Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pFSense vs Unifi gateway / firewall

    Scheduled Pinned Locked Moved General pfSense Questions
    49 Posts 12 Posters 7.8k Views 14 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z Offline
      zaphanathpaneah
      last edited by zaphanathpaneah

      I know this is a over saturated topic and I'm not here to start a "battle of the bands" disscussion becasue it's mute. pFSense is superior in so many ways. However what I would like to ask / say really is I found an articles where so many people are moving away from pFSense to unifi since the release of theire latest software release. The reviews are very positive and the promise of true security and ease of use. The hardware under the hood is lack luster, but, people dont seem to care since the specs are not advertised. However that does not stop the migration away form pFSense. Serious professionals are now migrating their environments to UniFi and recommending their customers to do the same. The reason, Simplicity and unification. One software to manage it all in a simplified way. No complicated configurations that require NASA level expertise. I get it and Netgate does not really compete in this space and neither do they want to. But, what I have read is UniFi is not as robust as pFSense and its audience are generally looking for a simple approach to network security.

      So..that being said here is my question. Will Netgate ever consider a redesign of its web interface for pFSense? Keep the customization but make it easier to configure? I am not an expert so I do struggle at times with configuration. I am not even sure my instance of PFsense is configured correctly, but it does works and I tinker when things dont. I love the software for its security and highly configurability, but wish it was easier to manage. I wish Netgate provided better hardware. I also wish Netgate provided videos to demonstrate rule creation, log analysis, surricata configuration and a few more. Examples of rule sets or configuration and how it should work in practice would be very helpful rather than just describing what the configuration is. And yes I have RTFM. (read the %$#$!@*manual)

      Unifi is compelling and I'm considering the switch because of all the hype, but not sure I want to trade the comfort of security for a pretty interface, which is all it is really. So your thoughts? Be gentle.

      SteveITSS C 2 Replies Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @zaphanathpaneah
        last edited by

        @zaphanathpaneah
        moot*

        You may get biased answers here... :)

        Unifi adds wireless. etc. management but needs a controller. We’ve set up Unifi but just for wireless. As I recall it doesn’t have a lot of custom configuration, add ons, etc.

        AFAIK Netgate still has their “hangout” videos online, that may be what you’re looking for. Or https://docs.netgate.com/pfsense/en/latest/recipes/index.html ?

        I worked on a new client’s Sonicwall the other day and found it doesn’t have host overrides. I could have solved an issue in like 10 seconds on pfSense.

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        johnpozJ 1 Reply Last reply Reply Quote 0
        • S Offline
          scottjh1
          last edited by

          Based on limited knoweledge of the Unifi firewall I am not impressed. The new version is said to be easier to use. Tom from Lawrence Systems did move to Unifi, although I am not sure if it is his home or business. Pfsense has come a long way from humble beginnings. While configuration can sometimes be complex it is very stable, and secure when correctly configured. Pfsense has passed the test of time continually proving it is a solid product.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator @SteveITS
            last edited by johnpoz

            @SteveITS said in pFSense vs Unifi gateway / firewall:

            You may get biased answers here... :)

            I would nominate this for the understatement of the week ;) hehehe

            Last time I played with unifi for firewall was back when the usgp3 was a thing, had one for awhile - and my son was using it for a while (loaned him mine).. Which I admin remotely for him. Since I was only using it as a temp stop gap while waiting for my 4860. Was not impressed and could not get back pfsense fast enough - but was running pfsense as vm back then and when updated my internet speed the vm could not keep up. And the usgp3 couldn't really either unless turned off their ids/ips stuff.

            I been using their APs forever, and the controller software has come a long way for sure - but I hate how they keep moving stuff. One version you do something in the gui here, then then they move it - and can't find it, etc.

