*** Official Ubiquiti Discussion Thread ***

No worries. I'm pretty certain that it uses Wireguard under the hood so performance should be decent.
I like all the security features of the Firewalla (they're only doing one thing rather than Ubiquiti's fingers-in-every-pie, and they do it exceptionally well) but the multi-gig options are just too expensive ($900 plus import taxes). I don't know if Unifi have really improved their content filtering side of things (it was pretty basic last time I used a unifi gateway) but I think the dream machine offers me the best way to link all 3 sites.
 
Last edited:
This looks like a really interesting Network Application update:



Overview

Added support for Passpoint / Hotspot 2.0.
Requires firmware version 7.0.63/6.6.75/6.6.76 or newer.
Added AP Analyzer.
Gives full insights into Access Point performance and usage analytics.
Add Pro AV support to the Port Manager.
Pro AV on UniFi Switches uses QoS to automatically optimize traffic for specific audio and video environments by matching and prioritizing latency sensitive traffic. Configure Pro AV on individual ports using the Port Manager.
Requires firmware version 7.1 or newer on your UniFi Switch.
Supported models: USW-Pro-24/48-PoE; USW-Pro-24/48; USW-Pro-Aggregation; USW EnterpriseXG-24; USW-Enterprise-24/48-PoE; USW-Pro-Max-16/24/48-PoE; USW-Pro-Max-16/24/48

Added support for Advanced IGMP Snooping options.
Required USW firmware version 7.1.14 or newer.

Add Packet Capture option for Access Points.
Requires AP firmware version 7.0.63/6.7.1 or newer
Supported models: U7-Pro, U7-Pro-Max, U7-Pro-Wall, U7-Outdoor, U6-Pro, U6-IW, U6-Enterprise, U6-Extender, U6-Enterprise-IW, U6-Mesh, U6-Mesh-Pro, U6-Lite, U6-LR, U6+,
Future version will include also support for Gateways and Switches.

Improvements

Allow renaming the default network.
Allow editing host address and netmask when Auto-scale is enabled in network settings.
Added option to download Inspection logs when connected remotely via Site Manager.
Except for sites using NeXT AI Inspection. Support coming in future versions.
Added support for showing IPv6 addresses for UniFi Devices.
Requires AP firmware version 7.0.63 or newer.
Requires USW firmware version 7.1.14 or newer.
Added touchscreen rotation settings to switches.
Required USW firmware version 7.1.14 or newer.
Added Channelization page.
Added all clients tab to the clients page, only visible for smaller deployments.
Added alphabetical sorting for most of the dropdown selections.
Added Native VLAN column to Port Manager.
Added warnings to the AP side panel when powered by an insufficient power source.
Added Top Client column to Traffic Statistics.
Added IP address to Admin Activity logs, requires UniFi OS 4.1 for showing in Remote connection sessions.
Improved validation for SNMP settings.
Improved network auto-scale.
Start scaling when 90% of the addresses from the pool are used.
Improved default sorting in the Clients page.
Clients are now sorted by name instead of vendor.
Improved loading for the Topology page.
Improved application resiliency.
Prevent configuring RADIUS MAC Authentication when using WPA2/WPA3 Enterprise.
Updated list of supported File types in the Next AI Inspection.
Updated WiFi password requirements for Brazil.
This is a change required due to a new ANATEL legislation.
This change only takes affects on gateways with built-in WiFi. *
* Currently applies to all AP's, this issue should be fixed in a future release

Bugfixes

Fixed the inability to pause/resume 6GHz WiFi networks.
Fixed the inability to sort on Download/Upload columns on the Client page.
Fixed an issue where the Last Seen date was not shown for some offline UniFi Devices.
Fixed an issue where invalid maximum 6GHz WiFi speed limits were applied to AP's.
Fixed incorrect Policy Based Site-to-Site VPN status reporting in rare cases.
Known issues
USW-Lite-16-PoE might not show correct device image directly after upgrading.
 
Last edited:
All I want from Unifi is SAML auth to the controller and some sort of shameless clone of Aruba cloud auth
 
Just checking as its been a while since I've used Unifi so there are some features I want to check in on.

I know that on edgerouters it is (was?) possible to set different DNS servers for different VLAns, can I do that on the latest unifi/os (dream machine pro or SE)? I use cleanbrowsings safe dns servers for the kids vlans presently, as well as a private dns server for work devices.

