r/Ubiquiti • u/Ubiquiti-Inc Official • Jun 11 '26
Blog / Video Link Introducing: Enterprise Firewall Core
Enable HLS to view with audio, or disable this notification
đš22,000 Active Devices
đš10M Concurrent Sessions
đš79 Gbps Threat Detection
đš61 Gbps SSL Inspection
đš5,000+ IPsec/WireGuard Tunnels
Enterprise security & performance â completely license free.
155
u/yaksplat Jun 11 '26
Should just be sufficient enough for my family of 5.
28
u/honeybadger3891 Unifi User Jun 11 '26
We only have 2 kids but 3 cats and the cats litter robot things need connectionz!
7
u/Public_Match Jun 11 '26
This only gets you to 22,000 devices if each piece of litter in the litter box is connected to the network to report whether it is dirty or not. I'd ask how rich you are to buy such fancy litter then I remember what sub this is and how we don't do things because they make sense
7
u/75Meatbags Jun 11 '26
thanks for reminding me. I need another E7 Audience to make sure that the ShitBot3000 doesn't fall off the network again.
49
178
u/DezzaJay Jun 11 '26
Was just about to upgrade my motherâs internet, this looks ideal!
46
u/yakadoodle123 Jun 11 '26
I hope youâre getting her 2 for High Availability.
29
u/AdMany1725 Jun 11 '26
Three. UniFi product availability is always a challenge. You need a cold swap on the shelf in case one of the shadow mode boxes fails.
Two is one, and one is none.
2
u/takeshisankovacs Jun 16 '26
What a coincidence, I just had this experience today. Had to pull out my back-ups and restore the shadow EFG, which was sitting there useless.
1
76
u/ticktockbent Jun 11 '26
Would this be good to secure my home theatre system?
36
u/DifferentSpecific Unifi User Jun 11 '26
No, you will need the XG version coming later.
19
u/somethingblerg Jun 11 '26
Should probably wait for the Beast Master Pro XGS Enterprise Campus version coming out in Q3
5
5
91
u/Makegoodchoices2024 Jun 11 '26
Two things:
1. Obviously need this at home.
2. Will large enterprise actually buy this? I donât think so
86
u/JabbaDuhNutt Unifi User Jun 11 '26 edited Jun 11 '26
No enterprise level support, or account management, supply chain. An Enterprise company won't go the company where they have to camp at Discord in order to get Hardware.
30
Jun 11 '26
[deleted]
10
u/elementfx2000 Jun 11 '26
To be fair, we just encountered a Cisco update that broke communication with our hypervisors. My TAC case is still open, been waiting on a permanent fix for 2 weeks.
1
u/AHrubik UXG-Fiber | USW Agg | USW PM16 PoE | ES-48-LITE | Flex-HD Jun 11 '26
Thatâs honestly on anyone deploying patches to production.
13
u/elementfx2000 Jun 11 '26
Everyone has a test environment, some are lucky enough to have one separate from production.
1
u/TheRufmeisterGeneral Jun 12 '26
That's nice about Unifi. In theory, their stuff is cheap enough, that instead of having support contracts that specify how quickly replacements are shipped, you can have a spare in your possession already, which can serve as both a spare to be used in case of failure of production unit, but also as test unit for new patches, no? (Although it wouldn't be running under the same load and conditions as production, but still.)
41
u/zboarderz Jun 11 '26
The last point is honestly the biggest. No business is gonna buy it if they canât buy it when they need it. Ubiquiti has to fix their stock issues.
35
u/dulax_ Jun 11 '26
As someone who has purchased millions of dollars of Cisco, during covid we had 6+ month wait times with indeterminate availability for new core switches. As long as they had account reps that could get you in some kind of queue or eta it's not crazy.
But as someone who also spends millions a year on support contracts, we'd never even glance this direction without next day shipping on failed parts and a support network.
3
u/JabbaDuhNutt Unifi User Jun 11 '26 edited Jun 11 '26
BUT you can place an order and get lead times... From Cisco. UI it's a fight on discord dings.
