message being sent by disgruntled customers complaining about a company’s seeming lack of foresight or excess of greed, or both?
Unless all the walls in your house are heavily reinforced concrete, I don't see how you need that many APs.
This kind of setup is easily achievable with UniFI POE gear, but will hit the 5 device limit of this router. The original USG didn’t have this limit.
Having one AP per floor is normal for coverage, so that would be 4 to serve the inside.
And even in a brick house a lot of the interior walls are still just plywood or drywall, even in the UK AFAIK.
What is interesting though is that OP said it is sufficient with one AP per floor plus one outside. So apparently propagation within one floor is fine, but between floors or to the exterior is not. In that case, it has to be a building where the interior walls are mostly just drywall, and the exterior walls and floor slabs are reinforced concrete with little in terms of openings. Which sounds more like an apartment building than anything else?
[1] https://www.nist.gov/publications/electromagnetic-signal-att...
We’ve got 3 UniFi APs downstairs here, 2 up. There are still things on the periphery that only just cling on, and when you’ve got stuff like that it takes a lot of airtime.
I have a pretty large house and I would be fine with this - I have three AP's and a 48 port PoE switch for the 36 drops in my house.
The limitation is totally product segmentation, since their prosumer equivalent all in one (the UDR) costs double, but that's fine, I feel. It's not like they're raising the price of the existing offerings because this budget model exists.
I'm not sure what are you trying to say with this - yes, obviously, people who don't buy extra APs don't have extra APs, but why are they relevant to conversation about UniFi prosumer products?
It's not like UniFi customer base is a person who doesn't use anything outside their ISP equpiment.
UniFi has way more options to play around with and functionary rich so I $149 seems quite decently priced.
https://ui.com/microsite/static/media/use-case-2.fd99bcc2.jp...
So I guess each one of those devices can manage 5 unifi devices, going only by the image it looks like in their setup there is one AP for each device (if that is how the ui works).
For example, a networked device in a conference room might require access to VLANs designated for both guest internet and internal company resources. In this case, the port would be configured as a 'trunk' port, allowing traffic from multiple VLANs (each identified by a unique tag) to pass through. This setup ensures that the device can communicate across different departmental or functional network segments, such as VLANs for e.g. IT, Marketing, or Sales, etc.
Using VLANs over physical LANs or different subnets is fundamentally about enhancing network management efficiency and flexibility. The core advantage of VLANs is that they allow network administrators to segment and manage the network logically without the need for physical rearrangements. This means an engineer can configure and reconfigure network segments without the need to physically move cables or hardware (or even be on-site).
Even if there are 20 departments, a development, testing/qa, and production server environment, phones, printers, 12 conference rooms, a dmz, an IoT, staff, and guest wifi, backups on their own vlan, a management vlan, and multiple vpns, you would still come under 50 with a few more to spare.
If you have a network like this it might also behoove you to physically separate it out so guest infrastructure and production, and management interfaces are all on completely different devices and thus each network doesn’t need all vlans.
Unifi doesn’t sell the highest quality of equipment that could necessarily support more complex environments in the first place but needing more than 50 vlans on one physical network sounds almost unsustainable.
> limit on their top of line stuff
AFAIK, the limits are 64 VLANs for USG/UDM and 255 on US/USW. Not a tiny prosumer routers here.
It only runs UniFi Network, so you have to buy more things, that also run UniFi Network, to get into any of their other products like Protect.
I like their stuff but lately a lot of their stuff feels just confused to me, like they don't know what they want to be.
... And I haven't upgraded anything since. Their new products are totally undirected, they aren't making items that are obvious and needed. Their software is falling behind and they just don't care.
Case in point: the usg pro 4 is years old but they havent released an updated affordable just-the-border device. Their new stuff like the dream machine, and now this, just isn't the right thing to replace what was there before. The VPN on there doesn't work with recent Android or iPhone, and they just don't care.
Adding even the most basic firewall rules is hard. The single pane of glass got a major interface overhaul, and they added a huge amount of hard-to-turn-off phone-home crap at the same time. Enshittification reigns supreme.
And don't forget other runty hardware like the poe ceiling lights and doorbell.
