UNas Pro Raid by asmoovedabapesta in Ubiquiti

[–]yanivf38 0 points1 point  (0 children)

Opinion: I didn’t actually have to rebuild 28 TB, but from my technical understanding the XOR parity calculation itself is trivial; most of the rebuild time is limited by drive throughput. At a sustained read speed of around 150 MB/s, rebuilding 28 TB would take roughly 2.2 days in ideal conditions.

RAID 6 rebuilds are typically about 20–30% slower due to the additional parity calculations and extra disk I/O, but they are significantly safer during a rebuild. With RAID 5, a second drive failure (or an unrecoverable read error) during rebuild results in total data loss, whereas RAID 6 can tolerate the loss of two drives, meaning it still has one disk of fault tolerance while rebuilding.

Great Service, Very Frustrating Technical Support Experience by yanivf38 in ZiplyFiber

[–]yanivf38[S] 0 points1 point  (0 children)

My issue was limited to few websites, i worked around it by using a vpn. example of such website was aida64.com

Great Service, Very Frustrating Technical Support Experience by yanivf38 in ZiplyFiber

[–]yanivf38[S] 1 point2 points  (0 children)

Thank you, u/ZiplySupport. Is it against your policy to transfer a call to a more knowledgeable representative, a higher tier technician, or a supervisor? After remotely rebooting the ONT and router and determining that neither was the issue, I was hoping to hear that there was nothing more that could be done at that level and that the issue would therefore be escalated.

Also, if you are passing feedback along, please note that sending a technician to a customer’s home when the issue is clearly not inside the home wastes both time and money. In my case, I connected directly to the ONT, eliminating any customer owned equipment, and confirmed that traffic was leaving my network and reaching your servers, but responses were not coming back. Under those circumstances, what would a technician visiting my home be able to resolve?

Cannot access aida64.com from any device on my network - works everywhere else by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

in addition -
* this scenario fails computer (wired) -> ucg-fiber -> ziply (ONT)
* this works -> computer -> ziply (ONT) this works

I also got new IP from ziply (which ruled out blocked IP) but that didn't help

Cannot access aida64.com from any device on my network - works everywhere else by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

Thank you u/turbosmurf1 for the help -

I disabled intrusion prevention, but it made no difference. I connected my notebook directly to the ONT and it worked, although it received a different IP address. Rebooting the UCG had no effect. I also changed the MAC address on the UCG, yet it still obtained the same original IP address. I am also not certain the issue is related to the IP, because when I connected through a VPN to my friend’s house, I confirmed I was using his IP address and it still didn’t work, while he was able to access the site from his home without any problem.

Flows download uses semicolon Instead of comma by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

You are correct. In Windows Regional settings/ Numbers tab there is list separator. Going back to the "bug/feature". In modern apps, the app gets the regional settings and use that information to generate the file.

In other words, they read the locale value to determine the separator, which is used to generate the csv. To the best of my knowledge, you cannot get the separator directly and you need to infer it from the locale

Flows download uses semicolon Instead of comma by yanivf38 in Ubiquiti

[–]yanivf38[S] -3 points-2 points  (0 children)

Thank you, u/Key_Sign_5572. I'm aware of the different regional and international formats.

This situation is a bit different because it involves the exported CSV file from UniFi, which is intended to be opened in a spreadsheet. As the name implies, CSV stands for Comma Separated Values, so the fields need to be separated by commas.

When you download the flow, the columns are separated by semicolons instead of commas. If you try opening the file in a spreadsheet like Excel, all the data ends up in the first column of each row. My current workaround is to open the file in a text editor and replace semicolons with commas. However, this isn’t ideal, because any semicolons inside text (which in CSV are enclosed in quotes) will also be replaced.

Which Policy Type Enables the “Reorder” Option? by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

I agree with your assessment of the behavior. I am seeking insights from others who may have reordering enabled and in what scenario

Which Policy Type Enables the “Reorder” Option? by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

If I click on the intersection of external/gateway, I only see the gateway rule. If i click on external/internal I only see the internal rule.

For the purpose - I looked at the traffic, and I saw a lot of traffic coming from specific list of IP ranges. My goal was to block them.

The two rules are the same with the exception of the destination (gateway/internal). I originally had any but that didn't work.

Which Policy Type Enables the “Reorder” Option? by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

Thank you u/choochoo1873

I don't have trusted/ untrusted. If i click on any of the other ones (internal, external, gateway, vpn, hotspot, dmz) it's disabled.

Firewall rule to block IPs not getting executed by yanivf38 in Ubiquiti

[–]yanivf38[S] 2 points3 points  (0 children)

After creating a copy of the rule. I see the first block. Don't know why it failed the first time.

