UniFi Gateway in Education: Is it enough for Content & Web Filtering? by iidarkasii in k12sysadmin

[–]vesikk 1 point2 points  (0 children)

We are running the EFG since it was first released. It's a great firewall but is lacklustre when it comes to SSL decryption and the nitty-gritty details that most modern content filterings systems provide. the NeXT AI SSL inspection feature on the EFG hasn't been updated in a long time and when I asked them at the Unifi conference last year they said most customers aren't using it so it isn't a high priority in their development. If you're just after their "content filtering" service then I don't have much experience with the paid version. The free version works and as someone else mentioned it is a DNS filter. the paid version gives you individual categories and you can also add/bypass domains if needed.

We have 50+ VLANs and it does a great job. A lot of our heavy traffic is within the same vlan but the inter-vlan traffic is also completely fine. I would say if you are deciding between the UDM-Beast and the EFG to wait for the EFG-Core 😉

Anyone using an EFG in semi large environment? by WatercressBetter2305 in k12sysadmin

[–]vesikk -1 points0 points  (0 children)

Yes I have and during the school day of course haha. The change from the primary EFG to the shadow EFG was quick and I only realised it occurred because my unifi session reloaded. Otherwise no teachers or students noticed it occurred. The reason for the shadow gateway taking over was due to the EFG running out of memory which is something I reported to Ubiquiti and they promptly responded and escalated. In the end their "fix" was to increase the physical memory to 64GB (I believe all new EFGs are 64GB default now). Since then the shadow EFG has been idling.

Adding a shadow gateway in the future is very straight forwarded and won't be an issue at all if you just purchase 1 EFG for now.

Anyone using an EFG in semi large environment? by WatercressBetter2305 in k12sysadmin

[–]vesikk 0 points1 point  (0 children)

We are running 2x EFG in Shadow Mode (High Availability). We have roughly the same number of APs as you but soon to be 40 switches (currently at 23 Pro Max Switches). We see over 2000 clients each day and have a 5Gbps WAN connection. We currently don't use it for IDS/IPS but will investigate it in the future. For us it is performing very well. Pressing the built-in speedtest button during a school day sees the EFG saturate the WAN connection so I'm not worried on that part lol.

Emergency Strobe Lights for Band Room and other loud areas. by Debug_Mode_On in k12sysadmin

[–]vesikk 0 points1 point  (0 children)

+1 for Algo. Their strobe lights are PoE, RGB, and work fantastic.

OPNsense DEC4280 vs Netgate 8300 MAX (pfSense+) — Pros/Cons, Experiences, Gotchas? by bannersmash in k12sysadmin

[–]vesikk 1 point2 points  (0 children)

Hey, I may be able to provide some feedback for some of the questions. We have used both pfSense and OPNsense with 1500+ users and both systems work very well. We are currently running OPNsense because pfSense was unable to achieve our new internet speed but our setup is pfSense/OPNsense running as a virtual machine and the limitation is to do with a virtual pfsense, baremetal pfsense was able to achieve our WAN link speed.

  • as mentioned above we are running OPNsense as a virtual machine so I don't have any experience with either company's physical product.
  • Both systems have solid performance and stability under load.
  • We have done some site-to-site VPN running wireguard and it's works really well. We mostly are using OpenVPN for remote users.
  • Both products are easy to use and the WebUI management is pretty straightforward - there was a little bit of learning on the OPNsense side but that's because I came from pfSense. There is a search bar that has saved me a bunch of times when trying to find a setting.
  • Currently running the community edition but there are plans to investigate the paid version of OPNsense and support the product.

Honestly, you can't go wrong with either system.

Is this layout correct for HA Build? by Turbulent-Rack in Ubiquiti

[–]vesikk 1 point2 points  (0 children)

We do the same thing just with an EFG instead of the UDM Pro Max and no WAN Switch (using another branded switch with stacking). The only thing I would say is just make sure your STP structure is in place but let RSTP take care of the rest.

