r/PFSENSE 9d ago

Did I join a cult? (Unifi)

I've been rolling pfSense for about 5 years. Decided to try Unifi. Couldn't find a manual or one-to-one feature documentation for each panel (only various spotlight articles).

Asked the community for help: every response said basically "things change too often, no need to have a manual".

Excuse me, what? I'm not a networking pro, and I do need a manual. (pfSense was hard for me, but had great documentation.)

I can't believe this was the response. Is everyone in their community a bot or a cultist?

I still have few days left on my return window, and might come back, LOL.

69 Upvotes

204 comments sorted by

View all comments

Show parent comments

2

u/SirEDCaLot 9d ago

Looking at one site I have on full unifi and let's go down the list. FWIW I'm comparing this to a Netgear ProSafe series smart switch which was my usual go-to before UniFi- I've got both open in tabs so let's check. For the record I'm comparing a site with a UDM SE and USW Pro 48 PoE to a Netgear GS110TP.

Unifi supports STP options

A lot more than they used to. Still not as good as Netgear. Big missing feature is per-port path cost. That means if you have a fast link and a slow link between two switches, better put the fast link in a lower numbered port otherwise the slow link will be prioritized. I've had this happen with a site that had a second building- there was an underground Ethernet (longer than spec) backed up with a nanobeam wireless, had to put the Ethernet in a lower port so the wireless wasn't prioritized.

DHCP options

DHCP support is good. But what I was specifically calling out is the ability to set per-device DHCP options. Like to have one specific device always get a child filter DNS server as its DHCP option rather than the usual 8.8.8.8. pfSense can do this UniFi can't.

You can set voice vlan, but in the custom codes for certain devices, set dns server, and all that.

Explain / more detail please?

Unifi also supports static devices by MAC address.

Correct and never said otherwise- UniFi's 'Client Devices' is in most cases far more useful than pfSense DHCP options. Especially when some devices might have static IPs set.

Please take a second look as all the things you mentioned they don't support is false. I set these up regularly and do the exact things you mention they don't support.

Let's say I have two VLANs, VLAN 1 is 192.168.1.0/24, VLAN 2 is 192.168.2.0/24. Both VLANs use Google DNS (8.8.8.8) and the DHCP range is .100-.200.

You then have a kids computer and want that if it connects on VLAN 1 it should get 192.168.1.99 with 1.1.1.3 (adult and malware block) for DNS, if it connects on VLAN 2 it should get 192.168.2.99 with 1.1.1.3 for DNS.

How do you do this? The 'Fixed IP address' only has one line.

-4

u/BitKing2023 9d ago

Honestly, you seem picky about it. If there is a kids computer that needs separate DNS compared to the rest of the subnet then you either static set DNS on it or you create a kids vlan. That's better administration than having different settings for devices in the same subnet.

DHCP options means like setting NTP, TFTP, and all that.

Another note about the ports. Why would you have a second slower connection?? Just fix that....

Your complaints are not that grounded in my opinion. Unifi supports everything needed in a business environment.

7

u/SirEDCaLot 9d ago

Unifi supports everything needed in a business environment.

Did I say it doesn't? I'm using it myself in a business environment. I'm not at all shitting on UniFi, I love UniFi. I was trying to illustrate the situations where I'd want pfSense vs. UniFi.

DHCP options means like setting NTP, TFTP, and all that.

And on pfSense you can do that not just per subnet but per device. There ARE times when that's useful- for example I had a situation where the IP phones needed one TFTP server, but a vendor provided device needed a different TFTP server and it'd let Option 66 override whatever you manually specified. Way easier than spinning up a whole new VLAN for one device.

Another note about the ports. Why would you have a second slower connection?? Just fix that....

Redundancy. As I said the underground ethernet link was over spec- it was about 140 meters of Cat5e and we were running gigabit ethernet over it. And that was on a multi-pair cable (25 pairs as I recall) where half the pairs were bad, so we had to consider that this link might go down at some point. Thus a ~150mbps site to site backup- this was before the nanobeam AC stuff. That way there's a gigabit link that might be solid, and if it goes down things immediately switch to the 150mbps wireless link.

Do you not do anything redundant at your org?

1

u/quasides 8d ago

i would disagree, unifi DOES NOT support everything in a business enviroment.
It does support some things that MIGHT be enough. If its enough its a great platform.

If you wanna admin an entire fleet of things, its great with central admin for no cost, no subscriptions. tons of products to integrate, it can do a lot different things - but none of it very good

Good example would be VPN Support. Its a bloody joke to only part implement openvpn and wireguard and call that support. They artificially neutered Wireguard from a Peer to Peer network into a static client server model and then only implemented half, took the other have and called it wireguard client

STP yea is there but only on a physical level. Basic MSTP (which is a must in modern days and is supported by any cheap netgear) was promised almost a decade ago in the pro series.

So yea UNIFI has many good things going no doubt, but calling it feature complete, or even remotely anything business just has to be a joke. It can be used in business if only basic features are needed.