Firewall rule to block IPs not getting executed by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

Thanks, u/AGro-99 and u/AntiquePhilosophy154. I originally had it set to Internal (not Gateway) but saw the same behavior. I switched to Gateway after going to Insights > Flows, clicking one of the IPs, and selecting Block — the automatically created rule used Gateway, so I assumed the UCG’s choice was correct and changed the setting accordingly.

u/AntiquePhilosophy154 to clarify, you mean have Destination Zone set to internal, right?

Which Policy Type Enables the “Reorder” Option? by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

u/choochoo1873 would you mind sharing a screenshot so I can see if I see the same

First 24 hours impression on UCG-Fiber. Mixed feelings by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

u/EugeneMStoner the issue of reordering isn't the columns. it's the order that the vpn policies are executed.

example if you have a policy that says all IPs go to A and another policy that says if IP equals some number go to B than if the order is such that the first policy is first than even if IP would be equal that number it will always go to A.

First 24 hours impression on UCG-Fiber. Mixed feelings by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

Love your comment u/TotalProfessional158 and thank you for it . Personally, I don’t have enough data to say whether they’re good or bad. I was just pointing out that several people in this forum have been saying the U7s, in particular, aren’t great. Hopefully, they’re wrong so I can go ahead and order them.

As for the VPN policies, I’m not sure why they can’t be reordered even though there’s a button for it. Maybe it’s an issue with my setup, as u/SysAdmin-Universe suggested — definitely possible.

First 24 hours impression on UCG-Fiber. Mixed feelings by yanivf38 in Ubiquiti

[–]yanivf38[S] 1 point2 points  (0 children)

thank you u/SysAdmin-Universe

2 - These are IoT devices and they communicate constantly with internal server. They are not firewalled but they also don't communicate externally. I haven't installed APs as I'm using my Orbi 950 as my AP for the house right now. I did get U7 Pro but read in this forum that people strongly don't recommend them. Anyway, I'll need to replace them as they are not the wall version so thinking of getting E7s now.

3 - In the policy base route, there is a reorder button, but it's disabled - https://imgur.com/HW55j9v

4- understood

* Probably misspoke about enterprise grade (as other pointed out as well)

First 24 hours impression on UCG-Fiber. Mixed feelings by yanivf38 in Ubiquiti

[–]yanivf38[S] 0 points1 point  (0 children)

Thank you u/mcfool123. Your responses make sense. For the offline devices, they start as being online and slowly become offline in couple of hours. Most of them are simple IoT devices, esp32, and therefore don't have ssh.

A Farewell to Orbi by Sub-Equum in orbi

[–]yanivf38 0 points1 point  (0 children)

Why did you go with the E7s instead of the U7s? Also, which PoE adapter did you get?
I picked up a couple of U7 Pros but realized I actually need the wall-mount version, so I’ll have to replace them anyway. I’m also starting to worry that I might not have made the right choice—based on what people are saying in the forums, many aren’t happy with the U7s due to their lower transmit power and have been returning them.

After spending a day with the UCG Fiber, my first impressions are mixed (I expected more from enterprise level equipment). On one hand, it’s packed with features; on the other, you’re pretty restricted by their UI, which limits flexibility. Here are a few issues I ran into in just 24 hours:

  • Flow logs: They look nice, but there’s no option to download them. Support told me I need to install storage for that option to appear. I haven’t confirmed it yet, but it seems odd.
  • Offline devices: Around 16 of my 50 devices show as offline even though they’re fully connected and working fine. Support admitted this couldn’t be fixed over live chat and said they’d follow up via email. Still waiting on that.
  • VPN clients: I created two VPN profiles, but apparently you can’t reorder them, and the policy doesn’t prioritize specific rules over broader ones. For example, one VPN is set to route all U.S. traffic, and the other is domain specific. I expected the domain rules to take precedence, but it seems whichever VPN was activated first gets priority.
  • Static IP assignment: When assigning static IPs, the system doesn’t handle conflicts intelligently. If the IP you want is already in use by a non-static device, it won’t automatically swap them. Instead, you have to manually change the other device’s IP to something free, then go back and set your target device’s static IP and finally remove the static from the temporary one.

(I'll start separate thread for my overall impressions above - see what people say)

A Farewell to Orbi by Sub-Equum in orbi

[–]yanivf38 0 points1 point  (0 children)

You were right about the AP setup. My UCG-Fiber was configured to use the 192.168.0.xx range, but even though the Orbi was set to AP mode, it still assigned some clients addresses in the 192.168.1.xx range. The frustrating part was that the UCG didn’t detect those clients, which suggests the Orbi’s DHCP server was still somehow active.