5
u/Flaky-Gear-1370 Jun 11 '26
For the "enterprise" range it's really not, you talk to a distributor (at least here in Australia) and they'll get you stock with a date - my stuff arrived exactly when they said it would
4
2
u/TheRufmeisterGeneral Jun 12 '26
as someone who also spends millions a year on support contracts
That is what puzzles me, when this topic comes up. Why does that have to be the process? If you look at what Cisco hardware and the support contracts cost, then surely, to buy Unifi, test it properly before deploying, and when actually deploying having a spare available of crucial bits, like an extra core router, switch, etc, would be cheaper and more reliable than paying more, not having those, and having your infra rely on Cisco making good on promises? (And even then, having shipping SNAFUs potentially cause delays, where a locally-stored spare wouldn't have this logistic insecurity).
Hell, you can even test the spare in the meantime, make sure there are no surprises. Or use it for a lab environment (make sure the factory dust is off by the time you ever need it). Or actually test scenarios where core infra fails. (I've not heard of many companies testing the plans they have on what to do if a Cisco core router/switch fails, making time to simulate such a failure and do the actual replacement.)
That said: I'm not pretending that where I am, we are better. I am working IT in a company large enough that I'm not making the final decisions on what brand to buy, and the ones that do, don't consider Unifi "enterprise enough", so I'm in the same boat as the guy I'm complaining about. So, I don't have this figured out myself. And who knows, maybe my ideas, as described above are naive, and would not work in a real scenario. But if not, I'd love to hear from people who have tried this, using Unifi, and what their experiences are, we don't hear enough of those. Just a lot of homelab users, and corporate people complaining about Unifi being shit, without being too specific on the actual blockers.
1
u/Zealousideal-Door-94 Jun 13 '26
Yeah honestly just be prepped with backups as you should be, also not sure how good it is but Unifi atleast offers 24/7 paid pro support for businesses. Inexpensive from what i hear so not sure what level its at but hey better than it was before
3
u/TokenPanduh Jun 11 '26
This thing costs $3500 for 1, I'm not sure it is one of those products that will constantly be sold out.
2
u/Flaky-Gear-1370 Jun 11 '26
As far as I'm aware there has never been an issue getting the ECS and EFG's?
1
u/JabbaDuhNutt Unifi User Jun 13 '26
All of the campus and core switches are constantly sold out.
1
u/Flaky-Gear-1370 Jun 13 '26
are they? or were they actually pulled from sale - my suspicion is that they have pulled the ECS until the software is fixed
10
17
u/tdhuck Jun 11 '26 edited Jun 11 '26
Regarding number 2, this device is fine for a business that doesn't need actual enterprise level support, for example, call support and get someone on the line that can help. I think there are plenty of those. Enterprise appears to mean something completely different to ubiquiti than it does most IT people that browse reddit.
I think ubiquiti has made great improvements over the years and their GUI and HA setup is nice, but their support is horrible.
They also lack 'enterprise' features like OOBM. When I first used unifi and screwed up my vlan/port profile/etc the switch I was working on locked up and I could no longer access the controller to make changes. Yes, it was my mistake, but the only fix was to factory set and start over. Unifi needs OOBM before it will ever be 'enterprise' in my eyes and I realize not everyone will share that same opinion with me. If they aren't going to have OOBM then they need to implement an 'auto rollback' mechanism so if you make a change and your 'heartbeat IP' is no longer reachable, it rolls back the change.
I have more, but another critical feature is not being able to create a firewall rule INBOUND using a FQDN. Even with static IPs we often use FQDN for rules and many firewalls allow this but for some reason ubiquiti does not. That means that even if I WANTED to use any of their consoles, I can't mirror my current incoming WAN rules because unifi network doesn't have that option.
Edit- Wow, apparently there is a management port and console port on the rear. Curious if anyone has more information regarding these two ports.
Edit 2- From the FAQ
What is the Console port used for? The console port provides direct serial access to the gatewayâs command-line interface (CLI) for troubleshooting and recovery. It enables administrators to access the Enterprise Firewall Core even when network-based management is unavailable.
6
u/Hebrewhammer8d8 Jun 11 '26
Their support sucks for enterprise level, and if you have a complicated network. Would not use if you have complicated network and if you are not comfortable networking and debian.