            I have a couple of their switches (flex mini) that I use for where I need a few more switch ports, in my guestroom, in the av cab, etc. They are teeny tiny, and they do switch ;)

            But as my firewall/router - I don't think I would move to unifi.. I get the appeal of one pane of glass sort of thing.. But I will stick with pfsense and my cisco for my firewall/router and main switches. But yeah unifi has my vote for APs and misc switches. Not really a fan of their higher end switches - but do like the really small footprint of their mini switches. And the price point for those is good. And you can manage them easy enough for vlans, etc.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

            Z chpalmerC 2 Replies Last reply Reply Quote 3
            • Z Offline
              zaphanathpaneah @johnpoz
              last edited by

              @johnpoz Yeah...thats kind of what I think. I have TP-Link APs because they were rated faster than UniFi and could had better range. However for the $$ theire mini switches are truly compelling. I do need a 10GB switch but my 4100 does not support 10GB so I need to look for a 6100 or 8200 on eBay. I need stability and that is something I am not sure UniFi has just yet. So this is my delimer. Do I continue to invest in pFsense or invest in UniFi echo system? I love the trouble shooting tools that comes with pFSense and I heard Unifi does not have them. So I would prefer to stay with pFSense. Also this forum in invaluable and a great help when I get stuck sometimes.

              Thanks guys, Cheers. Oh...& BTW...I think I will get a Unifi AP and switch but keep pFSense.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • T Online
                tgl
                last edited by

                Another person here using pfSense for firewall/router and UniFi just for wireless APs. I follow the community.ui.com forums, and there are lots of complaints all the time there about routing and network issues. But their wifi gear is pretty solid.

                1 Reply Last reply Reply Quote 0
                • chpalmerC Offline
                  chpalmer @johnpoz
                  last edited by

                  @johnpoz I would nominate this for the understatement of the week ;) hehehe

                  I second that comment!

                  This thread got me remembering the past and I was just wondering if Chris Buechler was still with Ubiquity and did a quick search.. appears not. Found this on the googley..

                  "Alta Labs is proud to announce Chris Buechler, Industry Legend and pfSense Co-Founder, has joined our team as Principal Architect. He will be primarily focused on the new Router and Switching product offerings we are developing."

                  Glad he is doing well.

                  Triggering snowflakes one by one..
                  Primary- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1
                  Lab Unit- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator @zaphanathpaneah
                    last edited by

                    @zaphanathpaneah said in pFSense vs Unifi gateway / firewall:

                    TP-Link APs because they were rated faster than UniFi

                    The omada line? Those are pretty much copies of unifi are they not? Sure was last time I looked at their controller. But yeah I think they come in cheaper - what I can tell you is recently updated my aging ac models to U7 lites - and for $99 they have been working great.. Pretty happy with their performance at that price point.

                    I don't really have a use case for 6ghz, and sure don't need 10ge for my APs - but having the 2.5ge as upgrade path was nice.. Not currently using it.. But at 99 bucks hey all for the ability to move to 2.5ge at some point.

                    They for sure are knocking the price point under 100 by not including the injector.. But lots of people have poe switches these days anyway. I ended up picking up the 2.5ge capable injectors for 20 bucks each for the 2 I got. I prob could of just kept using the one injector for the pro because it was normal poe. But the other 2 I had a lr and lite were passive models. And hey the injector was 10+ years old as well.

                    What tplink/omada AP(s) do you have? When I was toying with updating my old APs a while back I was looking at omada. But for what I was looking at - there was no reason to spend the money since really didn't have any need above the wifi 5 (ac) my mine could do.. But recently got new phones with wifi 7, and been reading some threads about the old models giving up the ghost.. And I was shit mine are 10+ years old. And to replace mine with new U7 lites it was only a couple hundred bucks - I went with 2 vs 3.. Since I had hard wired stuff I had in the guestroom - so an AP in that part of the house wasn't doing much anyway.

                    It gave me a new toy to play with - and the new ones can do 192 bit wpa3 enterprise.. No reason to run it - but I did it anyway ;) since now my new APs could do it. What is funny is using wpa3 enterprise without the 192 bit I couldn't get my phone to connect at wifi 7, it would if just wpa3 psk - but with enterprise only wifi 6. Until I enabled the 192 bit, changed out my certs to be of proper 192 bit strength.

