• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Adding a Ubiquity UniFi Access Point

Scheduled Pinned Locked Moved General pfSense Questions
15 Posts 10 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    Balanga
    last edited by Balanga Mar 20, 2019, 8:15 AM Mar 20, 2019, 8:00 AM

    How would I go about adding a Ubiquity UniFi access point to my LAN?

    I understand I need a software controller. Could this be installed on pfSense?

    1 Reply Last reply Reply Quote 0
    • T
      tomashk
      last edited by Mar 20, 2019, 8:36 AM

      Yes, you need controller at least for configuration of AP and for that it is enough to run it on your PC. After that you can turn it off. There is unofficial way to install it on pfSense - https://github.com/gozoinks/unifi-pfsense - as any unofficial solution, it may work for you or not :).

      N 1 Reply Last reply Mar 20, 2019, 9:03 AM Reply Quote 0
      • N
        NogBadTheBad @tomashk
        last edited by Mar 20, 2019, 9:03 AM

        @tomashk said in Adding a Ubiquity UniFi Access Point:

        Yes, you need controller at least for configuration of AP and for that it is enough to run it on your PC. After that you can turn it off. There is unofficial way to install it on pfSense - https://github.com/gozoinks/unifi-pfsense - as any unofficial solution, it may work for you or not :).

        Please don't install the controller on your pfSense box its a router not an appliance server.

        You can configure an AP from the Unifi software on a phone.

        Do you just have the single LAN subnet or are you planning others via VLANS?

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        T 1 Reply Last reply Mar 20, 2019, 10:16 AM Reply Quote 0
        • T
          tomashk @NogBadTheBad
          last edited by Mar 20, 2019, 10:16 AM

          @NogBadTheBad said in Adding a Ubiquity UniFi Access Point:

          Please don't install the controller on your pfSense box its a router not an appliance server.

          I agree. It is OK to install it only if you like experiments :)

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Mar 20, 2019, 10:40 AM

            As experiment.. Sure he can do this in his "lab" <rolleyes>

            I run my controller on VM on my NAS, it doesn't need much... You can run it on your main PC as well.. It runs on multiple OSes.. Windows, Mac, Linux..

            They don't even support a BSD version... That is completely on you and not support by unifi, etc.

            Buy one of their little key (usb stick computer) to run it on... Or yeah if all you want to do is setup the 1 AP, you can do that with their phone AP... There is zero reason to run it on your firewall!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • O
              occamsrazor
              last edited by occamsrazor Mar 20, 2019, 11:04 AM Mar 20, 2019, 10:47 AM

              In addition to the docker options, which I personally found harder to maintain, if you happen to have a QNAP NAS there is a .qpkg package that is a one-click install and has proved very reliable for me.

              pfSense CE on Qotom Q355G4 8GB RAM/60GB SSD
              Ubiquiti Unifi wired and wireless network, APC UPSs
              Mac OSX and IOS devices, QNAP NAS

              1 Reply Last reply Reply Quote 1
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Mar 20, 2019, 10:49 AM

                Im not running it on docker, Im running in it full VM running on VMM, on a ubuntu server min install. But yes those are all valid places to run it - vs trying to shoehorn it on to your "firewall"

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 1
                • O
                  occamsrazor
                  last edited by occamsrazor Mar 20, 2019, 10:59 AM Mar 20, 2019, 10:56 AM

                  I did look at the option of running it on pfSense when I first started. The attraction of running on the same device is appealing, until you look at the details. Everyone seems to agree that conceptually it is a bad idea, as well as likely being much harder to maintain and posing more risks. The thing about the controller is it doesn't need to be running 24/7 for the switches and access points to continue working, so it's fine to have it on a device that reboots occasionally, or you need to do other stuff with. pfSense on the other hand is critical for the running of my network and internet access, so I'd rather not take any risks messing up pfSense.
                  I've been running both the Unifi SDN controller and Unifi Video .qpkg packages on my QNAP NAS for a while and so far so good. Had no issues at all with the SDN controller. That said I am tempted by the Cloud Key Gen2 to perform these two functions....

                  pfSense CE on Qotom Q355G4 8GB RAM/60GB SSD
                  Ubiquiti Unifi wired and wireless network, APC UPSs
                  Mac OSX and IOS devices, QNAP NAS

                  1 Reply Last reply Reply Quote 0
                  • S
                    stephenw10 Netgate Administrator
                    last edited by Mar 20, 2019, 12:49 PM

                    I don't use them but as I understand it there are some functions that require the controller to be always on. Captive portal?

                    Of course you can just do that in pfSense anyway...

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • G
                      Grimson Banned
                      last edited by Mar 20, 2019, 12:54 PM

                      If you have an unused Raspberry Pi you can use it for the controller just fine.

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator
                        last edited by Mar 20, 2019, 12:57 PM

                        There are some features that want it to run all the time for yes.. The big one for me is information!!! Easy to see who is on, what AP they are connected too, how much bandwidth they are using.. History of such info, etc. etc

                        exampleinfo.png

                        I blocked out part of my ssid names... It is possible to look up location based upon war driving db on where a specific SSID is, etc.

                        I just updated the AP to current beta firmware, which is why the connected times are no longer than a day, etc.

                        The controller provides a wealth of information, which can just be interesting or can be invaluable in troubleshooting an issue, etc. etc.

                        loadsofinfo.png

                        But sure the captive portal stuff could just be run on pfsense..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 1
                        • R
                          rawla
                          last edited by Apr 8, 2019, 12:36 PM

                          Is the port AP is connected to needs to have the native VLAN?

                          N 1 Reply Last reply Apr 8, 2019, 12:39 PM Reply Quote 0
                          • N
                            NogBadTheBad @rawla
                            last edited by NogBadTheBad Apr 8, 2019, 12:42 PM Apr 8, 2019, 12:39 PM

                            @rawla

                            It used to, but I think you can used a tagged VLAN now.

                            Best check the Ubiquity forums.

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            1 Reply Last reply Reply Quote 1
                            • T
                              tman222
                              last edited by Apr 10, 2019, 2:04 PM

                              I would strongly recommend keeping pfSense and the Unifi controller software separate (i.e. either on separate machines or at least in separate VM's). While I do use Ubiquiti AP's myself and have generally been pleased with their performance, I am not as impressed with the stability of the Unifi controller software. I used to run it on a Ubiquiti Cloud Key but have since upgraded and now run the controller on a Debian Linux VM on top of Proxmox. This works a lot better because it allows me to take regular snapshots of the VM to roll back to in any there are issues with an update.

                              You can see in this script here what is installed:

                              https://github.com/gozoinks/unifi-pfsense/tree/master/install-unifi

                              This adds quite a few extra packages to a stock pfSense install - again, I really recommend against doing this. Cloud keys aren't that expensive, and a VM to run the controller requires very few resources. The software controller software can also be run on a local machine and even in the cloud.

                              Hope this helps.

                              1 Reply Last reply Reply Quote 0
                              • J
                                jdeloach
                                last edited by Apr 10, 2019, 2:53 PM

                                If you just have ONE Access Point and are not interested in all the charts, logs and graphs that is generated with the controller software, just use the Apple IOS app to install and setup the access point. Since the app is FREE, it's a lot cheaper than the Cloud Key and easier than configuring the controller software.

                                That's what I did and it works great. You can change IP addresses, update the firmware, etc all from the IOS app.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                  This community forum collects and processes your personal information.
                                  consent.not_received