The company just needs to buckle down, make good stuff, fire the product astronauts, fix obvious major problems before adding pointless new features.
... Suffice to say, my next hardware refresh almost certainly won't be from this company.
Personally, I'd like to see more prosumer devices that support 2.5GbE/10GbE.
InTune doesn't even list it as a supported VPN, and everything I see to deploy it suggests some kind of hack to bypass UAC for one specific app because the end-user software requires Admin permissions to startup and hook.
When we use L2TP with UDM Pro we get ~0.1Mbps across the wire from macOS and ~20Mbps across the wire with Windows, and yet the same VPN server running on a Mikrotik will easily achieve ~300Mbps. L2TP is so easy to deploy .. it's built into Windows and macOS. I wish they would just stop telling everyone to switch to WG and fix the performance issue that is clearly Unifi specific.
NB we are a business and our average spend for Unifi is $50K per year so we have a right to complain.
Most businesses never give their users admin permissions because it's a security can-of-worms, so for Unifi to push Wireguard for business doesn't make much sense. Happy for someone to point me at a turnkey Wireguard solution that just-works with InTune.
> Fixed the issue where WireGuard VPN could not be used through Intune-deployed MSI installation.
Source: https://wiki.ui.com/docs/identity-enterprise-endpoints-0671
Tailscale?
Needing local admin would make WG a non-starter for many organizations.
L2TP performance issues aside, I don't see how it's UniFi's fault that Microsoft's ecosystem is poor. I don't have many positive things to say about InTune.
...there is tailscale
Now that you mention it, the small PowerEdge is not that expensive and might be the best way to deploy as Intel Xeon has AES NI.
In the cloud(s), even.
Isn't the UniFi Gateway Lite[1] just that?
[1]: https://techspecs.ui.com/unifi/cloud-keys-gateways/uxg-lite
what unifi sold people on was cloud managed easy config and it just started working somewhat in the last version for me. Really feels like they need to triple down on the software front and beef the midrange hardware.
I just looked the other day - as I'm getting symmetric 2gb fiber in a few months and unifi has some wild high end router but it seems like it needs more on the CPU and ram front still, too. OpenSense here I come?
My next product will be so ething else, because all the new stuff doesn't buy into the "KISS" anymore.
Not sure why you think the VPN doesn't work. I haven't had a problem.
The doorbell is awesome. The POE ceiling lights were a mistake.
There's also the trust issue; the VPN problem has been known for years. If they won't maintain a key security component of their key security device, why would I trust them with anything?
"What is UniFi Express? It's a UniFi stack in a box." What the heck, lol?
"Wi-Fi at remote sites." It's a 5G hotspot?
"Secure WAN VPN between remote offices." It's managed Wireguard?
It's a Wi-Fi AP with a weather forecast LCD on the front? I must not be the target demo.
If you want to deploy a typical small office traditionally you’d have wifi, switching, routing, firewall, vpn. Typically some of this would be integrated into a single box (routing and firewall for example), but you have a bunch of different specialist bits of equipment to manage and interoperate.
This is unifi’s version of “we provide a one stop shop”, with your entire network managed through a single and of glass
It’s nothing unique, but it’s unifi’s version.
The enterprise is coming to the home.
Anything that isn't basically your home office is running a solid NGFW with SSL interception.
Run your endpoint security on your devices
Your average mom and pop business is more likely to have a wifi AP/router/NAT gateway combo from their ISP than something as feature rich as Unifi, let alone a real NGFW.
As for things like HIPPA - that’s why you do URL categorization and bypass those destinations.
Finally URL categorization isn’t perfect, and you end up with a leaky solution that is again, as I said, a giant cess pit of regulatory toxic waste.
It's pretty easy when you have your own PKI infrastructure. Which is surprisingly manageable if you have decent people running active directory services. Which is usually the single source of truth for LDAP integrations with NGFW anyway.
You can do cool things like having corporate devices have their own machine certificates that enable an always on VPN to access central resources (updates, AD, etc.) and switch to a user profile certificate as soon as a user logs into the device to get VPN/firewall access to resources that user needs.
