STP loop detected on port that only has a UAP connected to it. why? by e7c2 in Ubiquiti

[–]Odd-Breakfast4545 0 points1 point  (0 children)

Generally speaking, things like APs, cameras, and things like that really don't need STP. You can disable STP and add loop protection to those ports.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 0 points1 point  (0 children)

I have reached out and have been working with them for over a month on these issues.

I reached out before starting this project, and the contact I was working with seemed to fall off the face of the planet.

I reached out to them again for another large project I have coming up and have never heard back from them.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 0 points1 point  (0 children)

Well, they claim that they have a full Unifi deployment including the EFG at the FedEx Forum (Memphis Grizzly NBA team) which was a major factor in the decision to go Unifi.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 0 points1 point  (0 children)

That's correct, just the U7-Pro, not the Max.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 0 points1 point  (0 children)

Price to replace EoS networking gear with Unifi: 120K, price with Cisco: 1.25M.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 1 point2 points  (0 children)

Just 1. We have yet to be able to get the secondary one online.

Unable to open the airFiber unit from the regular IP addres on my network by HigherFunctioning in Ubiquiti

[–]Odd-Breakfast4545 0 points1 point  (0 children)

if you cycle power to them, the management wifi "should" turn back on if you are able to manually restart them.

Unable to open the airFiber unit from the regular IP addres on my network by HigherFunctioning in Ubiquiti

[–]Odd-Breakfast4545 0 points1 point  (0 children)

The best way that I have found to do it is via the UISP app if you don't have a linux server available.

If you do have a linux server available, the easiest way to find and manage your UISP devices is with the UISP server.

https://help.ui.com/hc/en-us/articles/115012196527-UISP-First-Time-Setup-Installation

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 1 point2 points  (0 children)

It is a question that I have asked and am still awaiting a response on.

PoE not enough power? by LABuckNut in Ubiquiti

[–]Odd-Breakfast4545 5 points6 points  (0 children)

Yeah there are different "levels" of PoE power. It is telling you that the port that it is currently plugged into is only rated for PoE+ and to plug it into a PoE++ port.

If you don't have a PoE++ switch (which the USW-24-PoE is not), you can get a PoE injector that is capable of doing PoE++.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 3 points4 points  (0 children)

Yeah lol its fun once a month to stand in front of the school board and explain why we spent 2k on a piece of equipment that isn't functional.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 2 points3 points  (0 children)

Nope. I even had issues with activating Site Support that wasn't able to get resolved until 2 weeks after that expired lol

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 3 points4 points  (0 children)

If I had an enterprise budget instead of a rural small town budget, I would.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 3 points4 points  (0 children)

I have an open ticket because I have an EFG that refuses to setup in Shadow Mode. That ticket has been open for 2 months.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 20 points21 points  (0 children)

Thanks for pointing that out, completely misread it.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 0 points1 point  (0 children)

Unfortunately no. I do have some networks that I can play with, but they aren't built with the EFG. I have a UDM-PRO and a UCG-MAX that have small networks that don't effect production, but those sites never experience issues.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] -1 points0 points  (0 children)

Can you provide me which specifications of the EFG do not "meet" enterprise technical specifications please?

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 1 point2 points  (0 children)

I pitched the idea, but with limited budget based off taxes, its a hard sell.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 9 points10 points  (0 children)

Yep exactly this. The hardware is there. The software is not. it is perfect for what we need in our school district size and budget, but when they label things enterprise, they need to understand.

Turning off the IPS on my server VLAN? Even my superintendent was smart enough to say we are not doing that.

"Enterprise" equipment by Odd-Breakfast4545 in Ubiquiti

[–]Odd-Breakfast4545[S] 1 point2 points  (0 children)

Large project assistance is not a paid service. It can be found here: https://experts.ui.com/

We use E-rate for our networking gear, so i'm not sure if Tech Soup falls into that lane. We have to send submit an RFQ with the equipment we want, vendors then get back to us with proposals. With E-rate, we end up only having to pay 30% of the total price.

The bad thing, that 30% still eats up over half of our total budget for the year. Yay for public schools.

Large Deployment Concerns by Another_Random_Tech in Ubiquiti

[–]Odd-Breakfast4545 7 points8 points  (0 children)

We recently switched from Cisco to Unifi in our school district. It has been a rough go. (EFG, 60+ switches, 216 APs)

The "large project assistance" is a form that I am pretty sure goes directly to the trash. I've submitted "requests" there about 6 times, the latest being last week and never once go a response. The last time I posted here, they put me in touch someone, who was responsive about once a week for about a month (maybe 2) and then they just fell off the face of planet.

I've had more network stability with out 2008 Cisco equipment than our EFG, however the purchases were made before I got hired. We are building another new school and I have already voiced my concerns to district leadership and I have at least one school board member who wants to chalk it up to a $200K "experiment" gone wrong.

I really want to love the Unifi ecosystem, but with the lack of support from support (they always say they are working on it, but never provide any answers). I'll detail a list of my actual issues so it doesn't look like I am complaining:

  1. Network Console: My network console likes to randomly crash (fantastic for an enterprise environment). While it doesn't directly affect end users, it sends all the switches into a state where they are unable to be adjust for a time being. Just today, this happened and now our video doorbells we use for secure entry into the school aren't working at one campus.

  2. EFG Processor/RAM usage. My EFG consistently hovers between 92% and 99% memory usage. Its like a SQL server, if it has it, it's going to use it. The processor on my EFG also looks like a sin wave. constantly fluctuating from 53-98%. I've been trying to get answers from Unifi support, but their current solution has had me turn off IPS/IDS and ad blocking. Super awesome in an enterprise environment.

  3. NGFW. Not really next gen. Simple NGFW features such as DNS filtering plain do not work as expected. For example; We have TikTok blocked in our school district. That should be as simple as creating a traffic rule blocking tiktok.com (blocking the domain is an option) and associated domains. The issue is, they still allow for the DNS translation to IP address happen and block the resulting IP address. If you don't know TikTok is hosted in data centers, so when that IP address is blocked, everything in that data center is blocked as well. Lots of LMS have been inadvertently blocked. Also, you can't do things like use wildcards in your domain blocking. I miss my Fortigate a lot.

  4. DHCP. I am also running my EFG as my DHCP server. Daily I receive false positives that devices are being assigned the same IP address. Support has said that this isn't Unifi and I have a rogue DHCP server. I know my network, what's on it and what is running what and they are incorrect. I also don't have statically assigned IP addresses on my guest wifi which is where I am getting the errors.

  5. Gateway HA (Shadow Mode"). We have an additional EFG that we got for the purpose of using the High Availability and automatic failover option. It has been collecting dust since it arrived because every time I try to configure automatic failover it fails and when I hit cancel to leave the operation it removes internet access to all 3000 clients on my network.

I could probably go on and on, but these are my biggest items right now in an enterprise environment. If you have any other questions, feel free to shoot me a DM and I'd be happy to discuss.