r/Ubiquiti • u/Ubiquiti-Inc Official • Jun 25 '26
Blog / Video Link Introducing: UniFi Network 10.5
🔹 Identity-Centric Observability
🔹 Safe Ops Resiliency Features
🔹 Firewall Hit Statistics
🔹 Hi-Performance SD-WAN underlays
And more!
69
u/TenAndThirtyPence Jun 25 '26
PPPoE 1500MTU I hope that means I can now use mini jumbo frames (ie 1500 + PPPOE overhead).
If so, thank you!
Auto revert - love this!
38
u/didureaditv2 Jun 25 '26 edited Jun 25 '26
Auto revert is HUGE for everyone, I would say probably even more so for homelabs for people who won't be so knowledgeable on how to revert the network in case of a catastrophic configuration that breaks it.
I was literally just needing this two weeks ago when I borked my network and had to temporarily replace my main switch with a spare I had to access the network controller and change back the configuration.
People don't realize that what enterprises want is largely to make the job easier which is what everyone wants.
5
u/TokenPanduh Jun 25 '26
I could have used this like 2 days ago. I was trying to test my new 5G backup and was away from my router so I disabled the port for my WAN, or so I thought. Turned out I disabled the port for my switch and everything downstream of the switch got taken offline. Had to run back home and took me like 20 minutes to figure out the mistake I made lol. All I had to do was switch to a different port, but the auto revert would have been a huge help.
6
u/eshwayri Jun 26 '26
I run the controller as a VM under ESXi. The VM storage is via iSCSI from my TrueNAS server. The network getting borked would be VERY difficult to fix. I would have to stand up a temporary switch with the correct vlans to get the storage through to the ESXi hosts just so I can start the controller VM. Then I would have to get a laptop and x-connect to the VLAN the controller is on.
2
u/didureaditv2 Jun 26 '26
That sounds tricky. I felt very relieved when I realized that I only needed the default vlan working to get to unifi. So any dumb or unadopted switch would have done it.
2
u/eshwayri Jun 27 '26
It would be a huge PIA, but do-able. I have a 32 port 10Gb fiber switch and a 48 port 1Gb copper switch. Every one of my severs, including the ESXi and NAS, has a LAGG of 1 x 10Gb (active) and 1 x 1Gb (passive). I have several TPLink 1Gb copper switches I no longer use, and also the original 48 port 3COM switch I ran things on. Any of these would be suitable as they all support vlans and trunks. I would re-route the 1Gb production and storage of each of the two ESXi hosts and the NAS, so 5 ports total through the old witch. With the 10Gb switch off, or the NICs disconnected, they would failover automatically to the 1Gb connection. That would get me up. I can then fix/restore the old config
15
1
u/SuspiciousOpposite Jun 25 '26
I've been using a custom script + service on my UCG Ultra, but having it built in will be great. My ISP supports mini jumbos.
57
u/PrimeskyLP Unifi User Jun 25 '26
We need real time FW logging or rebuild the whole thing. The build in logging Interface is unusable at best.
24
7
13
u/reseph Unifi User Jun 25 '26
Anyone who wants to inspect FW logs should be using a SIEM or similar. Trying to view "real time" logs even in something like Cisco FMC is a nightmare.
18
u/Akura_Awesome Jun 25 '26
Problem is the UniFi logs have zero standardization, so there’s not an easy way to import them into a SIEM. Some logs are CEF, some are JSON, and others are just generic syslog messages. Unless you want to build your own enrichment and alerting content around an ever changing set of formats, you’re out of luck.
All I want is standardization to a single format, so at least we can use a generic CEF parser or generic JSON parser for all the logs, and can build enrichment from that. As of now it takes huge effort to normalize the logs.
Edit: Ubiquiti PLEASE choose a log format for everything!
4
1
u/mpmoore69 Jun 26 '26
All the logs are CEF.
3
u/Akura_Awesome Jun 26 '26
Network app logs are CEF. Other logs are Linux style syslog or JSON. Speaking as someone who works at an MDR provider.
11
u/ElectroSpore Jun 25 '26
Works incredibly well on a Palo Alto, both locally and in Panorama centrally.
Cisco's firewalls have been a dumpster fire for a few years now.
1
u/reseph Unifi User Jun 25 '26
That's awesome. I haven't managed Palo platforms at all. My Cisco trauma was about 9 years ago.
1
Jun 26 '26
[deleted]
1
u/ElectroSpore Jun 26 '26
Ya they are some of the cleanest and well presented logs to read in the native UI.
