Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Site Notices
Posted: 2/7/2021 12:05:30 AM EDT
I have a mostly Unifi home network.  Untangle server on a home-built i3, Unifi 8 port switch, an AC-Pro, and AC-Lite, and a Nano M5.

I want deep packet inspection and better integration and information on traffic than Untangle is giving.  I also use a pi-hole for most blocking, and now that I'm using the NG version of Untangle ($50/yr) I realize I'm not using any of the features over the free version.

I've got some Ring cameras that could benefit from a range extender or two.  2900 sq ft house, two-story.  

I'm looking at upgrading to a Dream Machine Pro, and possibly upgrading the entire wifi network to current hardware.  Probably $600-1000 depending on if I go with the range extenders that offer ethernet bridging, which I also use.

Wondering what other brands are out there that I should be considering.  I'm not interested in a mesh network from google or amazon or whatever other big companies are offering spy devices.  But back in the day TP Link had a similar product line to the UniFi stuff, and I think netgear did too.  Just curious if other brands have caught up to, or surpassed, UniFi.

There are plenty of great things about UniFi stuff, and a lot I don't like, too.

Opinions welcome.

Link Posted: 2/7/2021 12:49:46 AM EDT
[#1]
Quoted:
I have a mostly Unifi home network.  Untangle server on a home-built i3, Unifi 8 port switch, an AC-Pro, and AC-Lite, and a Nano M5.

I want deep packet inspection and better integration and information on traffic than Untangle is giving.  I also use a pi-hole for most blocking, and now that I'm using the NG version of Untangle ($50/yr) I realize I'm not using any of the features over the free version.

I've got some Ring cameras that could benefit from a range extender or two.  2900 sq ft house, two-story.  

I'm looking at upgrading to a Dream Machine Pro, and possibly upgrading the entire wifi network to current hardware.  Probably $600-1000 depending on if I go with the range extenders that offer ethernet bridging, which I also use.

Wondering what other brands are out there that I should be considering.  I'm not interested in a mesh network from google or amazon or whatever other big companies are offering spy devices.  But back in the day TP Link had a similar product line to the UniFi stuff, and I think netgear did too.  Just curious if other brands have caught up to, or surpassed, UniFi.

There are plenty of great things about UniFi stuff, and a lot I don't like, too.

Opinions welcome.

View Quote


I haven't used it myself, but if I ever wanted more than what my USG can do I'd probably build myself a pfSense box.  I have Unifi nanoHDs through my house, and they've been fine.  Also heard good things about Ruckus if you aren't wanting to stay in the Unifi ecosystem.
Link Posted: 2/7/2021 12:54:38 AM EDT
[#2]
Been using dream machine pro for 9 months almost and it’s been flawless.
Link Posted: 2/7/2021 2:03:58 AM EDT
[#3]
I've been running a Dream Machine (not Pro) for several months. I replaced my Unifi USG-4 with it. Much faster processor and better specs overall. Built-in cloud key and access point. I've been happy with it.

I also have two other Unifi access points on it, a 16 camera POE NVR, a 48 port Cisco switch and a QNAP 8 bay NAS (with a Pi-hole docker on it). It gives a pretty good view of the network.
Link Posted: 2/7/2021 7:01:14 AM EDT
[#4]
My UDM Pro works great, but the APs have been buggy lately
Link Posted: 2/7/2021 8:15:11 AM EDT
[#5]
Link Posted: 2/7/2021 12:55:22 PM EDT
[#6]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
how they built that thing.  at that cost without POE is beyond me.

i personally would rather have the edgerouter 6P or above, with a US-8-60W  or 150W if you need more power.  but with just 2 AP's the 60W would be fine.

then upgrade to 2 Flex HD's or 6LR AP's or  at least the standard LR Ap's

View Quote



Will the 6P do everything the DM Pro will do?
Link Posted: 2/8/2021 6:56:41 PM EDT
[#7]
Link Posted: 2/8/2021 10:25:49 PM EDT
[#8]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
are you using a computer as a controller already?  if so why not just keep it that way.  i've used a 11 year old macmini for 11 years as my controller.   IF i leave the controller running

packet inspection?    no idea why or what you are needing to do there.     https://help.ui.com/hc/en-us/articles/204951104-EdgeRouter-Deep-Packet-Inspection-Engine

i would still rather have a non dream machine,  i would prefer POE ports instead of using poe adapters
View Quote

They are making it so you can't run your own NVR anymore. Have to buy theirs.
Link Posted: 2/9/2021 5:10:23 AM EDT
[#9]
Link Posted: 2/9/2021 10:04:11 PM EDT
[#10]
I have a PfSense box Core i3 ($300ish).
Cisco 2690 $80ish used.
2x  Cisco Aironets - $80-100ish used.

100% uptime other than reboots for updates in something like 3 years. Not bad for < $600 worth of used equipment. I do keep cold spares of power supplies, though.
Link Posted: 2/9/2021 10:26:36 PM EDT
[#11]
Going from Untangle to a USG Pro would be a HUGE downgrade in my opinion.

