Ubiquiti Networks UniFi UXG Pro Setup and Overview
Vložit
- čas přidán 6. 08. 2024
- The UniFi UXG-Pro is a beast! It's the perfect upgrade for USGs. The only missing feature we've found is the site-to-site auto VPN. Other than that this can handle way more than people are giving it credit for! Check it out! Let me know in the comments what videos you want to see for this device!
Hire us: williehowe.com
Affiliate Links (I earn a small percentage of the sale if you use these links):
My AmazonLink: www.amazon.com/shop/williehowe
Telnyx Referral Code: refer.telnyx.com/cv6cm
HostiFi Affiliate Link: hostifi.net/?via=willie
Netool: netool.io use code WILLIEHOWE to save at least 10%!
Digital Ocean Referral Link: m.do.co/c/39aaf717223f
Patreon Link: / williehowe
Time Stamps:
00:00 - Intro
00:15 - Let's look at the setup in the rack!
01:50 - UXG Pro Specs
02:45 - MSRP and where folks get hung up - memory
03:20 - It can do a lot -- the language has just changed
03:50 - The missing feature
04:29 - Adopting the device - it's EASY!
06:10 - Quick look at the device in UniFi
06:50 - The words I get hung up on!
07:15 - What do you want to see?
07:30 - It's a good device but so are USGS
08:00 - VPN missing option
08:25 - Tell me what you want!
08:30 - Wrap up!
Contact us for network consulting and best practices deployment today! We support all Grandstream, DrayTek, Obihai, Poly, Ubiquiti, MikroTik, Extreme, Palo Alto, and more!
Come back for the next video!
Twitter - @WillieHowe
TikTok - @whowe82
SUBSCRIBE! THUMBS-UP! Comment and Share! - Věda a technologie
I’d be interested in a video on how to replace a USG in an existing network with a new UXG Pro, backed by a remote controller. Things to look out for etc..
+1
Same, but with a local controller.
+1
Was this video ever made? This is a use case scenario I have for my UXG-Pro lol
Hi Willie. I would love to see a process where you replace a USG / USG Pro with this UXG, retaining all of the settings of the USG
I had a UDM Pro. It died and was replaced under warranty. The new one bricked while updating the firmware, so they replaced it again. The next one had a dead LCD screen so they replaced it yet again. As soon as that one showed up I immediately sold it and bought the UXG Pro instead.
The UXG has been up and running solid as a rock for almost a year now. Absolutely flawless for me.
are you using the UXG Pro for routing or a separate router when you switched?
@@mattmcguire348 Using it for the routing. Works perfectly
Awesome great to hear!
After getting an upgrade from 100mbit to 1gbit Internet, I've learnt that my USG-3P can't do IPS/IDS on a gigabit connection. The USG caps the download speed heavily, so Iwill most likely get this. Good to see it looks straightforward to use; thanks for the video. I already have a CloudKey Gen2+, AC Pro, a PoE switch from Ubiquiti and would like to stay in the eco system.
I have an “auto” site-to-site VPN between two USG’s on the same controller (located at one of the sites). Both sites have public WAN IP’s, one of them is fixed/static. I don’t see an obvious upgrade path for this setup? But maybe all the UDM/UXG’s have powerful enough HW to use OpenVPN (so I can use FQDN’s for the config)? Anyway, please continue to comment on site-to-site VPN capabilities in upcoming videos. Thank you for your excellent content - much appreciated, Willie! 😊
Replacing the usg pro 4 on a existing setup what is on a different lan ip range for the uxg. Tried that but did not work, no internet access.
Great video Willie! I'd be interested in WAN failover and IDS/IPS setup
FYI Wan failover is as simple as setting up your second wan and it will automatically switch if a failure occurs. Test it by simply disconnecting the cable off of WAN 1.
Like many others I am most interested in inserting this in an existing network, except I do not have a USG. I bought this as primarily a security device, planning to put in on a 10G port of my Cisco ASR 9000 which will continue to handle all routing functions. I would like to put it between the router and my core switch that feeds our office, and ideally various servers as well. Ideally without impacting traffic at first, and then using it to secure each device behind it one at a time. I'm at a bit of a loss on how to best do this and since its a running network, downtime needs to be minimal.
Thanks for the vid. Might be interesting to see another vid on dns with the new UI (I guess somewhat related to the new device). I'm still using the old json file from like 3 years ago. Seems like when the internet modem gets rebooted I can't reach mydomain.home. I may need to redo it all from scratch and purge all the little configuration artifacts. I know you have other dns videos and split dns out there though so I might need to rewatch one of those.