I am pretty sure Unifi doesn't have a new device quarantine like Firewalla but is there some clever way I can prevent a new device from say getting an ip address when it connects to a certain network?

Content filtering - I know Firewalla was leaps and bounds ahead on this (one of the reasons I switched). Now I can technically keep my firewalla device as just a network device and not a router, and have it act as a content filtering device but I'm kinda hoping to sell it to recoup some money to put towards 3 dream machine SEs (gulp). The content filtering is excellent on Firewalla, and a lot is aimed at families, right down to application filtering. Safesearch, youtube for kids, etc that kinda thing. I know CF exists on Unifi but has it changed at all in the last few years? It was exceptionally basic when I last tried to use it and effectively just not good enough.

Can block at an individual device/vlan/network/group level in Firewalla, I don't recall that level of granularity in unifi, its going to be more the vlan level?

Adblocking - I can set this at many levels across different vlans in firewalla. Eg on the kids vlan its strict, on our network its moderate with sponsored ads blocked, on my work network its strict but sponsored ads allowed. I could go back to the pihole type route but I'd really rather not across 3 (possibly 4 if my sister in law gets in on it) houses.

Port scanning - its a nice feature that I can routinely scan my network(s) for any open ports I might not be aware of.

Lot of questions I know - TIA!
 
Last edited:
possible to set different DNS servers for different VLAns, can I do that on the latest unifi/os (dream machine pro or SE)?
Yes, under the DHCP options for a VLAN/network.
I am pretty sure Unifi doesn't have a new device quarantine like Firewalla but is there some clever way I can prevent a new device from say getting an ip address when it connects to a certain network?
I don't think it does, it's been asked for a few times so may be on the roadmap.
The content filtering is excellent on Firewalla, and a lot is aimed at families, right down to application filtering. Safesearch, youtube for kids, etc that kinda thing. I know CF exists on Unifi but has it changed at all in the last few years? It was exceptionally basic when I last tried to use it and effectively just not good enough.
I don't use it, but it looks pretty basic. None, work, family. But they don't appear to be configurable.


You can set individual client/network rules, but you'd have to configure it all yourself using traffic rules.
Can block at an individual device/vlan/network/group level in Firewalla, I don't recall that level of granularity in unifi, its going to be more the vlan level?
Block what exactly?
 
Last edited:
Block what exactly?
I'm able to block certain things (youtube, tiktok, custom urls, custom apps, internet at certain times, gaming sites, gaming services, gambling sites, social, porn etc) but I guess most of this can be done via dns at the vlan level.

Its just a nice feature to be able to pick a device or group and add certain rules.
 
Last edited:
I'm able to block certain things (youtube, tiktok, custom urls, custom apps, internet at certain times, gaming sites, gaming services, gambling sites, social, porn etc) but I guess most of this can be done via dns at the vlan level.

Its just a nice feature to be able to pick a device or group and add certain rules.
Ah, yes you can do that. You can select all devices, a specific one, or a network. Then block individual websites, apps, app groups, IP addresses, regions etc.

Clean-Shot-2024-08-07-at-10-09-38.png



Clean-Shot-2024-08-07-at-10-11-44.png
 
No worries. You'd have to check the release notes to see which version it came out in, I use Early Access versions as I very rarely get issues with them.
 
Actually, sorry, a follow up question occurs.

Looking at the datasheets for the UDMs, the VPN max speeds are listed at 800mbps (except the pro max which is unlisted or at least I can't find it, but I assume its the same)... which seems somewhat optimistic, and real world figures Ive been able to find look more like 2-300mbps. This is most likely more than enough but given that I'll reasonably regularly want to shunt large files between places, and all will be on 2.5GB or 5GB internet reasonably soon, am I really limiting my performance options by hooking up 3 SEs? I know they're a few years old but we're not likely to see any faster VPN support in the near future are we?
 
What sort of speed are you hoping for? VPN speed over 1 Gbps is not easy to achieve with regular hardware.
 
I've decided I want to have a better home network where currently my VM Router is in passthrough mode and my TP-Link Router does the work.

I've seen, quite, a few videos on YouTube about the Unifi stuff and as I am a sucker for shiny things, and I do like the look of how uncomplicated a lot of the day to day home network set up looks, I think I'll be buying the following.

