No video

UniFi June 2024 Update: New Features & Long-Awaited DNS Rollout!

  Рет қаралды 39,367

Lawrence Systems

Lawrence Systems

Күн бұрын

Пікірлер: 107
@corycoffey9474
@corycoffey9474 2 ай бұрын
I have been very happy with Unifi software updates within the past 6 months. I can say I have moved off pfsense to a UDM SE into production. I never would have thought I would do this a year ago.
@jacksoncremean1664
@jacksoncremean1664 2 ай бұрын
I'm pretty impressed these past 6 months too. If they add support for 3rd party blocklists, and actually give you granular control over Suricata then I may not switch to OPNsense.
@AHumanMale
@AHumanMale 2 ай бұрын
Same. Went from a Netgate 3100 which was EOL to a UXG-Pro. Couldn’t have considered that a year or two ago.
@marcuschong84
@marcuschong84 2 ай бұрын
same here, from a N100 with pfsense to a UDM SE and couldn't be happier
@jochenx6944
@jochenx6944 2 ай бұрын
Unfortunately, while some released features are great, I no longer consider Ubiquiti/UniFi products reliable in performing advertised tasks. For example, when they released the Doorbell Pro, it was advertised with Fingerprint and NFC functionality. Neither of these „coming soon“ features were ever released nor has any timeline been published. A vendor that lies to their customers once will do this often, the other instances are just not yet known. -> Ubiquiti/UniFi is not trustworthy equipment.
@chaosfenix
@chaosfenix 2 ай бұрын
I would love them to keep expanding here. I would love to be able to upload custom block and allow lists to their DNS ad blocking. I would love if their DNS system could basically absorb the feature set found in pi hole. Without being able to add custom lists and possible more importantly custom allow lists it is still necessary to have a separate pi hole.
@tonygerassi1502
@tonygerassi1502 2 ай бұрын
There is literally 2 features that keep me using pfsense as a side cart to my UniFi setup at home. UDP relay for an mdns repeater to allow SDDP and Roku streaming across different networks.
@AHumanMale
@AHumanMale 2 ай бұрын
Completely agree about the greatly improved quality of UniFi updates. A few years ago I would hesitate to update very often and used to expect problems. Now I don’t worry much about it. Though I still don’t allow my devices to auto-update, and I never will. That’s just asking for trouble…
@Darkk6969
@Darkk6969 2 ай бұрын
There's nothing really wrong with auto updates. Just don't let it apply the day of release. I usually set mine to update themselves after 14 days of release to give them time to catch anything that may cause things to seriously fail.
@gregorydelapierre582
@gregorydelapierre582 2 ай бұрын
DNS forwarding was the biggest improvement i was waiting for since i migrated from PFsense for a more integrated approach. I still dislike the FW side of Unifi but there are so many good things with Unifi when you manage 2 remote sites.
@christophrechtlehner
@christophrechtlehner 2 ай бұрын
Ad blocking and DNS overrides where the only reason why i had to host my own DNS server. Or rather two, because i needed a secondary zone as a failover. Now that failover is no longer necessary, because I don't need DNS if my entire routing is down. This feature greatly reduces my upkeep and maintenance work.
@MrSunDevil23
@MrSunDevil23 2 ай бұрын
I am a certified Cisco/Meraki engineer but I do not like where they are going. I recently changed my home lab from Meraki to UniFi and I love it. Mostly due to your videos and straight forward explanations. While I understand all the concepts, each vendor has unique ways of presenting them. Thank you for the easy and technical descriptions. I can’t wait to totally ditch Meraki (licenensing) for something better.
@michaelh5722
@michaelh5722 2 ай бұрын
I was a UniFi user from when the USG was first released (for home) but eventually got so frustrated I switched to Firewalla Gold when that was released. The Firewalla is brilliant, but seeing the improvements UniFi has been making and also quite impressed with Protect, I’m very tempted to get a UCG Ultra to try out.
@DBravo29er
@DBravo29er 2 ай бұрын
I'm actually shopping UniFi Max vs Firewalla Gold Plus right now. What is your opinion for strictly home use with lots of media streaming and WFH on a Gigabit connection?
