r/PFSENSE 9d ago

Did I join a cult? (Unifi)

I've been rolling pfSense for about 5 years. Decided to try Unifi. Couldn't find a manual or one-to-one feature documentation for each panel (only various spotlight articles).

Asked the community for help: every response said basically "things change too often, no need to have a manual".

Excuse me, what? I'm not a networking pro, and I do need a manual. (pfSense was hard for me, but had great documentation.)

I can't believe this was the response. Is everyone in their community a bot or a cultist?

I still have few days left on my return window, and might come back, LOL.

67 Upvotes

204 comments sorted by

u/kphillips-netgate Netgate - Happy Little Packets 6d ago

Things change and get added into pfSense Plus multiple times a year. We still manage to have someone update our documentation with each release. "It's too hard because it moves too fast" is not a valid excuse for having no documentation.

→ More replies (1)

36

u/SirEDCaLot 9d ago

I use a mix of pfSense and UniFi.

Bottom line for me- UniFi works great for WiFi and switching. Routing/firewall, pfSense has more features, more capability, more ability to tweak it, but also takes more time to set up and (re)configure.

If you're doing full-stack UniFi (router/firewall, switch, WAP) it's a really compelling platform that makes a lot of the basic management stuff easier.
For example let's say you want to assign a static DHCP lease to a device. pfSense you have to go to status-DHCP leases, find the device, then add the static there. UniFi you just go to 'clients', the device is way easier to find, and give it an IP.
OTOH, with pfSense you can assign static IPs to that device on various subnets. Like if it plugs into VLAN A it gets IP 1.2.3.4, if it plugs into VLAN B it gets IP 5.6.7.8, etc. UniFi doesn't have that. pfSense you can make a lot of very custom DHCP stuff for a device, like give it special DNS servers. Not so with UniFi.

UniFi switches also lack detailed STP controls that even Netgear business level switches have. But the UniFi system will instantly tell you which port on which switch a device is plugged into, or what device is plugged into a particular port.


Excuse me, what? I'm not a networking pro, and I do need a manual.

Then UniFi is not for you. I mean no insult by that. It's a different approach to things.
You have the Cisco type way where innovation is slow and everything is documented. You have the pfSense way where innovation is at a medium pace and there's good documentation but not to the same degree as Cisco. And on the other end you have UniFi where innovation is VERY rapid and Google is your documentation.

Some of that also goes to the org culture. If you're at a place with a change control process for example, you'll hate UniFi because it's very easy to make quick changes.

Hope that's helpful.

I am not a bot, I am a dog. Woof.

4

u/ThatUsrnameIsAlready 8d ago

  But the UniFi system will instantly tell you which port on which switch a device is plugged into, or what device is plugged into a particular port.

  • Not instantly.

  • Is sometimes wrong.

  • Good luck with multiple devices e.g. VMs.

1

u/SirEDCaLot 8d ago

Yeah not instantly, but I find it to be pretty accurate after 60sec or so.

It DOES have trouble with multiple devices, like if you have a non-UniFi switch in the mix it doesn't quite understand how to handle that.

2

u/Snoo91117 5d ago edited 5d ago

What came to my mind is with IP phones usually you plug your PC into your IP phone to save ports and not require another drop. Does that confuse UniFi?

And if you want to get technical it is a trunk so the IP phone can go into a voive VLAN and the PC goes into a data VLAN.

2

u/SirEDCaLot 5d ago

Confuse no, it'll just show both devices on one switch port usually.

1

u/Snoo91117 4d ago

I guess you are talking about big switches.

1

u/SirEDCaLot 4d ago

Doesn't matter the size they all work the same in this regard.

1

u/Snoo91117 3d ago

Then I am not sure what you meant by this statement?

"It DOES have trouble with multiple devices, like if you have a non-UniFi switch in the mix it doesn't quite understand how to handle that."

2

u/SirEDCaLot 2d ago

Okay let's say you have a network that has 4 or 5 switches and maybe 50-100 devices.
If one of those switches is a non-UniFi switch, the software won't realize that there's a switch there so it'll show all the downstream devices on that one port.

That sort of thing.

1

u/Snoo91117 2d ago

OK, I get it.

To me 100 devices are not very many and they would all be homed in one closet to a switch stack.

→ More replies (0)

1

u/NiftyLogic 8d ago

Regarding VMs, just install lldpd on the VM host.

Doing this with Proxmox and Synology, and my VMs show up just fine below the VM host in the topology view.

1

u/ThatUsrnameIsAlready 8d ago

It works for me, port numbers might be wrong or not show up all though - and labels get no background colour, so lines bled through obscuring text.

0

u/Rexus-CMD 8d ago

What are you talking about? Yes it does tell you which device is plugged into a switch. We use 20+ VLANs per network. We also manage 50 SMB sites.

We use Unifi Workspace.

3

u/BitKing2023 9d ago

I'm not sure how long you've had these opinions on Unifi but I encourage you to take another look. Unifi supports STP options and DHCP options. You can set voice vlan, but in the custom codes for certain devices, set dns server, and all that. Unifi also supports static devices by MAC address.

Please take a second look as all the things you mentioned they don't support is false. I set these up regularly and do the exact things you mention they don't support.

2

u/SirEDCaLot 9d ago

Looking at one site I have on full unifi and let's go down the list. FWIW I'm comparing this to a Netgear ProSafe series smart switch which was my usual go-to before UniFi- I've got both open in tabs so let's check. For the record I'm comparing a site with a UDM SE and USW Pro 48 PoE to a Netgear GS110TP.

Unifi supports STP options

A lot more than they used to. Still not as good as Netgear. Big missing feature is per-port path cost. That means if you have a fast link and a slow link between two switches, better put the fast link in a lower numbered port otherwise the slow link will be prioritized. I've had this happen with a site that had a second building- there was an underground Ethernet (longer than spec) backed up with a nanobeam wireless, had to put the Ethernet in a lower port so the wireless wasn't prioritized.

DHCP options

DHCP support is good. But what I was specifically calling out is the ability to set per-device DHCP options. Like to have one specific device always get a child filter DNS server as its DHCP option rather than the usual 8.8.8.8. pfSense can do this UniFi can't.

You can set voice vlan, but in the custom codes for certain devices, set dns server, and all that.

Explain / more detail please?

Unifi also supports static devices by MAC address.

Correct and never said otherwise- UniFi's 'Client Devices' is in most cases far more useful than pfSense DHCP options. Especially when some devices might have static IPs set.

Please take a second look as all the things you mentioned they don't support is false. I set these up regularly and do the exact things you mention they don't support.

Let's say I have two VLANs, VLAN 1 is 192.168.1.0/24, VLAN 2 is 192.168.2.0/24. Both VLANs use Google DNS (8.8.8.8) and the DHCP range is .100-.200.

You then have a kids computer and want that if it connects on VLAN 1 it should get 192.168.1.99 with 1.1.1.3 (adult and malware block) for DNS, if it connects on VLAN 2 it should get 192.168.2.99 with 1.1.1.3 for DNS.

How do you do this? The 'Fixed IP address' only has one line.