Thank you for the video. I would love to see info about logs and info gathering for troubleshooting purposes like WIFI handshake errors or DHCP not handing out IP to a device or client VPN drops, etc. Also I don't think there is anything like Netstat on there but where would you find that kind of information.
Willie, I have an old USG with a 150w Switch 8 and a gen 1 Cloud Key. I am toying with a good upgrade to allow three AP's and two Cameras. Thiss is looking like it will be my first choice along with a new Cloud Key, "if I can find one".
I'd love to see a video where you setup the OpenVPN client to connect to an external OpenVPN server, and set up routes to allow excess to devices behind the UXG. I've been battling to get this working...
Great Vid. would you set up Vlans with this unit, or would you set up VLANs using the pro switch. which is recommended? Thank you,
Video for Guest Portal/ SSL install, come on Howe!
Hi Willie, I noticed in another video that you have an old router model USG-XG-8. Could you make a comparison between the new UXG Pro versus the USG-XG-8? Thank you!
Can you upgrade the ram? What is the actual throughput with IDS/IPS enable? Thanks for sharing 👍
Could you compare this to running an Edgerouter (Say ER-4) and hosted controller - things that Edgerouter can do that UXG can't and vice versa? We only deploy Edgerouters because USG's have just been too feature limited, but we use unifi for switching and WiFi and would love to bring routing/firewall into the same pane of glass (that being said - UISP just gets better and better and makes it so much easier than it used to be). Main features we can see lacking are WAN balancing and ability to upload wizards (we use Pritunl for VPN), DHCP lease list....main thing we want that Edgerouter doesn't have is IDS/IPS
I am interested in Throughput when QOS, IDS/IPS enabled.
Can we disable the NAT on this device?
Hi Willie, do You also have the "Internet Source IP" grayed out in the LAN settings?
hey is it possible to configure WAN1 as port 3 and WAN2 on port 1?
Can you add vlan tag to the wan port, and set the wan port mac address, without going json file ?
The Auto S2S VPN has been "coming soon" for 2 years (since the UXG was launched in EA).
I would like to connect at UXG Pro to a UDM Pro via SFP with the internet running from the UXG to the UDM. Can you do a video on how to do that?
What features do I gain (other than hardware)when upgrading from a USG?
I like this device, have one in play here. It's not for the "home user' but I will say this, Willie is 100 percent correct this device can do a lot of things people don't realize, perfect? No, but powerful and versatile, absolutely.
I have at work and at home. YES it can be for the home user as well !! Overkill but fun to play with.
Thanks for that video: Just a question. I had a USG pro 4, switched to UXG Pro with cloud key 2. I don't get internet on devices via switch. But the internet on the firewall is there.
I testet it via putty an traceroute on the UXG pro and it worked. But no way to get access via PC and other devices. Change back to USG 4 pro, everything works fine. What could that be??
Would be nice to get help :-)
Just took the leap and ordered one of these to replace a UDMP that is constantly overloaded - out of resources
Can it do full tables on bgp?
Hi Willie: thanks for the great videos! I have a site with a large network with a UDM-pro, which is getting bogged down because it is running other services. I am interested in finding out whether the UXG Pro can offload the Network application so the UDM Pro can focus on its other services. This site doesn’t have a cloud key.
As of now it's not officially supported or advertised in that way even though the UXG-Pro is called a "routing offload." Regardless, the UXG (at this moment) can't be adopted by the UDMs, so in theory you will need two controllers at play to make both work if you can (ck +udm OR cloud/offsite + udm). I believe with some finagling of subnets and stuff you can make the two gateways not collide, as I've seen a couple people say they have.
I wouldn't be surprised if in the future they make the UXG-Pro adoptable by UDMs as not only have a lot of people been asking your same question, but they literally call it a "routing offload" and unless it's offloading the load from a UDM it would just be a plain router, no...?
Willie - i want to adopt mine to my current site, but i use a windows based cloud controller. Is that possible?
Hey boss. thanks for the video - so what I'm not clear of is why this vs the udm-pro if the udm-pro can perform all of these functions and more ?
You can host multiple sites on the same controller with the UDM.
I would swear they make it hard to find a somewhat revealing spec.. Anyone has a link to throughput datasheet?
I want to see ipv6 capabilities, dual wan v6
You have a USG-XG-8 and UniFi Server! Wow! How do you like them?
