Everything Wrong with the UDM-Pro (2024)

preview_player
Показать описание
In this video, I "review" the UDM-Pro from the perspective of an advanced networking need. Brace yourself, because it sounds like I'm not too fond of this device and I slam a lot of its most useful features. In reality, I still use it as my primary gateway and it works very well. It just isn't the same cost-to-feature ratio as other Ubiquiti offerings.

Timestamps:
Intro: 00:00
Confusing Firewall Rules: 02:33
NAT Configuration: 06:05
VPN Woes: 08:08
Wireguard Client Woes: 19:30
SNMP: 27:06
OSPF: 29:30
Security Services & Logging: 35:53
Multi-Site Management: 41:35
AD Block & Threat Reporting: 43:07
GEO-IP Filtering Logs: 47:21
Shadow Mode: 54:40
General "Unifi" Miscommunications: 57:40
SSH Access: 58:45
Subjective Frequent Outages....:1:00:13
Outro: 1:01:23
Рекомендации по теме
Комментарии
Автор

Excellent review Toasty I hope Unifi listens to your comments! I use the UDM Pro in a business environment with about 100 connected devices because it's almost plug and play, decent GUI, no annual license, reasonably good IPS and IDS, Wireguard VPN for cell phones and automatic Internet failover and the price point makes is affordable for SMEs.

carlyleroberts
Автор

as a UDM owner, I pray Ubiquiti watches this

kgury
Автор

This is excellent feedback for Ubiquiti. I agree the advanced firewall rules are somewhat ambiguous in how one might interpret them.

bryandulock
Автор

Hi Toaster! - that was a good run thru with all the services - good work and hope Ubiquiti developer see the review - good work

jesjen
Автор

3:20 Can you add an update in your description or comments for what version firmware and software this is? In the video it shows "Network 8.1.113". I believe the version 9 software allows zone based firewall rules also.

johnson
Автор

I agree with those a lot of your feedback I currently manage an environment with about 1500 clients 57 unifi switches and 73 APs. My firewalls are sonic wall currently. I did buy the Enterprise grade unifi gateway EFG Enterprise Fortress Gatewa or whatever it's called to play around with and I hope to eventually be able to switch over that I will say in the past year they have added a lot of extra features and done a great job expanding the capabilities of their routers. But I will say the quality of their equipment and ease of use in future set is unmatched for the price even if they do have some weird quirks to them. Anyway great video and I hope ubiquiti watches this and continues there expansion of product features and does a little clean up.

CDWD-Project
Автор

Why did you create all the firewall rules to prevent your VLAN's from talking to each other instead of using the "Isolate Network" checkbox under each network? Is there an advantage to creating your own rules vs. using the checkbox to enable the unifi predefined rules?

GarvsTavern
Автор

Did you have any chance testing the throughput rate for the UDM Pro when using small MTUs like 64, 128 or 256 byte packets (L2)? A quick check I did lately tended to show that when hammering the device with a steady stream of small packets, throughput drops like a brick (I do know that for 64 and 128 byte packets it is impossible to obtain 1G throughput on L2, but based on my readings it was in the ballpark of 200 to 300Mbps max. (As with you it IS my main router and gateway at home, but as you I am in IT/networking and know a couple of things testing networks on L1/L2 when it comes meeting SLA requirements on throughput/stability/frame loss so I am curious about what you are eventually able to measure)

RealLordy
Автор

Snmp support recently got enabled on UDM Pros via network GUI, so hopefully someone found at ubiquity found your video.

WickedFalcon
Автор

@Toasty, I'm currently running dual Edgerouter4's in a VRRP configuration.
I am considering moving to something else that is similar in functionality and technicality, not necessarily retaining a VRRP config, but I don't want to go to any of the UDM lines like the Pro, SE, Pro Max, etc for the reasons you've pointed out in this video, but also because I feel that these devices, especially the Pro, are still too buggy in their reliability for my liking.
What would you recommend?

darrenoleary
Автор

Thanks @Toasty. An excellent review that all the other YouTubers "UI fanboys" would never be able to show (or understand).
P.S.: "Shadow mode" is surely the most stupid implementation of anything which could remotely be called "HA" I have ever seen in my life. It is a complete joke.

f.d.castel
Автор

We have route based tunnels going from UDMP to other firewall brands without problems using IPSEC. But of course that might not work for all scenarios. But we use it to tunnel from remote offices to servers in a data center. So it can be done

driver
Автор

Hi there, super nice content ive been a unifi consumer for the las few years, but right now with all this mayor upgrades that they have done, im in need of some consulting and brainstorming for an specific scenario that i acquired with EOL switches need to be upgraded and a fortinet routing environment. looking foward to replace it all with unifi, so any advice or idea exchange will be very helpful.

Chris-jwf
Автор

NAT. On the wan interface you can have multiple IPs and NAT different subnets services or devices through a specific one. So that does exist.

driver
Автор

On a second note: the current EA version of the UI operating system covers a lot (really, I mean it) of your worries already such as your remarks on NAT and SNMP. Seems they have been watching your channel closely 😊. I subbed by the way as there was really a ton of useful information in this video

RealLordy
Автор

what a great and veyr detailed video. Funny enough i was leaning very heavily on replacing my pfsense netgate 6100 with either a UDM Pro or the EFG. I was still skeptical because i knew beforehand of the shortcomings of the product but after watching this video...ooffff...i will stand down for now. For now, my pfsense box which i leverage for BGP dynamic routing along with IPsec vpns seems to be the way to go.

Really appreciate this video my man. Good work.

PowerUsr
Автор

is port forwarding are working fine on this device? also someone claim that you cannot login if no active internet? please confirm.
thank you

HOOBasics
Автор

Has your view changed with Network version 8.4.54 installed? I noticed under routing NAT does appear now. I guess you don't use 2FA on any of your clients VPN's? This is a major problem with the UDM-Pro as none of their VPN servers support it. SNMP v3 on my UDM-Pro running 8.4.54 doesn't show my UDM-Pro but it does show my USW Enterprise 8 PoE switch.

andrewenglish
Автор

Hi Toasty. Just discovered your channel while looking for info on the Ubiquity U7 Outdoor access point. Would you be willing to do a video on the subject and show us the configuration process? Also, I HATE that everything has a “controller” so could you also show us if there is any way to access it without using the controller? If so, what can it do or not do. For example, can it connect to dual or triple wifi bands without the controller? Hmmm, this sounds like it may take TWO videos after which I will have more questions, lol. But if the procedure would be the same as your “Unify AP - First Time Setup” video, please let me know and I will just follow that video. Thank you. Oops - it just occurred to me that you would have to BUY the access point to do a video about it when all I’m trying to do is extend my wifi to help my surveillance cameras reach back to my router better because their signals are weak and unreliable at 175 feet away. 😔

angelsoul
Автор

Have you ever tried to test the speed across VLANs? For me I could only get 1Gbps if devices are in different VLANs even with 10G ports connected (to a 10G switch under UDM and it is connected to UDM's 10G port).

FishWong
visit shbcf.ru