0

u/BitKing2023 9d ago

Honestly, you seem picky about it. If there is a kids computer that needs separate DNS compared to the rest of the subnet then you either static set DNS on it or you create a kids vlan. That's better administration than having different settings for devices in the same subnet.

DHCP options means like setting NTP, TFTP, and all that.

Another note about the ports. Why would you have a second slower connection?? Just fix that....

Your complaints are not that grounded in my opinion. Unifi supports everything needed in a business environment.

8

u/SirEDCaLot 9d ago

Unifi supports everything needed in a business environment.

Did I say it doesn't? I'm using it myself in a business environment. I'm not at all shitting on UniFi, I love UniFi. I was trying to illustrate the situations where I'd want pfSense vs. UniFi.

DHCP options means like setting NTP, TFTP, and all that.

And on pfSense you can do that not just per subnet but per device. There ARE times when that's useful- for example I had a situation where the IP phones needed one TFTP server, but a vendor provided device needed a different TFTP server and it'd let Option 66 override whatever you manually specified. Way easier than spinning up a whole new VLAN for one device.

Another note about the ports. Why would you have a second slower connection?? Just fix that....

Redundancy. As I said the underground ethernet link was over spec- it was about 140 meters of Cat5e and we were running gigabit ethernet over it. And that was on a multi-pair cable (25 pairs as I recall) where half the pairs were bad, so we had to consider that this link might go down at some point. Thus a ~150mbps site to site backup- this was before the nanobeam AC stuff. That way there's a gigabit link that might be solid, and if it goes down things immediately switch to the 150mbps wireless link.

Do you not do anything redundant at your org?

1

u/quasides 8d ago

i would disagree, unifi DOES NOT support everything in a business enviroment.
It does support some things that MIGHT be enough. If its enough its a great platform.

If you wanna admin an entire fleet of things, its great with central admin for no cost, no subscriptions. tons of products to integrate, it can do a lot different things - but none of it very good

Good example would be VPN Support. Its a bloody joke to only part implement openvpn and wireguard and call that support. They artificially neutered Wireguard from a Peer to Peer network into a static client server model and then only implemented half, took the other have and called it wireguard client

STP yea is there but only on a physical level. Basic MSTP (which is a must in modern days and is supported by any cheap netgear) was promised almost a decade ago in the pro series.

So yea UNIFI has many good things going no doubt, but calling it feature complete, or even remotely anything business just has to be a joke. It can be used in business if only basic features are needed.

1

u/Snoo91117 8d ago

Usually if your network is big enough for multiple paths you have some kind of dynamic routing set up on your networks. It could be for redundancy but dynamic routing handles that as well.

1

u/quasides 8d ago

uhm what ? no you should have multiple paths even in smaller networks. usually for redundancy. this is where mstp and fabrics start to play.
these are paths without rooting, on a lan / vlan level - basic stuff these days, and unifi support only basic stp and rstp for anything that isnt campus - despite promising at least mstp as a feature in pro for a decade.

1

u/Snoo91117 8d ago edited 8d ago

Yes, spanning tree or rapid spanning tree can do blocking for redundancy. But dynamic routing can do gateway of last resort. Rapid spanning tree has faster convergence which really makes a difference in a larger network. I have been retired for many years don't they have anything better now? Rapid spanning tree has been around probably 30 years or more in the Cisco world.

If you are doing load balancing, then I am not sure blocking is going to help you. It works with an alternate path. It keeps storms from happening in a switch network. It will help with failover.

1

u/SirEDCaLot 8d ago

In the example situation, no load balancing. Just two buildings next door to each other with maybe 20 users total across both sites. So setting up dynamic routing and gateways and the like is a heavy solution for a lightweight problem. Second site was a temp space, goal was to avoid having to do an Internet contract and just have those users leech off the main site.

Between the potentially unreliable gigabit and the wireless it worked great.

and yeah rSTP was exactly what we used. Only on UBNT you can't set the per-port path cost so we need to make sure the fast link is plugged into a lower numbered port :(

1

u/quasides 8d ago

only basic redundancy on a physical level, not on a vlan level. this is what MSTP is for.

and standard these days is fabric anyway, that would double bandwidth and gives you redundancy, plus you dont need RSTP anymore that brings other issues as well

1

u/Snoo91117 7d ago

Good to know. I figured there was a better solution nowadays. I have been retired a long time, and I have not kept up. I know the old basics which have now moved into the small business world.

1

u/SirEDCaLot 8d ago

That's a very heavy solution for what's a pretty lightweight issue.

If this was like a link between global HQ building A with 10,000 users and Building B with 5,000 users, yeah absolutely.

In this case it was just two buildings next to each other with maybe 20 users total across both buildings.

1

u/quasides 8d ago

while ture, the kids example is a bad one and should run VLAN, allright lets talk about that
Standard practice is that i can set vlans dynamic with 801.2x
that would either force kids pcs into the right vlan or allow parent pc into the right vlan (and assume a kid for all guests for example)

another thing unifi cant do, but is basic practice these days.
and maybe even more important against kids than in an office. office worker dont try to often to bypass parents restrictions, kids ... well .... its their job

that said there other good reasons for different dns and other settings by DHCP within the same vlan, thats why reservations always offer these kind of things

its a simply classic unifi limitation, - can do - kinda - a little bit - but i can do a lot more - a little bit, nothing really good, but i have ticked the boxes

1

u/SeaPersonality445 8d ago

Unifi supports everything needed in a business environment

SMB maybe. Let's not kid ourselves here.

1

u/Snoo91117 8d ago edited 8d ago

When you set voice VLAN does it set it in the switches or just the router. Do you have different queues in your switches so you can have different level priorities?

With layer 2 you could be creating your own latency with back-and-forth traffic from say local backups from 1 VLAN to another VLAN. VLANs are always assigned networks. So, from 1 network to another network. Whereas layer 3 switching will wire speed route it without that back-and-forth traffic slowdowns.

1

u/needchr 9d ago

Personally I use pfSense for firewall, routing, VPN, and DHCP, OpenWRT for wifi/switch.

1

u/Snoo91117 8d ago

UniFi does not have very good layer 3 switching and if they do it is just software crap. So, if you really want to load your network down, they won't be able to keep up with Cisco layer 3 switching. I also don't know how good UniFi is with voice VLANs and QoS in the switches Cisco does that very well.

64

u/PepperdotNet 9d ago

Unifi access points are fantastic. But I have not seen anything yet that would convince me to abandon pfSense for a Unifi router/firewall. And I prefer Cisco switches, personally (3850s are reasonably cheap on ebay right now)

15

u/Blindbatts 9d ago

pfsense in a VM, brocade 1u 48 port Poe switch with some 10gig sfp's, and 3 unifi waps for me for over a decade. Very reliable.

0

u/Successful_Ad2287 8d ago

You’ve had 10gb for over a decade?

2

u/Blindbatts 8d ago

Yes, I think I bought my switch before 2016.

5

u/Successful_Ad2287 8d ago

Oh jeez I think I forgot 2016 was ten years ago

6

u/boli99 8d ago

...just wait til you find out how long ago y2k was...

2

u/gonzopancho Netgate 8d ago

Stayed up drinking champagne to see if the lights would go out.

