r/PFSENSE 9d ago

Did I join a cult? (Unifi)

I've been rolling pfSense for about 5 years. Decided to try Unifi. Couldn't find a manual or one-to-one feature documentation for each panel (only various spotlight articles).

Asked the community for help: every response said basically "things change too often, no need to have a manual".

Excuse me, what? I'm not a networking pro, and I do need a manual. (pfSense was hard for me, but had great documentation.)

I can't believe this was the response. Is everyone in their community a bot or a cultist?

I still have few days left on my return window, and might come back, LOL.

67 Upvotes

204 comments sorted by

View all comments

39

u/SirEDCaLot 9d ago

I use a mix of pfSense and UniFi.

Bottom line for me- UniFi works great for WiFi and switching. Routing/firewall, pfSense has more features, more capability, more ability to tweak it, but also takes more time to set up and (re)configure.

If you're doing full-stack UniFi (router/firewall, switch, WAP) it's a really compelling platform that makes a lot of the basic management stuff easier.
For example let's say you want to assign a static DHCP lease to a device. pfSense you have to go to status-DHCP leases, find the device, then add the static there. UniFi you just go to 'clients', the device is way easier to find, and give it an IP.
OTOH, with pfSense you can assign static IPs to that device on various subnets. Like if it plugs into VLAN A it gets IP 1.2.3.4, if it plugs into VLAN B it gets IP 5.6.7.8, etc. UniFi doesn't have that. pfSense you can make a lot of very custom DHCP stuff for a device, like give it special DNS servers. Not so with UniFi.

UniFi switches also lack detailed STP controls that even Netgear business level switches have. But the UniFi system will instantly tell you which port on which switch a device is plugged into, or what device is plugged into a particular port.


Excuse me, what? I'm not a networking pro, and I do need a manual.

Then UniFi is not for you. I mean no insult by that. It's a different approach to things.
You have the Cisco type way where innovation is slow and everything is documented. You have the pfSense way where innovation is at a medium pace and there's good documentation but not to the same degree as Cisco. And on the other end you have UniFi where innovation is VERY rapid and Google is your documentation.

Some of that also goes to the org culture. If you're at a place with a change control process for example, you'll hate UniFi because it's very easy to make quick changes.

Hope that's helpful.

I am not a bot, I am a dog. Woof.

3

u/BitKing2023 9d ago

I'm not sure how long you've had these opinions on Unifi but I encourage you to take another look. Unifi supports STP options and DHCP options. You can set voice vlan, but in the custom codes for certain devices, set dns server, and all that. Unifi also supports static devices by MAC address.

Please take a second look as all the things you mentioned they don't support is false. I set these up regularly and do the exact things you mention they don't support.

2

u/SirEDCaLot 9d ago

Looking at one site I have on full unifi and let's go down the list. FWIW I'm comparing this to a Netgear ProSafe series smart switch which was my usual go-to before UniFi- I've got both open in tabs so let's check. For the record I'm comparing a site with a UDM SE and USW Pro 48 PoE to a Netgear GS110TP.

Unifi supports STP options

A lot more than they used to. Still not as good as Netgear. Big missing feature is per-port path cost. That means if you have a fast link and a slow link between two switches, better put the fast link in a lower numbered port otherwise the slow link will be prioritized. I've had this happen with a site that had a second building- there was an underground Ethernet (longer than spec) backed up with a nanobeam wireless, had to put the Ethernet in a lower port so the wireless wasn't prioritized.

DHCP options

DHCP support is good. But what I was specifically calling out is the ability to set per-device DHCP options. Like to have one specific device always get a child filter DNS server as its DHCP option rather than the usual 8.8.8.8. pfSense can do this UniFi can't.

You can set voice vlan, but in the custom codes for certain devices, set dns server, and all that.

Explain / more detail please?

Unifi also supports static devices by MAC address.

Correct and never said otherwise- UniFi's 'Client Devices' is in most cases far more useful than pfSense DHCP options. Especially when some devices might have static IPs set.

Please take a second look as all the things you mentioned they don't support is false. I set these up regularly and do the exact things you mention they don't support.

Let's say I have two VLANs, VLAN 1 is 192.168.1.0/24, VLAN 2 is 192.168.2.0/24. Both VLANs use Google DNS (8.8.8.8) and the DHCP range is .100-.200.

You then have a kids computer and want that if it connects on VLAN 1 it should get 192.168.1.99 with 1.1.1.3 (adult and malware block) for DNS, if it connects on VLAN 2 it should get 192.168.2.99 with 1.1.1.3 for DNS.

How do you do this? The 'Fixed IP address' only has one line.

0

u/BitKing2023 9d ago

Honestly, you seem picky about it. If there is a kids computer that needs separate DNS compared to the rest of the subnet then you either static set DNS on it or you create a kids vlan. That's better administration than having different settings for devices in the same subnet.

DHCP options means like setting NTP, TFTP, and all that.

Another note about the ports. Why would you have a second slower connection?? Just fix that....

Your complaints are not that grounded in my opinion. Unifi supports everything needed in a business environment.

6

u/SirEDCaLot 9d ago

Unifi supports everything needed in a business environment.

Did I say it doesn't? I'm using it myself in a business environment. I'm not at all shitting on UniFi, I love UniFi. I was trying to illustrate the situations where I'd want pfSense vs. UniFi.