@michaelh5722
@michaelh5722 2 ай бұрын
@@DBravo29er I think it really depends on whether you need the Parental Controls or not. The rest of the feature set seems to be roughly similar now. I’d say the negative with the Firewalla is it’s mostly managed from their phone app. You can login via the desktop but it isn’t as good and not all features are available. Even if I go back to UniFi, I will keep the Firewalla in bridge mode. Then basically all the main networking admin will be through UniFi and the parental controls though Firewalla. I will say the Firewalla has been absolutely rock solid and I’m extremely impressed. It has never gone down for any reason besides an update.
@DBravo29er
@DBravo29er 2 ай бұрын
@@michaelh5722 Fantastic reply and exactly what I needed to know. I do really need the parental controls (several young sets of eyes in the home), so that seals the deal for me. My silly Netgear Orbi only uses an App, so...though not optimal....I'm used to that. I only use the web interface for my Netgear managed switches.
@DBravo29er
@DBravo29er Ай бұрын
@@michaelh5722 I grabbed a Gold Plus about a week after the exchange above. I'm very pleased so far for my use case. Running symmetrical Gigabit fiber. Firewalla GP actually sees 1122 down and 1150 up when using the 2.5G port on the ONT. Very pleased. The only issue since that the Gold Plus runs warmer than I would like. SO I grabbed some 10mm adhesive rubber feet on Amazon and the temp on the top of the FGP chassis dropped 10 degrees F just from air-gapping the bottom plate. We're now in my range of warm-but-normal. 👍
@Sevenfeet0
@Sevenfeet0 2 ай бұрын
I’ve been with UniFi since the end of the 5.x days. The platform had promise but the software had a long way to go and bugs often crept into releases or in some unfortunate cases, bricked hardware (it happened to me once). These days the software model and QA is far better and there is clear momentum with the team to close feature gaps that have been out there for years. Every 30-60 days we get new features and by and large it’s pretty stable.
@leefelske9999
@leefelske9999 2 ай бұрын
I've been happy with Unifi over the last 5 years.... i have a couple hundred devices spread out over a couple of offices and clients. will be setting up my first UDMSEPRO this month down the road from you in Ann Arbor in. an office / warehouse we picked up for operation at U of M construction we'll be doing for the next 4 years... Picked up an Enterprise switch and other gear wtih it... We'll be seeing how well we pipe into our Corp headquarters in Toledo... should be interesting... it's been getting easier to use every year that's gone by
@r.e.434
@r.e.434 2 ай бұрын
Biggest bummer is that there are no good firewall logs / SIEM integration
@MB-ei2ct
@MB-ei2ct 2 ай бұрын
And you can't turn off nat to use a more civilized gateway/firewall
@ashuggtube
@ashuggtube 2 ай бұрын
@@MB-ei2ct you can use a non-Ubiquiti gateway/firewall if you wish
@hpsfresh
@hpsfresh 2 ай бұрын
It is sooooooooo stupid to not let import dns records from csv…. people have a lot of them
@jasonklems8584
@jasonklems8584 Ай бұрын
anyone else seeing an issue where cutom dns records done work if you have content filtering enabled for your vlans ?
@dan_lev
@dan_lev 2 ай бұрын
I"m getting close to changing over from Meraki to Unifi. Not a huge organization, maybe 100-120 endpoints. Our meraki bills are ridiculous and their switch pricing is completely unacceptable.
@kevinclinthorne
@kevinclinthorne 2 ай бұрын
Very excited for actual BGP support, I've been running it on my UDM pro for a while now, but I've always been a bit worried about it breaking. Will be really nice to have it actually supported finally
@RonLaws
@RonLaws 2 ай бұрын
Is the DHCP still missing important options for UEFI Network boot? It has a Legacy PXE option but lacks a UEFI option so far. very annoying.
2 ай бұрын
Could you please do a malicious domain test on NextDNS vs ControlD?
@1Sbnelson
@1Sbnelson Ай бұрын
Great video, thanks for all the work you're putting out there for us all I've dove into the deep end of the UniFi pool and there's one place that's a little frustrating and seems to be a hole in their product line. At home i've got 1400mbps dl speeds from my ISP but it seems that the only way to fully realize my full dl speeds would be to go to a Dream Machine Pro, which is WAY overkill for my home. It sure would have been great if the Ultra line had 2.5 LAN ports
@headlibrarian1996
@headlibrarian1996 2 ай бұрын
ACLs are still bidirectional?