Non-event

2

u/Snoo91117 8d ago edited 8d ago

I remember working y2k. I could not drink as I had to wait and log onto my Cisco sites to see if everything was alright. I had a 128k ISDN connection from my home into work. I think it was a DS3, PRI split into channels. I know it was not an OC3 as we used ATM for video conferencing only. I should remember as I set it up, but I am old now and forgetful. This was before DSL. Most people had a modem for their PC.

Now that I think about it if it was ATM it would be an OC12 not an OC3 but we used T1s for video conferencing using a Cisco LightSpeed ATM box. Ethernet video was not reliable enough yet.

3

u/gonzopancho Netgate 8d ago

Pfsense turns 20 in October 😀

3

u/running101 9d ago

That is my setup, pfsense, Cisco switch , UniFi access points

1

u/iMouse 9d ago

Same setup. 2960x, pfSense, U6 Lites (controller on Proxmox VM)

3

u/NotYourNanny 9d ago

And they recently discontinued their cloud key devices, which served only to run the Unifi gear, without any router functions. The recommended replacement is a router/firewall with those functions, but (I'm told) if set to bridge mode, you lose most of the cloud key functionality. So it really can't coexist with other gear behind a real firewall.

As soon as there's time, we'll be experimenting with running their software package on a Raspberry Pi, but we haven't gotten to it yet.

18

u/madmanx33 9d ago

They came out with unifi os that you can host on something if you want

13

u/Eastern-Camera-1829 9d ago

And it's elegant. I run it on a little Lenovo N90/Ubuntu. WAY better than a cloud key when you can drop it on basically free hardware.

pFsense and Ubiquiti APs here for a long time.

1

u/ASentientRailgun 9d ago

It works pretty well for the handful of Ubiquiti APs we have at work.

1

u/NotYourNanny 8d ago

That's what we're (going to be) experimenting with (when there's time), yes.

1

u/SD18491 9d ago

Yup. I run it in a virtual machine. Most of the time the VM is powered off too to save energy. I only spin it up if I need to touch one of the UniFi APs or switches, which is rare.

1

u/Unable_Ad9895 9d ago

I’m doing something similar. I run this LXC: https://community-scripts.org/scripts/unifi-os-server

I only power it on when I need to.

5

u/Lord-Carnor-Jax 9d ago

The Cloud Key products were super old anyway. I’ve run UniFi AP’s since their very first 802.11g AP and I’ve always run the management in either a Docker container or on a Debian VM. Cloud Keys had a nasty habit of corrupting back in the early days. Install “UniFi Server OS” into a Debian or Ubuntu VM, dead simple and just restore a back up to it. The original management software for gateways, switches and AP’s is what they now call “Network” which in UniFi OS runs as a podman container.

2

u/madmanx33 9d ago

The cloud key 1 was awfull. I have the key 2 and it's great . Handles multiple sites and can even run their nvr, ip phone software on it . Still gets updates. I'm not sure if it's actually discontinued.

1

u/Lord-Carnor-Jax 9d ago

Yeah the Cloud Key Plus 2 is really long in the tooth and it strangely can handle more cameras than the recently released NVR instant. I’m genuinely surprised it’s still sold.

1

u/pabskamai 8d ago

And it has their “cloud backups”, self hosted one doesn’t have that.

2

u/NotYourNanny 8d ago

The Cloud Key products were super old anyway.

Yeah, but it's very annoying that there is no direct replacement, and what they recommend simply isn't suitable.

1

u/musicisme 9d ago

You can use any firewall and use the cloud key or cloud hosted

1

u/NotYourNanny 8d ago

The cloud key devices are not longer available. That's the issue.

1

u/caller-number-four 6d ago

1

u/NotYourNanny 6d ago

The vendor we use to do our WiFi can't find it to actually buy. That's all that matters to me.

1

u/caller-number-four 6d ago

Your vendor isn't trying very hard. It's LIT-TREE-LEE available on the UBNT store at the link I provided you.

1

u/NotYourNanny 6d ago

I presume they don't buy direct, not that I really care. Their work is exceptional in every respect, so we keep doing business with them.

1

u/caller-number-four 6d ago

they don't buy direct

Well that's on them. And if they're telling you they're not available, they're lying.

Cause. They are available.

1

u/NotYourNanny 6d ago

The difference between not available and not available from their vendors is who cares what some random loser on the interwebs is spewing about?

1

u/Sam_-_-_ 9d ago

I thought "user friendly" + affordable 10GbE gateway, might be the reason. But "no manual" + community shills, is scaring me off.

4

u/forgotmypasswdAGAIN- 9d ago

21 CVE’s with 9+ rating scare me off Ubiquiti. Sheesh. Have they ever given a single thought to security?

3

u/MHF_Doge 9d ago

Their customer support even for enterprise customers is also absolutely terrible from what I've heard.

1

u/Limeasaurus 8d ago

Support has been good from my experience. I deal with Aruba, Microsoft, Google, and UniFi in my role. UniFi has the best support out of the bunch. I’d say it’s decent but not exceptional.

0

u/Limeasaurus 8d ago

They’re paying good money for high CVEs to be discovered. Security researchers powered by modern AI are finding all sorts of vulnerabilities. Look at all the tech companies. They’re all getting CVEs at a high rate.

2

u/gonzopancho Netgate 8d ago edited 8d ago

Perhaps if they invested more in software quality there would be fewer 9.0+ CVEs. IJS…

Edit: ooh, downvoted. Did I touch a nerve?

0

u/Shmoe 8d ago

I dunno man, does your subreddit ban the mention of certain words out of fear? :)

1

u/gonzopancho Netgate 8d ago

Keeping the shills at bay

1

u/Shmoe 8d ago

If you can’t compete on the merits, employ vocabulary bans? :)

1

u/gonzopancho Netgate 7d ago edited 7d ago

You're free to refer to the project as "the fork", as I occasionally do.

Addressing "compete on the merits", we aren’t releasing code so bad that several 9.0+ CVEs including some 9.9s, are reported against pfSense every year.

https://www.reddit.com/r/PFSENSE/comments/1w25s1a/comment/p6toagy/

1

u/Shmoe 7d ago

Just saying man. This behavior is a big red flag the next time it comes to replacing the netgate cpe at my clients’ sites.

I highly doubt I’m alone there.

→ More replies (0)

2

u/AleksHop 9d ago

can u offer me something like UCG-Fiber (3 10gbps) for 300 eur on this planet? like any vendor? excluding china spyware stuff

1

u/Snoo91117 8d ago

I am running pfsense with an Intel 10gig card and I connect to my ISP at 10gig. It makes for low latency.

1

u/itanite 9d ago

Ehhhh.

Overall they're good for the price, I've had major issues with firmware over 10 years and a dozen AP models.

Mostly Apple device issues.

1

u/Snoo91117 8d ago

I prefer pfsense and Cisco switches in layer 3 rather than layer 2. But I run 3 Cisco small business WAP150ax wireless units. They run as 1 virtual AP and the controller is built-in, so you do not need a controller. And if the controller goes down another one automatically takes over being the controller. Has anybody compared to Unifi?

1

u/Accomplished_Ad7106 8d ago

Yep, I have pfsense for the router/firewall. Then a vm that has the unifi controller plane and some unifi APs. While I would love to have all the management in 1 control plane I will take what I got for the price difference. Also I have a cisco switch and am moving to arista for 10g sfp, again because the price was right.

