Unifi – James Batchelor https://james-batchelor.com Useful I.T & VoIP Ramblings Fri, 17 Jul 2026 11:07:04 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.6 https://james-batchelor.com/wp-content/uploads/2025/05/cropped-cropped-logo-jb-202505-32x32.png Unifi – James Batchelor https://james-batchelor.com 32 32 Unifi UGC Ultra Migration https://james-batchelor.com/index.php/2026/07/17/unifi-ugc-ultra-migration/ Fri, 17 Jul 2026 11:07:04 +0000 https://james-batchelor.com/?p=1088 Continue reading "Unifi UGC Ultra Migration"]]> I’ve been using Draytek at home for routing for the past 10 years or so, with the latest being the 2927 in use for the last few years. With the release of the newer 2928 model this year, it’s inevitable that my router will be going end-of-life pretty soon.

Instead of following on to its natural successor, is there anything else out there that can handle a moderate network setup?

I stumbled upon a Unifi UCG Pro, and at £104 it’s at a price point that’s almost justifiable to get just to see what it can do. After checking some core features I need for my network would be achievable, I ended up getting one.

The UCG Pro claims 1 Gbps IPS throughput, which fits my 900Mbps/105Mbps connection. Let’s see if it becomes a suitable replacement…

Why Switch Now?

Going down the Draytek route initially was due to a “eat your own dog food” scenario, where my previous employer deployed these in mass, so it was handy to have a router I was familiar with and a point of local reference for any capabilities or troubleshooting.

At the time (circa 2018), the feature set that a Draytek offered for the price point seemed superior to the Unifi offering, which at the time, personally seemed a bit of a style of substance.

Fast forward to today, and the realisation that I no longer need to touch a Draytek again, a few “features” of DrayOS are really starting to grate on me:

  • IPv6 compatibility: It ignores my delegated /48 prefix assigned by my ISP (Zen), instead configuring a single /128 address. I can set this up manually per machine, but its seemingly impossible to assign a /64 per VLAN and configure it with SLAAC or DHCPv6.
  • Change something = reboot: Almost every change on the web GUI results in a reboot prompt. I’ve been advised on a “DCNA” course that these can be clicked away from, but the ambiguity of what changes stick after a power loss is a guessing game. Couple of examples; changing authorised SNMP IP’s work instantly, but if powers lost before a commanded reboot, it returns to the previous values. Also, IPv6 WAN setup will appear changed in the GUI, but will not actually take effect until reboot.
  • Hardware acceleration: The 2927 was advertised as offering 950Mbps WAN throughput, but only if hardware acceleration is enabled. Without, the max I get is around 550Mbps. What the route decides to pass onto HW processing is very hit and miss, consecutive speed tests can return 950Mbps or 550Mbps seemingly at random.
  • Route policy: The routing / load balancing options are great. However, every change regardless of its priority results in the router slamming closed every open NAT session. Extremely annoying when streaming anything with a large buffer (such as radio on a smart speaker stopping 10 seconds after making a change).

Why Unifi?

Apart from recent recommendations, I already use their access points for WiFi coverage, as they are far superior to any Draytek WiFi implementation, these AP’s are managed via a cloud controller running on a local Debian VM.

The GUI, despite being limited to AP’s only, seems information rich and doesn’t seem to require that much upskilling to translate network setup from a Draytek to Unifi point of view.

As mentioned, 10 years ago I heard (second hand) that the entry level routers seemed lacking in certain features, such as VPN options and the ability to load balance over multiple WANs. But a bit of research seemed to suggest that entry level Unifi’s have now caught up.

Impressions on the Unifi UGC Ultra

Setup

On first hands on, I’d like that you can access the router GUI with a local username and password, no Unifi account required. This alleviates any concerns that issues with Unifi (outage or moving to paid subscription model) will not lock you out of your own device… for now. It does nudge you heavily to adding an account (akin to old Windows 10 installations), but the GUI is reachable without. The only caveat of local only access is that remote access to the GUI is not available unless an account is added, but once an account is added, local access is still available.

Once in the GUI, there is a little hand-holding wizard in getting the WAN connection up, and assumes a DHCP connection. However, PPPoE is clearly available and easy to get you up and running (without a reboot, looking at you Draytek). 

With WAN connected, it performs a speed test with the results used to set the anticipated speeds (presumably for QoS), then hopes of surviving a reboot are quashed by a substantial update and restart. Reboot times are approx. 2-3 minutes, so will be noticeable to the casual browsing session.

From there, the hand-holding stops and you’re left at the main GUI. Configuring a network setup is pretty intuitive, but I get the feeling that a few of the settings are in awkward places in the aim to preserve a tight menu structure. It’s been a few days since adding an SNMP community string, and I’ve lost where it is already.