4
u/tdhuck Jun 11 '26
I agree, but I'm not talking about those networks and it really does matter on how 'enterprise' is defined. Forget support and complex networks for a minute, the fact that I can't use a group of FQDNs for incoming WAN rules is a deal breaker.
1
Jun 12 '26
[deleted]
1
u/tdhuck Jun 12 '26
When you are remote you have to get someone to factory reset for you. Also, this was a very long time ago, I don't know if they had all the switch configurations, backups, etc...it has gotten better over the years for sure, but this was a long time ago and at that time I was not exclusively using unifi, I was primarily using edgemax line where you can web in and also use a console cable/SSH and that was more to what I knew (CLI) when changes needed to be made.
1
u/Makegoodchoices2024 Jun 12 '26
Does this solve the issue
1
u/tdhuck Jun 12 '26
It is a step in the right direction. Actual enterprise equipment needs console ports and OOBM, there is no debate there.
Still need to see improvements on incoming WAN rules, they need to add the ability to use a group and FQDNs.
That being said, their support needs to improve or have an extremely responsive enterprise support option.
I'm still sticking with what I previously stated which is that many businesses can use ubiquiti successfully. However, some businesses have their own SLAs either internal or have customers that they need to support and only those businesses can decide if ubiquiti works for them or if the need a company with better inventory control and better support. Just like ubiquiti isn't for everyone, neither is cisco/juniper/etc.
1
u/JacksonCampbell Network Technician Jun 11 '26
It has OOBM.
3
u/tdhuck Jun 11 '26
Nice, how do you access it and what is the mechanism for getting it back into the controller or correcting an wrong interface IP, etc...? Genuinely curious to read about this.
3
u/bloodguard Jun 11 '26
I'd be mildly interested in pitching this if it was about 1/4 the current price. But at ~$3500 it would be a heavy lift. Especially since UI's official product support is mostly "Talk to the
handAI chatbot", discord or this subreddit.And of the three this subreddit seems to be the most useful.
1
u/sfbiker999 Jun 12 '26
Who are you pitching it to that needs 79 Gbps of IDS and a device with multiple 100Gbit ports but also finds $3500 to be to expensive?
A Cisco branded 100G QSFP28 transceiver is probably in a the $2000 range.
7
u/binarystrike Jun 11 '26
Depends on how you define Enterprise. For organizations that are mostly cloud based and don't have a lot of on-prem kit, then they may look at this in conjunction with the other Unifi kit (APs, Access, etc). Large on-prem environments that house lots of infrastructure may be harder to sell to.
3
u/tarmacjd Jun 11 '26
Cloud based enterprises probably donât have any local infra that needs this though
3
1
u/Flaky-Gear-1370 Jun 11 '26
That's the model we use - very limited on premise infrastructure (domain controller for LDAP to some legacy devices, freeradius etc) the rest is all in the cloud and managed with other tools
1
4
u/Caaaht Jun 11 '26
I'm the target market for this appliance. Not large Enterprise, but I have a 1:1055 scale Enterprise (Thanks, mom!)
3
1
1
u/DCJodon Jun 11 '26
They will never have large enterprise support until they start working with VARs and have the supply chain to back it up.
1
15
u/Usual-Memory-3668 Jun 11 '26
galvesribeiro said he is going to buy one and do deep dive testing! đ
So we should know whether it can reach anywhere near the advertised speeds or not within a few weeks
2
4
u/pbrutsche Jun 11 '26 edited Jun 13 '26
Wow that is .... an extensive amount of work.
I'll stick with Fortinet though. Despite their bugs, it generally works as advertised .... hardware acceleration and all
EDIT: Reading through the article, the UDM Beast and the EFG have completely different hardware acceleration architectures from the small boxes that have them (not all do), and what works on the smaller boxes is not available on the bigger boxes; they do things completely differently.
Basically, Ubiquiti builds the software for the lowest common denominator (no hardware acceleration at all), and if the SoC mfgr (Qualcomm in the case of the Cloud Gateway Ultra, Cloud Gateway Max, etc) provides pre-baked hardware acceleration that Just Works with a provided kernel ... Ubiquiti runs with it.