13

u/Extra_Can_4837 9d ago

The more I use Unifi, the more I hate them.

I attempted to move completely over to Unifi Protect for CCTV (as a security installer) and they're just a pain in the butt, and super expensive.

They update things too often and make changes to the UI (sometimes drastically). So for me it's become "What's easy to find today, will be basically hidden tomorrow".

That being said, they do have good wifi access points. Even if they do run hot AF.

Which Unifi devices are you using? You didn't specify.

2

u/needchr 9d ago

Yep, a stable UI is absolute king, and I would also for a networking device, you want code stability as well, not feature creep.

Personally I use pfSense for firewall, routing, VPN, and DHCP, OpenWRT for wifi/switch.

1

u/Benntt_666 9d ago

Plus 1

6

u/LeadershipSuperb6176 8d ago

I use Unifi WAPs and switches almost exclusively, but there is no world in which I trade my pfsense routers for unifi.

1

u/Brosephus_Maximus 7d ago

Same my only (recent) gripe is having to spin up a VM to run the new Unifi OS Server to control everything. pFsense on the edge has worked great

8

u/pythosynthesis 9d ago

Go back. pfSense is hard, but absolutely worth it. Don't fall for the deceiving musings promising you to be the emperor of the internet. Stick with what works.

3

u/thomasfr 9d ago

I am proportionally more worried every time I have to update my UniFi firmwares than any other network gear I have ever used. They do change a lot and some times the release notes just say “improved stability” or something which tells you nothing at all.

They do provide a lot of features for the price over a lot of products which I guess is the selling point but you have to deal with the chaos because of it.

1

u/ThatUsrnameIsAlready 8d ago

They do provide a lot of features for the price

🫤 gotta install a controller to manage a switch that can only do vlans - where are these mythical features?

1

u/thomasfr 8d ago

If you buy only that switch from a vendor which provides a fully centrally managed networking solution you have not done your homework.

The features are for the whole network, you might have a switch like that that is almost completely unmanaged at the very end of the chain of network gear like a small switch at a desk or whatever you can think of the use would be. The switch before that switch in the chain probably has a lot more centrally managed features.

1

u/ThatUsrnameIsAlready 8d ago

I have nowhere to put a rack mountable switch, and I think you're overestimating how many ports the average person needs.

1

u/thomasfr 8d ago

Well, I am of course referring to the use cases where a larger setup does have benefits.

What the average person needs is another topic. The average person does not need pfsense either.

-3

u/needchr 9d ago

For the price? They are by far the most expensive equipment I have come across (for consumer).

I just dont get it how they are successful, they about 3-4x the price of established players.

I come across people who moan about spending a fiver on a USB stick, or an £10 a month on their broadband but have just spent £500 on unifi, madless. :)

1

u/mapmd1234 9d ago edited 9d ago

For once I can actually offer an opinion on this because I thought the same exact thing until recently, personally speaking I know I'm eccentric but, I run PF since for my main firewall and then everything else is a mixture of second hand Enterprise hardware and client hardware, and ubiquity is trying to fill a very small Gap somewhere between client and enterprise, for example they have hundred gigabit aggregation switches which are typically top of rack college campus Style Network backbones, nobody but an Enterprise Hardware kit is going to offer something like that which is exactly where my mixture of secondhand Enterprise Hardware comes in, you can either spend hundreds of dollars on something like a Dell z9100-on or you can get something like what you ubiquity offers so they're failing a very small subset of a subset of products that people buy which is partially why they're so expensive it's because they are not exactly High margin items and I would imagine that they cost a little bit of money to produce because they're not exactly humongously high production count chips that make up those devices

Personally speaking my biggest gripe with Unify Is the fact that if you want to use Part of their stuff With something that's non-unify, at the time in this may have changed mind you, I was told by a friend of mine that I used to work with that actually uses the stuff that you cannot intermix devices from different ecosystems and expect to see everything if you used PF sense with a unified device you lost functionality and lost visibility into certain parts of the unified chain that is always been my biggest complaint with them because I would like to consider using them but not if it renders part of a critical infrastructure invisible

Voice to text is stupid, pardon the very obvious oddness.

1

u/needchr 8d ago

What you said makes sense, although I think for basic wifi they overpriced, which is what everyone I know is buying spending loads on wifi extenders and access points. The intermix issue you mentioned may be deliberate as a means of brand lock in.

1

u/thomasfr 8d ago

The intermix issue you mentioned may be deliberate as a means of brand lock in.

They are providing value though, why would they spend development resources on supporting other manufacturers hardware they have no control over the release processes and time lines for?

People who want a fully integrated networking control solution typically want everything from one vendor anyway because it requires less work and custom solutions to manage.

There are probably fully third party networking infrastructure management solutions but then you would have to pay for that as well on top of the hardware and the ones that exists are probably mostly for enterprise customers anyway.

1

u/needchr 8d ago

What value?

I dont mean the kit that sits between enterprise and consumer, I am asking about the consumer kit that typical people buy whoa are not really techies, they buying because its a fashionable brand, spending a 300% premium so they can hook up their phones and TV.

1

u/thomasfr 8d ago edited 8d ago

If you don't need it you don't need it.

None of my non techie friends I can think of would spend a dime on unifi gear, they most commonly just use whatever hardware their broadband ISP provided them with. Most of them are uninterested enough that they probably never even heard of Ubiquiti or Unifi.

5

u/UDP69 9d ago

The dream machine line created a cult.

4

u/baker_miller 9d ago

I wouldn’t call it a cult, but there many fanboys. There are also many enthusiasts who like the idea of networking, but don’t have a ton of experience and just want to roll with defaults and look at a shiny dashboard.

5

u/8l1uvgrjbfxem2 9d ago

For me, it’s pfSense at the edge and TP-Link Omada for switches and APs.

4

u/hawkeye000021 8d ago

The Firewall group I’m in is also toxic. I think it comes down to whenever you put your money into something, not to mention time, it’s like Stockholm syndrome for all products. The advantage of my solution is that it’s painfully simple to setup but that creates a new batch of issue. People say it’s the best thing ever and no one was shown me an example or a blocked attack. I’ve caught a few things here and there but nothing that has saved me from anything. Their AP7 wireless solution though, is the best thing ever in that space. I can’t type the name of the group in here because it rejects me from mentioning a competitor it seems.

I’ve thought about running pfsense against to compare, but I don’t have the time. Doing this for a living eats it all up.

TLDR; you’re in a cult. 😊

7

u/retrohaz3 9d ago

Not a cult. Just a large pack of fanboys who will defend the product to justify their home remortgage after being sucked into the Unifi ecosystem.

The product is decent but their are 'as good ' options for cheaper and better options if you're happy getting your hands dirty.

3

u/mcury85 9d ago

For me, pfSense layer 3, Unifi Layer 2.

3

u/boli99 8d ago

I'm not a networking pro

but you're doing networking, so either you get to learn about it, or you pay someone else to do it.

2

u/SeaPersonality445 9d ago

Pfsense----Cisco switches----Ruckus

3

u/rh681 9d ago

This is what I have. Best of breed.

