New Idea

Please publish SNMP MIBs

Submitted by -
Status: New Idea

EdgeSwitches currently support/use several standard MIBs, however there are some OIDs that are unique/proprietary to EdgeSwitches and are not defined elsewhere.

 

Observium and others apparently have obtained a set of EdgeSwitch MIBs, included as part of their (3rd-party) monitoring solution distributions but not otherwise available from UBNT directly.  The last count has almost 40 separate MIB files for EdgeSwitches.

 

There are now a pair of UniFi MIBs available and referenced in the release notes for current releases, but there do not seem to be any other MIBs available.

 

It seems most are searching for and using these 3rd-party references, but ideally UBNT should be providing these directly.  Perhaps another section on the product download pages for 'SNMP MIBS" in addition to the existing "Firmware" and "Documentation" sections could be added with this content?

 

Send DPI statistics to UniFi controller.

Submitted by -
Status: New Idea

Please allow for DPI data to be sent to the UniFi controller. I do not need to be able to make any changes from UniFi. I would just like to populate DPI statistics.

Request: update Strongswan (IPSEC) and OpenVPN versions on Edgerouter

Submitted by -
Status: New Idea

When the next update for the ERL is prepared:

  1. Please add the newer version of Strongswan than 5.3.2 (preferably the current release 5.5.1). the currently included version in the ERL (5.2.2) does not play nice with IOS. Dead Peer Detection and MOBIKE lead to dropped connections. (https://wiki.strongswan.org/issues/2126).
  2. Please update the OpenVPN version as the current server only supports TLS 1.0)

it should not be too dificult as these updated packages are already avaialble for Debian..

 

Thanks

Redundant power supply on EdgeRouter Pro series

Submitted by -
Status: New Idea

Hi,

EdgeRouter Pro can and are often used as mission-critical routers in networks. It is a nice piece of hardware and the software make it a very viable alternative. It would be great to make the next generation of EdgeRouter Pro series power-redundant, so they can be connected to two power feeds at the same time.

This will help design fully-redundant networks, with both failure tolerance in case of one internal PSU failure as well as redundant and avoid SPoF design from a power perspective.

 

Many thanks and keep up the good work!

SSL certs from https://letsencrypt.org

Submitted by -
Status: New Idea

I really would liek to see the end of Self-signed certs and implemnetion of https://letsencrypt.org for EdgeOS.

This would be great move in right direction for out of the box SSL.

 

Command Abbreviation

Submitted by - a month ago
Status: New Idea

This seems to be something that VyOS already has

 

For example, I would like to be able to run stuff like this:

conf

ed int eth eth1

set add 192.168.1.1/24

PPPoE uptime

Submitted by -
Status: New Idea

Would be nice to be able to see the PPPoE connection uptime.  My old router running OpenWRT/LEDE firmware had this implemented.  Any word on when we could see this on the EdgeOS platform?

 

New to this forum and I believe I posted in the wrong place originally.

 

HERE is my original post with some progress on a simple PPPoE uptime script.

 

 

Edgerouter Centralized Management Console

Submitted by -
Status: New Idea

It would be nice to see something like AirControl or UniFi for managing / viewing multiple edge routers (centralized configuration backups, mass firmware updates, etc). Anything like this in the works? Maybe call it EdgeControl and mimic the functionality of AirControl?

Ethernet Port negotiation

Submitted by - 2 weeks ago
Status: New Idea

 

Could there be a "1000m/full duplex" option?

 

When connecting to AT&T they ask that it not be on Auto, but a fixed speed

Let's Encrypt for Web UI

Submitted by -
Status: Duplicate

I'd love it if:

 

    1) The router has a valid hostname and

    2) $hostname:{80|443} reaches the device

 

the device would (automatically) reach out and and obtain a Let's Encrypt certificate for the Web UI. (Note: Let's Encrypt is 100% free so it would not cost the operator anything.)

 

DNS mode (manual) would be a handy backup as well

Hardware Offloading on ER-X(-SFP)

Submitted by -
Status: Implemented

To increase the throughput add hardware offload support to ER-X(-SFP) for NAT, PPPoE and VLAN. I think the SoC supports this and there is only a driver needed. 

Intrusion Prevention/Detecton

Submitted by -
Status: New Idea

It would be nice if we had a IDS system for EdgeMax ...

IGMP Snooping

Submitted by -
Status: New Idea

IGMP Snooping would be nice in EdgeMAX (ER-X-SFP) since it's mandotary for many IPTV implementations to work (for example Swedens biggest ISP / IPTV provider, Bredbandsbolaget).

Zone Policy (GUI)

Submitted by -
Status: New Idea

I did a quick search and didn't find this suggestion already, but please pardon me if it already exists.

 

I would like to see the ability to create and manage Zone Policies within the GUI.

Additional Network Services: NTP and Radius Servers

Submitted by -
Status: New Idea

I'd really love to see an NTP server built into the EdgeMax router software. I currently syncronise my router to a Stratum 1 server and would like the ability to create a "local" Stratum 2 server for all client devices.