It solves the pre-pipping problem of sending out devices to remote workers without them having to login before hand to load their profile on the same network as AD. And it's secure.
The alternative is to go cloud and in-tune everything and use Entra id, etc. which seems more popular but you lose a lot of control in my opinion and have a massive attack surface because unlike on-prem AD, the cloud is just some amorphous blob that you can't lock down using the usual things like firewalls.
Most of the time there are white lists that exempt huge amounts of known traffic to common SaaS services, and known company resources (like Health Insurance) traffic, but if it not a known service than that traffic should absolutely been decrypted and inspected.
Cisco, Palo Alto, Zscaller, etc all do this
Don’t use any of their unifi routers tho, can’t speak to that. I have an ER-4 at home and the remote office has a pfsense 1U.
I eventually moved to OPNSense but the router I bought from them died. The interface was too cumbersome anyways, from the perspective of someone that just wanted WireGuard server+client, IPS/IDS, and VLAN.
I finally moved to Firewalla and it is lightyears ahead of Ubiquiti, OPNSense, and any other solution I've tried from a power user perspective. I use this with Ubiquiti APs connected to my Pi running the Ubiquiti management software, which works out quite well.
The Firewalla is far easier to use, has a way better UX, and covers 95% of the power user tasks.
https://help.ui.com/hc/en-us/articles/115005445768-UniFi-Gat...
Seems like all you can do I hope they do not spy on your traffic and sell data. I run a reputable VPN for that very reason I don’t trust even my publically traded ISP.
IDK, seems suspect. Or at least requires more trust than I am willing to hand out.
You seem to be confusing the built in VPN server for a VPN provider. I do not see a "free VPN" mentioned anywhere on the website or in the app. All this enables you to do is access your home network remotely, your data isn't being funneled to a third party server because the server is your router.
The DNS defaults to Cloudflare if I remember correctly. You can replace it with Unbound or DNS over TLS with your provider of choice.
The ad blocking is done with locally downloaded blocklists.
And you can do much more than VPN/DNS, so I'm not sure why you walked away with the impression that this is all you can do. You can configure VLANs, you get IPS/IDS, push alerts to your phone, tons of other features that put it more than on par with OPNSense/PFSense for my use case.
Regarding price, the value is in the software. Firewalla's UX is so far ahead of OPNSense or a UDM that I can't fathom going back to one of those. Seriously, both feel positively prehistoric in comparison. And I'm fine with paying for that, because software is expensive, and apparently no one else has managed easy to use software that supports a prosumer featureset, and I was sick of spending hours configuring my UDM or OPNSense router.
I get your concern about closed source, but that's not a problem for me personally - most of my devices run closed source code, including my Ubiquiti gear, and it's not like anyone compiles OPNSense or PFSense from scratch when installing onto their router anyways.
The thing cools fanlessly/passively, can do IDS/IPS + WireGuard server and client at 1Gb speeds, and is trivially easy to configure even with a smartphone, which neither my OPNSense DEC-840 or my UDM Pro could do (at much greater price points.) If you can find similar functionality and ease of use at a lesser price point, I'd love to know.
Give it time. Nothing has made me believe in community-driven FOSS like watching the alternatives over a long enough time span. And to be fair, sometimes it really is a long time span, but the outcome is nearly always the same in the end.
Can’t believe I spent $300 + on the Netgate that couldn’t handle 1 Gbps traffic WITHOUT IDS/IPS turned on. Even a $50 EdgeRouter X can do gigabit WAN!
My Ubiquiti setup (one LR and one lite) was done back in 2018, devices on the network is roughly the same in the past 5 years, only phones laptops changed due to upgrades. Since 2020/21 their firmware updates started dropping support of old device randomly, or support become worse (devices get disconnected frequently or full bar but not responsive). First was my Kindle 3G keyboard, then Fitbit Aria Scale, then quite a few smart switches/plugs. I literally scratched my head to understand the settings, but they just won’t connect to the Ubiquiti AP. I had to buy an Eero as backup and continuously migrate these older devices as they are unable to connect. Their most recent firmware update last week kicked my Sony TV off the network(bought in 2018), I have no idea what they are thinking and wasted 1 hour rebooting and blaming Sony, then found it connect to the Eero AP just fine.