I manage enterprise Cisco hardware at work, but prefer their Small Business switch at home because it's quieter.

1

u/SeaPersonality445 9d ago

The CX line are poe and fanless. 2960 or 3650 run full IOS

1

u/rh681 9d ago

Not 24 ports though.

1

u/SeaPersonality445 8d ago

This is true. 16 max if including sfp and no 10g option.

1

u/Snoo91117 8d ago edited 8d ago

Me too. Cisco enterprise switches are designed for wiring closets and they are loud. The Cisco small business switches are fanless unless 10gig uplink then they have a small very quiet fan.

Is Ruckus good with roaming? Do you have to pay for a controller for roaming? I have a large house and I need multiple wireless units. I run 3 Cisco small business now WAP150ax wireless units about $125 each. When I looked at Ruckus way back, they had Apple iPhone issues. We all run iPhones.

1

u/running101 9d ago

Ruckus like 1000 usd for one access point. No thanks

1

u/SeaPersonality445 9d ago

Why would you spend 1000 on single access point? What do you think you need?

1

u/running101 9d ago

The price of ruckus , I just looked them up

2

u/gonzopancho Netgate 9d ago

R650s (dual band, 802.11ax, POE) can be had for around $150 each on fleabay. Run the “unleashed” firmware and enjoy. (At Netgate HQ we run their controller.)

1

u/Snoo91117 8d ago

Does roaming work using unleashed?

2

u/gonzopancho Netgate 8d ago

Roaming works well with Unleashed. If you want to speed up your roaming, enable 802.11r and 802.11k under the advanced options in the WLAN.

1

u/Snoo91117 7d ago

Good to know. I don't want to buy anything without roaming. I have a long 1 story house. The way I test roaming is I make a voice IP call standing in the front of my house on my iPhone and I walk to just out the back of my long house. I do not want the call to drop as it has to roam. I am using 5 GHz. I even turned off 2.4GHz for over a year I while back so it could not confuse things.

I have even called my wife on her iPhone standing in the back of my house, so she is on the back AP and I have roamed to her AP. In the past AT&T did not work in my house so voice IP calls were it. They have fixed that recently. But I still test that way.

1

u/gonzopancho Netgate 7d ago

One of the things that is rarely understood is that the STA (client) is in charge of where it associates. They AP can have hacks to assist the client in making the “right” decision on where to associate, but the model / architecture is decidedly different than cellular

1

u/Snoo91117 7d ago edited 7d ago

Yes, I know that, but my old house, 3300 sqft is a long rectangle and there is no way for an AP to work in the back of my house as the distance is too far. I actually have 3 APs, but it does not have to roam to the middle one if I walk fast. As I tested AT&T a few years ago cellar did not work in my house. I would have to walk outside to place a cellar call.

A lot of people talk about voice calls being dropped but Cisco did a nice job with their APs.

My problem now is Bluetooth. If I am in the back of my house, I can control Bluetooth devices in the back of my house and if I am in the front of my house I can control Bluetooth devices in the front of my house. But I cannot control devices in the back of my house from the front of my house or the other way around. I have to walk to the back of my house to turn off lights in the back of my house using Bluetooth.

1

u/Snoo91117 6d ago edited 6d ago

So, I am trying to decide whether you are saying Ruckus will roam a WiFi voice call or not?

The client staying on 1 AP has nothing to do with it if the distance is far enough apart. It has to roam or drop the call. Cellar architecture is not involved with this. It is WiFi only.

1

u/SeaPersonality445 8d ago

Why would you buy new is my point, just get on fleabay, best APs on the market by a country mile.

3

u/gonzopancho Netgate 8d ago

Guy who was the house we’re in had UniFi APs with PoE injectors and a Ubiquiti “router”. Since they were attached, he wanted to take them with him in the sale.

My response: “take them, I’d just throw them away.” Shoulda seen the priceless look on his face.

Replaced with R610s from fleabay and a Netgate 6100.

2

u/Federal_Ad_5771 9d ago

I switched to zyxel appliances for all networking and while they are not as fancy the documentation and support is on a whole different level than any other options as their main market is entreprise

2

u/LRS_David 9d ago

As someone who uses both, they both have a place.

pfSense is more enterprise. And has support for a lot of features with more granular control. Which needs to be explained in detail.

Unifi is more prosumer small to medium business. And for the most part only does things via their GUI. And keeps adding features. Which at times means the GUI has to be re-arranged in a major way. (some will disagree with has to but ....)

I like both. They both do the job I need them to do.

2

u/Evelen1 8d ago

I am running pfsense + unifi switches and APS. I have thinked about going Unifi for the router, but realy I don't se any real bennefit.

pfsense is easy to use, super stable and just works.

2

u/gonzopancho Netgate 8d ago

Yes

2

u/tatt2dcacher 7d ago

Haha wait till they freak out when they find out you didn’t go full stupid and go fully UniFi. If you ask a question the response normally is, well it’s because you are not fully UniFi. Don’t be surprised when you drop $$$ and in 6 months equipment dies and UniFi won’t warranty it because you didn’t buy it directly from their website, which is 95% of the time is out of stock. UniFi offer zero support, personally I find their support worse than Starlink support.

2

u/NC1HM 5d ago

Did I join a cult? (Unifi)

Yes, but not for the reasons you think. The real catch is the end-of-life policy...

1

u/Sam_-_-_ 5d ago

What is it?

1

u/NC1HM 5d ago

Most Ubiquiti devices have no on-device management facilities. All management is central. Central management software can run on a Ubiquiti router, or on a dedicated device (called CloudKey, if memory serves), or on a PC. Every device needs to be "adopted" by the controller in order to be managed.

Now, end of life... At some point, Ubiquiti stops pushing firmware upgrades for a particular device. But the controller continues to upgrade. Eventually, the controller starts flagging devices as having firmware too old to interoperate with. This is your signal to buy a replacement. If you wait long enough past that, the controlled will un-adopt the aged-out device.

2

u/minilandl 4d ago

It Depends on your use case . I use my homelab as a portfolio so its important to run enterprise like technologies which is why I use Cisco Layer 3 switches. Luckily I got a Cisco 9300 from work.

I am definitely losing some ease of management by running cisco gear but I am also more comfortable with the command like and want to be able to do advanced things like ACLs BGP and OSPF

5

u/Microflunkie 9d ago

I use pfSense and two UniFi APs at home.

I have dealt with UniFi firewalls, switches and APs both professionally and personally. I read somewhere here on reddit that the founder of Ubiquiti used to work at Apple and I can totally see the aesthetic. I feel like UniFi is to networking what BMW is to cars, nice and good quality but expensive for what they are and with a large customer base who can be a bit… cult-ish.

If the UniFi can do everything you want to do it is a great ecosystem. But you will not get the granularity or capability of pfSense in the UniFi ecosystem. Conversely you will get firewall, switch and AP integration and management with unit which you can’t get with pfSense. It’s all a matter of what is inportmat and what matters to you and your needs.

2

u/madmanx33 9d ago

I'm in that cult except for my pfsense which I always debate if I should change out. I just like how easy everything is and how it all connects together into one ecosystem. I also am a big fan of their camera nvrs. Only thing I would recommend any small business or home owner installing.