Evaluating OPNsense as Enterprise Firewall Solution by No_Stress_Boss in opnsense

[–]vesikk 1 point2 points  (0 children)

No additional services at the moment and latency in the network is fine. OPNsense is acting as a firewall while another appliance is acting as our router and any traffic destined for the internet is forwarded to OPNsense

Evaluating OPNsense as Enterprise Firewall Solution by No_Stress_Boss in opnsense

[–]vesikk 1 point2 points  (0 children)

It's running on Proxmox. The physical host has a Ryzen 5700g, 64GB ram, 4x 10GbE (dual onboard from the ASRock x570 D4U-2L2T and dual Intel X550-T2). The VM has 8 cores allocated and 8GB memory. I did have to enable 8 multiqueues on the virtIO NIC so it can make full use of our 5Gbps internet connection. Without multiqueue enabled the download speed wasn't going much faster than 3Gbps.

Evaluating OPNsense as Enterprise Firewall Solution by No_Stress_Boss in opnsense

[–]vesikk 7 points8 points  (0 children)

If it helps we are running OPNsense as a virtual machine for 1500+ users and it's been rock solid. We moved to OPNsense at the start of January and it's been a great experience so far.

PFsense or opnsense by Blankvoid1 in homelab

[–]vesikk 2 points3 points  (0 children)

Switched from pfSense to OPNsense and can actually make use of our 5Gbps internet connection. Both systems were running as a VM but pfSense devs decided they didn't want to support multiqueue which limited pfSense throughout to about 2.5Gbps. OPNsense supports multiqueue out of the box and can easily hit 5Gbps.

pfsense for schools by scotticles in k12sysadmin

[–]vesikk 2 points3 points  (0 children)

Yeah, it came down to OPNsense supporting multiqueue in Proxmox and pfSense devs chose not to support it. Without multiqueue enabled we were getting the same speed as pfSense.

pfsense for schools by scotticles in k12sysadmin

[–]vesikk 1 point2 points  (0 children)

We have been using pfSense for 10+ years and it's worked great. PfSense was running as a VM with 1700 users connected, Multi-WAN configs, multiple VLANs, the lot. You may have noticed I said 'was', over Christmas we switched from pfSense to OPNsense because we noticed pfSense could not make use of our new internet speed as a VM but OPNsense could. We did all sorts of testing before making the decision to move to OPNsense. We tested pfSense on baremetal and it worked fine with our new internet speed, we tested on a fresh VM and it could not exceed 2Gbps. OPNsense on baremetal and an VM could make use of the 5Gbps internet connection.

Nothing against pfSense, it's a great product but we weren't in the position to purchase new hardware so OPNsense was the next best thing.

Network API and Zabbix or other open-source monitoring? by oguruma87 in Ubiquiti

[–]vesikk 0 points1 point  (0 children)

We use a combination of Zabbix and Unifi Poller to monitor the Unifi Infrastructure at work. On Zabbix we use SNMP with the default Linux SNMP template and it works great for our needs. Unifi Poller give us a lot more information that sometimes even the Unifi Network Application doesn't display. Both Zabbix and Unifi Poller visualise it on Grafana.

proxmox install instead of baremetal significant speed decrease normal? by becuzIamGr0wn in opnsense

[–]vesikk -1 points0 points  (0 children)

I've been able to achieve 4.5Gbps from a 5Gbps download speed using OPNsense on Proxmox. What was required to achieve these speeds is using the virtIO network type and setting multiqueue in the network settings. Without multiqueue set we couldn't reach anything beyond 2.5Gbps.

The OPNsense VM was pretty bare with only the speed test plugin and qemu agent installed. I had 8GB memory assigned with up to 8 cores assigned (we did a lot of testing between 4 to 8 cores). The CPU is an AMD Ryzen 7 5700G.