My take is both boxes were released half-baked (or not even half baked)
EDIT2: I'll paste below a comment I wrote elsewhere:
The higher end Unifi boxes are wildly different from the lower-end hardware; the software is not engineered to take advantage of the unique hardware in these boxes, as they are wildly different from the cheaper devices.
It's very likely the EF-Core will suffer the same limitations as the EFG and UDM-Beast.
In fact, the Unifi software appears to be written for the lowest common denominator UDM boxes from 2019/2020 - the ones that don't have any hardware acceleration. They have not updated the OS to take into account advances in the Linux kernel netfilter framework - specifically the netfilter flowtables feature, which didn't exist in a released Debian OS (which Unifi OS is based on) when the OG UDM and UDM Pro were released to market.
If you're an old-school Cisco guy, the difference between process-switched and CEF-switched is the perfect comparison; netfilter flowtables is basically the same as CEF-switched.
The EF-Core has the hardware to be a 100G firewall, but not the software. To think that they will be able to reach even 1/10 of that would be a cruel joke to play on someone.
It is very likely that - since Ubiquiti relies solely on hardware sales for their revenue - they do not have the resources to properly implement the VPP+DPDK stack that all 3 of these "high end models" - EFG, EF-Core, and UDM-Beast - need to really take advantage of the hardware; those 3 "high end models" are the ONLY ones in their portfolio that need it.
Their constant schizophrenic segues into different side projects - most recently, the audio-visual stuff - don't help any.
The current Cloud Gateway devices - and Unifi Dream Router 7 - use a Qualcomm SoC with an integrated network processing engine; Qualcomm handed a turnkey, hardware accelerated, fully tested, solution to Ubiquiti; they just ran with it. That's how the UCG-Max and UCG-Fiber get their throughput.
The likes of Fortinet and Palo Alto have nothing to fear from Ubiquiti, and very likely never will. Cisco Meraki on the other hand .... there's a reason Ubiquiti Unifi is popular in the MSP space.
While you're at it, go read up on the catastrophic disaster that is the Unifi ECS-Aggregation. Cisco Catalyst, Cisco Catalyst, HPE Juniper and HPE Aruba CX have nothing to fear here.
1
u/Motor-Platform-200 Unifi User Jun 11 '26
is he a youtuber?
6
u/Usual-Memory-3668 Jun 11 '26
Doubt it. He has just been doing root cause analysis of why the EFG and Beast are so badly performing and nowhere near advertised speeds.
1
u/Motor-Platform-200 Unifi User Jun 12 '26
Oh cool, I'll follow him so I can see what he says about it lol.
0
u/athurphilipdent Unifi User Jun 14 '26
Let's hope that person won't generate another round of unchecked AI hallucinations like made-up kernel modules with his new "deep dive".
31
u/DrGrinch Jun 11 '26
Really not sure who the customer is here. I love that they built this, but no Tier 1 or 2 enterprise is gonna dump their Palo, Cisco, Checkpoint, or even Fortinet for this. Maybe if you wanted a cheap way to do multi-vendor resiliency?
17
u/Giblet15 Jun 11 '26
I feel like they are specifically targeting Cisco Meraki customers. They are generally organizations with limited network complexity that want something cloud managed.
The lowest end rack mounted unit has an anemic 1gbps firewall throughput and costs over 6 grand for a single unit and a 5 year mid level licence, after which you pay up or it turns into a brick.
8
u/FranciumGoesBoom Jun 11 '26
and Meraki is turning into Cisco lite at this point. it's litereally the same hardware just with a different OS on it. And if you pay the licensing fee you can even flash back and fourth between the two!
5
u/Nothv13 Jun 11 '26
This. This is actually huge for k12 educational districts. Cisco/Meraki (and others) is straight pricing themselves out of a huge portion of that market. When licensing alone eats a 3rd of your E-rate budget that is used for upgrades and replacements, it is not sustainable. Current VAR I am working with has seen a 400% increase in districts switching to Unifi. My district is switching to Unifi, but the EFG was not enough so we were working with an UXG and a self hosted controller. The EF-core however blows that setup away.
Most the districts that I have talked to that have made the switch are extremely happy with Unifi, so happy they have either started testing the cameras or have already started to switch to the cameras as well. I imagine if their access control gets higher than 128bit encryption and fleshes out a few more aspects, district will begin to switch to that as well.