L2 VLAN setup and configuration of the different networks is straightforward and a quick task to replicate for another router (all without rebooting), Although use of the “auto” options is disabled to replicate another network one to one.

Throughput

As advertised, speeds are able to reliably achieve advertised speeds, within the confines of my 900Mbps/105Mbps connection (Openreach profile speed is 1Gbps/115Mbps).

IPv6

The pressing reason for getting this unit was to get a working IPv6 setup. Luckily, this has been achieved. 

Zen’s IPv6 was discovered by the router by setting the WAN configuration to SLAAC connection and specifying the prefix delegation option, giving use of the /48 range.

Subdivisions and allocation of the range on the LAN side was not as customisable as I’d hope, however. When enabled on a VLAN, a /64 range is allocated and the subnet address cannot be customised, the first range configured gets ::1/64, the second 1::1/64 and so on. Since my VLAN IDs take a non sequential arrangement, I’d prefer a more customisable setup to match my VLAN IDs.

VPN

Possibly the weakest feature of the USG discovered so far, whereas a Draytek offers all options for dial-in or LAN to LAN (inc. dial-out), the Unifi offers a lesser selection: 

– Dial-in: Wireguard, OpenVPN, L2TP
– Dial-out: Wireguard, OpenVPN
– LAN to LAN: OpenVPN, IPsec

The goal for my setup was to re-establish an IPsec VPN with a remote site running a Draytek 2763, however this highlighted a compatibility issue that I may go into with a future post.

As a compromise, a Wireguard session was established, with Unifi as the server, Draytek as the dial-out client. This works and is stable, but not without a performance hit, seeing throughput drop from 115Mbps over IPsec (limited by the FTTP upload profile) to around 60Mbps which is not the best outcome.

Logging

The Unifi GUI is truly superior in finding out what your clients are doing, but not comprehensive. 

Traffic logging by each network device is available for easy viewing, along with application insights to help surmise where the traffic is going (albeit based on Unifi’s interpretation of the destination by IP).

FireTV doing FireTV things

This is something you could only dream of while using a Draytek, but as mentioned, not perfect. 

I always get suspicious when my Grafana dashboards plot a spike a spike in WAN traffic that I was not expecting, and while I can see the spike in the Unifi dashboard, drilling down to the specific device is not as easy, and you’ll easily resort to checking every device to see the culprit.

Firewall logging on the other hand is as verbose as possible, showing each time my commercial cameras attempt to call home.

A little detail, but a possible concern. The WAN connections show a little icon of the ISP’s logo. Sure it’s a little touch to the UI, and the source code links to the ASN of the ISP, but it’s hard to dismiss if other metrics are being collected on your usage of the product.

Under the hood

One of the most surprising discoveries is this unit is just a Linux box, running Debian 11 on ARM:

Enabling SSH on the controller gives you root access to the OS, where you discover that it’s running familiar open source applications. This gives great troubleshooting options (as found with the aforementioned VPN issue) as resources are available from both the Unifi and wider Linux community. Changes to configuration files may be more tricky, as the GUI autogenerates the files upon each save, but certainly better for beginners than trying to navigate a closed source CLI..

This also helps for SNMP collection, as the generic Linux device template in Zabbix suffices.

The only reservation is that it is running Debian 11, which enters end of life on 31st August 2026. Hopefully these units will undergo a next version upgrade, or that Unifi will maintain the kernel past public withdrawal.

Summary

Simply put, for the price point, it makes for a great upgrade for any ISP supplied router, or as a quick replacement for any business class router running a 1Gbps service, assuming WiFi is handled elsewhere.

]]>
WiFi: Draytek 2927ac WiFi vs Unifi NanoHD https://james-batchelor.com/index.php/2022/06/20/wifi-draytek-2927ac-wifi-vs-unifi-ap-nano/ Mon, 20 Jun 2022 20:50:00 +0000 https://james-batchelor.com/?p=806 Continue reading "WiFi: Draytek 2927ac WiFi vs Unifi NanoHD"]]> A Draytek, be it a 2765, 2865, or 2927 based on WAN connectivity and LAN complexity is my go to device for a router. More than likely these are the ‘ac’ variants as WiFi provision is expected rather than featured.

In newer Draytek models the perceived performance of wireless as been lacking based on earlier models such as the rock solid 2860n/plus with reduced range and throughput speeds, in particular poor VoIP performance for my industry.

This could be down to the passage of time and how WiFI has become even more ubiquitous, in demand and ultimately a more congested radio band. Regardless an alternative solution needs to be explored.

Previous dabbling with deployment of Unifi access points have yielded trouble fee results, so this would be a quick win. Trouble is, the default AC-Pro and AC-LR are in serious supply shortages at present. Wifi 6 variants have better stock availability but also have a higher purchase cost.