                    I also recently picked up a UTR, man is the thing tiny.. I had no real use for it since I have gl.inet travel router.. But was like what the hell lets see what all the commotion is about. No use for its transport mode or even its wireguard - but its so tiny ;) It's performance is underwhelming - but was easy enough to setup, and it works from my testing. I will give it a go on a trip I have coming up in a few weeks.. But nice little bit of kit to throw into my bag.

                    I was also looking at their sfp wizard - and was almost going to pull the trigger.. Not so much to use their sfps or anything in equipment that locks sfps down. I was more interested in being able to pop a sfp in an get all the info about the sfp.. But it doesn't really seem to do that - just sort of copy paste firmware. I was hoping I could pop in a sfp and see on my phone the details - make, model number, etc.. My eyes are not as good as they were, and reading the small print on an sfp a pita.. But new phone with the macro camera is working great for that ;) If they add that feature in the future I might rethink.

                    Other thing that has been nice with updates lately - they are moving to their OS server for their software, and they finally made it drop dead simple to use your own cert for the interface. And the APs finally got an update to drop bear so the ssh is more up to date - even do pq (post quantum) key exchange.

                    One thing I wish they would add, maybe the omada/tplink does this? Is tell you what encryption a client uses, be it wpa2 or 3? I can see it on my phone if I install the developers diagnostic wifi profile. But would be nice to easy see if client used wpa 3 or 2 when you use the compatibility mode.. I mean I doubt my iot is going to ever support it.. But would be nice info to see on the controller.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                    Z 1 Reply Last reply Reply Quote 1
                    • AndyRHA Offline
                      AndyRH
                      last edited by

                      One thing I look at and I like about pfSense is the infrequency of patches and upgrades. Software that does not need to be patched often if a good sign of quality control. While the way Netgate announces new releases needs an upgrade, the fact they are frequently late on releases is a sign they do real testing and real bug fixes.
                      Not being a follower of Unifi firewalls, patching required should be a high value point of comparison. Which one needs to patch more often?
                      A random person on the internet saying one is better than another may give you something to look at, but should be a low value comparison point.
                      As others have said, Unifi APs are good and I use them as well.

                      o|||||||o
                      8200

                      johnpozJ T 2 Replies Last reply Reply Quote 2
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator @AndyRH
                        last edited by

                        @AndyRH to add to that - I have not run across a buglist or roadmap of any sort for unifi - not saying their isn't one but I follow the releases pretty closely, mainly for my APs - but since the controller is the same for both APs and their firewall/routers you see all the changes and reports when a new version is released..

                        I have never noticed any sort of listing of these issues, like redmine or anything.. Where you can see when something is reported or requested as feature when it is targeted for fix/release.

                        But I do notice a lot of posts about - yeah that was nice you added X or fixed Y.. But what about Z that has been asked for since version A, etc.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                        1 Reply Last reply Reply Quote 1
                        • T Online
                          tgl @AndyRH
                          last edited by

                          @AndyRH said in pFSense vs Unifi gateway / firewall:

                          Not being a follower of Unifi firewalls, patching required should be a high value point of comparison. Which one needs to patch more often?

                          Yeah, software churn is really UniFi's weakest point right now. They put out new versions often (every month or two) and they are constantly redesigning the GUI. I don't love that about them. It doesn't affect wifi-only installations so much, but if you have a complicated firewall setup you can expect periodic headaches along the line of "where did they move feature X to?" or "how am I supposed to do X now?". Of course, you don't have to accept every update right away ... but the more of them you skip, the more headaches you'll accumulate to be dealt with at once.

                          johnpozJ 1 Reply Last reply Reply Quote 2
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator @tgl
                            last edited by

                            @tgl and even when they add a feature - like this new digital twin thing.. They are not clear on the requirements to use a feature.. I see where I can add generic stuff.. But doesn't seem to work how others with unifi routers are showing their screens, etc.

                            My current pet peeve is now that they moved to this OS Server thing - their stuff is getting some love on updates, 5.0.16, etc.. and 5.1 even but since I have OS Server just installed on a vm, seem to be stuck on 5.0.6..