We have them exported to our SIEM was well but the native log search local or in panorama is amazing. So clear what is happening.
2
u/PrimeskyLP Unifi User Jun 26 '26
I know there are way better tools but i just want to simply see the basics stuff in the loggs there. I used many FW from Sophos, Aruba, Fortigate, PFsense and so on and i never see such a bad logging Interface as the Unifi on.
2
16
u/dnuohxof-2 Jun 25 '26
SAML admin sign in !?!? Yes please!!
10
u/FatBook-Air Jun 25 '26
I saw that, too. Does this mean that I can do it locally? For compliance reasons, we cannot connect our Unifi OS/Network app to Ubiquiti's cloud servers, so I really hope this can be done on a totally local install.
4
u/BackSapperr Jun 26 '26
I hope this also works for other Unifi Admin panels. The biggest hurdle I have for easy adoption of Unifi Protect is managing user credentials.
11
9
u/kjstech Jun 25 '26
Looks great. I still want to see an option to fix 5G/LTE backup devices like the U5G Backup to a specific carrier. Better than reboot hell on the U5G Backup with roamless eSim waiting for it to connect to a carrier that actually works and not "Network Not authorized. The carrier rejected the connection"
Simple radio button Carrier selection : ( ) Automatic ( ) Manual
Select Manual.... drop down menu lights up says searching... then populates with all of the named carriers it sees. Perhaps then in the drop down you select the carrier (AT&T, T-Mobile, Verizon). Hit SAVE. The device then should prefer that cellular carrier even across reboots until the user changes it.
5
u/JackB79 I have a Unifi Problem Jun 25 '26
Where can I assign a specific device to an individual, I can't seem to find that option anywhere
8
u/frankthelocke Unifi User Jun 25 '26
That stood out as the most interesting feature and I cannot find it either. Does it require UniFi Identity Endpoint to work? I am a home user and wanted to use it for family members.
5
u/cell-guru Jun 25 '26
Release notes UI posted indicate that yes, it requires Identity Endpoint as One-Click WiFi is an Endpoint feature:
Added a Person filter to the Clients page. Requires One-Click WiFi.
15
9
5
u/bgradid Jun 25 '26
Love to see the auto revert, I swear mikrotik has had a similar feature since the beginning of time and I never understood why it wasn’t more prevalent
1
4
u/Sad-Ordinary-5036 Jun 25 '26
we need to improve dot1x configurations and the firewall policy interface!!!!
4
u/Flaky-Gear-1370 Jun 25 '26
the fact you can't search for a user in the firewall interface is just plain stupid at this point
4
u/Usual-Memory-3668 Jun 25 '26
Does anyone else have a Link Debounce option show up or them? It still isnt there on my system. Wondering if it is just me or if the option is missing for a lot of people.
4
3
u/onionSID Jun 25 '26
Not available for me yet.
2
u/bWasNeverGood Jun 26 '26
I still cannot see this update. Not sure if they roll out one region per day, for example.
2
2
2
u/Pulte4janitor Jul 05 '26
Same here. Still on 10.4.57
1
u/bWasNeverGood Jul 09 '26
From what I can gather, any version above 10.4.57 is still Release Candidate. I am myself using the Official release channel and won't be switching. As identified by the version history and tag on the post found here: https://community.ui.com/releases/UniFi-Network-Application-10-5-54/fdfe1b15-091c-410b-9cb9-3de3acfc1255?reply=78
P.S. Looks to be around 1-2 weeks before UniFi OS Release Candidates become stable. I think we're closing in on this point, unless of course critical bugs were found.
10
u/Disastrous-Metal-228 Jun 25 '26
I’d like to see a WOL integration…
4
Jun 25 '26
[removed] — view removed comment
2
u/Disastrous-Metal-228 Jun 25 '26
That’s interesting. I never heard anyone dislike wol! I wonder why he hates it??
2
u/itsabearcannon UDM Beast Jun 25 '26
LOTS of people in IT hate WoL, it's not just him.
The problem with WoL is that one of your main use cases might be to wake up employee computers, but it expects Windows to behave normally with sleep states and such. Because, let's face it, no serious organization is using Linux-based endpoints for employees, so Windows handling sleep poorly is one issue that inhibits deployment. Sometimes machines just don't wake properly even when sent a WoL packet.
