Help me plan/ budget for a network upgrade

Kartajan

Golden Member
Feb 26, 2001
1,264
38
91
I currently have a functional home network, but I feel that both performance and security are.... lacking. I have a "ATT GigaPower 1000Mbps internet connection" but am only averaging 500/250 (915/250 within the ATT network) on my hardwired devices.
I have my Asus RT-AC68R doing most of the "security" part, with software based anti-malware running on endpoint PC's (All Win10 machines).

My thought is to plan out for a "single pane of glass" setup, possibly "Ubiquity" driven.

initial thoughts:
1x USG-PRO-4 to replace the AC-68R for routing/ DHCP/ Security
1x ES-24-LITE to replace the 16 port TP-Link (to add link aggregation functionality)
2x UAP-AC-Lite to replace the wifi on the AC68R/ EX6100 access point
1x "Cloud Key" to manage

I am open to suggestions/ input on if my thinking is off, I just want to gain better performance and security at a somewhat reasonable cost.
Revised_Network_Map.jpg
 

boomhower

Diamond Member
Sep 13, 2007
7,228
19
81
I'd consider replacing the edge router with a unifi router so you can manage it all from the same interface. You could save some money going with just the USG rather than the Pro.
 

ch33zw1z

Lifer
Nov 4, 2004
37,763
18,039
146
Last post in that thread is a while ago?

Wonder how's it doing now. The US is very tempting to replace my er-x with. I would like the DPI feature
 

sdifox

No Lifer
Sep 30, 2005
94,995
15,119
126
Last post in that thread is a while ago?

Wonder how's it doing now. The US is very tempting to replace my er-x with. I would like the DPI feature

Shipped over two years ago and still no full gui exposure to config? That is two life times in computer hardware.
 

ch33zw1z

Lifer
Nov 4, 2004
37,763
18,039
146
Good things come to those who wait? lol...

Seriously though, if a GUI is required, then the ER series may be better. The ER-Lite DataSheet shows 1mil PPS, like the USG, compared to the ER-X 130kpps
 

sdifox

No Lifer
Sep 30, 2005
94,995
15,119
126
Good things come to those who wait? lol...

Seriously though, if a GUI is required, then the ER series may be better. The ER-Lite DataSheet shows 1mil PPS, like the USG, compared to the ER-X 130kpps
Cli and json is fine for corp environment, but opbis a home user so he has to be aware of it. That is all.
 

kevnich2

Platinum Member
Apr 10, 2004
2,465
8
76
Shipped over two years ago and still no full gui exposure to config? That is two life times in computer hardware.

The USG is actually perfect for home users. There is no gui except through the unifi pane of glass but that's the entire intent. You gain A LOT of visibility into the traffic in your network and going to the internet with the USG. I have more advanced needs so I run a pfsense myself but have began considering the USG simply for the DPI features but until they have more advanced features that I need exposed through the unifi control panel, I can't use it yet. I do use the USG for my lab network though.

The edgerouter, however, is more geared towards business and enterprise users. Excellent device but you gain more control by getting very used to the CLI.
 

sdifox

No Lifer
Sep 30, 2005
94,995
15,119
126
The USG is actually perfect for home users. There is no gui except through the unifi pane of glass but that's the entire intent. You gain A LOT of visibility into the traffic in your network and going to the internet with the USG. I have more advanced needs so I run a pfsense myself but have began considering the USG simply for the DPI features but until they have more advanced features that I need exposed through the unifi control panel, I can't use it yet. I do use the USG for my lab network though.

The edgerouter, however, is more geared towards business and enterprise users. Excellent device but you gain more control by getting very used to the CLI.

How is the dpi in pfsense? I just doing basic firewall with mine.
 

kevnich2

Platinum Member
Apr 10, 2004
2,465
8
76
How is the dpi in pfsense? I just doing basic firewall with mine.
It's actually not bad, but not NEARLY as clean on the front page as it is in unifi dashboard. There's lots of add in packages for pfsense and likely I'm just missing one that would work for this but I don't have the time to go through every single package and test them all out yet.
 

sdifox

No Lifer
Sep 30, 2005
94,995
15,119
126
It's actually not bad, but not NEARLY as clean on the front page as it is in unifi dashboard. There's lots of add in packages for pfsense and likely I'm just missing one that would work for this but I don't have the time to go through every single package and test them all out yet.
Peril of open sorce, too many variants.