                            Same thing when they added their wifi doctor, wasn't visible until I updated my APs to U7 line, etc.

                            And don't get me started how they said you need to move to OS Server because we not going to provide the network application on its own any more, then guess what they did and they are still are - but I can not seem to get to be able to use the update they list for the controller software that runs on OS Server to just update that portion.. Have to wait til the OS server sees the update for the network application to be able to update it..

                            Yeah there is no way I would move my whole network to them.. APs ok - don't really need any of the fancy stuff they love to play with like digital twin.. Just need to set the psk on the ssid and a vlan id for it ;)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                            1 Reply Last reply Reply Quote 1
                            • Z Offline
                              zaphanathpaneah @johnpoz
                              last edited by

                              @johnpoz My AP is blazing fast, especially if im standing right below it. (ceiling mounted). I had to get an injector as I did not have a POE switch. The thing is I like my network rack quiet and any tp link switch with POE currently has a loud fan attached which is anoying. I got a TP Link OMADA switch off ebay and thought i could swap the fan for a quiet one but the switch complained alot with beeps as it detected there was no fan installed even though there was. the electronics is designed to look for a specific fan.

                              I have a 2.5gb managed fanless switch and its great but editing videos or transfering large files is slow at times. So I need to get a 10gb switch which ill get from Unifi. TP Link switches are very $$$ and they are noisy. they are big andloud. I need SFP+ & 10gb rj45 on my router but my 4100 does not have it. i could go to a 4200, 6100 or 8200, or 8300 but they dont have 10gb rj45 either. So SFP+ will have to work.

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ Offline
                                johnpoz LAYER 8 Global Moderator @zaphanathpaneah
                                last edited by

                                @zaphanathpaneah said in pFSense vs Unifi gateway / firewall:

                                10gb rj45 either

                                Why would you not just use a fiber connection for 10ge? Pretty much any copper 10ge more than likely has a fan if it has more than a few ports - they run hot..

                                Normally you would uplink from your switch to your router with fiber. Sure something that has 10ge copper you could use into your switch..

                                Blazing fast doesn't tell me anything btw - what is the model number? Mine are blazing fast too - no where near it ;) blazing fast really isn't a technical term heheheh

                                I have a 2.5gb managed fanless switch and its great but editing videos or transfering large files is slow at times.

                                2.5ge is capable of about 280MBps - can your disks do more than that.. I use 5ge between my nas and pc and I see 400MBps - it can not sustain that forever, it burns through the cache, and then drops down to what the disks can do which are about 250MBps.. But when only moving a few GB file see 400..

                                Unless your using nvme on both source and destination - 10ge isn't going to be the upgrade you think its going to be.. Sure I would run 10ge too if wasn't cost prohibitive, but then I would have to spend money to be able to have the space I need all in ssd vs hdd, etc. etc. It can turn into a never ending cycle

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                                Z 1 Reply Last reply Reply Quote 0
                                • Z Offline
                                  zaphanathpaneah @johnpoz
                                  last edited by

                                  @johnpoz All good points. I have NVMEs on one side but not both. So the speed will be limited to the cache size and HDD speeds. What I do is save to an local HDD and transfer between. I am working with hundreds of gigabytes of data so every second counts.

                                  As for my TP Link APs, I'm using an older EAP and I'm currently getting close to 700mbps, which is not super great considering I have 1gb service from my carrier. However this is more than adequate for my smart tvs and kids online schools. I had 2.5gb service at first thinking it would increase bandwidth and I would see great speeds, but the bottle neck was always in my environment.

                                  Cheers

                                  johnpozJ 1 Reply Last reply Reply Quote 0
                                  • johnpozJ Offline
                                    johnpoz LAYER 8 Global Moderator @zaphanathpaneah
                                    last edited by johnpoz

                                    @zaphanathpaneah if all you move the data between is your pc and your nas - you don't need to uplift the whole network for that. My network is only 1ge, but my pc and nas have a 5ge between them as SAN (storage area network) if you will.

