UniFi Dream Machine Pro Review

Published:
Last Updated: Oct 27, 2020

Written by

Ubiquiti’s UniFi Dream Machine Pro (UDM Pro) is an incredibly versatile all-in-one security gateway and network appliance that I recently upgraded to from the entry-level UniFi Dream Machine (UDM). In this review, I’ll share with you why I decided to upgrade and how I migrated the controller configuration from the UDM to the UDM Pro.

Additionally, the new UDM Pro also replaced my UniFi Cloud Key Gen 2 that I used in combination with UniFi Protect, the company’s video surveillance system. So I’ll talk about that change as well.

If you’re contemplating purchasing the UDM, the UDM Pro or the new UniFi Security Gateway Pro 4 (USG Pro 4), but aren’t entirely certain which option is best, scroll down to my comparison of these entirely different devices.

UniFi Dream Machine Pro

Michael Kummer

UniFi Dream Machine Pro Review
Features
Hardware
Performance
Ease of Use
Value

Summary

I’m incredibly happy with my UDM Pro because I love its simplicity. Plus, the UDM Pro helped me consolidate my networking infrastructure while making it more capable and powerful at the same time.

4.9

Pros

  • Combines multiple appliances into one
  • Easy to set up and configure
  • Great value
  • Incredibly powerful hardware

Cons

  • No Power over Ethernet (PoE) ports

UDM Pro Review

How I deployed UniFi in our home (video)
How I deployed UniFi in our home (video)

What’s so cool about the UDM Pro is that it combines many features into a unified appliance, thus allowing you to consolidate your networking infrastructure.

Here are some of the highlights of the UDM Pro:

  • Ethernet router and advanced firewall (including IDS, IPS and DPI).
  • Eight-port gigabit switch.
  • Dual WAN ports for redundancy.
  • Two 10 Gbit SFP+ ports.
  • UniFi Controller, Protect, Access and Talk.

The only thing it doesn’t have is a built-in Wi-Fi radio, because that wouldn’t make any sense considering that the UDM Pro is meant to be mounted in a rack and the metal cage would interfere with the radio signal.

UniFi Dream Machine Pro in my rack
UniFi Dream Machine Pro in my rack.

So, who is the UDM Pro for? 

I think the UDM Pro is the perfect all-in-one appliance for small or medium businesses and “prosumers” who want more control and flexibility over their networking infrastructure. As I mentioned in the beginning of this article, I chose the UDM Pro because I wanted to consolidate my infrastructure. 

Also, I didn’t need (or want) a wireless access point (aka the UDM) inside of my network rack. But even if I was just getting started with UniFi, I’d probably buy the UDM Pro and make it my network’s command center.

Technical Specifications

An 8-port UniFi switch provides power over ethernet
The UDM Pro doesn’t have any PoE ports. That’s why I’m keeping this eight-port switch around.

The UDM Pro is a fairly powerful appliance that should be able to handle all of your networking needs and then some. Below is a table with the most important specifications.

Specifications
CPUQuad-core ARM Cortex-A57 at 1.7 GHz
RAM4 GB DDR4
WAN ports(1) 10/100/1000 RJ45 WAN port(1) 1/10G SFP+ WAN port
LAN ports(8) 10/100/1000 RJ45 LAN ports(1) 1/10G SFP+ LAN port
IDS/IPS throughput3.5 Gbps
NVR storage3.5″ HDD Bay (2.5″ HDD also supported)
Power supplyRedundant (support for PSU failover)
UDM Pro technical specifications.

One of the things I didn’t like about the old UniFi Security Gateway (USG) was its comparatively weak CPU, which didn’t allow the intrusion detection system (IDS) and intrusion prevention system (IPS) to operate without significantly reducing network throughput. 

For example, with IDS/IDP enabled on the USG, I got speeds of less than 100 Mbits — just a tenth of what my ISP supports.

The UDM Pro, on the other hand, supports up to 3.5 Gbps — more than enough for my requirements.

I also appreciate the redundant WAN ports and power supply, even if I’m not leveraging those at the moment.

Last but not least, I like that I can simply stick a 4 TB hard disk into the appliance to store all of the video footage my cameras record.

Security Features

UDM Pro Threat Management (IDS)
UDM Pro Threat Management (IDS).

I have over 50 devices connected to my network, most of which exchange data with services on the internet. Most of these devices are a black box to me; I have no clue how they’re doing what they’re doing.

I don’t even know if they use SSL or other security protocols for their data and my network.

That’s why I appreciate the fact that the UDM Pro has some great security features built into the appliance, including:

  1. DNS content filtering
  2. Endpoint scanning
  3. GeoIP filtering
  4. Honeypot
  5. Threat management

I currently use threat management to alert me to any potential security issues. You can also have those threats automatically blocked, but I decided to get alerts only.

I also use the endpoint or network scanner to automatically monitor all connected endpoints for potential security issues. 