@bdouglas
@bdouglas 2 ай бұрын
Love the content as well as your presentation. Thank for all the goodness!
@Incredulous1972
@Incredulous1972 2 ай бұрын
if they just invest a little more effort into modern, dynamic security features and routing features.... they could take over and dominate the SMB market.
@DBravo29er
@DBravo29er 2 ай бұрын
New to the SMB/home lab firewall space. Are Unifi and Firewalla the *ONLY* non-subscription options?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 ай бұрын
pfsense is a popular option as well.
@DBravo29er
@DBravo29er 2 ай бұрын
@@LAWRENCESYSTEMS Thank you for the reply. I have seen that. However, I'm an IT neophyte and have several kids under 1 and just don't have a ton of time to learn a new ecosystem right now. I know that may seem lazy, but there are only so many hours in the day. I'm currently using Netgear Defender on my Orbi Mesh router and have become fully aware that it is a flawed solution. The accessibility and usability of UniFi and Firewalla is a HUGE benefit to me and my use case.
@F0XH0UND007
@F0XH0UND007 2 ай бұрын
I have deployed about a dozen unifi APs and not once did I have issues with them. Only time I ran into a problem was with a gen1 cloud key. Overall great product and will always recommend.
@andreas7944
@andreas7944 2 ай бұрын
Their APs had issues in the past and the current Wifi7 models are still considered unstable. There is a strong pattern with Unifi APs => new AP Generation = many bugs, stability issues and not suitable for production environments. It's almost a tradition. Don't get me wrong, the hardware usually is quiet good. But they tend sell prod hardware with beta software. And that is annoying.
@steven_b007
@steven_b007 2 ай бұрын
On my "UCK_Gen2-Plus" (in UniFi OS version 3.2.12), when I changed the "Network" application from version 3.x to 4.x, ALL my cameras (on a VLAN which is not the same as where the "UCK_Gen2-Plus" is) disappeared. They are only visible (fortunately) in "Protect". Opened an incident at Ubiquiti -> they can't find .... so I'm only moderately happy with this system.
@RK-ly5qj
@RK-ly5qj 2 ай бұрын
For me the most needed feature (besides what already came out) is to have FW rules better implemented. I think they are doing it cuz "simple" mode is something what could be in the feature. Where you would have simple gui where you can chose src dest with protocols and protections. Like Fortior sophos or else has. I hope that Ubi is gonna do the job done ;)
@hisroyalhgness7279
@hisroyalhgness7279 14 күн бұрын
hello, great video, thinking of going with a UDR + 1 or 2 UAP. My setup is to fit this purpose: 1) needs to connect up to 20 devices(but currently 8) including future NAS 2) has to have channel separation for streaming and gaming, work and IOT 3) main router(from ISP, can LAN connect it to UDR, or UDR will replace it) is at ground level, not wired up to upper level, so mostly will need a type of mesh or access point, 4) might use a raspberry pi for ad blocking infront of UDR 5) might use psense if UDR firewall is not much. advanced Any suggestion whether UDR will be good for this setup?
@bentheguru4986
@bentheguru4986 2 ай бұрын
Yeah, brought back old issues, blocked internet on "Guests" network option ticked. Also broken SFP ports and needs the the ports to be reset and reconfigured. PITA if you have LAG. Now forced to use Legacy GUI to re-adopt devices that hang which is now very common when the device is marked "Resolve" becasue the controller application is stuggling with all the network management noise. A bit tip for anyone using UniFi, put your network management on its own IP subnet and put all your other networks on other VLAN's. It's more improtant than ever with stuff like sprectrum and other stuff that floods the controller. UDM-Pro users, you are stuck with that rack-mounted home product as you can't VLAN the cameras away from the management network and Protect won't work on anything but it if you are using cameras on the UDM-Pro's.
