Ubiquiti
- VPN Client Kill Switch
I am getting used to Ubiquiti, and recently added a VPN Client to cover one of my VLANs. Am I correct in my understanding that having no
Fallback
option is essentiall a Kill switch that will not allow traffic to pass outside of the VPN in the event it goes down? - Firewall rule check
I recently started playing with UDM after having been in PFSense for the last few years. In PFSense, I had a pretty organized rule set for each VLAN, and it was pretty easy to read and follow compared to the single list for rules in UDM (though it makes up for it in other areas).
I'm trying to recreate some of my original rules and flows, but wanted to get another pair of eyes on them to be sure I am using
"LAN In"
and"LAN Out"
correctly (especially on the rules where I try to only allow necessary devices/ ports out to WAN). - Setting UDM Pro to a non-default network
Just joined the club and got my first piece of ubiquiti gear! I spent some time doing the initial configuration and adding my VLANs, static IPs, however I ran into a bit of an issue that I'm sure is a quick fix.
By default the UDM Pro is on 192.168.1.1, and that's fine. I actually use the 192.168.1.0/24 as a management VLAN for networking devices that other VLANs don't need access to.
The problem I'm running into is that this default space that the UDM Pro is on does not have an option for a VLAN tag. I can change the IP of the default network to be something else like 192.168.100.0/24, and make a management VLAN on 192.168.1.0/24, but then the UDM Pro will grab a 192.168.100.0/24 address (since it is on the default network).
How, after doing this, can I set the UDM Pro to be on this new management VLAN and not the default?
- More UniFi Wi-Fi 7: U7 Pro Max, Pro Wall, and Outdoor Preview — McCann Techevanmccann.net More UniFi Wi-Fi 7: U7 Pro Max, Pro Wall, and Outdoor Preview — McCann Tech
This preview covers the specs and my initial impressions of Ubiquiti’s latest batch of Wi-Fi 7 UniFi access points: the U7 Pro Max, U7 Pro Wall, and U7 Outdoor.
- Wi-Fi motion detection
Think we’ll ever get something like this? I miss it from my old Plume network.
- Protect view device
Hello I've been using a chromecast with Google tv on a portable monitor to have my cameras displayed, but it seems the chromecast is pretty under powered. I am wondering if anyone has had any luck with the 4k version of the chromecast or another cheap streaming device like the Walmart onn that loads the protect app better.
Currently one camera view works fine but using a four camera view is tough because you have to open and close the app over and over until every thing loads up, then if someone rings the doorbell and it goes to the doorbell view you start all over to get it back
- UniFi 7 Introducedstore.ui.com Access Point U7 Pro - Ubiquiti Store United States
Ceiling-mount WiFi 7 AP with 6 GHz support, 2.5 GbE uplink, 9.3 Gbps over-the-air speed, and 300+ client capacity.
- Protect access with wireguard vpn
Since the whole security issue popped up, I decided to disable remote access for both my udm pro and UNVR.
I am able to access the udm pro via the unifi app through wireguard but I am unable to access protect.
Has anyone gotten this to work?
- [UDMP] Wireguard doesn't allow Server <-> Client pings
So I have two sites: my home network and my cloud VPSs. I have setup a FreeIPA domain that I would like to use for all my machines, local and remote. While I wait for Linode/Akamai to add their new VPC feature, I want to create Wireguard tunnels from each VPS to my home network with my UDMP as the router. I tried to set it up through the UI, however I can't ping to/from the server wireguard interface when connected. So I tried to set it up with
wg-quick
but alas that isn't working either. I have the firewall port for wireguard open with both Internet In and Internet Local. I'm not even trying to get LAN access yet because I can't even ping over the tunnel. This has seriously frustrated me and I need to see if I'm just majorly fucking up or if I'm sane afterall and the UDMP just isn't good for Wireguard.Server conf: ``` [Interface] Address = 192.168.84.1/24 ListenPort = 51820 PrivateKey = [server private key]
[Peer] PublicKey = [client public key] AllowedIps = 192.168.84.20/32 ```
Client conf: ``` [Interface] Address = 192.168.84.20/24 PrivateKey = [client private key]
[Peer] PublicKey = [server public key] Endpoint = [server hostname]:51820 AllowedIPs = 192.168.84.1/32 ```
I had PostUp and PostDown rules set, but they didn't seem to make a difference. It seems they're mostly for configuring routing with iptables. Can I please get a sanity check here?
Edit: It was dns. It's always dns. Apparently the UDM Pro doesn't like IPv6 for Wireguard (and supposedly a lot) and the domain name I was using for my home network was double stack. I tested against it's current IP address and when that worked I made a subdomain that was IPv4 only and it's working great now.