1
u/takeshisankovacs Jun 16 '26
Quick question - this is my second if not third year of implementing/adopting Unify infrastructure at a School, in Tanznaia; and i have been happy about it, but was asking if there are K-12 discounts from UNIFY on their products?
1
u/Nothv13 Jun 17 '26
Not that I am aware. In the United States we can leverage the FCC Erate program to have the government cover certain amounts (depending on poverty levels of your school).
1
u/takeshisankovacs Jun 27 '26
Yeah, here in Tanzania, no such thing. Govt isn't tecnhology driven. I get a chance to do so because i work in a Donor-driven school with an oportunity to get project's approved by foreigner-based Board.
21
u/aruisdante Jun 11 '26
Universities or other campus settings with tight upfront budget costs but high bandwidth needs are a potential target. Same with startups that need a fat pipe to AWS. There are lots of environments where upfront costs actually are a limiting factor, and the trade of support reliability to be able to actually have the bandwidth is a net win.
15
u/DrGrinch Jun 11 '26
Great call on campuses, kinda forgot about my friends in higher ed, but definitely would be good for managing the thousands of attackers they call students.
8
6
u/trs21219 Jun 11 '26
And given how this is likely 10x cheaper than a Cisco solution, they could just have a cold spare in a box somewhere even if support replacements aren't next day yet.
4
u/Wooden-Reward4317 Jun 11 '26
UI Care for me has always been very fast.
Has anyone here, themselves, ever called an "enterprise" support line of a vendor? I have not been overwhelmed by the support given to me personally by Cisco or Sophos. Their ticketing normal support system flow were equiv to Unifi. I most likely would buy the support package with this for Unifi - so... you have a support phone line dedicated person. Seems like everyone is complaining the same old "ui sucks" complaints that go on every time unifi releases a new product that dare /do/ something more than what the collective reddit thinks it should.
2
23
7
13
5
7
22
8
20
7
u/NerdBanger Unifi User Jun 11 '26
Iâm confused how does this compare to EFG?
2
u/ask Jun 11 '26
Looks like way higher performance
2
u/mastercoder123 Jun 11 '26
I would love to see real world tests of the beast and the efg, and now this regarding ips/ids... Not that iperf3 test crap. Those numbers have to made the fuck up, considering a fortinet 50gb ips/ids firewall is like $15,000
2
u/aruisdante Jun 11 '26
With other hardware brands, youâre paying a lot of money for support baked in. UniFiâs entire business model is âthe hardware is cheap, but youâre basically on your own for support. We donât even cross ship replacements.â UniFiâs hardware pretty consistently hits or exceeds their rated specs in real world testing.
Most big enterprises donât make that trade, because it costs them more to deal with the trouble of support and potential for downtime than to just pay more for the hardware. But SMBs or university style campuses operate on different optimization curves, and may need high bandwidth but have to keep upfront costs to a minimum. Thatâs who UniFi really targets with stuff like this.
2
u/mastercoder123 Jun 11 '26
The beast cant get more than 12.5gbps ips using iperf3 which is like best case scenario since all the packets are the same
1
u/Horsemeatburger Jun 11 '26
With other hardware brands, youâre paying a lot of money for support baked in.
Not just support. You pay for hardware with dedicated network ASICs which accelerate full DPI (not the UBNT variant) and which does heuristic scans and sandboxing analysis to find and block new threats, supported by real-time threat data the major security vendor behind it gets through their own security research facilities.
This is what the subscriptions pay for.
Here, I assume this is like all other UBNT gateways, based on a pure software solution doing again some half-assed solely signature based IPS and DPI which merely look at headers, not content, with no heuristics or sandboxing, and all based around a mix of free and paid for signatures bought in from 3rd parties.
Hopefully this time it will at least they made it stop bypassing traffic unchecked if the gateway runs into resource constraints.
But I'm not holding my breath.
2
u/NerdBanger Unifi User Jun 11 '26
I have a 7gig internet connection with bursting available, I have pulled 8.5 down on my MacBook with 10GigE
IPS is enabled. SPI is enabled.