Cloud Gateway Ultra, was thinking of waiting for the Max but I don't need any of the other features it gives over the Ultra.
8 Port Lite POE Switch
U6 Pro or +, I've got to look closely at them to decide which will suit me better
That little non POE, apart from powering it, switch I can use for my TV, NAS, Sky Stream and PS5

For what I need I think that'll be a good start.
 
The Max doesn't run Unifi OS so would need an additonal cloud key or cloud subscription. So another vote in favour of the Ultra probably.My mistake they've released a cloud gateway max. Couldn't find it initially!

The Max is 2.5GbE though, rather than the 1GbE of the Ultra, so if you need/want multi-gig ethernet the Ultra won't really cut it. If you don't need that though should be fine.
 
Last edited:
I have the Ultra, it's good. If you don't intend to have a faster-than-1Gb service then the Max is an unnecessary spend - if it was £160 without the storage it would be an easy decision to just buy it for a bit of future proofing, but it's over twice the price.
 
Last edited:
I've decided I want to have a better home network where currently my VM Router is in passthrough mode and my TP-Link Router does the work.

I've seen, quite, a few videos on YouTube about the Unifi stuff and as I am a sucker for shiny things, and I do like the look of how uncomplicated a lot of the day to day home network set up looks, I think I'll be buying the following.

Cloud Gateway Ultra, was thinking of waiting for the Max but I don't need any of the other features it gives over the Ultra.
8 Port Lite POE Switch
U6 Pro or +, I've got to look closely at them to decide which will suit me better
That little non POE, apart from powering it, switch I can use for my TV, NAS, Sky Stream and PS5

For what I need I think that'll be a good start.

This is almost the same setup I've been considering, so I'd be interested in whether you've gone ahead with it etc.

All my cabling is in, I'm just trying to decide on devices and waiting for openreach to upgrade us to full fibre
 
This is almost the same setup I've been considering, so I'd be interested in whether you've gone ahead with it etc.

All my cabling is in, I'm just trying to decide on devices and waiting for openreach to upgrade us to full fibre
I have pretty much that setup, Ultra connected to 900Mbps Vodafone fibre, loft mounted 8 Port POE Lite Switch, U6-Pro in the loft, U6 Mesh in the study downstairs and a second in the kitchen meshed to the study. I've got a 5 port flex switch in one of the bedrooms, powered over POE from the loft switch, which has a Sky stream, TV and couple of other things hardwired to it.

Only reason I have so many APs is the insulation under the flooring upstairs blocks almost all wifi signals and the same goes for the fridge/freezer and cooker in the middle of the house.

Have to say its been really good, stable, performs well and let me isolate off parts of the network for IOT and other devices from the main home user devices.
 
Apart from both switches saying they were adopted by another console and having to reset a couple of times before getting adopted everything pretty simple to setup.

Just need to sort out cabling now. Which will be a fun job.

daGBjDJ.png
 
This is almost the same setup I've been considering, so I'd be interested in whether you've gone ahead with it etc.

All my cabling is in, I'm just trying to decide on devices and waiting for openreach to upgrade us to full fibre
This is very similar to the setup I went for recently. Unfortunately though the Cloud Gateway Ultra will not work with BT EE IPTV Box so I am using a ER-X Router at the minute. I went for the U7-Pro AP and it has been brilliant. I live in a town house so 3 floors and it reaches the top floor easily whilst just located on the ground floor. I have really noticed the improvement when gaming over WIFI compared to the BT Superhub, it's night and day difference, I just with they would fix the EE IPTV issues on the gateway. I have raised a feature request and they have said the dev's are looking into it so let's see.
 
Last edited:
Probably one for @ChrisD. (sorry :p) but just in case anyone else knows - can I run Protect on a cloudkey2 on the same network as the dream machine SE, without the cloudkey wanting to be the network controller as well? Reason being I've read that the SE fans are obnoxiously loud if you put a hard drive in, and for a while I will be running it in my office. Long term it won't be an issue as it will be in the loft, and I can migrate protect to it properly at that point, but currently my controller is the cloudkey (I use Firewalla as the router/gateway but the cloudkey does all the wireless vlans).
 
Last edited:
Back
Top Bottom