@Overlanding
@Overlanding 2 ай бұрын
Quick question: Last time I switched router and came across the UDM Pro four years ago I went for and OPNsense box because of the UDM phoning home with no way of disabling it. Is Ubiquiti still not giving customers the ability to opt out of *all* their data collection or are the devices still phoning home? I like the UDM Pro Max because of it’s 5Gbit IPS and consider buying one but a router phoning home is a big No from me.
@papaorti1842
@papaorti1842 2 ай бұрын
Thanks for the video. However, my DNS-test did not work for whatever reason. Set up an A-record for test.test to an internal IPV4 address. dig command shows correct name resolution but if i enter test.test in safari I end up with a google search on this. Have no idea what is going wrong here.
@Andrew-B324
@Andrew-B324 14 күн бұрын
What is the significance of interference. Is this something to worry about? Should I try to eliminate it completely?
@malyzeli
@malyzeli Ай бұрын
I'm trying to set up custom DNS entries for my local network, but it seems that it's not possible with USG-3..? There is no DNS tab in my Routing section even with latest Controller version and unfortunately I didn't find any relevant information in official documentation. I know I can configure host records via `controller.json` file, but I hoped that this UI update would be available for legacy devices too... :/
@LorneCash
@LorneCash Ай бұрын
When connected via the Wireguard VPN is it possible to access local resources by hostname (DNS) rather than IP address? OP Would you consider making a video on this topic?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Ай бұрын
If you setup the DNS then yes.
@albertostrazzabosco9244
@albertostrazzabosco9244 2 ай бұрын
U7-Pro-Max: a dedicated antenna for scanning the environment? ... it does not sound totally new to me. I'm still waiting for WISP feature in my UAP-AC-SHD. It will be nice if the scanning feature (without disconnecting all other devices) will be reintroduced in UAP-AC-SHD, like it was time ago. 😕
@djdunc
@djdunc 2 ай бұрын
Hey Hive Mind! With the new availability of proper Shadow Mode on the UDM Pro range, if I wanted to add LTE backup using their offering, would I need two for failover, or is there another way of doing it? Normally using a teltonika unit I'd just put a small switch in line to split the feed.
@bothorsen4292
@bothorsen4292 2 ай бұрын
The BGP should be helpful for on-premise kubernetes clusters using MetalLB. I'm keeping my fingers crossed for this, at least
@michaelventarola7100
@michaelventarola7100 15 күн бұрын
Does it support PTR records?
@KevinMorse
@KevinMorse 2 ай бұрын
I was burned by upgrading from release 7 to 8 of the software. I have clients using site to site VPN with USG and the site to site functionality stopped working after the upgrade.
@alandoyle95
@alandoyle95 2 ай бұрын
do you have issues with their switches showing as needing to be adopted a ton after updates? or reboots?
@MacGyver0
@MacGyver0 2 ай бұрын
Is it necessary to safely stop netwok dependent applications like VMs with nfs drives before unifi network app update?
@andrewwebb5871
@andrewwebb5871 2 ай бұрын
Can we get a guide on how to set up acl's on unifi switches now its available?
@Raven82PL
@Raven82PL 2 ай бұрын
Is it available in a self-hosted docker controller? I can't seem to find it? Or is the USG3 a problem here?
@Greenerkev1
@Greenerkev1 2 ай бұрын
Thanks!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 ай бұрын
Thank you
@ashuggtube
@ashuggtube 2 ай бұрын
Nice one Tom, thanks very much!
@BaMb1N079
@BaMb1N079 2 ай бұрын
the dns feature should not have been rolled out without cname support. that's literally the most important thing on a local network if you wanna keep maintenance low and reliability (regarding web applications for example) high.
@jasonklems8584
@jasonklems8584 Ай бұрын
Agreed, without cnames, whats the point. Also, if you have content filter checkbox enabled on vlans, the custom dns records will/may fail. I have an open ticket with ubiquiti for the past 2 weeks. no fix yet
@trendkill9970
@trendkill9970 2 ай бұрын
Does it possible to use Unifi Express only as a local controller to host Unifi Network? I would like to use unifi express behind my pfsense firewall.
@MB-ei2ct
@MB-ei2ct 2 ай бұрын
Yeah eh? If only we could turn off NAT. It's 2024 ffs
@MB-ei2ct
@MB-ei2ct 2 ай бұрын
Unfortunately you've got yourself nothing more than an AP with a little screen otherwise.