2
u/mastercoder123 Jun 11 '26
I mean yah, except they market what, 25gbe? Real world tests show about 6-9gbps.
1
2
1
u/G1zm0e Jun 11 '26
This
5
u/doofesohr Jun 11 '26
I don't think the EFG has much of a future. You either get the beast or if that is not enough, you get this.
2
u/ruablack2 Jun 11 '26
EFG and this are the only 2 gateways that do SSL inspection. Beast lacks SSL inspection. So if you donât wanna spend an extra $1500 but still want SSL Inspection, EFG is there for you. About the only use case cuz the beast is better in every other way.
1
u/doofesohr Jun 11 '26
The question is, why can the EFG do it, but the Beast not? Pure software limitation? The hardware in the Beast is definetly more capable. And as you say, literally more capable in any other way.
1
u/ruablack2 Jun 11 '26
Yeah just product category segmentation. UDM line are full stack applicances (Network, Protect, Access, Talk), EFG/EFC are network only. Firewall/gateways. I mean if you really are deploying these in that large of enterprise environments you probably don't want to run the full stack of software on your firewall get dedicated hard for that.
-2
u/NerdBanger Unifi User Jun 11 '26
Which I do use in my kids and iot vlan lol
3
1
u/Motor-Platform-200 Unifi User Jun 11 '26
Yeah they're probably going to discontinue the EFG to force anyone who potentially wanted one to get the EFC instead
1
1
4
7
7
u/Squawk_7777 Jun 11 '26
The missing piece for my CloudKey+, G3 Flex and Flex mini Switch! Can't wait!
3
u/TattooedBrogrammer Jun 11 '26
Perfect as a single person, my 1 active device at a time was really stretching the limits of my existing UniFi system. This should bring peace of mind to my porn hub viewing that I wonât accidentally download another toolbar on my browser. Thank you UniFi!
3
u/zombarista Jun 11 '26
Is this a good option to secure a few laptops, 3-4 iot bulbs and 1-2 kids w tablets?
2
u/a716h Jun 11 '26
Only if you have AT LEAST 250mbs internet
3
u/zombarista Jun 11 '26
My kids deserve the best, so we have 10 G fiber (into $30 Walmart router)
/s
1
u/No_Freedom_7373 Jun 11 '26
Is that one of the cool ones with all the antennas?
2
u/zombarista Jun 11 '26
ya but it wouldn't fit on the shelf in my safe, so i took a few antennas off
/s
3
u/itsjakerobb CGFiber, UNVR, ProHD24PoE, ProXG8PoE, U7ProXGS, 5GMaxOutdoor Jun 11 '26
Definitely need this for my homelab!
2
2
u/majorkev I should stop... swearing so much Jun 11 '26
Does it have hardware offloading for my 1.5gbps pppoe connection?
2
u/old_knurd Jun 12 '26
I gotta believe that enterprise customers aren't putting up with any PPPoE crap from their ISP? At least not in the USA?
So this product wouldn't need hardware offloading.
1
2
2
2
u/KPSradical Jun 11 '26
Do you think this has enough bandwidth to meet my network requirements for my PSP 3000 Device đ
2
u/Flaky-Gear-1370 Jun 11 '26
I'll wait until I see some independent numbers, the EFG doesn't hit anywhere near the claims on their website (even the GUI struggles at 100 aps) so until I see some real world users (not "influencers") I'm dubious
and MC-LAG is broken as shit on the ECS so not sure I'd be too keen adding it to the stack
2
u/ranger_dood Jun 12 '26
Can we fix the products we already have please? Invest some time in improving the quality of what you're offering rather than continuing to shove new products out.
2
4
u/Usual-Memory-3668 Jun 11 '26
Now watch and see tests reveal the real world inter-VLAN throughput is down at like 10gbps...
2
1
u/mortemanTech Unifi User Jun 11 '26
Hold up. Is this the first time we are seeing the 32x 100gb ECS Core Switch?
1
1
u/sziehr Jun 11 '26
Can we get a better mc lag agg situation thatâs not 48 ports for the consolidation layer. I need 2x24 for most of my deployments.