The USG Pro can't do half of what Untangle can do.  You just need to learn to better utilize Untangle.
Link Posted: 2/14/2021 3:07:46 PM EDT
[#12]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Going from Untangle to a USG Pro would be a HUGE downgrade in my opinion.

The USG Pro can't do half of what Untangle can do.  You just need to learn to better utilize Untangle.
View Quote



As I age I not only lose patience but also the ability to learn and remember cognitively-intensive tasks, such as building routing and firewall rules from scratch.

Untangle has been good, I actually like pfsense better but I felt like I needed a PhD to use it.  I may try IPFire again just to see where its at, haven't used it in years.

I am using the $50/yr subscription of Untangle and I'm not getting anywhere near the information I want, such as packet inspection stuff that I believe is possible, but I have not figured out.
Link Posted: 2/14/2021 3:28:19 PM EDT
[#13]
I love my Palo Alto 220 at home. However it takes some weed and feed every month to keep things humming along. It also helps I manage PAs at work too.
Link Posted: 2/14/2021 3:43:12 PM EDT
[#14]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



As I age I not only lose patience but also the ability to learn and remember cognitively-intensive tasks, such as building routing and firewall rules from scratch.

Untangle has been good, I actually like pfsense better but I felt like I needed a PhD to use it.  I may try IPFire again just to see where its at, haven't used it in years.

I am using the $50/yr subscription of Untangle and I'm not getting anywhere near the information I want, such as packet inspection stuff that I believe is possible, but I have not figured out.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Going from Untangle to a USG Pro would be a HUGE downgrade in my opinion.

The USG Pro can't do half of what Untangle can do.  You just need to learn to better utilize Untangle.



As I age I not only lose patience but also the ability to learn and remember cognitively-intensive tasks, such as building routing and firewall rules from scratch.

Untangle has been good, I actually like pfsense better but I felt like I needed a PhD to use it.  I may try IPFire again just to see where its at, haven't used it in years.

I am using the $50/yr subscription of Untangle and I'm not getting anywhere near the information I want, such as packet inspection stuff that I believe is possible, but I have not figured out.



It's all in the reports or you can create your own reports.  What specifically are you looking for?


UniFi traffic stats are complete bullshit.  Mine wonve said that my thermostat use 1.2TB in a single month
Link Posted: 2/14/2021 3:44:09 PM EDT
[#15]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I love my Palo Alto 220 at home. However it takes some weed and feed every month to keep things humming along. It also helps I manage PAs at work too.
View Quote



I almost got one of those but their throughput is horrible for the price with most features enabled unless you have a sub 100Mbps connection.
Link Posted: 2/14/2021 3:57:16 PM EDT
[#16]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



I almost got one of those but their throughput is horrible for the price with most features enabled unless you have a sub 100Mbps connection.
View Quote
Handles my 600-700Mbps connection just fine. My one complaint on performance is the management page and commit times. Other than that it's been fantastic.
Link Posted: 2/14/2021 4:46:21 PM EDT
[#17]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Handles my 600-700Mbps connection just fine. My one complaint on performance is the management page and commit times. Other than that it's been fantastic.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:



I almost got one of those but their throughput is horrible for the price with most features enabled unless you have a sub 100Mbps connection.
Handles my 600-700Mbps connection just fine. My one complaint on performance is the management page and commit times. Other than that it's been fantastic.



You must not run IPS or Threat Prevention?

https://www.paloaltonetworks.com/resources/datasheets/pa-220-specsheet

The $400/yr license fee drove me away too.
Link Posted: 2/14/2021 6:47:35 PM EDT
[#18]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



You must not run IPS or Threat Prevention?

https://www.paloaltonetworks.com/resources/datasheets/pa-220-specsheet

The $400/yr license fee drove me away too.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:



I almost got one of those but their throughput is horrible for the price with most features enabled unless you have a sub 100Mbps connection.
Handles my 600-700Mbps connection just fine. My one complaint on performance is the management page and commit times. Other than that it's been fantastic.



You must not run IPS or Threat Prevention?

https://www.paloaltonetworks.com/resources/datasheets/pa-220-specsheet

The $400/yr license fee drove me away too.
All services are turned on. PA usually under specs the hardware performance. They have upped it since initial release with some operating system performance improvements.

I have a bunch of hard block rules before anything gets to the IPS and threat prevention. It keeps the logs much cleaner. About two dozen threat intelligence feeds deduped and optimized.

also under 20 rules keeps traffic running smoothly as well.

I purchased a lab unit. License cost is $100/yr. initial hardware cost $400. Having a very good partner is helpful.

Global Protect is what will bog it down the most. Debating on using a second lab unit for GP if I start using it more.
Link Posted: 3/1/2021 3:35:16 PM EDT
[#19]
My dream Machine Pro has been running fine for a while now.  