I know the device comes with 2 gig ports and 2 fiber ports. Are those static in that the 1 gig and 1 fiber labeled for WAN are only able to be used for WAN and the same for LAN or can you really use all 4 ports however you'd like. I am getting a dual WAN setup, but I'm not sure i'll get a fiber offload from an ISP, so I'd like to know if i can use both normal gig ports for WAN1 and WAN2 and use one of the fiber ports to just go to LAN.
They can be assigned any way you want.. The only caveat is that there must be at least one WAN port assigned.
Can the UXG do the same level of content filtering as the UDM Pro
We will have to look now that 3.0 is available
Does this experience the same issue as the UDM pro with more than 40 unifi devices attached? Any time I've reached to ubiquiti they always say my issues are related to having more than 40 unifi devices connected to the udm pro. Thanks for the information
@@WillieHowe does the uxg
An obvious and perhaps naive question, but what are the main reasons you might want to upgrade from a USG?
Failover and Load balancing would be a good video to see
Load Balancing is not available yet. Failover is as simple as configuring your WAN2. No other tweaks necessary
Hi Willie, quick question, I am planing on rather big deployment, deploying a UXG Pro + NUC (with UnifiOS on it) + SWXG 16 + a bunch of SW 48 POE + around 100ish AP's in a hotel enviroment (150 rooms), what I am trying to find out is the UXGP enough to cover all of that throughput, I decided to go with NUC as controller, because as far as I have seen no other Unifi equipment can support so much conected devices, just wanna hear your Yay or Nay on this?
Running on a nook may be a good move here.
@@WillieHowe ty good sir, you are a gentleman and a scholar :*
@@capnjackswallows2888 don't tell anyone!
Hello everyone
I have a question about Unifi's security gateway
I use the USG Security Gatway Pro 4
My Internet speed from IPS is 1000/200 Mbit
When I use *Filtering Mode* I only have around a maximum of 500/200 Mbit
If I switch off the filter and activate the "Hardware Offload" I have a throughput of around 900/200 Mbit.
However, I no longer have any protection because the firewall eats up performance.
Can someone tell me what it would be like if I replaced my USG Security Gateway Pro 4 with the new Gateway Pro from Unifi, would my throughput be better and be faster or wouldn't that make that much of a difference?
What do you think ?
Thank you for your answers
Dany
It's literally right the unify software that if you use certain features it reduces your overall speed. The uxg is a much better choice than the USG.
@@WillieHowe thanks Willie for your feedback and thanks for all your great Video i love it Take care !!
Can I set this up behind another firewall? All I wasn’t to the gateway features, we are strictly a Fortnite house.
Why would you want to do this?
@@WillieHowe I want the gateway features on the sites visited and it handle the VLANS.
Why UBNT thought not having auto VPN for this device was a acceptable at GA is beyond me. There's plenty of people that use it with USG's, you know the key market that this device is aimed at and can't upgrade to UXG-Pro without having to manually build their site to site VPN's. That's not very SDN is it? Maybe it makes a return if Wireguard gets added. UBNT are their own worst enemy sometimes.
Imagine requiring 10GbE routing capabilities, but not needing any feature a USG is missing. Seems to me like it’s quite the niche product.
@@WillieHowe proper DNAT and SNAT. Full control of features and not a simplified version of what’s possible on EdgeOS.
To be fair, even if this is stuff I’m not up to date on and they recently fixed it… I still don’t like the new UI, even for stuff like wireless and switching. I find myself using the search bar for basic stuff and when possible switch back to the old interface. I usually adapt to interfaces rather quickly, but not this one.
The routing features in the old UI are already way less easy to navigate compared to EdgeOS, even when many features are missing. Stuff missing from EdgeOS UI is at least available through the config tree or command line.
I will consider deploying UniFi routers as soon as it has all the features, available through the UI and a better track record of being bug free (have they already fixed WAN failover on UniFi? That was the reason I defaulted to Edgerouter to begin with).
@@WillieHowe I understand. USG’s have their place. But the only users I can think of, besides enthusiast like you and me who go way overkill, that need more than 1GbE WAN speeds are reasonably big companies. And those reasonably big companies usually also need the features UniFi security gateways are lacking. Don’t you agree?
Ubiquiti needs to integrate the cloud controller/key into all of their routers.
Agreed!
That's what the UDM line is and everyone hates them for it... That is not at all what the people want.