Mentioned it before, but since a few days ago my unifi devices (2 wifi APs, a small switch, plus one Debian VM with the controller, all on it's on VLAN) are not allowed to do outbound traffic anymore, with the exception of NTP, DNS and one trusted apt mirror.
Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on different AWS IPs a lot more often, even without me navigating the web interface. Other than that, no ill effects. Device firmware update notifications are gone, just says "up to date" now.
Interestingly, I still see the ad for their "dream machine" on the dashboard, as it seems to be baked into the controller. It's also trying to load external resources from "net-fe-static-assets.network-controller.svc.ui.com" while navigating the new web interface. The "classic" interface still seems to be truly self-contained. Using the latest controller version as of today (6.1.71-15061-1).
Condensed firewall logs for reference below. Not that it matters much, but why not.
There was a falling out between teams while I was there because the cloud team wanted to collect stats from APs even when users disabled analytics in the UI. It was so bad that some of the developers and one of the leads quit because they didn't want to be a part of it.
Someone on Reddit started reverse engineering it https://www.reddit.com/r/Ubiquiti/comments/lwr4ud/update_ubi... The APs are reporting things like connected clients and client stats according to recent dumps. Do you have analytics disabled in the UI and this is still happening?
Yep, analytics is disabled. Thanks for the link, didn't look into the data being sent. But I can't confirm my devices trying to send out data if I SSH into them (just tried it for the 1st time).
I've DNS-blackholed trace.svc.ui.com (maybe it's slightly different, this is from memory) and plan to entirely wipe and sell all my UI gear within the next two months.
I have said this before, but would like to reiterate that I am never touching or buying anything branded as Ubiquiti or owned by Robert Pera.
This hardware is far from cheap and consumers are literally paying for adware/spyware. I really hope Ubiquiti stock takes a nosedive over the next year.
Depending on your viewpoint. Compared to an enterprise setup with similar features? Basically free. Compared to your average all-in-one home router, however, these are very expensive.
Are they, though? The only difference my parents (for example) would recognize between their ISP router and Ubiquiti would (might) be that the WiFi is "a bit better". And talking about security is a bit moot, given the topic of this thread.
Don't get me wrong, I see why you would spend money on Ubiquiti gear; in fact, I run a similar setup. But for your average non-technical user, it's going to be a harder sell. It's the same reason you (probably) don't run a several thousand euro enterprise WiFi at home.
If you've got under a half dozen devices in your network, just go with the ISP provided one. When you start approaching dozens of devices, the ISP ones tend to choke.
And yes, Ubiquiti most definitely isn't for non-technicals (Except for the AmpliFi stuff). It's more prosumer grade stuff. More features than the "gaming wifi" crap but still easier to configure than official Cisco stuff.
You're probably right, but blocking doesn't seem to be a problem. I'm going to leave it like that for now. Not sure I would need any more firmware updates for hardware which came out 3-4 years ago anyway, but I think enabling 13.224.195.59:443 for the devices only (not the controller) would trigger and download firmware updates.
Looking at the firewall logs it seems the devices try to ping (ICMP type 8) a bunch of AWS IPs every few hours. The controller tries to connect 80/443 on different AWS IPs a lot more often, even without me navigating the web interface. Other than that, no ill effects. Device firmware update notifications are gone, just says "up to date" now.
Interestingly, I still see the ad for their "dream machine" on the dashboard, as it seems to be baked into the controller. It's also trying to load external resources from "net-fe-static-assets.network-controller.svc.ui.com" while navigating the new web interface. The "classic" interface still seems to be truly self-contained. Using the latest controller version as of today (6.1.71-15061-1).
Condensed firewall logs for reference below. Not that it matters much, but why not.
Unifi controller VM:
Unifi devices (all ICMP 8):