After I completely wiped the site configuration and migrated to the "new way" of doing it (I wish I had taken notes, I don't play with it often) and ensuring each AP got a fresh configuration, things stopped being "Weird".
I especially had issues with various IoT style sensors (e.g. ESP32) falling off, my largest annoyance was water leak sensors.
I wish I had some more technical notes to hand you, but it was definitely worth the evening of my time to basically "turn it off and back on again" from scratch.
Depends on specific model. Qualcomm-based ones are still good.
https://help.ui.com/hc/en-us/articles/205204070-EdgeMAX-How-...
I'm reallt happy with it.
Are you doing persistence (keep settings/data after reboot) with Unifi OS 3?
What do you mean by "QUIC vulnerabilities are a 3 or 4 packet compromise"?
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth.
I like Google Dart and other Google products but I see too many potential issues with QUIC. From my personal experience it has behaved suspiciously on my network.
Actual prosumer+ products like Sophos XG (free), Untangle Home, *sense blow it out of the water, though, by giving actual offerings for features where Unifi gives a diet version.
That all being said, it's definitely a cut above most consumer networking setups, maybe with the exception of Asus -- they do a pretty solid job.
I was so displeased with having to run a proprietary server on my internal infrastructure (which depended on MongoDB of all things, which no distro seems to ship anymore) just to manage my UniFi AP-Lite that I flashed it with OpenWRT and never looked back.
I'll stick to my PCEngines box running OpenBSD + mikrotik managed switches + OpenWRT, thanks.
This setup is hardly much more complicated than the inherent complexity of any non-trivial home network and can be managed with SSH and a web browser.
This is probably asking for too much but I would a set-up that allows me to operate at home:
- 10Gb router (packet switching to fully saturate the number of physical ports)
- 10Gb switch
- 6/6e AP
- 10Gb firewall with IPS/IDS
Even just wanting a 10Gb switch for the home is nearly impossible, I doubt I will find a 10Gb router/ngfw that runs at line rate.It seems strange that networking, outside of the data centre and WiFi, seems to be stuck in 2001.
Somewhere in the early 00s computers started to come standard with gigabit. I think you could order a PowerMac G4 with gigabit in 2000. To put that in perspective, at that time VCRs were still the most popular way to watch a movie.
the tables turn slowly, but the mass market for 10gig is just not here yet besides all-10gig soho switches beeing available for some time now.
major point: 10gig uses vastly more power than 1gig, making integration (esp. in laptops) challenging.
other point: ids/dpi at 10gig line speed is challenging, requiring a powerful cpu on the router and flawless integration.
au contraire; even for wifi 5 aps like original Turris Omnia (3x3 MIMO, 80 MHz) or Ubiquiti nanoHD (4x4 MIMO, 80 MHz), the gigabit uplink was the bottleneck.
> major point: 10gig uses vastly more power than 1gig, making integration (esp. in laptops) challenging.
Only 10GBase-T. For a networking equipment, you would want SFP+ anyway.
Laptops slowly are losing wired Ethernet entirely. Meanwhile, 2.5GBase-T is still good enough for laptops, and does not represent integration challenges.
it's also good enough for most soho infrastructure needs
There is one potential hurdle though: they specifically mention that it can handle 1G of traffic even if you enable a bunch of features. They would have had to upgrade the processors to be able to make the same claim at 2.5
If they are making it a point to address that in this current product I feel like they want to make sure that type of call out doesn’t happen again.
I guess they could always do a Tri-Band, WiFI 6E with 2 2.5xGbps Ethernet for $199. ( That would be awesome )
I also wouldn't call it nothing, 2.5g switches have much higher consumption and get hotter, let alone 10g.
Why should a backup from my laptop to my file server be limited to 1gbps? Has nothing to do with outside connection. Tehre are a lot of use cases for faster home networking irrelevant of network speed to the external world
Otherwise the wireless throughput is nowhere near gigabit so you would be limited by that anyway.