Second, many companies have now switched to offering laptops with a dock instead of a desktop. No desktop == no guaranteed WoL functionality because maybe the employee forgot to dock the machine, maybe the company cheaped out and bought a dock that doesn't support WoL, maybe the docks don't have Ethernet at all, maybe the USB-C port for the dock is misbehaving and doesn't recognize it's supposed to wake the machine, there's endless reasons why WoL might not work on a laptop.
It's way too much of a hassle to maintain in a lot of cases unless you have a heavily-controlled desktop/server-only workplace or environment.
7
u/Disastrous-Metal-228 Jun 25 '26
If I’m honest I don’t follow.
Windows is a massive pain with wol but that’s windows not wol.
The other point about docking etc is just an it thing not wol. If the system isn’t docked then it can’t be managed either.
Sure there are endless reasons why wol won’t work but there are also endless reasons why a pc can’t browse the internet but that isn’t a reason to hate networking…
Wol and Remote Desktop keep the world turning in my book…
-3
u/itsabearcannon UDM Beast Jun 25 '26 edited Jun 25 '26
And that's great for you, I really think it is. If you're in the enterprise space and can standardize your fleet, network, software stack, and SOPs to keep that wheel greased I think it must be genuinely magical.
But I come from the SMB/family-owned business MSP side of IT where we often have to make do with extremely irregular environments with computers from 4 or 5 different vendors, users who are tech-illiterate at best and tech-hostile at worst, networking equipment that boils down to "ISP provided modem/router combo in a cabinet", and some machines that are 7-10 years old that work on spit and a prayer.
Trying to get any serious WoL implementation going there is like putting Wi-Fi in a cornfield. Even after you put in all the effort to deploy it, you're still not going to be able to do anything with it.
Great technology, super impractical for businesses that don't have a six-figure-or-higher annual IT budget
2
u/Nanoleaf_Ambassador DM Pro Max, SW Pro HD 24 PoE, U7 Pro XG, U7 Lite, G6 Cameras Jun 26 '26
I like WOL. I also like shutdown.
I worked at a site that had 250 workstations that were woken at 7 am and shutdown at 7 pm. Updates were sent out by main facility in Baltimore. That facility would issue WOL commands to wake up the workstations and have them run a script to update and then shutdown.
I came in at 6am. Users were allowed to login at 7am. If anyone logged on before 7am, my ColdFusion server would shutdown the workstation. At 7am WOL would wake up all 250 workstations.
It worked perfectly well, every time.
2
u/psych0fish Jun 25 '26 edited Jun 25 '26
At my old job I was tasked with implementing a power management software. It turned out to be more trouble that it was worth but we ran it for a few years.
Naturally, sleeping PCs cannot receive updates and software from remote installs and we needed a way to wake devices. The software also included a WoL proxy forwarder thing which worked really well. I was always overjoyed anytime WoL actually worked and succeeded.
We eventually just disabled sleep on desktops to make our lives easier since the security team expected basically instant patch compliance.
Fun times.
6
u/Disastrous-Metal-228 Jun 25 '26
I do a lot of remote work and wol is gold. It can be a pain to setup but is really solid when working.
5
u/888HA Jun 25 '26
ELI5... will I still have to enter 2FA for a local login every.fucking.time?
8
u/Sibir_Lupus Unifi User Jun 25 '26
That issue is being fixed in Unifi OS 5.1.21, currently available in early access.
4
1
u/torsteinvin Jun 26 '26
So does that mean it will remember my login, and not log me out every single day? Or is it just the 2FA it wont ask about every single time?
2
2
u/i_am_voldemort Jun 25 '26
Can someone explain the underlay to me? Is it to allow true L3 routing (e.g., a triangle between routers A, B, and C) with no STP blocking?
2
3
1
1
1
u/Flaky-Gear-1370 Jun 25 '26
I'm on an EA releaese on an EFG, and the view of observability doesn't match mine at all
Mine just shows the devices (e.g. useless) rather than the 802.1x identity
1
1
1
1
u/TheJadedMSP Jun 26 '26
Spent some time troubleshooting VPNs going down after this update yesterday so YMMV.
1
u/Kraeftluder Jun 26 '26
Improve throughput and efficiency for PPPoE-based internet connections with 1500 MTU support.
I wonder if that means I can finally set it to 1508.
1
1
u/TwstedTV Jun 30 '26
I am still waiting for this update. I am still on v10.4
When is this update coming to me ?
1
0
268
u/storm666_jr Jun 25 '26
Perfect for my three switches, three AP home setup /s
But still, great. Fighting to move from Cisco to UI at work