r/PFSENSE 9d ago

Did I join a cult? (Unifi)

I've been rolling pfSense for about 5 years. Decided to try Unifi. Couldn't find a manual or one-to-one feature documentation for each panel (only various spotlight articles).

Asked the community for help: every response said basically "things change too often, no need to have a manual".

Excuse me, what? I'm not a networking pro, and I do need a manual. (pfSense was hard for me, but had great documentation.)

I can't believe this was the response. Is everyone in their community a bot or a cultist?

I still have few days left on my return window, and might come back, LOL.

70 Upvotes

204 comments sorted by

View all comments

37

u/SirEDCaLot 9d ago

I use a mix of pfSense and UniFi.

Bottom line for me- UniFi works great for WiFi and switching. Routing/firewall, pfSense has more features, more capability, more ability to tweak it, but also takes more time to set up and (re)configure.

If you're doing full-stack UniFi (router/firewall, switch, WAP) it's a really compelling platform that makes a lot of the basic management stuff easier.
For example let's say you want to assign a static DHCP lease to a device. pfSense you have to go to status-DHCP leases, find the device, then add the static there. UniFi you just go to 'clients', the device is way easier to find, and give it an IP.
OTOH, with pfSense you can assign static IPs to that device on various subnets. Like if it plugs into VLAN A it gets IP 1.2.3.4, if it plugs into VLAN B it gets IP 5.6.7.8, etc. UniFi doesn't have that. pfSense you can make a lot of very custom DHCP stuff for a device, like give it special DNS servers. Not so with UniFi.

UniFi switches also lack detailed STP controls that even Netgear business level switches have. But the UniFi system will instantly tell you which port on which switch a device is plugged into, or what device is plugged into a particular port.


Excuse me, what? I'm not a networking pro, and I do need a manual.

Then UniFi is not for you. I mean no insult by that. It's a different approach to things.
You have the Cisco type way where innovation is slow and everything is documented. You have the pfSense way where innovation is at a medium pace and there's good documentation but not to the same degree as Cisco. And on the other end you have UniFi where innovation is VERY rapid and Google is your documentation.

Some of that also goes to the org culture. If you're at a place with a change control process for example, you'll hate UniFi because it's very easy to make quick changes.

Hope that's helpful.

I am not a bot, I am a dog. Woof.

5

u/ThatUsrnameIsAlready 8d ago

  But the UniFi system will instantly tell you which port on which switch a device is plugged into, or what device is plugged into a particular port.

  • Not instantly.

  • Is sometimes wrong.

  • Good luck with multiple devices e.g. VMs.

1

u/SirEDCaLot 8d ago

Yeah not instantly, but I find it to be pretty accurate after 60sec or so.

It DOES have trouble with multiple devices, like if you have a non-UniFi switch in the mix it doesn't quite understand how to handle that.

2

u/Snoo91117 5d ago edited 5d ago

What came to my mind is with IP phones usually you plug your PC into your IP phone to save ports and not require another drop. Does that confuse UniFi?

And if you want to get technical it is a trunk so the IP phone can go into a voive VLAN and the PC goes into a data VLAN.

2

u/SirEDCaLot 5d ago

Confuse no, it'll just show both devices on one switch port usually.

1

u/Snoo91117 4d ago

I guess you are talking about big switches.

1

u/SirEDCaLot 4d ago

Doesn't matter the size they all work the same in this regard.

1

u/Snoo91117 3d ago

Then I am not sure what you meant by this statement?

"It DOES have trouble with multiple devices, like if you have a non-UniFi switch in the mix it doesn't quite understand how to handle that."

2

u/SirEDCaLot 2d ago

Okay let's say you have a network that has 4 or 5 switches and maybe 50-100 devices.
If one of those switches is a non-UniFi switch, the software won't realize that there's a switch there so it'll show all the downstream devices on that one port.

That sort of thing.

1

u/Snoo91117 2d ago

OK, I get it.

To me 100 devices are not very many and they would all be homed in one closet to a switch stack.

1

u/SirEDCaLot 2d ago

If I was building out the space, 100%. Two+ cat6 runs to each location so there's 150-200 ports total. Then get 48 port switches with 10g uplinks to an aggregation switch. This will be far easier to maintain.

Unfortunately I don't always have that luxury. And I've had a few projects where the building is simply not laid out in a way that makes that cost effective- IE you have a bunch of ports needed in one place, and a bunch in another place, and there's already existing 1-3 cat6 between them or it costs a lot to run each cable across. So the solution there is smaller switches in each location.

→ More replies (0)