Perhaps putting it another way will help -- according to the FCC's most recently release Internet reports[1], only 13% of subscribers have at least 940 mbps down. However, 57% are at least 100 mbps, but less than 940 mbps. There's a juicer market segment for gig and below than there is for above gig. Increasing the prices to attract 13% of the market isn't terribly worth it in this case.
https://store.ui.com/us/en/pro/category/all-unifi-cloud-gate...
They also have multi-Gbps switches up to 25Gbps SFP28:
The only reasonably priced router I could find about 6 months ago that would NAT at line speed was the TP-LINK Onada ER8411. I ended up going with an all Oanda network which seems to work fine but ubiquiti had originally been my first choice.
[1] https://ubntwiki.com/products/unifi/unifi_dream_machine_pro
Routers with 2.5gbe uplink are hard to find and even more expensive.
ASUS has some all-in-ones with 2x 10GbE ports but I wouldn't recommend them to anyone.
The market is undeserving the everyday consumer.
It's why there are multiple YouTube channels dedicated to reviewing Chinese no-name 2.5gb switches from AliExpress. The big names have just turned to blind eye to pump out the same outdated devices they've been pumping out for years.
Obviously 2x 10G uplinks don't make a whole lot of sense ;)
Enabling the IDS drops throughout to about 3G (IIRC) but IDS is snake oil at the best of times.
https://ca.store.ui.com/ca/en/pro/category/all-cloud-keys-ga...
Finally a viable USG3 replacement.
I had never enabled the traffic inspection stuff on the USG, so it was neat to finally get a look at that stuff after having it inactive for years. I'd been thinking about getting one of the UDM things but since the USG was working well I figured I'd wait until something like this came along. So far, so good!
But man, it's just too hard to find available stock. It took me time to find the dream router and even now it's out of stock, and, this new device is also out of stock.
Businesses aren't buying this shit.
I watched a video yesterday from a german medical cannabis business where I recognized unifi APs in the building. Their camera system was (as one would imagine) unifi too.
Anecdote of course, but I see these everywhere.
Remote access, decent ecosystem, reliable. What's not to like?
The only problem I have on occasion is stock.
UniFi requires a controller that gives you a single pane of glass style interface to control everything. Most of their controllers can run multiple applications, the top two being Network and Protect. Network runs their Routing, WiFi AP's, and Switches and gives you in depth data about what's going on where. Protect is their NVR system, which also does some AI stuff and ties into a few other things like Ring does.
This device is a bit low powered, so only runs Network; they do sell standalone NVR's that will tie into it and run Protect. The $50 more expensive UniFi Dream router is similar, but has a switch with POE built in to run a couple of AP's or cameras, and can run both Network and Protect (with caveats; it's not terribly powerful and it only saves Protect footage to an SD card).
So you can think of it as just a fancy AP, but it's also the base building block of a much larger ecosystem.
As a note, the weakest link of the system is, IMO, the routing. Running UniFi with a more professional router of choice is a common way to go.
> single pane of glass style interface
Everything on one screen in a GUI with graphs. I THINK it comes from aviation, where the transition from steam gauges to MFDs to really big MFDs meant some massive UI changes.
That may not be quite accurate, but it’s as close as my brain can do this late.
> UniFi Express is a complete UniFi Networking stack in an ultra-compact, plug-and-play form factor. It runs UniFi Network and features a powerful gateway engine and built-in WiFi 6 with seamless meshing.
All their Omada products can communicate with a controller which can auto configure the devices and actively coordinate handover of clients between WiFi APs.
I’m running it in my house and I’m pretty happy. Through the controller web page UI you centrally define your VLANs and wireless networks and then it updates all your equipment configuration for you.
I don’t think I’d ever bother with their gateway product as pfSense seems to be way more capable.
Companies like Ubiquiti (under the UniFi brand), Meraki, etc. make these products such that they can all work together as an ecosystem, e.g. so you can log into a single dashboard and manage the network as well as every individual device's configuration from one place. This is the difference between a so-called "managed" switch (or wireless access point) versus an ordinary dumb one. UniFi also makes PoE security cameras that are managed through their ecosystem in the same manner.