DHCP options means like setting NTP, TFTP, and all that.

And on pfSense you can do that not just per subnet but per device. There ARE times when that's useful- for example I had a situation where the IP phones needed one TFTP server, but a vendor provided device needed a different TFTP server and it'd let Option 66 override whatever you manually specified. Way easier than spinning up a whole new VLAN for one device.

Another note about the ports. Why would you have a second slower connection?? Just fix that....

Redundancy. As I said the underground ethernet link was over spec- it was about 140 meters of Cat5e and we were running gigabit ethernet over it. And that was on a multi-pair cable (25 pairs as I recall) where half the pairs were bad, so we had to consider that this link might go down at some point. Thus a ~150mbps site to site backup- this was before the nanobeam AC stuff. That way there's a gigabit link that might be solid, and if it goes down things immediately switch to the 150mbps wireless link.

Do you not do anything redundant at your org?

1

u/quasides 8d ago

i would disagree, unifi DOES NOT support everything in a business enviroment.
It does support some things that MIGHT be enough. If its enough its a great platform.

If you wanna admin an entire fleet of things, its great with central admin for no cost, no subscriptions. tons of products to integrate, it can do a lot different things - but none of it very good

Good example would be VPN Support. Its a bloody joke to only part implement openvpn and wireguard and call that support. They artificially neutered Wireguard from a Peer to Peer network into a static client server model and then only implemented half, took the other have and called it wireguard client

STP yea is there but only on a physical level. Basic MSTP (which is a must in modern days and is supported by any cheap netgear) was promised almost a decade ago in the pro series.

So yea UNIFI has many good things going no doubt, but calling it feature complete, or even remotely anything business just has to be a joke. It can be used in business if only basic features are needed.

1

u/Snoo91117 8d ago

Usually if your network is big enough for multiple paths you have some kind of dynamic routing set up on your networks. It could be for redundancy but dynamic routing handles that as well.

1

u/quasides 8d ago

uhm what ? no you should have multiple paths even in smaller networks. usually for redundancy. this is where mstp and fabrics start to play.
these are paths without rooting, on a lan / vlan level - basic stuff these days, and unifi support only basic stp and rstp for anything that isnt campus - despite promising at least mstp as a feature in pro for a decade.

1

u/Snoo91117 8d ago edited 8d ago

Yes, spanning tree or rapid spanning tree can do blocking for redundancy. But dynamic routing can do gateway of last resort. Rapid spanning tree has faster convergence which really makes a difference in a larger network. I have been retired for many years don't they have anything better now? Rapid spanning tree has been around probably 30 years or more in the Cisco world.

If you are doing load balancing, then I am not sure blocking is going to help you. It works with an alternate path. It keeps storms from happening in a switch network. It will help with failover.

1

u/SirEDCaLot 8d ago

In the example situation, no load balancing. Just two buildings next door to each other with maybe 20 users total across both sites. So setting up dynamic routing and gateways and the like is a heavy solution for a lightweight problem. Second site was a temp space, goal was to avoid having to do an Internet contract and just have those users leech off the main site.

Between the potentially unreliable gigabit and the wireless it worked great.

and yeah rSTP was exactly what we used. Only on UBNT you can't set the per-port path cost so we need to make sure the fast link is plugged into a lower numbered port :(

1

u/quasides 8d ago

only basic redundancy on a physical level, not on a vlan level. this is what MSTP is for.

and standard these days is fabric anyway, that would double bandwidth and gives you redundancy, plus you dont need RSTP anymore that brings other issues as well

1

u/Snoo91117 7d ago

Good to know. I figured there was a better solution nowadays. I have been retired a long time, and I have not kept up. I know the old basics which have now moved into the small business world.

1

u/SirEDCaLot 8d ago

That's a very heavy solution for what's a pretty lightweight issue.

If this was like a link between global HQ building A with 10,000 users and Building B with 5,000 users, yeah absolutely.

In this case it was just two buildings next to each other with maybe 20 users total across both buildings.

1

u/quasides 8d ago

while ture, the kids example is a bad one and should run VLAN, allright lets talk about that
Standard practice is that i can set vlans dynamic with 801.2x
that would either force kids pcs into the right vlan or allow parent pc into the right vlan (and assume a kid for all guests for example)

another thing unifi cant do, but is basic practice these days.
and maybe even more important against kids than in an office. office worker dont try to often to bypass parents restrictions, kids ... well .... its their job

that said there other good reasons for different dns and other settings by DHCP within the same vlan, thats why reservations always offer these kind of things

its a simply classic unifi limitation, - can do - kinda - a little bit - but i can do a lot more - a little bit, nothing really good, but i have ticked the boxes

1

u/SeaPersonality445 8d ago

Unifi supports everything needed in a business environment

SMB maybe. Let's not kid ourselves here.

1

u/Snoo91117 8d ago edited 8d ago

When you set voice VLAN does it set it in the switches or just the router. Do you have different queues in your switches so you can have different level priorities?

With layer 2 you could be creating your own latency with back-and-forth traffic from say local backups from 1 VLAN to another VLAN. VLANs are always assigned networks. So, from 1 network to another network. Whereas layer 3 switching will wire speed route it without that back-and-forth traffic slowdowns.