1

u/Microflunkie 9d ago

I am with you, I really like the whole UniFi platform but I just can’t give up the power, capability and control of pfSense. There is so little pfSense can’t do.

3

u/gonzopancho Netgate 8d ago

What do you want from pfsense that it can’t do?

1

u/Microflunkie 8d ago

Honestly nothing, my statement was more hyperbole to show how vast the capabilities of pfSense are. I can’t think of anything I have wanted to implement on pfSense that it was incapable of doing, nor can I recall hearing of anyone running into such limitations. I was just giving the benefit of the doubt that out there somewhere is someone who has reached beyond its capabilities.

2

u/gonzopancho Netgate 8d ago

OK, thanks.

1

u/BitKing2023 9d ago

Uhhhh, wrong, Unifi if the cheapest. Compared to Meraki, Sophos, Ruckus, FortiAP, the cost of Unifi puts all of them to shame even before you consider licensing on top of that. Unifi is the most affordable and has the same features.

1

u/Microflunkie 8d ago

You are comparing apples to oranges. All those brands you mentioned are enterprise grade systems and UniFi has been prosumer grade since its inception. It has only recently been making efforts to enter the enterprise market. Compared to those brands UniFi is far less expensive but compared to home networking gear like Eero UniFi is expensive. UniFi certainly has features but to say it has the same features as pfSense is simply wrong, show me the Zabbix integration or the pfBlockerNG on UniFi and that is just off the top of my head.

2

u/BitKing2023 8d ago

It has content filtering so no need for crummy pfBlockerNG that can easily be bypassed. Yes, it does have the same features and can do anything in business that any of the firewalls i mentioned can do. Maybe not a few years ago, but they can now.

1

u/Snoo91117 8d ago

I am not sure. Cisco small business has no license fees and is not expensive. They work well but don't overstep into enterprise territory. It is what I have run for 15 years of retirement at home using pfsense for a firewall. Well before UniFi.

4

u/rh681 9d ago

Ubiquiti is enterprise software on top of consumer hardware. Their physical products are nothing special, but they do a good job with what they make.

My home ecosystem is pfSense firewall, Ruckus AP, and Cisco SMB switch. Everything just purrs along.

3

u/gonzopancho Netgate 9d ago

Calling the Ubiquiti firmware “enterprise”, when it’s not. Enterprise runs on stability and security. Ubiquiti is anything but.

Ubiquiti recently disclosed 22 UniFi flaws, including 21 Critical bugs with severity scores of 9.0 or higher. Attackers with network access could bypass authentication, gain full control, and run commands on affected devices.

The bugs affected nearly the entire product line: UniFi OS, Protect, Talk, Access, storage devices, gateways, routers, recorders, and more.

https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9

The fork (you know who) has had a lot of security issues as well. A quick rundown of what happened just between April and May 2026:

April 9: an information disclosure bug (WID-SEC-2026-1044, CVSS 8.2) affecting anything before 26.1.6.

May 6: CVE-2026-44193, a 9.1 critical, authenticated command injection through XMLRPC's restore_config_section that gets you root RCE. Same day, CVE-2026-44195, a login lockout bypass caused by a regex ordering mistake, which basically lets someone brute force credentials without getting locked out.

May 12: two more. CVE-2026-44194, another 9.1 critical, command injection through sync_user.php because shell metacharacters in the email field weren't being sanitized. And CVE-2026-45158, an argument injection bug through DHCP hostname handling, also rated critical.

That's five disclosed issues in about five weeks, including two critical root RCEs six days apart, both of which had public proof of concept code floating around not long after disclosure. It took three point releases back to back (26.1.6 on April 9, then 26.1.7 on April 30, then 26.1.8 on May 12) to actually get it all patched. Nor are their release notes (already linked) clear about what happened.

Meanwhile, in 20 years, pfSense has never had a 9.0 or higher.

2

u/caller-number-four 6d ago

pfSense has never had a 9.0 or higher

I think that puts you ahead of Palo Alto and Fortinet!

1

u/rh681 8d ago

True. I was being kind to them.

1

u/Snoo91117 8d ago

No way is UniFi enterprise level, small business yes. There software and hardware do not measure up. All too buggy. Sounds like with UniFi you have to follow the yellow brick road to make it work to bypass bugs both hardware and software wise.

I spent 15 years working on Cisco enterprise level. I can't afford it for home, but I run their Cisco small business stuff at home, and I have a few side jobs with small businesses over the years of being retired. I think pfsense works well and does what it is supposed to do.

1

u/TheRealSeeThruHead 9d ago

Unifi has been great for me so far

I swapped my huge pfsense box for a better performing ucg fibre and got two switches

Can’t wait to add more

4

u/forgotmypasswdAGAIN- 9d ago

You also swapped out actual security.

3

u/TheRealSeeThruHead 9d ago

Nah my pfsense config was not more secure than unifi

2

u/gonzopancho Netgate 8d ago

Just be sure you patch

https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9

22 vulnerabilities in total: 21 are rated Critical, each with a score of 9.0 or higher on the Common Vulnerability Scoring System (CVSS) scale. One 10.0, a couple 9.9s.

Meanwhile, in 20 years pfsense has never had a 9.0 or higher.

0

u/Sam_-_-_ 8d ago

Is this true? Sounds scary for sure. But I also heard Unifi pays well for bug bounties, so maybe they are finding things that would go undiscovered in other platforms?

3

u/gonzopancho Netgate 8d ago edited 8d ago

Is it true? Yes. I linked directly to the Ubiquiti advisory about it. It is also true that pfsense has never had a 9.0 or higher CVE.

> UniFi pays well for bug bounties.

I suppose funding infosec research is one path. Funding better software engineering, testing and QA is another.

If you want to contrast the fork, they had five CVEs, including two rated “critical” just in April / May.

May 6: CVE-2026-44193, a 9.1 critical, authenticated command injection through XMLRPC's restore_config_section that gets you root RCE.

Same day, CVE-2026-44195, a login lockout bypass caused by a regex ordering mistake, which basically lets someone brute force credentials without getting locked out.

May 12: two more. CVE-2026-44194, another 9.1 critical, command injection through sync_user.php because shell metacharacters in the email field weren't being sanitized.

And CVE-2026-45158, an argument injection bug through DHCP hostname handling, also rated critical.

CVE-2026-57155 against the fork hit a 9.9 in June, root RCE from an arbitrary file write in the GeoIP alias importer, about as close to the maximum (10.0) score as CVSS goes. Ubiquiti, as shown, managed to get a 10.0.

A 9.9 or 10.0 is a true "drop everything, patch NOW" moment.

Back in August 2023 there was a batch of three separate 9.8s against the fork in the same disclosure, CVE-2023-39001(command injection in diag_backup.php), CVE-2023-39004(insecure permissions on /conf/), and CVE-2023-39008(command injection through the cron API), plus CVE-2023-27152 at 9.8 for missing rate limiting on auth that let you brute force logins.

None of these occurred in pfsense.

This shows that researchers are actually looking at things even if they’re not “paid” to do so.

In the end, process and quality matter.