                                    My pc has its 1ge connection in the network via 192.168.9.0/24 and so does the nas. But there is a 192.168.10/24 network between the pc and nas - no gateways set no dns..

                                    When I want copy files between my pc and nas I use the 192.168.10.x address.

                                    400MB.jpg

                                    That was a 2.5GB file - almost hard to catch the copy in a picture ;)

                                    Got a 5ge nic for pc, few bucks.. And a 5ge usb nic for the nas, since can not install any actual network card in the nas.. This slows it down a bit, and only can do like 3.5gbps between.

                                    $ iperf3.exe -c 192.168.10.10
                                    Connecting to host 192.168.10.10, port 5201
                                    [  5] local 192.168.10.9 port 38204 connected to 192.168.10.10 port 5201
                                    [ ID] Interval           Transfer     Bitrate
                                    [  5]   0.00-1.01   sec   432 MBytes  3.57 Gbits/sec
                                    [  5]   1.01-2.01   sec   416 MBytes  3.51 Gbits/sec
                                    [  5]   2.01-3.01   sec   422 MBytes  3.53 Gbits/sec
                                    [  5]   3.01-4.01   sec   423 MBytes  3.53 Gbits/sec
                                    [  5]   4.01-5.01   sec   421 MBytes  3.52 Gbits/sec
                                    [  5]   5.01-6.01   sec   420 MBytes  3.54 Gbits/sec
                                    [  5]   6.01-7.00   sec   420 MBytes  3.54 Gbits/sec
                                    [  5]   7.00-8.00   sec   416 MBytes  3.50 Gbits/sec
                                    [  5]   8.00-9.01   sec   391 MBytes  3.26 Gbits/sec
                                    [  5]   9.01-10.02  sec   422 MBytes  3.52 Gbits/sec
                                    - - - - - - - - - - - - - - - - - - - - - - - - -
                                    [ ID] Interval           Transfer     Bitrate
                                    [  5]   0.00-10.02  sec  4.08 GBytes  3.50 Gbits/sec                  sender
                                    [  5]   0.00-10.02  sec  4.08 GBytes  3.50 Gbits/sec                  receiver
                                    
                                    iperf Done.
                                    

                                    Doing this would cost you a fraction of the $, and could use either fiber or copper this way.. Where is your nas in relation to your pc?

                                    I would see prob a good 1gpbs more if was limited by the usb in the nas.

                                    I move quite a bit of video between my nas and pc - for my plex server. Some days 100s of GB for sure. So I get where you are coming from.

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                                    Z 1 Reply Last reply Reply Quote 1
                                    • Z Offline
                                      zaphanathpaneah @johnpoz
                                      last edited by

                                      @johnpoz Ahh.....brilliant!!! this is actually what I need. I have two NAS one for the family, a 2 bay Synology with 10gb and and home server with trunas running that has 16gb with more on the way. it has both 2.5gb and 10gb rj45 nics. I can run a connection between my pc and the nas itself and that would give me the bandwidth I need. thanks for the tip. The entire home does not need 10gb, just me so this is brilliant. I will be installing jellyfin soon so this will will come in handy also for transfering Blueray rips. I just need a cheap 10gb nic for my pc.

                                      johnpozJ 1 Reply Last reply Reply Quote 0
                                      • johnpozJ Offline
                                        johnpoz LAYER 8 Global Moderator @zaphanathpaneah
                                        last edited by johnpoz

                                        @zaphanathpaneah yeah it can be an easy solution if your pc and nas are in areas where you can run a new wire for the higher speed connection. If they are separate and you only have the 1 current network wire it can become a bit more difficult.

                                        My pc sits right next to my rack where the nas.. So its a few feet of wire.

                                        nassan.jpg

                                        Normally not a fan of jumbo - but since this an isolated network with just the pc and nas on it, upping the mtu to jumbo got be about 20MBps more..

                                        Let us know how it turns out - and what kind of speeds you can get on transfers.