- Unifi Express initial observations
I bought a Unifi Express to upgrade my parents in law from an old orbi mesh system that I handed down to them. I'm hoping this will improve their network, and allow me to remotely help them more easily.
After receiving the device, I decided to first test it out in my network to see if it was a viable replacement for my USG-3P and my RPI4-4GB. TL;DR: it is not.
My setup: 1x U6 Lite 1x AC-AP Lite 1x AC-Mesh 1x Nano HD 1x USW-8-60W 1x Lite 8 POE 1x Flex Mini 1x USG-3P 1x Raspberry PI 4-4GB running pihole, Homebridge, controller 1x Raspberry PI zeroW running redundant pihole and critical redundant homebridge items Centurylink Symmetric gigabit fiber
I have around 35 smart home wifi devices and in generally around 55-60 total clients connected to my network.
I loaded a backup from my RPI4 controller to get started.
My initial attempt just failed, as I tried to like set it up while connected to my existing network. I was also just not used to dealing with a UnifiOS console device and the way that it works.
Loading the backup took like 30 minutes of an NFL football game, so I guess like 1 hour, but I did not time it exactly.
After getting it up and running I can no longer get the network application to load in my browser, it just keeps loading forever.
With nothing else happening, SSH to the console and running TOP shows that unifi-network-b process is using between 20-91% of the CPU. Load averages are around 4.5. The one good thing is that I was getting around the 940Mbps up and down at first, but it always starts out a bit slow at around 45Mbps, then it gets faster after about a second. Today I'm seeing 940 down and 500 up. Not sure if it is ISP or the device just getting slow. When I was using my USG-3P I normally see the symmetric 940 jump up to full speed immediately, without the initial hang up at 45Mbps.
Ultimately, it is nice to see that it can prioritize the internet to do its primary job when it is just completely swamped by relatively modest network I have setup.
This shows me that my true path forward is definitely the UXG-Lite while maintaining my RPI4 for the controller. I have no urgency to replace my USG-3P, but I would like to have the UXG-Lite at least available for shipping before the USG-3P crapps out so I am not caught with my pants down. I do have the ISP router I can pop in for an emergency, but I would like to stay in the ecosystem if possible.
I will post another update after I setup the gateway at my parents in law's house.
- Ubiquiti stocking issues
Ubiquiti makes some pretty great products, but too many of them are constantly out of stock. I was definitely giving them a pass in 2020, 2021 etc, but this is starting to look like it is now intentional. They are simultaneously out of the express, uxg lite, UDR, and the USG-3P. The only non rack router that is available in the store is the UDM, which they are no longer advertising without searching for it.
I know that the express and uxg lite are brand new, so maybe they can get a pass. The UDR has been out for well over a year. The UDM is just sort of too expensive to be bought without wifi6, and appears to be on the way out.
Further, the U6-lite is also sold out. This just forces people to pay an extra $30 for the U6+ with wifi6 on the 2.4GHz radio, and I'm not really aware of anything that uses wifi6 on 2.4GHz (maybe new mobile phones etc, but they will be defaulting to 5GHz...).
Ubiquiti even hired some B list actors to do an "Apple like" advertisement on their home page for the unifi express. Why? If you cannot produce enough to sell to people, why advertise for it? Is it to draw people in, and then force them to buy something more expensive?
- UDR in a townhome
Does anyone know if I use a UDR(plan on getting one once it’s back in stock) in the 3 level town home how I can extend the signal to the top level. Unfortunately I’m stuck with using the connection to the modem in the bottom level and it’s been difficult to get reliable signal through the house. I was thinking if I have the UDR on the bottom level and use either the U6 extender or the U6 mesh via a moca connection(don’t have Ethernet run in the house but I do have coax). Thanks.
- Unifi Network 8.x for self hosted Raspberry PI
Somewhat recently I had to update to the 64 bit version of Raspbian OS to use Unifi Network 7.x. I had to use the tutorial linked from pimylifeup. Today the apt update switched to the 8.x branch of distribution and it said my architecture of armhf was not supported. To fix it, I just had to edit the file: /etc/apt/sources.list.d/100-ubnt-unifi.list from "arch=armhf" to "arch=arm64". If you were already running the latest 7.x then this should get you up and running. If you are upgrading from something older, visit the linked tutorial to get everything you need to be updated.
- Any new 6E/7 AP rumors?
I’m in need of a new AP but it looks like the majority being offered are still Wi-Fi 5 or 6. Has anyone heard what may be coming next?
- Where in the file system does the UDMP-SE store it's ipsec tunnel configuration?