This sort of ecosystem is useful for people doing I.T. in commercial settings. You can use a single interface to manage a network in a huge office building with hundreds of devices, or to manage lots of smaller networks spread across different sites. This "UniFi Express" product seems more suitable for the latter, e.g. in cafes or small retail settings where you might just use it on its own or add a small number of additional switches/APs. It's similar to your home router+AP combo, but it also contains the management software I described before which is capable of adopting more UniFi devices and provides remote administration.
Edit: If you're curious, TP-Link's equivalent to UniFi is called Omada: https://www.tp-link.com/us/omada-sdn/
In a wifi router like your TP-Link, the control plane software is running on the box with the the switching hardware and wifi ap, so you've got a little single board computer running web server for the UI, and all the random dhcp/dns/etc and other doodads that can run on them.
In the Unifi world, you've got all the same functions, routing/switching/wifi etc, but instead of sharing one box, the functions are spread across a number of different devices.
As with a combination router/wifi/switch, the important part to a user like you or me is that control plane software- you plug the thing in, point your browser to 192.168.1.1 or whatever, and set things up. The Unifi world has this too, but that software component doesn't need to run in any specific place in your network. So for example, you could buy two Unifi Access Points which do nothing but talk to wifi clients, then you would need some kind of device capable of going your routing, and you might need a switch as well.
Ubiquiti sells a variety of little routers and switches that can perform those network functions, but which don't have any compute or storage resources that would be necessary to run the control plane software. However, they also sell little gizmos like the Cloud Key which can run the control plane software- it's just a tiny server with some flash storage and an ethernet port. I'll refer to that thing as The Controller.
When you change some settings on your TP-Link, the web UI app is twiddling with the the routing/switching/wifi/etc hardware or software on the device. In the Unifi world there's a web ui as well, running on the controller, but when you change a setting in the web ui, the controller decides which devices need to have their configuration updated, and sends out new configuration to them over the network.
Here's where I think things get confusing. The Controller software package can run on a wide variety of devices which are so different that the whole thing will seem nonsensical if you're used to regular wireless routers. You can buy a CloudKey and connect it to your network. You can download a copy of the Controller that will run on a Linux box on your network. Or you could do the same thing but have the Controller running on a machine that isn't on your network at all, like an EC2 vm. Or, Ubiquiti also sell some devices which combine two or more functions into a single device, like some of the "UDM" family of devices have compute and storage resources in addition to the switching/routing/wifi hardware, and have The Controller software installed in advance.
To give you an example of how flexible the controller placement is, I have a little Synology NAS that is able to run Docker, and on it I have an image that contains the Unifi Controller, so when I go the web ui for my network, I'm talking to a containerized web server on the NAS, which is managing the configuration of my devices, which are a router (I just replaced my USG 3P with a UXG-Lite yesterday), a couple of their little inexpensive switches, and a pair of Wireless Access Points.
What I like about this model is that I'm able to update pieces of it as I need to, and usually the individual pieces are fairly inexpensive. But what I dislike about it, as some other respondents on this thread have complained, choosing which devices you need is confusing as hell. They sell at least one machine which has a wifi AP, switch, router, and controller all in one box. Why not get that? The reason, I believe, is that many of the people who use this Unifi stuff are managing a bunch of networks at a bunch of different sites, like maybe at a bunch of retail locations or restaurants, where its way more convenient to have the controller running offsite, but then they decide to install some stuff at home and need a Controller which needs fewer resources so a Cloud Key or just running the stuff on your desktop would be ok.
This flexibility means that there's no single right set of hardware, no single best product, etc. Especially if you don't need multiple APs, I think a single-box wifi router will provide equal or superior performance with much less trouble, but once you need multiple APs, the Unifi stuff can be compelling if you're comfortable with the architecture, but I think it's difficult to decide which hardware bits to choose and what the best place to run the controller will be.
anyway apologies for the length- I found all this very confusing initially as well although I've grown fond of the Unifi stuff and thought it might be worth writing the whole thing out in case its useful to somebody considering this stuff.
People complain about the USG3 not being able to route 1gb/s (IIRC, it's 10 years old, and always capped at 250mb/s), or the UDMP Pro at 10GB/s IDS/IDP (It can run at 2.5GB/s with IDP and IDS). Wireguard and policy based routing (which is why most people were sticking away from their routers) are in place, and far simpler to maintain then alternating options from PFSense and Cisco. The magic VPN stuff really feels like Apple when it just works.