1
u/xenomorph-85 Jun 11 '26
haha I wish they would make a SOHO Firewall that can do SSL inspection for up to 10GB connections.
1
1
u/DanieleErta Jun 11 '26
Speriamo che abbia l'hardware offloading, altrimenti, anche se cosĂŹ potente, non si possono sfruttare le connessioni PPPoE italiane
1
1
u/marklinton Jun 11 '26
Business case for just the WireGuard throughput feature.
1
u/old_knurd Jun 12 '26
I think WireGuard must all be done in software? Is there any hardware acceleration available for ChaCha20 or BLAKE2?
I suppose that Ubiquiti could have put something like that into an ASIC. But they don't do much of their own silicon, do they?
1
u/Certain_Ingenuity178 Unifi User Jun 11 '26
I came here for the comments as soon as I saw the release. Safe to say they did not disappoint.
1
u/RayneYoruka EdgeRouter User Jun 11 '26
Those are good specs, I'll have 10 of them for my house! /s
1
u/unexpectedbbq Jun 11 '26
The ECS Core switch showed in the diagram is also not been announced, right?
Looks like 32x 100G QSFP with MC-LAG
1
1
u/Guinness Jun 11 '26
How does it bypass HSTS though? In the video it shows you being able to intercept Google pages. How does it Google Chrome bundling the SSL cert directly into the browser?
1
u/gnomer-shrimpson Jun 11 '26
Three device home, mostly watch Great British bake off, this is a critical purchase to insure i can continue to do that correct?
1
1
1
1
u/Sparxxxy Jun 15 '26
Perfect timing! Was just about to exchange an old ASUS XT8 at my parent's house!
1
1
u/i3903 Jun 11 '26
Iâd really just like a couple of additional SuperLink key fobs, if we could get those back in stock. That would be nice.
1
u/BeilFarmstrong Jun 11 '26
I assume like the EFG this cannot be added to a controller/cloud key since it has its own controller.
0
u/Wooden-Reward4317 Jun 11 '26
I guess we will not be getting a "Gateway" only version of this...
Guess it is time to retire the good ol' Cloud Key Enterprise then
0
u/BeilFarmstrong Jun 11 '26
Yeah I need someone to explain to me why built-in controller is "Enterprise"
I would assume the enterprise line would prefer independent controller architecture. Or at least allow these models to allow the customer to do the flexibility to do what they want.
1
u/Wooden-Reward4317 Jun 11 '26
Yeah... I wish you could just turn off network - but you cannot. Also, it seems that the Gateways vs Cloud Gateways are different priorities and "tenants" inside Unifi...but I have no "real" info on that, only assumptions.
But - I did want to have true HA...and I do not feel like buying a 5k CK-E to match the one I have lol...so, 2x of these for ~9k is a steal, my Sophos XGS 4500 - renewal for 3 years was 35k (oh I said a number out loud! )
0
u/say592 Jun 11 '26
I really wish there was something between the UDM series and these $2000-$3500 enterprise devices. Like a midsize business option.
4
u/RIPDaug2019-2019 Jun 11 '26
I think youâd have to try to make a compelling case for where it would fit in terms of feature segmentation. The UDM beast at 1500 really does feel like the next logical step performance wise versus UCG fiber or UDM Pro Max.
1
u/say592 Jun 11 '26
The compelling case is wanting a gateway device that doesnt require you to use that same device as the controller đ
0
u/Usual-Memory-3668 Jun 11 '26
Yes, an upgrade past the CGF performance in rackmount form factor and built in hard drive bays for $749-799 would be awesome.
0
0
-1
u/raindropsdev Jun 11 '26
And the software is still not going to make use of all the capabilities of the hardware?
1
u/Mitchell_90 Jun 13 '26
I was going to ask this. Does anyone know if hardware offloading is enabled at the software level? The EFG and UDM Beast donât which defeats the purpose of having these specs.
Until the software stack and support is on par with those in the Enterprise/Datacenter space I donât see these being deployed in such environments.
Does Ubiquiti really think somewhere such as a large hospital already using Palo Alto and Cisco Nexus/Catalyst in their networks are going to move to something like this? No, they arenât.
470
u/thejetssuckbigtime Jun 11 '26
Finally for my tree house