So I've gone elsewhere for cameras, switching and routing.
This release is a nice point in their favour though but I can't see myself going back all in on Ubiquiti.
So I've gone elsewhere for cameras, switching and routing.
This release is a nice point in their favour though but I can't see myself going back all in on Ubiquiti.
Their security issues in the past. Their failure to make the EdgeRouter handle DHCP and DNS properly. Etc...
I've since moved to cheap switches that support all port vlan trunks and LACP bonding, then just plug Proxmox into them and run OpenWRT in a VM for routing all the vlans. The Proxmox+OpenWRT combo even supports hot-plug virtual interfaces as more VLANs are lit up, they just pop up nicely in the web UI.
For the APs, TP-Link is less expensive and better performance. WiFi 7 and 10gbit for less money. No need to run a management OS in a VM either.
Thanks, they really seem like good alternative.
But EdgeOS was not the only fork, another one was VyOS (vyos.io). Pretty sure, that EdgeOS has done larger steps forward, especially, since it was bound to the hardware's developer.
So even though VyOS exists as the modern day Vyatta fork that is active and fully-featured, you can't really run it on the EdgeRouter hardware and since Ubiquiti stopped development, they're basically e-waste.
I still run one in a network but really shouldn't, since Ubiquiti are very rarely shipping security updates...
EdgeRouter 3.0.0 [1] adds official wireguard support (I've been using the "wireguard-vyatta-ubnt" package from Github [2]), UI changes and some other improvements/fixes. I haven't tried it yet but will. I have an Edgerouter3-lite and an ER-X.
[1] https://community.ui.com/releases/EdgeRouter-3-0-0/33ee3852-...
The new GUI looks nice and Wireguard is great! Not all good news sadly though, users in the comments there are pointing out that the kernel has hardly been patched from the versions two years ago... At least some packages like OpenSSH, dnsmasq etc. have had updates.
the one key point was that the EdgeRouters had hardware acceleration
The EdgeRouter Lite used a Cavium SoC, the EdgeRouter X family used a 32-bit MediaTek SoC. Hardware acceleration was buggy on both and is/was known to cause packet corruption.The main problem with the EdgeRouters was that Ubiquiti was basically just assembling off the shelf stuff. They didn't have the ability to fix SoC issues (or motivate the manufacturers to fix them). For years they didn't have the ability to do much Linux dev work either so the ER families languished on an end-of-lifed'd version of Debian. That experience and realization only motivated me to avoid future Ubiquiti products.
A while ago one update automatically enabled PMF (set to required, I believe) on all Wi-Fi networks. That didn't go great for me when half of my IoT devices stopped connecting and I wasn't available to fix.
[0] https://community.ui.com/releases/UniFi-Network-Application-...
Cheers!
I have a separate tower that's a old 9th gen intel that provides the large ~50TB ZFS NFS server. It used to be an intel Atom, but that finally died after 10 years so I moved the drives to a gaming PC I had lying around. Over the years, nicest thing about ZFS and Proxmox is the drives are fully independent of the hardware and the software OS they're attached to. Now, I just pass the devices through Proxmox to a Debian VM and they come up just like they did before.
Regarding the rest of the network, let's move from the edge in toward the 3x 1U servers and NFS storage box. I have 1gig symmetric fiber from Ziply. The ONT has cat5 running to 1 of the 4 gig ports in an Intel Atom C2758. The other 3 ports are bridged together in Proxmox to act as a switch. It kind of looks like an EdgeRouter-4 if you squint at the ports. This C2758 only runs a single VM, OpenWRT. The nice thing is I can take snapshots before upgrades, and upgrade or replace the hardware easily.
The OpenWRT VM is the most critical thing in the whole network. I try to manage it simply, I have some shell scripts that copy the /etc/config files into place and restart services for a simple IaC setup.
The main services OpenWRT provides are:
1. WAN DHCP client, my ISP doesn't offer static IPs. 2. One minute cron job that makes sure the A record for home.example.com is correct. *.home.example.com is a CNAME to home.example.com, this simplifies configuration and TLS cert management. 3. HAProxy runs on OpenWRT listening on 0.0.0.0:80 and 0.0.0.0:443 Extremely valuable for SNI routing of TLS connections. I moved the LuCI web UI to alternate ports, which is simple to do via config. 4. dnsmasq provides dhcp and dns for the main and guest VLANs. 5. OpenWRT is configured as a WireGuard server. Each wireguard client device is allocated an dedicated IP in a separate 192.168.x/24 subnet. This has been great for source based IP access control which I'll cover below. Wireguard clients connect to home.example.com.
That's it for OpenWRT. The key lesson I learned is it's been incredibly valuable to run haproxy on OpenWRT. All L4 connections terminate to it, but crucially it does not handle TLS certificates. It only forwards TCP connections based on the SNI in the client hello. HAProxy is also configured to use the PROXY protocol to preserve source IP addresses, which has been great for access control.