The only Unifi AC product that is plentiful is the NanoHD, so in desperation lets see if it is a justifiable upgrade to the Draytek offering…

Test Environment

There’s nothing scientific about the test setup here, I’m currently using a Draytek 2927ac for WiFi so will switch all home wireless traffic over to the Unifi AC-Nano (by cloning SSID and PSK) and observing any changes.

I’ll keep the Draytek radio’s active during use of the Nano, adding a ‘_D’ to the SSID to differentiate the devices for testing. This will also add a bit of competition on the radio spectrum that is now commonplace.

Location

The competing devices are placed within a foot of each other to give an accurate range comparison, I’ve chosen to suspend mount the Unifi as research suggests the antenna’s in the unit are somewhat directional.

As this is mounted on a fixture on the ground floor, I’d be interested on discovering WiFi performance on the first floor, ultimately to discover how directional the antenna’s are.

As mentioned, both Draytek and Unifi units will be broadcasting SSID’s and within a foot of each other, chosen as a worst case scenario of how each compete / compare in the radio spectrum (auto channel enabled on both).

Test Equipment

For simplicity, its a Samsung Galaxy Note9 using speedtest.net app, connecting to the same test server each time.

Test One

First test is an indoor line of sight, test phone is approx 25 feet away from the access points but still in line of sight.

Unifi:

Draytek:

I wouldn’t expect this to be a struggle, but both results were far shy of the available 550Mbps download bandwidth, however this could be down to the test server as it was kept as a constant. Upload reached full utilisation at 75Mbps.

Draytek wins this round.

Test Two

Relatively speaking I have a home that’s easy for Wifi, small and of traditional brick construction. To create a bit of a challenge for comparison the next will be from outside and within the car sitting on the drive, approx 50 foot distance

Unifi

Draytek

Something I’ve noticed during testing is the Unifi does seem to offer a better range over the Draytek, giving better bars / RSSI on the fringes of my network.

Results are pretty even, but from a VoIP perspective the latency and jitter under load is way too high to support real time media.

Test Three

More of a real world test, I have a Raspberry Pi Zero running in a garden shed running off a solar panel and 12V battery. The Pi Zero WiFi antenna is self contained on the chip, being a challenge to an access point to create a reliable connection to it from a distance.

The AC-Nano was installed on 9th June, although the ping times don’t show much of an improvement.

Summary

The results were disappointingly similar considering adding AC wireless to a Draytek router is around £40, compared to the £130 in buying the NanoHD (before required controller / Clouldkey).

Yes the NanoHD is not the most suitable product for the testing, but as mentioned this is the only one that has plentiful stock at the moment.

From testing, the Nano seems to advertise a better signal to devices than the Draytek, so ‘devices’ such as my car can pick up Wifi on the Nano where the Draytek could not.

But on comparison, this signal increase does not yield better throughput, devices that pick up the Draytek get more or less the same, with the Draytek advertising a greater speed.

From a VoIP perspective, where both pushed over 1 second latency on upload at load, neither can be considered a solution. I understand that a speedtest.net test aims to utilise all available bandwidth, but in real world scenarios, there nothing to stop any other application acquiring all available bandwidth during normal use and negatively affecting voice traffic at the same time.

Finally if you were wondering, suspending the NanoHD then using a device “behind” it (i.e above its location) worked fine.

Update: August 2021

Since initial testing I ended up reverting back to the Draytek for Wifi, as performance was the same and saved on powering another device. However I’ve now sourced an AC-Pro and replaced it in the same location as the NanoHD.

Performance with this model is improved, not so much from increased speed or reduced jitter but whats noticable is the reliability of devices on the fringes of range.

Below is a recent graph from the Pi Zero:

Its clear to see the AP-Pro’ installation on 9th Aug by the lowered ping times.

Its not perfect however as seen with the spikes, however am starting to suspect this is lining up with my activity in having other Wifi devices (laptop, mobile) in the same vicinity or between the Pi and Pro is causing these spikes.

If time permits I’d would like to revisit this compare the AC-Pro and NanoHD side by side, but for the original brief of is a NanoHD better than a Draytek, the answer is No.