@not2tired
@not2tired 2 ай бұрын
@@MB-ei2ct T.H.I.S. . (Re: turning off NAT)
@Neubs-xv8tw
@Neubs-xv8tw 2 ай бұрын
Love Unifi!
@mx338
@mx338 2 ай бұрын
I still hate that the U7 Pro Max is a thing, naming wise.
@peterpain6625
@peterpain6625 2 ай бұрын
Wait until they add an "Ultra" or "++" :D
@BoraHorzaGobuchul
@BoraHorzaGobuchul 2 ай бұрын
Nano ai
@UnknownEntity420
@UnknownEntity420 2 ай бұрын
Just wait till they bring out the u8 pro max ultra gaming plus, now with AI
@MeTheCoolDude
@MeTheCoolDude 2 ай бұрын
The joys of the founders of UBNT being ex Apple
@peterpain6625
@peterpain6625 2 ай бұрын
@@UnknownEntity420 Guess we could add "turbo"? ;)
@Dongdot123
@Dongdot123 16 күн бұрын
Unifi should partner with adguard
@christianlohmann8577
@christianlohmann8577 2 ай бұрын
Hopefully the DS-lite for Japan ISP is included … I want to dump my ISP default router still between my UDM SE and the wall. Double- or triple-NATting
@andreas7944
@andreas7944 2 ай бұрын
I am not sure about that. Even with a firewall like PfSense or OpnSense, I need a real DS and not a DS-Lite in order to make it work correctly. Usually you can give your ISP a call and ask for it. Just mention that you have problems with the double NAT that cannot be resolved with DS-Lite.
@nebhead77
@nebhead77 2 ай бұрын
I still have issues with the latest firmware on my Unifi AP AC Lites and AC Pro. I'm currently holding with 6.2.49 because if I update to the latest FW, my IoT devices will drop off the network. I want to love UniFi, but this is definitely holding me back from buying any more of their AP devices.
@andreas7944
@andreas7944 2 ай бұрын
Do not buy into their WiFi7 stack yet. I tried one and had to send it back. U6 is a quiet safe choice.
@MB-ei2ct
@MB-ei2ct 2 ай бұрын
But you can't disable NAT eh? Still? Lol
@magmf
@magmf 2 ай бұрын
You can 8.3 is in Early Access and you can manage NAT / SNAT / DNAT or disable NAT
@MAKuser
@MAKuser 2 ай бұрын
Oh, they finally reintroduced the interference scan, like we used to have with the UAP-AC-SHD, would you look at that 😅 Now wouldn't it be normal, if the feature that was previously removed with the old AP would just be reimplemented on the new UI...? Nah, this is Ubiquiti after all 😂
@nellermann
@nellermann 2 ай бұрын
mlag or stacking would go a long way to help us deploy unifi outside of SMB in core LAN. their firewalls are SMB and prosumer for sure, not enterprise grade and that is fine. We have a lot of environments with unfi for switching and wifi but not routing and firewalling.
@mrman991
@mrman991 2 ай бұрын
Unifi really seems to be the center point of a lot of my issues. This has me in the awkward situation where I have to constantly step back and try not to blame unifi as a first port of call.
@dataplatter
@dataplatter 2 ай бұрын
Hopefully they finish updating Hotspot soon- it’s kind of a half done mess since they started changing it after 7.3.83.
@user-sl4ul4nc3t
@user-sl4ul4nc3t 2 ай бұрын
When are they going to support DoH or DoT? I wish they would just stuff unbound in their controller.
@magmf
@magmf 2 ай бұрын
DoH is already supported for a while it is called DNS Shield
@johnhart5102
@johnhart5102 2 ай бұрын
love Unifi, but it's next to impossible to get hardware here in Canada
@BoraHorzaGobuchul
@BoraHorzaGobuchul 2 ай бұрын
The US is really close though, can't you but online there and ship?
@ashuggtube
@ashuggtube 2 ай бұрын
Surprised to hear it! The store on their website has a Canada instance, and there are resellers - what's the issue?
