cross-posted from: https://lemmy.world/post/21641378

So I just added a TP-Link switch (TL-SG3428X) and access point (EAP670) to my network, using OPNSense for routing, and was previously using a TP-Link SX-3008F switch as an aggregate (which I no longer need). I’m still within the return window for the new switch and access point, and have to admit the sale prices were my main reason with going for these items. I understand there have been recent articles mentioning TP-Link and security risks, so I’m thinking if I should consider returning these, and upping my budget to go for ubiquity? The AP would only be like $30 more for an equivalent, so that’s negligible, but a switch that meets my needs is about 1.6x more, however still only has 2 SFP+ ports, while I need 3 at absolute minimum.

I’m generally happy with the performance, however there is a really annoying bug where if I reboot a device, the switch drops down to 1G speed instead of 10G, and I have to tinker with the settings or reboot the switch to get 10G working again. This is true for the OPNSense uplink, my NAS and workstation. Same thing happened with the 3008F, and support threads on the forums have not been helpful.

In any case, any opinions of switching to ubiquity would be worth it?

2 points

I may be wrong here but the tp link issues were in the more consumer based hardware and not the eap and switch

permalink
report
reply
2 points

From what I’ve seen it seems consumer routers, but it raises flags is all, and makes me reconsider options.

permalink
report
parent
reply
6 points

Every network manufacturer has had some CVE for something.

permalink
report
parent
reply
1 point

Fair enough. Is there anything one can do to mitigate? Like I know for the recent issue in the news, a mitigation strategy for consumers is to basically reboot their router often. I keep my router and all hardware up to date, and try to follow news here. Not sure if there is really anything else I could do.

permalink
report
parent
reply
-4 points

Ubiquiti?

You can’t give me that garbage. I despise it, after setting up a single access point (plus also watching friends deal with it at client sites).

Besides the discovery issues and slow performance when trying to manage it, I had a random open network on it after setup. This network didn’t appear anywhere in the control panel. I could turn off the access point and the network disappeared.

It didn’t show up in the guest network config (which was turned off anyway). It had the same name as the WPA-protected network, it was just open - no security at all.

I had to reset the access point to get rid of this weird random open network.

What kind of garbage product does that?

Now let’s look at cloud keys. One has a hard drive in it. Just one drive, 3.5", which besides storing data also stores the OS. What? Why is the OS not on some firmware or at least an M2, since the drive is really for storing surveillance data (did I mention it’s a single drive?), what a joke. Why would I bother with such an expensive device that has zero fault tolerance, when I could simply buy a cheaper real machine, run multiple drives, and host the software there?

I lack the vocabulary to describe how bad Unifi is.

permalink
report
reply
8 points

Unifi + OpenWRT goes hard tho

permalink
report
parent
reply
1 point

Oh wow, hard to believe a huge bug like that would make it to production. What do you recommend instead? Stick with TP-Link?

permalink
report
parent
reply
12 points
*

Ubiquity is trash with fickle support based on the whims of what sells wide adoption. TP Link IMO is a decent value for the money if you want easy “prosumer” level networking gear. I have I have 3 TP Link APs as well as a 16 port 10g core switch and its great for my needs.

Mikrotik offers more features per $$ but its not as easy to use.

permalink
report
reply
-6 points

everything has trackers, even those APs or wifi routers flashed with 3rd party firmware (openwrt, ddwrt, etc). If OP is willing to spend time on doing packet tracing or even the most simple one like a setting up a localized dns server/sinkhole, OP might be amazed what lights up.

permalink
report
reply
2 points

You can try seeing if you can set the speed/duplex of NIC/ports manually if auto-detection keeps getting it wrong.

Unifi I like the APs for mesh & multiple SSID+vlans but I keep them on dedicated vlan with zero internet access because I don’t trust that I properly followed instructions to disable opted in analytics/telemetry. The mgmt software is alright but new UI wastes a lot of space. The PoE switch was alright until it stopped being able to keep a config last year. USG router I kept less than a year because it was too slow with any useful features enabled. I’ve glanced around at replacement APs here & there but pretty much waiting until I have more wifi 7 compatible devices and that’ll be another couple years.

permalink
report
reply
1 point

I actually tried this as my second step in trouble shooting, the first being using different ports.

In the non-omada management software, it defaults to 10G, and if the devices is on before the switch it negotiates 10G correctly and works at full speed (tested with iperf3). As soon as any of the 10G connected devices is rebooted, I’m back to 1G. To fix it, I then have to set the port to 1G with flow control on, apply changes, save config, refresh page, change to 10G with flow control off, apply, save config and it goes back to 10G again. Alternatively I can reboot their switch and it’s fine again.

In Omada its the same, fewer steps to get there but I have to sometimes do it 2-3 times before it works.

Same issue with both 10G TP-Link switches, so I’m thinking it might be the SFP. Using Intel SFP+ with FS optical cables. I’m using a DAC for the uplink from the 10G switch to my unmanaged 2.5G switch, and that doesn’t have the problem of dropping, always works max speed.

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 4.8K

    Monthly active users

  • 3.6K

    Posts

  • 77K

    Comments