]]>
Add Unifi Controller to CentOS 7 https://james-batchelor.com/index.php/2022/06/12/add-unifi-controller-to-centos-7/ Sun, 12 Jun 2022 18:49:46 +0000 https://james-batchelor.com/?p=793 Continue reading "Add Unifi Controller to CentOS 7"]]> I’m in the process of testing a Unifi AP (Nano), and need a controller to set it up. As its a temporary setup I choose the old faithful CentOS 7…

There are many excellent guides for setting up a Unifi Controller on CentOS 7, three that helped me:

https://community.spiceworks.com/how_to/128121-installing-unifi-controller-on-centos

https://nivethan.dev/devlog/setting-up-unifi-controller-on-centos-7.html

https://binhminhitc.com/networks-solutions/how-to-installing-unifi-controller-on-centos/

However since these were penned there are a few changes in the setup that need to be worked around:

Workarounds

UniFi.unix.zip Download Link

Unifi have stopped advertising the Unix files on the downloads, instead opting to show only the .deb Debian package. To get a file suitable for CentOS…

Navigate to https://www.ui.com/download/unifi/ and choose the download for Unifi Network Application for Debian:

Clicking download icon gives the following link…

Make note of the version number (here 7.1.66) and edit into the the following link:

https://www.ubnt.com/downloads/unifi/7.1.66/UniFi.unix.zip

MongoDB

MongoDB is no longer included in the default CentOS or EPEL repositories, so its own repository needs to be added to your system for prerequisites

Source: https://www.mongodb.com/docs/manual/tutorial/install-mongodb-on-red-hat/#install-mongodb-community-edition

Create a new file at /etc/yum.repos.d/mongodb-org-5.0.repo

Insert the following into the file:

[mongodb-org-5.0]name=MongoDB Repositorybaseurl=https://repo.mongodb.org/yum/redhat/$releasever/mongodb-org/5.0/x86_64/gpgcheck=1enabled=1gpgkey=https://www.mongodb.org/static/pgp/server-5.0.asc

Installation is now via:

yum install -y mongodb-org

Installation Guide

Disable SELinux, reboot for changes to take effect

sed -i /etc/selinux/config -r -e 's/^SELINUX=.*/SELINUX=disabled/g'
reboot

Create file to include MongoDB repositories

nano /etc/yum.repos.d/mongodb-org-5.0.repo

Add the following to the new file

 [mongodb-org-5.0]name=MongoDB Repositorybaseurl=https://repo.mongodb.org/yum/redhat/$releasever/mongodb-org/5.0/x86_64/gpgcheck=1enabled=1gpgkey=https://www.mongodb.org/static/pgp/server-5.0.asc 

Install prerequisites

yum install -y mongodb-org java-1.8.0-openjdk unzip wget

Download Unifi Controller

wget https://www.ubnt.com/downloads/unifi/7.1.66/UniFi.unix.zip

Unzip files to /opt directory

unzip -q UniFi.unix.zip -d /opt

Create data folder within Unifi directory

mkdir /opt/UniFi/data

Add new user to run service

useradd -r ubnt

Assign ubnt ownership of Unifi directory

chown -R ubnt:ubnt /opt/UniFi

Create firewall rules to allow access to Controller

nano /etc/firewalld/zones/public.xml

Add the following to the file…

  <port protocol="tcp" port="8081"/>
  <port protocol="tcp" port="8080"/>
  <port protocol="tcp" port="8443"/>
  <port protocol="tcp" port="8880"/>
  <port protocol="tcp" port="8843"/>
  <port protocol="tcp" port="27117"/>
  <port protocol="udp" port="3478"/>

Reload firewall for changes to take

firewall-cmd --reload

Enable MongoDB to start with the system, start it for first time and check its running

systemctl enable mongod
systemctl start mongod
systemctl status mongod

Create the service for Unfi Controller

nano /etc/systemd/system/unifi.service

Enter the following in the new file

[Unit]
Description=UniFi AP Web Controller
After=syslog.target network.target

[Service]
Type=simple
User=ubnt
WorkingDirectory=/opt/UniFi
ExecStart=/usr/bin/java -jar /opt/UniFi/lib/ace.jar start 
ExecStop=/usr/bin/java -jar /opt/UniFi/lib/ace.jar stop
SuccessExitStatus=143

[Install]
WantedBy=multi-user.target

Enable Controller to start with system

systemctl enable unifi

Start the Unifi Controller

systemctl start unifi

Controller should now be available for setup by browsing to
https://{IP ADDRESS}:8443/

Unifi Testing

I need the Unifi Controller in order to test the Nano HD AP, why? This is the only Unifi AP in stock in the UK at the moment, all other more preferred AP’s like the Pro, LR and HD are unobtainium along with the Cloud Key. Therefore in desperation its time to test if these will make a worthy substitute.

Its early days at present, but should testing go well and I choose to adopt Unifi as my home Wifi solution, I’d be deploying a slim VM running Rocky 8 to manage the infrastructure.

So far for testing; the AP is positioned a foot away from a Draytek 2927ac, at moderate distances the Unifi Nano is showing a 10db advantage over the Draytek on 2.4Ghz range, but curiously a 10db disadvantage on the 5Ghz range. And while devices report a better signal strength on the Unifi, bandwidth speed tests yield poor results.

I would hope that the Pro’s performance would be an improvement on the Nano, but for now that is entirely speculation since getting hands on one is impossible without paying scalper prices.

]]>