579
people found this helpful, as of 2023
ranked #28,179 most helpful
out of 571,544,897 reviews
★☆☆☆☆
In 20 years as a network engineer I've never seen such a disaster.
I've come to learn that the name "Security Gateway" is actually intended to be a joke. As soon as you plug this monster into your network it'll start wreaking havoc on all that you hold dear. The reason is because of two very poor decisions on Ubiquiti's part: First, they chip this thing with a static IP of 192.168.1.1. Second, you cannot "adopt" this device because the firmware version is too old and you can't update the firmware without adopting the device!
There are layers of stupid going on here. With it having that fixed IP address, you can't even hope to adopt it without going on a fishing expedition. I really hope you remember the material from your Cisco certification because you're going to need it. Assuming you remember the intricacies of IP subnetting, you can begin creating a virtual NIC and set it to the same subnet as the gateway (192.168.1.0/24). Unfortunately for you, as you're doing that you may notice that all of your other Ubiquiti networking equipment is systematically going offline.
Go ahead and contact support, they'll tell you it's impossible and that you must have something else wrong with your network. But everything was running fine for months until you plugged this little demon in. What's happening is that the USG includes a DHCP server which is up and handing out bogus IP addresses whenever a device goes to renew its lease. Far from being "impossible", it's a very real and very stupid thing to have happen.
The core issue is this ridiculous adoption process that no other vendor seems to require. Somehow Cisco and Juniper have managed to stumble along for the last couple of decades without such a concept. I wonder why... Some potential fixes for this issue are: have the adoption process (if it must exist) use multicast for device discovery and provisioning, or do not require adoption for the USG (if it's a Genesis problem), or use some other non-IP means (e.g. IPMI) to conduct the adoption and initial provisioning. Then of course the easy answer which won't work for everybody is to simply ship the thing with DHCP client enabled. Customers without a DHCP server will be stuck out. But in that case, just include one in the controller specifically for handling this case. Maybe style it as a wizard or something so it can't get messed up an the DHCP server and whatever other resources can be assured to be disabled and cleaned up once the adoption process is complete. But for the love of god do something. The way it ships now is completely unacceptable.
Most importantly, DO NOT PLUG THIS INTO A FUNCTIONING NETWORK or it won't function for very long. If you really have to get one of these, attach it to a physically isolated network, your uplink, and just a single multi-homed computer running the controller (or a cloud key). That way, the USG is isolated so it can't overrun your other DHCP server and take the network down by handing out bogus addresses. You should be assigned an address via DHCP by the USG so that you'll be able to "see" it and hopefully update the firmware and finally adopt it. How you ever regain confidence in Ubiquiti's products ever again? I have no idea.
April 2019 · Electronics · verified purchase