For your own home, if not Ubiquiti, what do you use nowadays?
For your own home, if not Ubiquiti, what do you use nowadays?
I've been using their devices for years, and I haven't had any problems setting them up.
For example:
/ip/firewall/filter add
is in the UI under the sidebar IP -> Firewall, then the Filter tab, then click add. The parameters are named the same in both too.
YMMV.
1) Their main push seems to use a thick client for admin which is a big no to me, otherwise the web ui in theory looks ok-ish. 2) Looking at their cli guide, it was cryptic as hell to me, and I deal with everything from cisco, arista, aruba, juniper, fortinet, pan, whatever from a cli or gui.
This was mostly confirmed a few weeks back, another old network engineer friend of mine hit me up asking if I've ever dealt with Mikrotik, and said no, but I knew where he was going. He'd screwed with it for a day or so supposedly just trying to make some L3 vlans, and finally a day or so later told me he'd made it work, but has never dealt with anything so terrible to configure from either gui or cli after having tried both, and he's another 20yr+ network engineer like me I trust not to be stupid.
That was all I needed to hear for future consideration.
Where you run into problems with 'tik gear is the differences that L3HW acceleration introduced into the mix. They didn't do what every other switch vendor does and limit features to what the switch chip supports and hide everything that the CPU can't handle away, so you have multiple ways of approaching most issues which threw me for a look as somebody who had been running JunOS gear in his lab for a while.
Once you get a feel for it then it's pretty straightforward to work with everything, though somebody used to an older generation of NOS like classic IOS (and associated clones) would have an easier time than me.
For reference, here's the config for my CRS317 acting as my "core" switch: https://gist.github.com/snuxoll/d63a155aa2155f53736a99d1cb27...
But I will say that the boxes of theirs that I bought about ten years ago are still going strong, never had a device fail on me, still receiving OS updates, still able to export and re-import my config to any of a wide variety of newer devices when the time comes.
Clearly they're not the right choice for everybody, but there are certainly up sides, if you're willing to grapple with the config.
Yeah, the CLI is a bit weird, but it's built on the same API calls that the web UI makes. So they're oddly consistent.
Rock-solid hardware and muuuch better UX that RouterOS.
Don't remember when I setup those, but probably well before Covid. Really fire-and-forget devices.
https://www.arubainstanton.com/techdocs/en/content/get-start...
Some more discussion here from years ago:
https://community.arubainstanton.com/communities/community-h...
Although, I imagine this type of stuff may not be made to work well without internet.
I notice that the linked docs article doesn't get listed if you go up the breadcrumb and try to go back down…
This is huge! Please link me to the evidence to back this up.
The NDAA blacklist was a happy compromise by the US government of banning the most egregious vendors that might find their way into sensitive facilities (Huawei, Hikvision, etc) while letting consumer focused brands that do the same (TPLink, Jetstream, Wavlink, etc) slip by so it didn't appear at face value to be a blockade of all Chinese made networking gear.
Taiwan on the other hand is less concerned about how China perceives their relations and bans all these vendors. They also ban Zoom.
Second, you seem knowledgeable about concerns w.r.t some supply chain attacks, at least from foreign actors, so do you have an alternative suggestion that isn't impacted by such concerns?
Ubiquiti is a non starter imo given their recent posture
Grievances start with "made in China" and end with firmware hacks from May of this year.
https://blog.checkpoint.com/security/check-point-research-re...
This implies the opposite of "the CCP has a backdoor to every device". Vulnerable devices from all manufacturers get exploited like this all the time.
Best built hardware I've used, and I'd still be using their PoE at home if they didn't patch out SSH/REST access a few years ago.