 

In addition, I'd love the option of a Radius server built into the router to handle 802.1X authentication without having to rely on a Windows server for such a basic task.

GUI for OpenVpn

Submitted by -
Status: New Idea

GUI for simple setup of OpenVpn Server mode would be great. Nothing fancy, just similar to what DD-WRT support today. Ideally, L2TP, PPTP and SSTP with local users support. This will be great for SOHO. 

10, 30, 60 minute graphs

Submitted by -
Status: New Idea

For cpu and RAM, and interfaces

IPv6 Support in Management GUI Interface

Submitted by -
Status: New Idea

In 2013, there have been an increase in IPv6 deployments by ISPs globally. In the country where I resides in, all FTTH (Fiber-to-the-Home) ISPs/RSPs have deployed IPv6.

I believe it is becoming more and more important for routers to support IPv6, and likely to be essential in 2014. I would like to strongly suggest and request Ubiquiti team to look into having IPv6 Support in GUI as part of the 2014 roadmap.


EdgeMax Router Lite and POE are great routers in terms of performance and affordability. It is a pity that the shortfalls in GUI is keeping some not-as-savvy (knowledgeable but not good with CLIs) consumers away.

Firewall/NAT - Group handling compared to Cisco

Submitted by -
Status: New Idea

There are a couple of issues I have with the way EdgeOS handles groups. My company uses both EdgeRouters and Cisco ASA devices. Cisco seems way more advanced in group handling compared to EdgeOS. You can specify single host devices, subnets and ranges. Whenever something in the network changes, be it subnets, host IPs or whatever, I almost never touch the firewall / NAT rules manually on Cisco devices. The only thing I do is modifying a subnet object or a host object - rules where these object are used, will be updated automatically. Sometimes I edit a rule and simply add or remove a new/old object with very few clicks because Cisco allows multiple selections. EdgeOS is different and groups in EdgeOS are not quite the same as network objects in Cisco environments.

 

 

First and foremost there is nothing like a single host object in EdgeOS. Address groups are .. well groups and can't be entered as translation target in a nat rule or similar even if the adress group contains only a single IP. As soon as a server is moved in the network, one would have to modify each and every rule where the server is used - manually, because the translation address is an IP, not a variable like a Cisco host object.

 

Second is that it's not allowed to select multiple groups (e.g. network groups). It's a single drop down list and as soon as a rule has to match more than one group, the rule has to be copied and modified to match every network group. Cisco can have several network groups in one rule. Yes, I could create a big network group containing all subnets in the other groups, but then it's unwanted redundancy again. As soon as one subnet changes, one would have to modify both the original network group and every other group where this subnet is being used. Nesting groups could be a solution, like a parent group containing several network groups - one change would be adopted by all groups where this specific sub-group is used.

 

Third: When doing a DNAT with subnets (e.g. 192.168.2.0/24 to 192.168.1.0/24) I can't select a network group as translation target as discussed above. But I can't even use a network group (with a single subnet in it) as destination match either. EdgeOS tells me to explicetly use destination subnets when translation to another subnet. Again, hardcoded IP addresses/subnets contrary to Cisco simply using a subnet object.

 

 

Most of the time it's no big deal to do the changes manually. But there is always the risk of a typo or simply missed rules. When firewall and nat rules are configured with subnet and host objects like Cisco does, then it's just a matter to change this object ONCE. In EdgeOS you might have to touch each and every rule as "groups" aren't allowed or can't be used in some situations.

 

 

Even though Cisco isn't beyond all doubt either, there's a lot Ubiquiti can learn of.

 

To use EdgeRouters in my company was my idea because they are a affordable and highly reliable. My colleagues at our headquarters were suspicous when I introduced them to the ER. The HQ uses Cisco only (money doesn't matter) but they were quite impressed of the capabilities of this nice piece of hardware and started to use it in small applications as well. Anyways, the GUI seems underwhelming and lacks lots of advanced functions that make things easier to handle. Unfortunately the above issues can't be solved via CLI either, same restrictions.

Well, at least Ubiquiti added the group names to the NAT overview since v1.7 or v1.8 I think, in v1.6 nothing was shown in the rule header when a group was used and that was a real pain in the ..... with lots of NAT rules without any source/destination shown..

 

Maybe Ubiquiti reconsiders the groups and gets some inspiration from my request.

 

 

Network Health of edgemax router in Unifi controller

Submitted by -
Status: New Idea

For a lot of customers we use the security gateway for some basic network setup. The main reason we choose for the SGW is because we can easily monitor the connection with a remote hosted unifi controller.

 

Now that the ER-X-SFP is here we would love to use that device to power the AP's at our customers.

Is it possible to add the posibility to register an edgemax router with the unifi controller to show up in the Network Health of the unifi controller. Preferrable with the speedtest function.