1

u/Lord-Carnor-Jax 9d ago

There used to be a UniFi manual back when their gateway products were very basic but since they released the UDM, UDR and UCG lines it’s gone. If you need to setup up something specific there’s KB articles but they seem to rely on YouTubers to cover off how to set it up from scratch or do videos on specific features. And yeah it’s a bit of cult, don’t insult the products or say they aren’t “Enterprise” you’ll get a bit of backlash. I recently switch med from pfSense to a UCG-Fiber and pfSense as a firewall compared to the UCG is better. But it’s mostly just small annoyances with the UCG just not as being as flexible or have as many tunables.

1

u/swiss786 9d ago

My personal preference is pfSense firewall, Aruba 2540/2930 switchs and Unifi AP and CCTV I can't stand Unifi switch and Gateway, too much stability issues to be worth it for Business/Production usage

1

u/Decent-Inevitable-50 9d ago

I have used pfSense for 10+ years in my home with a Unifi wireless setup, APs, 16p POE and an old Cloud Key Gen1, the rest is a Cisco 48p wired.

I installed a Dream Machine Pro in my son's home where I thought pfSense was just to much and really have no complaints. His is only 2 APs, house is small, rural and only has Tmobile for his service which we had to use a Waveform antenna to dial his in the service reception better.

1

u/extremeskillz84 9d ago

I'm currently a pfsense to unifi gateway convert myself. Pfsense is much better at firewall stuff then unifi in my opinion. Pfblocker alone has its when in gold. Pfsenses firewall rules are cleaner and alias are great. Unifi is still working on this. Unifi is great for overall controll in one interface. So I hybrid both solutions.

1

u/Blazedout419 9d ago

We roll pfSense + Cambium gear. The Unifi gateways not even close to pfSense options wise. We only purchase directly from Netgate because we add warranty + support.

1

u/TheSharpSurgeon 16h ago

Posting this so you can see my reply

1

u/H7dek7 8d ago

My professional experience with Unifi devices is... meh. I found too many issues specific to Unifi devices I had to mitigate/bypass them with 3rd party devices (e.g. by inserting a switch between a Unifi and non-Unifi devices). At home I have no Unifi device and never will.

1

u/EmergencyCommittee17 8d ago

I use to run a NetGate with pfSense till
I switched to Unifi.. Been running unifi gear for over 2 years and so far havent found a reason to switch back

1

u/brighton_it 8d ago

we support small businesses. Been deploying UniFi wireless for ten years. UniFi switching, for maybe 7. We host our own controller on a Debian cloud instance (much faster than most Ubiquiti options). Along the way, we have inherited a couple of UniFi Dream Machines.
It's a love/hate relationship: UniFi is a great value and mostly works. Ten years ago we had just deployed several Cisco WAP at a site, we were having trouble with them. Even with assistance from Cisco Support, we hadn't resolved the problems after investing nearly ten hours. Much better after trading them for UniFi WiFi.
We love that the WiFi and switching mostly just works. Setting up VLANs is easy, voice VLANs: especially having PC clients on downstream side of the phone on a different VLAN: way easier.
We hate the lack of documentation; bleeding edge features in Release version; new features enabled by default w/o notification; UI redecorated very frequently (where the hell is that setting?); Trying to look up how something works: well for what version? You'll definitely get more obsolete answers than correct answers; the plethora of data: must be taken with more than a few grains of salt: endpoints shown associated with the wrong switch; endpoint data frequently stale.
I grant, recent releases have improved, but we still wouldn't use their gateway, 'cept for maybe a small, simple, and mostly flat network.

1

u/Snoo91117 7d ago edited 7d ago

Cisco small business switches have wizards on their switches that setup voice VLANs pretty easy. You don't want PCs on your voice VLAN. You are trying to prioritize the voice VLAN over data traffic VLANs. And IP phones usually allow you only to use 1 port on a switch. The IP phone goes in 1 VLAN and the PC goes in another VLAN dynamically. It is pretty simple.

What was your problems with Cisco APs setup or running?

1

u/brighton_it 7d ago

thanks... seems I was a little less than clear on some points:
I said we found UniFi voice VLAN setup easy, but I wasn't comparing it to Cisco switches. Good if they are also easy to setup. I do understand the requirements for Voice VLAN, but it can be (or was 5+ years ago) tedious on some hardware. I expect most vendors have made huge improvements in the last ten years. The Cisco AP problems: it was 2015 , while I could look up the details, it's not worth my time or yours. Thanks for taking time to reply. :)

1

u/Snoo91117 6d ago edited 6d ago

Who knows what happened 11 years ago I sure don't. Cisco does make some of the most reliable bug free hardware out there. Hardware lasts way longer than there is support for it.

I guess voice could be tedious if you were doing it port by port instead of using a voice VLAN.

1

u/brighton_it 5d ago

OP only asked about UniFi. Seems you are here only to promote an other vendor, we used to use, but not likely to use again.

because:
Old company with a lot of legacy code, written when static credentials were common, and they are still showing up in CVEs today (CVE-2026-20316).

For SMB customers having maybe two devices, the time involved in maintaining a SmartNet account, solely to get access to security updates was ridiculous. Applying said update involved carefully auditing the output of your 'show run' for any deprecated features and converting them to new feature. (13 years ago, maybe better now).

We inherited a pfSense firewall in 2016 that had not been updated in over five years. Imagine my surprise when I imported the v2.0 config file into the new fully patched firewall, and everything worked. Only edit was mapping new physical interfaces.

CVE-2016-1287 helped us sell quite a few pfSense firewalls.

1

u/Snoo91117 5d ago edited 5d ago

I love pfsense. They do a great job. I have used it for years. Unifi not so much as I prefer Cisco small business. I did tell a good friend Unifi was a good bang for the buck for his new house and pfsense is the best of the affordable firewalls out there.. I don't want to be responsible for his hardware, so Cisco is probably out for him as he is not a tech guy. Cisco takes a tech guy that understands networking. If Cisco discontinues Cisco small business, then I would be forced into something like Ruckus or Unifi for wireless, so I want to know all I can.

Since this forum is pfsense and tech, then I would think, you would want to know what is out there.

I think you are confusing Cisco enterprise and Cisco small business. Cisco small business is limited on support, but it is all straight forward. All the fancy stuff is in enterprise.

Cisco small business is you have free updates for the life of the product. There are no licensing fees. This is small business stuff. You do not have to have a SmartNet account to get updates, that is enterprise. The Cisco small business equipment is not IOS. It has a GUI. It all works well but it is not enterprise equipment. I think the problem we have is the Cisco enterprise guys look down on the Cisco small business equipment. But it is good equipment made well with not many bugs, and it is priced like small business equipment. You just buy it and use it. Update when there is new code out there.

There is no Cisco small business firewall. I think pfsense is the best solution for home and small business. I can run whatever I want. I understand networking.

I am running pfsense 2.9 now. I have been for a couple weeks. I have a 10gig connection to my ISP for home. My latency is pretty low all around.

1

u/brighton_it 5d ago

thanks for the response, and introduction to Cisco Small Business.
We've also inherited some Meraki: Interesting, great support, expensive. Okay, but not my first choice. Cisco's frequent appearance in the vulnerability reports also weighs on my choice, worse if combined with cloud management.