Their WAPs are a bit pricey on for 6E support, but otherwise are generally considered the best prosumer WAPs available, and competitive (and cheaper) then most enterprise options. They are overkill if you don't need management, but in a IoT world, you need VLAN management. The VOP and security cameras and phones are solid. Best of all this run cloudless. You buy the hardware, the software is free and runs locally. Even their enterprise software is being ported to run on device (and free for prosumer use cases)
This is part of three new devices that are strongly targeting the old Apple base station market. The third - UDR ultra - is coming out soon (it was leaked in the same art dump that this and the other device was leaked) and has 2.5GB/s WAN and LAN. IF you want to run their VOIP / camera / door system, there is the UDM Pro and UDM Pro SE. I have the base level UDM Pro with a 2.5 GB/s primary and a 1GB fiber secondary. Works great, auto-failover, firewall management, VPN, RADIUS, etc.
In general, if you want WIFI and network that just works, but still does policy based routing, VLAN management, can dump to Prometheus (with unifipoller), run VOIP and security cameras (even with Homekit secure support, thanks to Scrypted), this is the solution for you. I run my in-laws and my parents network stack remotely with UDRs. I highly recommend them.
If you want to run your own hardware, or have even more power, buy your own and run OPNsense, or go upmarket. For everyone else, this stack rocks.
That said, I have a UniFi router and 3 wifi 6 APs and my network is super solid. Way better than any prosumer targeted router (note that I previously ran 3 netgear nighthawk). The UniFi stack was actually cheaper and is unquestionably more reliable. If you’re looking at those very high end prosumer routers, I’d very much advise taking a step back and looking at alternatives.
I was an old AirPort Express user and after trying other WiFi setups like netgear, etc this has been night and day. And moving was a breeze, unplug, get internet service, and plug in
https://help.ui.com/hc/en-us/articles/12594679474071-Standal...
I just picked up another UniFi Protect camera that was only taken out of the box once on a marketplace, just because the person wasn't aware of what they are buying.
On the upside, I haven’t touched the device since. In my experience they are fantastic for zero maintenance and ‘just works’ once setup
What exactly is "A complete UniFi networking stack" anyway? Is UniFi some protocol that extends WiFi?
Every single thing that can be wired will be wired. The UniFi Express seems to be geared towards mesh networking, I still don't trust that to be reliable.
https://www.gl-inet.com/products/gl-mt3000/
which comes with a 2.5 Gbit ethernet port (the UniFI Express caps out at 1 Gbit ports) and OpenWRT based firmware which looks like a decent price/value/form factor combo at ~USD 90.
Anyone who has more experience with UI: is this a comparable product?
Edit: it sounds like the UI products have a fleet management concept and are designed to work together (Apple-esque sum is greater, plug and play …)
https://community.ui.com/questions/UI-official-urgent-please...
The hardware is mediocre anyway.
Either buy Mikrotik as cheap and cheerful or go for broke with Ruckus/Meraki/etc.
With Ruckus the 2x2 stuff has turned out not too impressive so would need to shell out even more with 4x4. Meraki is incredible but the subscription model is hard to swallow.
For a typical home user who doesn't want/need Protect this seems decent, but I think the $50 upcharge for the UDR is absolutely worth it.
That said, the UDR is heavily limited in running Protect. I started hitting occasional problems running Network and Protect together when I hit 4 cameras.
It has the typical foibles of UniFi routing so I'm replacing it, but I haven't had too many issues with it tapping out the Gb port (when my cable line allows).
I wouldn't even try to add any fancy features to it and expect it to hold up though; it just doesn't have the power.
Oh, and one of the foibles is that if I do hit the router with a connection that saturates it it drops every other device on the network. So it being able to route above 500Mbit is kind of a non-starter I guess, as it can't do it to more than one client.
The other thing I noticed: you literally cannot access or use the management UI when you're saturating the connection. It just straight up will not load.
