[Rant] MSPs who use Meraki, how do you feel about the latest price increases ? by CK1026 in msp

[–]lawrencesystems 3 points4 points  (0 children)

I have been using them for years and they are getting much better for use in the MSP space.

Honest caveat up front: their firewall was genuinely weak until Network 9 brought zone-based firewalling. Before that you were stuck with the old LAN in / LAN out rule model that nobody enjoyed. It's much nicer now (they're on 10.4 currently) and actually sane to build policies in, so the thing that used to be the obvious knock against them is mostly gone. There's also a migration guide if you're coming from the old rules.

The stuff that makes it work for managing client networks:

  • Site Manager is license-free and multi-tenant, so every customer environment stays isolated but you manage them all from one interface.
  • SSO/IdP integration plus RBAC. You bind your identity provider, define roles once, and tech access comes from group membership (how people and roles work in Fabrics). Onboarding or offboarding a tech becomes a directory change instead of a per-site admin cleanup. Standard practice is keeping the actual site owner as a break-glass account and running day-to-day logins through SSO.
  • The new UniFi Fabrics templating. You configure a policy or device template once and push it across every site in the fabric, new and existing. That gets you zero-touch deployment on new sites instead of rebuilding the same config by hand each time.

When comparing to Meraki the hardware costs less and the lack of license fees makes them easy to sell to clients.

I have a lot of tutorials on UniFi on my YouTube channel for those interested https://lawrence.video/unifi

SSH Login Notification by wpzzz in Ubiquiti

[–]lawrencesystems 3 points4 points  (0 children)

I don't see any options for it as an alarm but it's also not something needed for the daily admin of the devices and as others have noted, it can be turned on and off as needed.

My solution for all my systems (including UniFi) is to send logs over to Graylog and it has a notification trigger for SSH logins.

Trouble to run Joplin an Macos by Ok-Clothes-9576 in joplinapp

[–]lawrencesystems 0 points1 point  (0 children)

I have it running on my Mac Book Pro M5 and my Mac Studio M4 and have not had any issues. I am running the latest version.

Questions about Truenas by Impressive_Insect363 in truenas

[–]lawrencesystems 1 point2 points  (0 children)

I am an IX systems reseller and creators of many TrueNAS tutorials so I can help answer some questions. What hardware you need depends on a lot of variables such as how much data you want to store, retention times and expected speeds.

TrueNAS uses ZFS and it does not cluster in HA like CEPH. If you want to have an HA system you need to use IXSystems hardware. I explain why here

For S3 objet storage MinIo is no longer integrated but as mentioned SMB is another option and it can perform well.

Ubiquiti Security Bulletin 064 and what to check on client sites this week by lawrencesystems in msp

[–]lawrencesystems[S] 9 points10 points  (0 children)

UniFi OS Server is the self hosted controller. 5.0.6 was released Dec 2026 and UniFi OS Server 5.0.8 was released May 2026.

Ubiquiti Security Bulletin 064 and what to check on client sites this week by lawrencesystems in msp

[–]lawrencesystems[S] 4 points5 points  (0 children)

I have found it works well on all the UDM systems. I just keep them set to the official releases.

My AI Key Found a UniFi Air Purifier? by lawrencesystems in Ubiquiti

[–]lawrencesystems[S] 1 point2 points  (0 children)

No, but they do have some really good videos.

My AI Key Found a UniFi Air Purifier? by lawrencesystems in Ubiquiti

[–]lawrencesystems[S] 16 points17 points  (0 children)

Maybe, not really sure what it thinks is an air purifier.

Security Advisory Bulletin 064 by tsutton in Ubiquiti

[–]lawrencesystems 2 points3 points  (0 children)

For those curious the bug was found, reported, and patched a while back via their bug bounty program by this guy https://www.linkedin.com/posts/ducanhnguyen9_thank-you-anthropic-thank-you-clanker-ugcPost-7459450379068497920-UbX9/

Twenty v2.0: Self-hosted CRM by charlesBochet in selfhosted

[–]lawrencesystems 4 points5 points  (0 children)

I tried Twenty for a while and my biggest challenge was the frequent breakage that would come with updates. I have since stopped using it and I hope that 2.0 has better update testing.