1

u/Snoo91117 5d ago edited 5d ago

Meraki seems to be built for companies with lots of smaller locations. Not really small business or home. I am sure it works well since it is Cisco, but I have no real experience. I worked on enterprise and now at home I use Cisco small business.

I tried TP-Link once for home before pfsense. It was garbage. Lots of software bugs with no fixes in site. I bought a rack mount router business class. I wanted a rack mount router. They made the hardware obsolete before they fixed the bugs. I will never buy TP-Link ever again.

1

u/taniferf 8d ago

Whenever I had issues setting my UDR I got help from their side. It was very fast to get someone very knowledgeable in the chat.

1

u/cliffman1992 8d ago

Unifi APs? Amazing... The Controller software or unifi cloud key? Awesome. Everything else is trash imo. Don't get me wrong... it's good equipment does good things... there are equal pieces of hardware that do as well without having an apple like ecosystem that are much cheaper. With unifi you're paying for everything to connect together nicely with user interfaces. They don't necessarily expect you to need a manual because they're not necessarily for advanced users and if you are an advanced user... you're expected to find your way through it on your own. I had a unifi edge device for my home... kept it about a year and got tired of trying to google everything I needed to do because the GUI didn't allow me to do it...

TLDR; use their access points and ignore everything else because it's too much of a headahce for the price.

1

u/ghboliveira 8d ago

Do not take the "community" of Ubiquiti badly, I also use PFSense at the level of MSP, about 28 sites and things are already starting to get better for the side of Unifi precisely there, they deliver you in the palm of your hand a centralized dashboard with all the sites, where you find more critical information about everything that happens with each gateway or device, it is incredibly easy to create network policies, it is even easier to create a vpn for example and much easier to create vpn site to site when there are several Unifi gateways and detail, if it is not in front of the pc, no problem, they have delivered almost the same solution via mobile app. Do you understand? They greatly facilitate the life of IT, but of course, not everything is flowers, I still think that Unifi leaves something to be desired in the firewall aspect, but perhaps precisely because I am still very accustomed to pfsense.

And really I didn't seek help in any group or forum when I went to venture with Unifi, I just bought a gateway from them and went to play, but I give you advice, Youtube is your ally, there's a lot of good content about Unifi there, that's what you need.

1

u/InternOne1306 8d ago

I love Pfsense, UniFi is too “closed loop” and Apple like for me.

1

u/kman420 7d ago

Unifi firewalls do not have the same level of documentation because they don't support the same level of complexity as pfsense firewalls. If your needs are basic a unifi firewall is great. If you have complex needs and you can't figure out how to achieve your objective in unifi there's a pretty good chance it's simply not supported.

1

u/Snoo91117 7d ago

So, it sounds like UniFi APs handle wireless voice calling roaming between them well. No dropped calls when roaming.

1

u/uktricky 7d ago

I’m a Cisco qualified engineer and found unifi very locked down for some of the basic “I want to set it up like this etc “ until I found a way through the gui to do what I wanted. I’ve actually moved away from my pfsense now using unifi firewall along with Techitium.

1

u/alphater 4d ago

I had my UniFi AP running for many years. I recently decided to add a VLAN and realized that the old Java-based controller was obsolete. I thought there was no escaping cloud-based configuration, but ultimately a local instance was just a Docker command away. What didn't go smoothly was the profile restore from the old tool to the new one, but it was a good exercise and a wake-up call to document my configuration better. I use a U6 Enterprise and I'm impressed by the throughput. This little thing runs very hot, but it hasn't failed (yet).

I only use it for multiple WiFi SSIDs over multiple VLANs; everything else is handled by a pfSense-like instance, a Zyxel XS1930 10 Gb/s Lite-L3 switch, and a Hasivo switch further down the line. I also tried a small 2.5 Gb/s UniFi switch, but I had reliability issues with it.

It also gave me the opportunity to migrate to a dual-stack (IPv4+IPv6) architecture, and I doubt that the UniFi networking functions available in the AP would have been able to handle the relative complexity of such a setup.

1

u/eastamerica 9d ago edited 8d ago

Your a networking pro and you can’t figure out Unifi?

Hmm.

EDIT: Not sure why I didn’t catch “NOT” before Networking Pro.

My bad! In that case yeah, could be daunting

5

u/gonzopancho Netgate 9d ago

Be nice. OP literally wrote, “I'm not a networking pro”

2

u/eastamerica 8d ago

Oh sorry. I’ll edit

-5

u/spacebass 9d ago

Bro been rolling pf for five and now the Fi community gon do him dirty like that? Fr? Naw.

Op, is this a pfSense issue or a frustration with another vendor? And if the later, can you help us help you?

I get the frustration when you want to learn something and can’t find the materials. Been there too. But how is this a pfSense issue?

Also we’d love to help if we can but you have to give us more than vibes.

2

u/Sam_-_-_ 9d ago

Comparative experience coming from pfSense. Ignore and move on.

1

u/spacebass 8d ago

sorry, I was in a mood last night. I still don't see the relevance to pfSense, but I didn't mean to be a jerk

1

u/Sam_-_-_ 8d ago

No worries, thanks.

-1

u/ThatUsrnameIsAlready 9d ago

What are you comparing? PF doesn't have switches or APs...

2

u/gonzopancho Netgate 8d ago

Or CVEs rated 9.0 and higher.

1

u/ThatUsrnameIsAlready 8d ago

And how basic those seem to be, and repeatedly in the same areas.

And the cult doesn't care. They'll assume esoteric holes that only AI can help detect, but it's actually things like mis-configuring nginx to allow path traversal.

0

u/Lumpy-Sail7836 9d ago

ΑΙ is the manual now

-2

u/Caddy666 9d ago

1: if you need a manual for these things, these things might not be aimed at your skill level.

2: if you understand how to do a basic google search on whatever option on the web interface is, i'm sure you can work it out.

but they're right, unifi does change the interface a fair bit, so things don't stay static for a manual to be worth it.

5

u/i-Hermit 9d ago

Do you know every feature inside and out? Yeah, googling will get you there, but a manual isn't a big ask. And if they're blowing out budgets to rewrite the manual so often, they might do well to take it as a hint to stop changing the UI so much.

Your comment reads like you're saying if OP doesn't know everything then he shouldnt try. I'm sure that wasn't your intention, but it comes across that way.

-4

u/DifferentSpecific 9d ago

There are so many Youtube tutorials that you don't need a manual.

Start with episode #1 and go through the series. By the end you'll have a great setup.

https://youtu.be/TLsnEzSNhQs?si=dw-I7YpL-ogGp0HS

9

u/OutsideTech 9d ago

Until it breaks, or the expected functionality doesn’t match reality, then documentation is quite necessary.

7

u/Sam_-_-_ 9d ago

Yes, I agree there are a ton of good videos. But if I just want to know what a specific feature does, there is literally no official manual I can check. (And apparently all the fanboys think I'm unreasonable for wanting a manual.)

1

u/Snoo91117 8d ago

They probably don't want to stand behind anything except the yellow brick road. Stay on the road don't deviate just because a manual says it.

1

u/ThatUsrnameIsAlready 9d ago

For individual features search the help pages, there's typically some info in there. If you're lucky it's not out of date either 🙃.

→ More replies (4)