@Margucci
@Margucci 2 ай бұрын
I still don't like the firewall rules as a whole. The old way of doing rules was cumbersome and not as straightforward as something like pfSense. The new rules are great but strange how they work. You can't even adjust their priority. I think they just need to ditch the old way of doing rules entirely and make the new way more robust. It reminds me of the old vs new interface they had when you had to switch back and forth for different settings and features.
@MB-ei2ct
@MB-ei2ct 2 ай бұрын
The Ubi firewall is trash. But you can't turn off NAT
@marcusmaciel6194
@marcusmaciel6194 2 ай бұрын
@@MB-ei2ct you can now with the latest early access version 8.3 :)
@MB-ei2ct
@MB-ei2ct 2 ай бұрын
@@marcusmaciel6194 OHH HE'LL YA BORTHER! Thanks! I can finally dust off this UX in my closet.
@thraxarioustailchaser158
@thraxarioustailchaser158 2 ай бұрын
Are they going to fix the U7? all the talk is that it's flakey. I'm having enough problems with my old AC pro wimping out. My old Wifi N AP was better and more reliable.
@rpetty
@rpetty 2 ай бұрын
Haven’t had any issues with mine.
@andreas7944
@andreas7944 2 ай бұрын
Yeah, I did not like the AC APs and the U7 firmware is not yet production ready in my eyes. It will be fixed, but that will take time. The U6 APs are really stable. Apart from that, certain Wifi7 features have not been implemented yet (afaik). The U7 firmware currently gets updates on a regular basis. But not every update makes it to the official release channel.
@dataplatter
@dataplatter 2 ай бұрын
Why DNS is under Routing is beyond me
@ashuggtube
@ashuggtube 2 ай бұрын
Got to put it somewhere… and the Routing section is the least worse choice. If the device offered any other client/server application services, like file sharing, it could go in that section.
@ashuggtube
@ashuggtube 2 ай бұрын
Best place for it without a significant interface change
@NetITGeeks
@NetITGeeks Ай бұрын
Too bad UniFi firewall and routing options have a loooong way to go even now to catch up to OpenSense and pfSense! What UniFi line has is very high quality hardware with poorly executed software/firmware.
@TechySpeaking
@TechySpeaking 2 ай бұрын
first
@nt-eli7333
@nt-eli7333 2 ай бұрын
3rd person
@in2thecloud769
@in2thecloud769 2 ай бұрын
Why Speak so Fast we are not all Native English
@ashuggtube
@ashuggtube 2 ай бұрын
You can use the cog icon in KZbin on your smartphone or web browser to change the playback speed to 0.75x and also turn on Closed Captions, these should help
Unifi G5 PTZ is HERE!
21:29
DPC Technology
Рет қаралды 23 М.
Top 13 Unifi Network Setup Tips - Planning and Optimization
40:02
Ethernet Blueprint
Рет қаралды 51 М.
❌Разве такое возможно? #story
01:00
Кэри Найс
Рет қаралды 3,3 МЛН
Survive 100 Days In Nuclear Bunker, Win $500,000
32:21
MrBeast
Рет қаралды 165 МЛН
PEDRO PEDRO INSIDEOUT
00:10
MOOMOO STUDIO [무무 스튜디오]
Рет қаралды 13 МЛН
The Joker kisses Harley Quinn underwater!#Harley Quinn #joker
00:49
Harley Quinn with the Joker
Рет қаралды 9 МЛН
UniFi Basics: Start the Right Way Without Breaking the Bank!
14:52
Crosstalk Solutions
Рет қаралды 179 М.
A Ubiquiti UniFi NAS Is Coming...
8:59
NASCompares
Рет қаралды 65 М.
Graylog 6: The Best Open Source Logging Tool Got Better!
9:36
Lawrence Systems
Рет қаралды 32 М.
Microsoft Is KILLING Windows | ft. Steve @GamersNexus
19:19
Level1Techs
Рет қаралды 407 М.
UniFi Cloud Gateway Ultra
16:03
Willie Howe
Рет қаралды 32 М.
The $299 Everything 10G Firewall NAS and Virtualization 1U
20:42
ServeTheHome
Рет қаралды 151 М.
❌Разве такое возможно? #story
01:00
Кэри Найс
Рет қаралды 3,3 МЛН