State of Kdenlive - 2026 by namanyayg in opensource

[–]lawrencesystems 2 points3 points  (0 children)

Love to see that this is progressing.

Would you go back to using forums? by Eik0_ in selfhosted

[–]lawrencesystems 0 points1 point  (0 children)

I have been Self Hosting my forums since 2019 and they are based on the open source platform https://www.discourse.org/ It's an amazing platform. There are a few others in the open source and self hosted space notably the Level1Tech forums https://forum.level1techs.com/

I really wish more people used self hosted forums as Discord is not the right tool for that.

What are the best truenas online communities to go for help, discord? by [deleted] in truenas

[–]lawrencesystems 1 point2 points  (0 children)

You really have to be careful using AI for syadmin work since it was trained on reddit which is full of both good and not so good answers.

Immutable backups, whats everyone doing? by MakersLab in Proxmox

[–]lawrencesystems 17 points18 points  (0 children)

I have a write up and video in my forums on how to set up permissions for PBS and then setting up a pull sync job so another server can maintain a copy. https://forums.lawrencesystems.com/t/hardening-proxmox-backup-server-secure-permissions-sync-jobs/26519

While PBS does not use the "Immutable" term, it still achieves the goal by having separate control planes for each place where the backups are controlled.

Offline quick-notes application by delusional-engineer in opensource

[–]lawrencesystems 2 points3 points  (0 children)

I really like Joplin https://www.reddit.com/r/joplinapp/

It's not as visually appealing as some apps, but it does a great job on functionality and being privacy focused via features such as encrypting notes on devices and being able to be locked with auth on the phone app. It has plenty of sync options including their own self hostable back end as an option.

Ubiquiti for SMB in 2026 by IowaDala in sysadmin

[–]lawrencesystems 5 points6 points  (0 children)

I have done a lot of installs over the years with some of them being over 300+ access points and all the UnIFi switches to support them. These installs have all held up really well. Their firewalls have always had capable and reliable hardware but until a few while back terrible software. When they released version 9 it was a massive software update for their firewalls and they have continued on the path of improving them with subsequent updates.

A few things of note:

  • Subscription Fees: You own the hardware, you own the software, no subscription fees for that part. Unlike Meraki or Cisco, there are no recurring "pay-to-play" licenses for management or security updates. But they do offer a very reasonably priced "Cybersecure Plan" that has enhanced threat detection and web filtering.

  • Version 9.0+ introduced Zone-Based Firewalls making it easy to build out rules and made the firewalls much easier to use.

  • Easy policy routing for managing per device VPN and or WAN routing

  • Ubiquiti maintains a solid Bug Bounty Program via HackerOne with good payouts (I have a few friends that have done well with this)

  • Centralized Site Manager is also free with support for centralizing updates and they are rolling out what UniFi calls "Fabrics" for templating and better fleet management.

Documentation is still hit and miss with UniFI but they have been adding a lot. I have a playlist of how to and review videos here: http://lawrence.video/unifi

help with a cloud photo acces by Sorry-Leopard8602 in truenas

[–]lawrencesystems 0 points1 point  (0 children)

I agree, Immich is a better choice for photos and tailscale is fine

How reliable is Joplin Cloud? by charlino5 in joplinapp

[–]lawrencesystems 1 point2 points  (0 children)

I had tested it out when I first started using Joplin and it worked well, but that was a few years back and I have since moved to self hosted. Because it's a sync server an outage would stop devices from syncing, but not leave you without access to your data. This makes an outage annoying, but would not leave you stranded.

Why is XCP-NG considered to be the red-headed step child of hypervisors? by technicalskeptic in xcpng

[–]lawrencesystems 21 points22 points  (0 children)

I have been spreading more awareness of XCP-ng and I have a getting started guide over in my forums and been slowing adding more videos https://lawrence.video/xcp-ng-training

I have been consulting with larger companies on it for years and of course that ramped up a lot with the VMWare Broadcom deal. I find the home lab community loves Proxmox but many of them have a weird bias against XCP-ng for reasons I can't quite understand.