Most TLS connections are forwarded to a single node Talos VM running on another Proxmox host. This VM runs Cilium, Istio, and the Gateway API. The istio envoy gateway is configured to accepts PROXY protocol connections, which means AuthorizationPolicy resources work as expected. By default, only connections coming from the local subnets, or the wireguard subnet are allowed. OpenWRT does hairpin NAT, so this works just fine, all sources connect to the WAN IP regardless if they're internal or external.
I don't do much with Kube yet, most of the traffic is forwarded on to another VM running Portainer. Most of my backend services are in Portainer. The Kube VM does handle Certificate and AuthorizationPolicy resources though, using cert-manager and Istio. This has been nice, I don't need to configure each service for TLS or access control in bespoke way, it's all in one place.
The only other thing to note is the Dell 1U servers have 3 of their 4 gig nics aggregated into LACP bonds. Similar to the Atom router, they're configured as a bridge in Proxmox and I use them for the Ceph data plane. 9 of the 16 ports in that TL-SG1016DE are just for Ceph and I'm able to get close to 600 MiB/sec reads (yes megabytes) which is pretty neat given 1gbit interfaces.
That's about it. Overall I'm trying to eliminate VLAN's, but it still makes sense to have them for Ceph and for a Guest wifi network.
Edit: Lastly I've maintained a home lab for 25 years and this is the best iteration yet. All of the trade-offs feel "right" to me.
https://community.ui.com/questions/U6-IW-how-to-trunk-all-5-...
> Tell me about the Trunk VLAN issue with the UW6-IW
The built-in 4-port switch in the U6-IW has significant limitations when it comes to VLAN trunking. etc...
> Did Ubiquiti fix the VLAN TRUNK issue?
Based on my research, No, Ubiquiti has not fixed the fundamental trunk VLAN issue with the U6-IW's switch ports as of early 2025. etc...
Im glad I dont emply you!
That's why I moved off as well. Maybe some day SDN (at least so far as the ubiquity experience goes) will become an OpenWRT priority.
https://community.ui.com/releases/EdgeRouter-3-0-0/33ee3852-...
But yeah they haven't released any new hardware in quite a long time. But nice to see they are still doing development work on the software.
We still use some Ubiquiti. Sometimes i use this script on a Debian VM:
https://community.ui.com/questions/UniFi-Installation-Script...
It’s great for pointing a livestream at a fish tank. It’s useless if you’re trying to record the outside of your house at night.
The router works still amazingly fine, only their software has some bugs.
Hopefully the Unifi devices are better since I eventually replaced it with Cloud Gateway Ultra after dabbling with a second-hand MikroTik.
The cameras will upload jpegs and mpegs to a local FTP server based on configurable triggers, which include 'AI' detection of animal/vehicle/human, all running on-camera.
I wrote a simple script to put all the daily uploaded jpegs on a HTML webpage (each linked to the video) for review. Home Assistant also has an integration that can do streaming and grabs the detection triggers as well.
I tried a Mikrotik router recently but conoared to the Ubi devices, configuration feels so clunky and complicated.
I have an ansible playbook that creates the image and I run it on a cheap fanless x86 box....
Ubiquiti's routers to me just seem to be prosumer routers with an "enterprise" UI on top. Whereas Mikrotik genuinely offer an enterprise experience (also still great for home) with the boring, drab, absurdly functional UI to back it up.
Ubiquiti looks beautiful; but you can't do anything with it.
Admittedly it's still not as awkward/bad as Draytek.
For our house I tried a Mikrotik, a TP Link and a Ubiquiti AP. The only one that really works in our case is the Ubiquiti. Also for a home that's mostly Apple hardware, you kinda need a manage wifi solution, because Apples WIFI stack have issues switching between APs and needs a controller to kick you off (I don't know if that's still the case). Ubiquiti have one of the only routers that will force Apple hardware to switch APs. Mikrotiks CAPsMAN isn't even really a WIFI/AP controller, it's just provisioning.
For all it's flaws, I still really want to just run 100% Mikrotik gear.
I don't have any mikrotik hardware new enough to support it so I haven't tried it myself yet and documentation is (as usual) pretty lacking, but like you I want to believe.
The Flint 3 just launched, and the headline feature is WiFi 7: that should be less of an issue if you're going with separate APs.
We use all Mikrotik hardware for routing. RouterOS is so flexible and capable. But it is absolutely not user friendly.
For large scale commercial deployments we use Ubiquiti equipment. There is always a Mikrotik router but the APs are all Ubiquiti. It’s just easier and cleaner for us to manage deployments that way.
I see no reason why someone just casually playing with their home network would use Mikrotik though.
We use Cambium for Point-to-Multipoint mostly because the price and selection is better than Ubiquiti but we use the wireless backhaul gear from Ubiquiti in a few spots.
To be perfectly honest if Ubiquiti had the right kind of hardware and management capabilities for us to serve as the root of any deployment I would probably use it everywhere.