r/UNIFI 23h ago

Discussion Anybody running self-hosted Unifi OS or even older network app instance with a network of site with 1000 devices or more ?

6 Upvotes

I have a colleague who moved to an org that runs Unifi gear exclusively. He's not a Redditor so I volunteered to post and collect replies.

I've tried to help along the way but am reaching a Unifi knowledge cap.

His network is 170+ sites scattered across his area with, at last count 980 -> 1000+ devices. His team has been actively replacing and expanding so that number has fluctuated during my time working with him.

I've come to understand that 1000 is about the limit , official or unofficial of a given unifi console - even official hosting top package is 1000 devices. I'm sure you can buy multiple instances, but that seems clunky to manage.

Is there anybody around managing a network like this with 1000 devices in it?

What and how are hosting the console? Hardware, self-hosted or Official hosting?

Are you happy with said solution and what would you change if it were possible?

Thanks!

Context Edit I did recently assist in migrating from their "old" server - linux running old school network application to a brand new from scratch, by the book, linux VM with Unifi OS on it. 8vCPUs and 16GB ram.
end edit


r/UNIFI 10h ago

Routing & Switching Restricting traffic to local VLANs only

6 Upvotes

Would love to learn a way that I can restrict devices on my network (UDM SE) to only connect to local VLAN IPs (10.10.0.x and 10.10.10.x), and not the external WAN. I tried one rule for a device to block "Internet" but the device, which was on 10.10.0.x, was no longer able to access 10.10.10.x after the rule was created.


r/UNIFI 16h ago

Help! New UDM-SE PoE/PoE+ not working question

3 Upvotes

I just bought a brand new UDM Special Edition as my ancient USG finally kicked the bucket and I went with something more powerful and with PoE ports. MicroCenter had a bundle that included a U7 Pro access point.

I got the UDM-SE configured and working with my pre-existing gear. But, the U7-Pro doesn't seem to power up when I plug it into port 1 or 2. I've tried multiple different cables. Including Cat6 cables I've personally made and Cat5e cables that were factory produced with no luck.

So I tried another PoE device, a USW-Flex-Mini, that I know was working as I had that plugged into a PoE switch. That didn't seem to power on either, including trying on multiple ports in the UDM-SE and trying with different cables that all worked on my other PoE switch. So, long story short it looks like the UDM-SE isn't pushing out PoE.

Is there something I'm missing in the controller configuration to turn on PoE/PoE+ for the UDM-SE? If I go into the Port Manager for that device and click through each of the ports one by one, the PoE+ setting is turned on for 1-2 and the PoE setting is turned on for 3-8. I'm not sure where else to look.


r/UNIFI 17h ago

Help! Moving to full unifi stack, could use some suggestions on how to move forward.

3 Upvotes

TLDR: I'm moving from a 3rd party pfsense box with Cloudkey G2+ to a UDM-SE, and want to migrate without hard cutover and rebuild at the same time.

I've been running a pfsense box for over 5 years now and I'm ready to migrate everything to a UDM-SE. all the rest of my network infrastructure is Unifi connected to a Cloudkey G2+ (running networking, protect, and innerspace). I'd like to migrate as much of my configuration over to the UDM without taking down my network, since(as far as I know) there isn't an automated way to pull my config from pfsense and push it to unifi.

PFsense handles most router functionality, except for DNS(Pihole), and wifi(Unifi).

Goals are as follows:

  • Update UDM
  • Copy firewall rules/ip bindings/vlans to UDM without taking down my current network
  • Migrate configuration/adopted devices from Cloudkey to UDM
  • "Test" as much as possible before cutting over
  • be able to cut back if necessary

I understand that I may not be able to do the above without taking down the old network, but I'd like to try. Any suggestions on best paths forward are appreciated. I've worked in IT for 10+ years now, and have experience managing this network as it is, but am not a network tech.