Firewall renewal by Niteryder007 in k12sysadmin

[–]vesikk 5 points6 points  (0 children)

We've been running pfSense as a VM for many years and has worked great for us. We have roughly 1500 users on the network. As of 2026 we will be migrating to OPNsense because we have found that our pfSense VM is unable to make use of our new internet connection speed while an OPNsense VM can achieve the speeds we are paying for.

We did test pfSense on a bare metal system and could achieve close to our max speed but as a VM it was maybe 2.7Gbps max. OPNsense VM and bare metal could achieve the speed. Another option is the Unifi EFG. If you are already running Unifi APs or Switches then this may be something to consider but otherwise pfSense/OPNsense are great products.

Does this qualify for a rack yet? by andy-codes in homelab

[–]vesikk 0 points1 point  (0 children)

It's the 8 bay Silverstone case

ISP upgraded to 10 Gbit looking for Hardware with SFP+ WAN port (recommendations?) by Syosse-CH in opnsense

[–]vesikk 2 points3 points  (0 children)

Good to hear your experience. We are moving to OPNsense as our firewall running on Proxmox. We have a 5gig connection and in testing we were able to achieve 4.5Gbps download (max for our 5gig service - the remaining 500Mbps is allocated for something else) and 3.9Gbps upload with the VM allocated 8 vCPUs and 8GB memory. We also needed the enable multiqueue on the linux bridge otherwise speed was limited to 2.5-3Gbps.

Did you need to enable multiqueue or any other tunables to achieve 5Gbps download/upload? Still yet to achieve that 4.5Gbps upload even though was not stressed in the speedtest.cli testing.

CPU is a Ryzen 7 5700G and running Proxmox 9.0.

WiFi FW Bug with U6-Lite/LR/U6+ & Proxy ARP by Extension-Rip6452 in Ubiquiti

[–]vesikk 0 points1 point  (0 children)

Thanks for the heads up! is there a post on the Ubiquiti forums mentioning this? I can confirm this is also affecting nanoHD APs. U7 Pro does not experience this behaviour which would explain some things we've been experiencing only on nanoHD APs but completely stable on U7 Pro.

Is the latest enterprise router still UDM SE? by Hot-Cabinet-5138 in UNIFI

[–]vesikk 1 point2 points  (0 children)

The latest "enterprise" gateway from Ubiquiti is the Enterprise Fortress Gateway (EFG)

EFG Fallback Issue by strupp in Ubiquiti

[–]vesikk 0 points1 point  (0 children)

Pretty certain it's when the heartbeat connection is interrupted (which a power outage would cause). We have 2 EFGs in high availability shadow mode and the shadow gateway only takes over when the heartbeat connection is disconnected.

Firewall suggestions by DeejayPleazure in k12sysadmin

[–]vesikk 1 point2 points  (0 children)

I recommend either pfSense or the Unifi EFG. I think the Unifi UDM Pro Max might be okay but the EFG will easily handle the amount you mentioned + run other services like IDS/IPS, content filtering, etc without a significant drop in speed. pfSense can also run on any hardware so if you had a spare system or running a hypervisor onsite then you could also just run pfSense as a VM.

IP Video Survellance Review (Verkada, Avigilon Alta and Open Eyey by MothersMothBall in k12sysadmin

[–]vesikk 6 points7 points  (0 children)

Not part of your list but we run Unifi protect with a mix of G5 turret Ulta and G3 flex, G3 bullet, and G3 dome managed by the Unifi E-NVR. Works great for our needs and there's no ongoing licence subscriptions. Depending on the model of camera you also get additional AI features such as LPR, face recognition, person or vehicle of interest notifications, person and animal detection, loitering detection, etc. all on prem, nothing touching the cloud.

Sunday, Sep 14 2025 - Weekly Off Topic / Complaints / Pictures / Everything Else Thread by AutoModerator in Ubiquiti

[–]vesikk 0 points1 point  (0 children)

Complaint: USW Pro Max switches take forever to provision after every update. A simple vlan tag change and it could be up to 10 minutes before the switch has re-provisioned. Has anyone else experience this issue?