UDMP is running UniFi OS 3.1.16 and I need a specific VPN configuration that StrongSwan supports but isn't possible to do in the GUI. Three years ago the files I need were located in /run/strongswan/ipsec.d/tunnels/ but they are no longer there. Does anyone know where they live now -or- how to edit a VPN config outside of the GUI?
- Am I barking up the wrong tree?
Hello,
Will try in some other communities but also posting here just in case there's a Unifi guru reading this ( ͡° ͜ʖ ͡°)
I have a weird home networking issue which I just do not understand at all. My set-up is a Ubiquiti USG-Pro 4, connected to a managed 8 port ubiquiti switch and then a generic 24 port unmanaged switch with various kit plugged into it including a qnap NAS running container services such a PiHole, Deluge, Plex, Nextcloud etc.
I have 3 access points (PoE) connected to the 8 port switch to run my wireless network and I also run some wired and wireless cameras with Unifi Protect
Everything runs fine EXECPT.....
Whenever any device (laptop \ mobile \ container running within the NAS \ whatever) connects to my VPN provider (ProtonVPN) and starts to download any sizeable data via that VPN link, my network latency on the USG goes from an average of 16 ms up to a network breaking 500+ ms.
I have tried....
- Turning off all IPS \ IDS \ traffic monitoring on the USG
- Completely replacing my generic unmanaged switch for another brand
- Downloading torrent files from P2P networks
- Downloading large files directly from the internet
- Removing PiHole as my DNS server (switching directly to 1.1.1.1)
- Using OpenVPN and Wireguard protocols
I have experimented downloading from the QNAP NAS, from a wireless connected laptop, from a mobile phone, from a wired computer with and without the VPN connected.
Without the VPN - all is good, speed is good (I have a 500GB down ISP connection) and latency is good (well below 18 ms at all times)
With the VPN - all starts fine but within 30 seconds or so latency is up at above 500ms and the rest of the network slows to a crawl.
So, is this an issue with the processing capabilities of the USG? or am I missing something really obvious here. Any advice appreciated.
- Do you keep missing restocks? Use UI Notify
I kept missing when products were in stock and have the “notify when in stock” checked on my UI account, but didn’t get emails when some items were in stock. I assume they didn’t stay in stock long enough. Crosstalk Solutions on YouTube made uinotify.net so you get instant email when items are in stock. Free to use unless you want to customize your selections. This morning the G4 Doorbell Professional was back in stock for a limited time and I was able to finally buy it after waiting a year. And no, I never received an email from UI about its availability.
- Dream Router & 3rd Party AP’s
Hello, first time posting to this community either here or back there if you know what I mean. I have just purchased a Dream Router to replace a TP Link Deco mesh system and would like to ask a couple of questions before I start tearing the old system down. One reason I got a mesh in the first place is because I have a building about 20m away from my house that I use as an office, I didn’t really want to run a wire from the house. The mesh just about gave me a connection and I could use the 2nd RJ45 port on the puck to get my ethernet only home automation system on the network down there. Speed is poor though and time moves on, my kids also use that space for gaming so a cable is now going to be run. My questions are these; can I use the old Deco pucks as access points to get me up and running quickly? They can be put into AP mode via their app. I also have two old DrayTek Vigor 2860n’s which can be put into AP mode, can I use them with UniFi without any problems? I was planning to run the cable directly from the DR to the office and then either connect it to an existing 8 port switch I have down there and plug a Deco puck into the same switch or just connect it to the DrayTek which would then act as an AP and provide 4 wired ports for use with various devices. Any advice is greatly appreciated!
- Dream Wall Pro — any info?
I see that it was announced about a year ago. Was it ever launched? If not, do you think it still will? It seems to check all the boxes for me.
- Why do I have a compulsion to collect Ubiquiti things?
Kind of a silly post, to be sure, but figured I'd put it up for the sake of the community...
I'm relatively new to the Ubiquiti community, buying my first gear a few months back. I wanted more control, more performance, or more options to fiddle with. I started with a UDM-SE, a U6E and two U6 Extenders. They've been great and significantly improved my overall performance.
But the rabbit hole opened up, next was a rack, then some UPSs. Then a SW24E (because I needed that 2.5G port for the U6E, right? The nest cameras were sold to get some Ubiquiti ones, a UNVR was just acquired. Getting a Doorbell Pro is only a matter of time, cause I need to get rid of that nest doorbell. I keep looking on line for used Ubiquiti gear on line (that's how I ended up with the UNVR and one of the cameras). I keep trying to think of reasons for other gear.
I've never really had a collector mentality for anything, but for some reason the Ubiquiti gear has trigger it. I've apparently drank (and am swimming) in the kool-aid. Anyone else need an intervention?