                                        My next nas will for sure be able to do 10ge, I don't have the disks to be able to actually saturate that.. Especially for really large transfers.. but normally if transfer a few GB at a time in a file or 2.. Not 100GB at once sort of thing - so pretty much most transfers are from my pc nvme drive to nas rust drive - but the cache on the nas works as a great buffer.. Bumping its ram from 8GB to 16 made for a drastic improvement with file copies..

                                        cache.jpg

                                        I was thinking if I could use the nvme in the nas as sort of tiered storage where I transfer to there, and in the background it moves it to the rust drives I could get higher sustained transfers for more data.. But have not been able to work out a good way of doing it since synology doesn't actually support any sort of tiered storage.. But this works pretty good.. And not having to watch paint dry as a move a 4-5GB file from pc to nas, etc..

                                        edit: just noticed - did I move 1TB from nas to pc in less than 24 hours? Wow ;) in the process of cleaning up the plex db showing impossible added dates, like 57 years ago sort of thing.. And it was messing up my storage graph..

                                        I'm over the 50% mark on my space, so working out future plans of adding more.. Freaking drives are so crazy expensive currently..

                                        storage.jpg

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                                        1 Reply Last reply Reply Quote 0
                                        • planedropP Offline
                                          planedrop
                                          last edited by

                                          I think I can provide some good feedback here, I've moved my entire (rather complex) homelab network between pfSense and Unifi like 5 times at this point. I keep coming back to pfSense, and for good reason.

                                          I actually think there are important differences between the two, and there's also an impact from the low complexity of modern networks for most small businesses and homelabbers.

                                          pfSense is far far far superior as an actual firewall and router, it has many more capabilities with rule flexibility, better default rule sets with no hidden BS rules (aside from ones clearly outline in documentation like IPsec), more custom settings, proper dynamic routing setups, the list goes on.

                                          Where Unifi excels is in fancier features, a better looking (notably, NOT more functional) UI, and raw routing performance value.

                                          As a firewall, Unifi has come a LONG way, but it's also still a LONG way behind higher end offerings like pfSense. What it does do though, is great flow tracking, it's IPS/IDS is far simpler to configure and manage, and it's content control features are better.

                                          It's funny really, in a lot of ways UI has focused on "NGFW" features while having a pretty bad core for routing, VPNs, and firewalling.

                                          To me, it's fun to have all the graphs to show traffic usage, where your traffic is coming from, etc... built into the firewall without the need for something more complex like ntopng or a SIEM with netflow data fed into it. But it's important to recognize those things are FUN, not necessities, and in the business world you'll have a SIEM anyway.

                                          Another factor is VPN performance, Unifi is just terrible in this perspective, despite their routing performance value being so high. If you need fast IPsec you basically can't do it. I mean hell, their gateway that can do 12 gigabit throughput with IPS enabled can barely do half a gigabit for IPsec and just over a gigabit for other VPN protocols. My midrange 6100 can do 3x that.

                                          The big reason I've gone back and forth is actually core routing performance though. My UDMP, a $300 ish device, can route my full 8 gigabit WAN, meanwhile my Netgate 6100, which was nearly $1000, can only push about 3.5 gigabit. But each time I do this swap, it only lasts for a few weeks (I always get the Unifi stuff matching my pfSense environment before making the swap, so it's usually several weeks of setup), then I miss all the stuff I could do with pfSense and importantly the reliability of it.

                                          I guess my final point, in my already way-too-long comment, is that frankly, most businesses don't need more advanced features or high speed VPNs anymore. Many of what we would call small businesses need internet access, ideally with a few VLANs to keep IoT, guest, etc... traffic separate, and that's about it. Unifi makes those things really easy to manage at scale and their base firewalling has gotten good enough to not be a complete shit show now.

                                          T Z 2 Replies Last reply Reply Quote 5
                                          • T Online
                                            tgl @planedrop
                                            last edited by

                                            @planedrop Good summary, thanks. I don't have the sort of direct comparative experience you do, but what you wrote squares with what I've learned from reading the ui.com forums.

                                            1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                            Privacy Policy · Cookie Policy