It is currently just acting as a router but I am about to start adding cameras and a hard drive for the protect system.
Link Posted: 3/1/2021 5:51:24 PM EDT
[#20]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
All services are turned on. PA usually under specs the hardware performance. They have upped it since initial release with some operating system performance improvements.

I have a bunch of hard block rules before anything gets to the IPS and threat prevention. It keeps the logs much cleaner. About two dozen threat intelligence feeds deduped and optimized.

also under 20 rules keeps traffic running smoothly as well.

I purchased a lab unit. License cost is $100/yr. initial hardware cost $400. Having a very good partner is helpful.

Global Protect is what will bog it down the most. Debating on using a second lab unit for GP if I start using it more.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:
Quoted:



I almost got one of those but their throughput is horrible for the price with most features enabled unless you have a sub 100Mbps connection.
Handles my 600-700Mbps connection just fine. My one complaint on performance is the management page and commit times. Other than that it's been fantastic.



You must not run IPS or Threat Prevention?

https://www.paloaltonetworks.com/resources/datasheets/pa-220-specsheet

The $400/yr license fee drove me away too.
All services are turned on. PA usually under specs the hardware performance. They have upped it since initial release with some operating system performance improvements.

I have a bunch of hard block rules before anything gets to the IPS and threat prevention. It keeps the logs much cleaner. About two dozen threat intelligence feeds deduped and optimized.

also under 20 rules keeps traffic running smoothly as well.

I purchased a lab unit. License cost is $100/yr. initial hardware cost $400. Having a very good partner is helpful.

Global Protect is what will bog it down the most. Debating on using a second lab unit for GP if I start using it more.



I was quoted $500/yr by Virtual Graffiti (Threat Prevention, PANDB URL Filtering, GlobalProtect, etc) for the PA-220 lab after the first year which was $200 and a unit cost of $600.

That's why I bailed.
Link Posted: 3/2/2021 10:37:25 AM EDT
[#21]
The Untangle box you have now will be a better product for DPI compared to anything Ubiquiti currently has on the market.

I honestly wouldn't really look for a new machine unless you need something in a different form factor.
Link Posted: 3/2/2021 6:59:22 PM EDT
[#22]
Discussion ForumsJump to Quoted PostQuote History
Quoted:



I was quoted $500/yr by Virtual Graffiti (Threat Prevention, PANDB URL Filtering, GlobalProtect, etc) for the PA-220 lab after the first year which was $200 and a unit cost of $600.

That's why I bailed.
View Quote


If you buy a PA-220 lab bundle you're looking at ~$600 for the first year.  That's inclusive of the hardware, 1-year subs/support, and tax/fees.  Your year-two price would be ~$100 for the sub/support bundle renewal.

Alternatively, you could look at a FortiGate 60F/61F for better performance but at a higher price per year since they have gotten away from NFR/lab SKUs.
Link Posted: 3/2/2021 7:51:43 PM EDT
[#23]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


If you buy a PA-220 lab bundle you're looking at ~$600 for the first year.  That's inclusive of the hardware, 1-year subs/support, and tax/fees.  Your year-two price would be ~$100 for the sub/support bundle renewal.

Alternatively, you could look at a FortiGate 60F/61F for better performance but at a higher price per year since they have gotten away from NFR/lab SKUs.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:



I was quoted $500/yr by Virtual Graffiti (Threat Prevention, PANDB URL Filtering, GlobalProtect, etc) for the PA-220 lab after the first year which was $200 and a unit cost of $600.

That's why I bailed.


If you buy a PA-220 lab bundle you're looking at ~$600 for the first year.  That's inclusive of the hardware, 1-year subs/support, and tax/fees.  Your year-two price would be ~$100 for the sub/support bundle renewal.

Alternatively, you could look at a FortiGate 60F/61F for better performance but at a higher price per year since they have gotten away from NFR/lab SKUs.


Yeah I could have lived with that pricing for the PA-220 at the time but when I was quoted much higher for the yearly I bailed as I couldn't find another vendor that would sell to me.  That led us to just go with Untangle at work since I had a good experience with it at home.

I haven't looked into FortiGate much but have heard good things about them.
Link Posted: 3/3/2021 3:17:51 AM EDT
[#24]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Yeah I could have lived with that pricing for the PA-220 at the time but when I was quoted much higher for the yearly I bailed as I couldn't find another vendor that would sell to me.  That led us to just go with Untangle at work since I had a good experience with it at home.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Yeah I could have lived with that pricing for the PA-220 at the time but when I was quoted much higher for the yearly I bailed as I couldn't find another vendor that would sell to me.  That led us to just go with Untangle at work since I had a good experience with it at home.

PA did it right with the lab bundles. It’s not as good as it used to be when they would toss PA-200s around like candy but it’s better than the others. PM if you want help running this stuff down in the future. That goes for anyone. At a minimum, I can tell you what SKUs to ask for.

I haven't looked into FortiGate much but have heard good things about them.
I spend most of my professional time working on PAs or FortiGates. They all have their pros and cons but you can’t go wrong with either of them.

Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top