5 ms·
As an alternative, I've been watching VyOS with great interest and it seems like they are finally going to release their controller and LocalUI interface this y
by robcohen 3y ago
As an alternative, I've been watching VyOS with great interest and it seems like they are finally going to release their controller and LocalUI interface this year, which is exciting. It seems to have a similar architecture as a Ubiquiti controller.
https://blog.vyos.io/ https://blog.vyos.io/
- fellowmartian 3y agoYeah I’m waiting for a good open source Linux-based firewall, it’s way overdue. Linux has surpassed FreeBSD in terms of networking, at least for the home/SMB router use case. I’m talking about Cake, eBPF, etc. I’m currently running Mikrotik x86 on a NUC, but their hardware support on x86 isn’t great. I’d rather switch to Vyos, but I’m too lazy to learn their CLI. Semi-related: OpenWRT is also genuinely not bad on x86, but it’s slightly too simplified compared to say Mikrotik or VyOS. It also runs great in a VM.
- n8henrie 3y agoSame! Have you looked into IPFire? That's the one I had my eyes on.
- fellowmartian 3y agoI actually used to run it years back, but it unfortunately hasn't been updated very much since.
- hnarn 3y ago> Linux has surpassed FreeBSD in terms of networking Can you elaborate on this?
- fellowmartian 3y agoAs I said above, it's stuff like Cake, which is an advanced QoS scheduler that helps eliminate bufferbloat (very relevant for home networks). Additionally, eBPF and XDP will soon be integrated into standard firewalls, which should speed them up dramatically, allowing for crazy high speed (or power efficient) routing on commodity hardware.
- _ea1k 3y agoOpenWRT also runs great on ARM. Even the Raspberry Pi can work well for home use.
- donmcronald 3y agoI always wanted to try it, but $8k / year for the cheapest stable release license isn’t in my universe for affordability. > It seems to have a similar architecture as a Ubiquiti controller. That’s a hell of an insult to be tossing around for an unreleased product. Lmao.
- robcohen 3y agoWhy’s that? I actually like the api system for Ubiquiti gear.
- donmcronald 3y agoThe Ubiquiti controller is fine if you're managing one site, but beyond that it's pretty poorly designed IMO. By far the biggest problem is that they don't give enough consideration to recover-ability of offsite devices. If something causes a device to disconnect from the controller their solution is to SSH in and re-adopt it. That doesn't work once you're dealing with hundreds of devices across dozens of sites. A good example of where that becomes problematic is to look at the controller hostname override setting they have. You could change it to 'unifi.invalid' and it would happily push that change out to a thousand devices and leave them in a state where you'd need to be hands on with every device to recover. If you can do it on purpose, they can do it accidentally with a buggy update, so, IMHO, there's always a risk that an update could break things pretty badly. That's not a hypothetical either. They (purposely) pushed an update that did something like that when they started supporting HTTPS for the inform URL several years ago. The second issue I have with it is more of a design issue. Sites should be somewhat sharded and I should be able to update the controller version on a per-site basis. I think that does a lot to reduce the risk of an update breaking things. I also dislike the default settings and prompts for auto-updates. I like the scheduled updates and think they're great, but the push to "update everything daily at 3:00 AM" is too much. I have a controller with 100+ sites and need to schedule updates to ensure any breakage is fixable via manual intervention up to the point of physically visiting a site. Edit: To clarify this, I'm sure I've been prompted to enable 3:00 AM auto-updates on the newer controller versions and accidentally clicking "yes" would be a huge headache for me. The "rolling update" was also pretty trashy when I tried it. That was years ago, but I think it simply updated APs sequentially and happily continued if the previous one didn't come back up. How hard is it really to implement a rolling update that stops and waits for intervention if even one device doesn't come back online? And the UI. I can't even use it without setting my browser to 80% zoom and it gets worse every time they push out an update. Everything is stuck into tiny little scrollable boxes. I have multiple 27" monitors and get stuck scrolling around in a 1" x 2" box that can't display more than 2 or 3 lines of config. Why? And then TP-Link copied them with Omahda. It's almost funny. I wonder if they even realize they're copying off the dumbest kid in the class. Lol.
- synergy20 3y agoubiquiti indeed ran vyos underneath then improved it over the years
- robcohen 3y agoI think you mean Vyatta