6 ms·
That sound like a terrible workplace. For your own home, if not Ubiquiti, what do you use nowadays?
by gene91 3y ago
That sound like a terrible workplace.
For your own home, if not Ubiquiti, what do you use nowadays?
- lotsofpulp 3y agoNot the person you replied to, but I like Aruba Instant On. https://www.arubainstanton.com/ https://www.arubainstanton.com/
- aetherspawn 3y agoLooks good but lacks layer 3 and fiber aggregation switches which we use in our SMB.
- mook 3y agoHmm, that looks like it must be centrally managed from the internet? Not saying it's not an appropriate replacement for Ubiquiti, but that seems like an opportunity for the same issues to show up… something that isn't remotely managed might be better instead.
- lotsofpulp 3y agoI think the "InstantOn" functionality requires internet for setting up, but it seems like there is a way to manage it locally without the use of the "InstantOn" functionality: https://www.arubainstanton.com/techdocs/en/content/get-started/switch-local-mode.htm https://www.arubainstanton.com/techdocs/en/content/get-start... Some more discussion here from years ago: https://community.arubainstanton.com/communities/community-home/digestviewer/viewthread?MID=454 https://community.arubainstanton.com/communities/community-h... Although, I imagine this type of stuff may not be made to work well without internet.
- mook 3y agoThanks! So it sounds like it may work, but it's very unclear it'll keep working. (Also I happened to be more personally interested in the APs rather than switches, and it's unclear if that also has a local management mode.) I notice that the linked docs article doesn't get listed if you go up the breadcrumb and try to go back down…
- hughesjj 3y agoTplink for aps and mini PCs for routers
- dixie_land 3y agoTP links are cheap and well made for its price, if you don't care that the CCP has a backdoor to every device
- sgerenser 3y agoI use TP link access points with my own cloud controller (running in docker container on my LAN) and a separate wired router. I don’t think there’s any concern with access points “phoning home” in this configuration.
- discardedrefuse 3y ago> the CCP has a backdoor to every device This is huge! Please link me to the evidence to back this up.
- mike_d 3y agoChina deploys plausibly deniable backdoors into internationally shipped network devices. Bugs that are remotely exploitable if you know they exist, but not obvious enough that they provide justification for the devices to be banned from import. These consumer devices are not exploited for intelligence gathering, but rather deployed as proxies that fall into one of two common buckets: acting as SOCKS proxies to relay attacks, and allowing a remote operator to scan for nearby wireless networks and bridge into them. The NDAA blacklist was a happy compromise by the US government of banning the most egregious vendors that might find their way into sensitive facilities (Huawei, Hikvision, etc) while letting consumer focused brands that do the same (TPLink, Jetstream, Wavlink, etc) slip by so it didn't appear at face value to be a blockade of all Chinese made networking gear. Taiwan on the other hand is less concerned about how China perceives their relations and bans all these vendors. They also ban Zoom.
- 3y ago
- scrlk 3y agoI've been considering MikroTik recently (specifically the RB5009 series). Main downside I've read about so far is that the UI/UX is a bit rough.
- bastard_op 3y agoYou think the UI is rough, try the cli.
- lillecarl 3y agoThere's a learning curve indeed, but it's also essentially just a thin wrapper around nftables (read iptables) so you learn about Linux networking by using them
- bastard_op 3y agoI've been using unix and linux since the 90's and linux full-time on every system of mine, and Tik's still seemed entirely counterintuitive to me. I'd rather just deal with iptables and linux directly without the wonky cli.
- sonicanatidae 3y agoI prefer the cli for Mikrotik, but that's true for most firewall, routers, etc. YMMV.
- doubled112 3y agoI actually found the Mikrotik CLI easy to learn because it and the GUI are basically 1:1. For example: /ip/firewall/filter add is in the UI under the sidebar IP -> Firewall, then the Filter tab, then click add. The parameters are named the same in both too.
- lbotos 3y agoI have a mikrotik https://mikrotik.com/product/hap_ac3 https://mikrotik.com/product/hap_ac3 that I bought as a sort of test and it's been working fine for my needs. the webUI isn't the best, but wiki docs were pretty straightforward and I've been decently happy.
- deep_origins 3y agoAnyone using Mikrotik these days? Been Mikro-curious for awhile and always see them thrown around as a Unifi alternative. Yet to hear of any firsthand implementations though. [0] https://mikrotik.com/ https://mikrotik.com/
- sam_lowry_ 3y agoI have half a dozen Mikrotik hAP AC and wAP AC devices with Openwrt used in various places for work and for home. Rock-solid hardware and muuuch better UX that RouterOS. Don't remember when I setup those, but probably well before Covid. Really fire-and-forget devices.
- bastard_op 3y agoAs a network engineer, I've considered them for my house, the price is right, but: 1) Their main push seems to use a thick client for admin which is a big no to me, otherwise the web ui in theory looks ok-ish. 2) Looking at their cli guide, it was cryptic as hell to me, and I deal with everything from cisco, arista, aruba, juniper, fortinet, pan, whatever from a cli or gui. This was mostly confirmed a few weeks back, another old network engineer friend of mine hit me up asking if I've ever dealt with Mikrotik, and said no, but I knew where he was going. He'd screwed with it for a day or so supposedly just trying to make some L3 vlans, and finally a day or so later told me he'd made it work, but has never dealt with anything so terrible to configure from either gui or cli after having tried both, and he's another 20yr+ network engineer like me I trust not to be stupid. That was all I needed to hear for future consideration.
- snuxoll 3y agoMikrotik has had WinBox for as long as they've been around and there's a lot of inertia around using it, but WebFig and the CLI are the only things I use (though I do have The Dude running through Crossover because it's useful). Where you run into problems with 'tik gear is the differences that L3HW acceleration introduced into the mix. They didn't do what every other switch vendor does and limit features to what the switch chip supports and hide everything that the CPU can't handle away, so you have multiple ways of approaching most issues which threw me for a look as somebody who had been running JunOS gear in his lab for a while. Once you get a feel for it then it's pretty straightforward to work with everything, though somebody used to an older generation of NOS like classic IOS (and associated clones) would have an easier time than me. For reference, here's the config for my CRS317 acting as my "core" switch: https://gist.github.com/snuxoll/d63a155aa2155f53736a99d1cb276f4e https://gist.github.com/snuxoll/d63a155aa2155f53736a99d1cb27...
- seany 3y agoRuckus 730/750/850 with unleashed firmware
- tekla 3y agoAruba. Some jank in the software, but the gear has been rock solid
- sl360 3y agoThe Instant-On gear is physically almost identical to the professional line, but with heavy software limitations. Best built hardware I've used, and I'd still be using their PoE at home if they didn't patch out SSH/REST access a few years ago.
- allarm 3y agoNot sure if they sell it outside of EU, but Keenetic is absolutely awesome. Been using their routers for a while, have a wifi mesh configured in my home built on their devices. https://keenetic.com/en https://keenetic.com/en
- alt227 3y agoDraytek routers are not perfect, the UI lacks polish, but I have never had one fail on me yet. Solid kit (even though you do need to keep up with the firmware updates to keep them secure)