I agree on the UI. Now that we are running the Protect app on an iPad all the time (my child is special needs so we use the cameras to keep an eye on everything) it has throttled pretty hard. Maybe 400Mbit now? I honestly hadn't tested it in a while, and haven't had the time to do in depth. It's absolutely slower now.
I have a Mikrotik CCR2004-1G-2XS-PCIE that will be my new router when I get around to it, and the UDR will be an AP and run the Network and Protect apps. We've been seeing weird issues ever since leaning on it harder, so I'm going to see how it does just being a Controller and AP.
I was intrigued to run protect on a cloud server with a 5g failure wan connection. But they got greedy. And now this.
I still run a uap6 and will do so until I get a wifi7 router. Currently running opnsense vm on proxmox but that crashes upon occasion and I need to stop start the vm.
Omada isn't perfect either, and the hardware design is worse, though it's been more reliable and with a lot of basics better locked down for me. I'd be delighted to have two strong competitors there, and there have been a few promising glimmers on UniFi, like PPSK getting some initial attention (4 years late is better than nothing). And certainly the basic switching and WiFi mostly works. Having a whole single pane of glass remains attractive, and either is a big upgrade over the kind of stuff a lot of people are coming from. Just take some of their promotional gloss with a grain of salt is all.
And as always AIO is something to balance as well. When I switched out the routing side of things for OPNsense I could maintain the whole rest of the stack as I pleased, including APs in optimal positions. The latter is less of a (or zero) concern in small spaces, but even then WiFi, switching, and routing needs don't always evolve in sync.
My OPNSense N100 PC + omada switch and AP was like $400 all said and done.
UniFi Express can route traffic at speeds up to 1 Gbps. Security features such as Device Identification, Traffic Identification, Country Restrictions, and Ad Blocking can all be enabled without impacting routing performance.
Does it hold with this company?
Their hardware is quite good. Their consumer line (AmpliFi) is Solidly Okay.
From a management perspective, their UniFi system is bar none one of the better solutions for large deployments where you've bought into their whole stack: Routers, switches, Firewalls, APs, everything. There's some things it does OK with other vendors (particularly switches) but it's meant to be managed under their garden.
The nice part is that you can preconfigure hardware, chuck them into a bin, and make it Just Work on the other side. Deploying 100 APs to a new location? Ship 'em direct to the site, they'll just Show Up in the unifi interface. New deployment? Drop a few bits of hardware on a bench, set it up locally, yeet to new location, install the rest, configure over the 'net.
Some people have sworn off them for a lot of papercuts: There's a few points where their UI just Doesn't Work. There's occasional spots where if you preconfigure it manually then try to use the management interface, you might exhaust a DHCP pool in an hour.
But the hardware has, and continues to be, maybe not "cutting edge" but slightly behind it at a price point that makes enterprises salivate and Prosumers go "Hmmm I could probably swing that." And it works for a lot of people.
That isn't to say every product they've put out has been a Banger. The Dream Machine was, at first, very much a mixed bag (and took several YEARS of True Believers really working with Ubiquti to get it right) and this is absolutely them recouping some design loss from their Aplifi Instant product (the case, design, even the screen is Very Similar to it). There's been versions of the controller hardware (and software) that have been... let's put it: Enough to send some people selling all their gear and moving vendors.
This device runs UniFi Network so it can host the configuration.
There is the cloudkey that can host the config
There are routers that host the config in their product line.
I don’t think it’s ever been the case that you “need” the app.
There is no other instruction for people without an app store. Not even in their help article.
https://help.ui.com/hc/en-us/articles/12594679474071-Standal...
> Log in to the UniFi Mobile App (iOS / Android).
Why do I need to log in to an app to set up a LAN device? It's complete nonsense and makes me ultimately distrust Unifi.
It's affordably prices and just works.
It's an entry-level WiFi router with UniFi's Network software, which provides the ability to buy more UniFi gear (switches and additional APs) if you have a really big house and/or wish to connect more than 1 device over ethernet. Unlike its bigger siblings, the Dream Router and the Dream Machine, it lacks additional built-in ethernet ports (i.e. you'd need to buy a switch) and can't host security cameras (the UniFi Protect product line).