The honey pot acts as an attractive target for malware, worms and other malicious traffic by simulating vulnerabilities.

I have also played with DNS content filtering, but noticed that it blocked some of the affiliate portals I was using. While allowing individual domains by adding them to a whitelist can be done quickly, I decided to disable that feature until I got a chance to do just that.

GeoIP filtering is also an interesting feature, but I couldn’t get it to work in Chrome or Safari on macOS. 

Price

Despite all of the features that UniFi managed to pack into the UDM Pro, the appliance is surprisingly affordable. 

As of this writing, the UDM Pro sells for $379.00 when you buy it directly from UniFi. You can also get it on Amazon*, but often at a higher price.

Buy Direct

UniFi Dream Machine Pro vs. UniFi Dream Machine

The UDM Pro replaced my UDM
The UDM Pro replaced the UDM I had before.

Ubiquiti has created the UDM product line to help new customers get access to advanced networking capabilities without requiring a ton of technical expertise or dozens of appliances.

While those principles apply to both the UDM and UDM Pro, the two appliances are less similar than you might think. Below is a comparison table that illustrates the major differences in features and specifications.

UDMUDM Pro
Form factorStandaloneRack appliance
Built-in switch4-port (gigabit)8-port (gigabit)
10 Gbps ports02
WAN ports1 Gbps(1) 1 Gbps, (1) 10 Gbps with redundancy
Power over Ethernet ports00
Wi-FiDual-band 802.11ac 4×4 wave 2N/A
CPUQuad-core ARM Cortex-A57 at 1.7 GHzQuad-core ARM Cortex-A57 at 1.7 GHz
System memory2 GB4 GB
IDS/IPS throughput850 Mbps3.5 Gbps
UniFi ControllerBuilt-inBuilt-in
Application supportN/AProtect, Access, Talk
Power supplyStandardRedundant (support for PSU failover)
MSRP$299.00$379.00
Comparison between UDM Pro and UDM.

As you can see, the UDM Pro is better than the UDM in almost every aspect. But that doesn’t mean you should get it.

The primary decision points you have to think about are:

  • Do you need an access point/router combo?
  • Where do you want to use the appliance?

If you don’t have a server rack and have no plans to buy one, the UDM is the much better choice because you can place it almost anywhere. In fact, it looks pretty slick, and your wife is unlikely to complain if you place it in your family room.

However, if you already have a rack full of UniFi appliances and are planning on replacing an older USG, then the UDM Pro is definitely the right choice. 

To learn more about how the UDM Pro compares to the new USG Pro 4, scroll down to my comparison at the end of this article.

Why I Chose to Upgrade From the UDM to the UDM Pro

udm-pro-integration
The UDM Pro is the perfect appliance for small and medium networks.

I was introduced to Ubiquiti’s UniFi appliances during the deployment of a mesh networking system from AmpliFi, UniFi’s sister brand. You can read more about AmpliFi and the reasons why I decided to migrate to UniFi in this post.

In a nutshell, UniFi offers a ton of flexibility, versatility and upgradability. That has allowed me to replace individual components and to consolidate my networking infrastructure, thus making it easier to manage.

For example, I initially had a UniFi Security Gateway (USG) to handle all my routing, paired with a first-generation UniFi Cloud Key (UCK) and a UniFi Network Video Recorder (UVC-NVR).

When I upgraded from UniFi Video 3 to UniFi Protect, I was able to ditch the old Cloud Key because UniFi integrated the NVR with the second-generation Cloud Key. As a result, I had one less device to manage.

Next, UniFi released the UniFi Dream Machine — an all-in-one appliance that would serve as a combination of a router, ethernet switch, access point and controller.

So I ripped out my USG and replaced it with the UDM. Then I realized that I didn’t need the Wi-Fi antennas built into the UDM because I had it sitting inside of my server rack. Plus, I still had a separate UCK 2 to power my video surveillance infrastructure.

That’s when I decided that replacing the UDM with the UDM Pro would be the logical next step. By doing so, I could get rid of the access point inside of my rack and I could also decommission the UCK 2.

UDM Pro Setup and Configuration

The UniFi brand is geared towards small and medium businesses. So you would expect it to require at least some degree of technical expertise to set up the equipment. While that assumption is true in some cases, a “greenfield” implementation (or fresh installation) of UniFi is dead simple.

If the UDM Pro is the first UniFi controller in your network, you can literally just follow the screens in the UniFi mobile app to get it up and running in a matter of minutes.

Below are the steps I took to set up the UDM Pro as part of a test run (so I could document them):

  1. Install the UDM Pro in my rack and plug in the power cord.
  2. Power down my cable modem.
  3. Connect the RJ45 uplink port of the UDM Pro with my cable modem using an ethernet cable.
  4. Power up the cable modem.
  5. Open the UniFi mobile app and tap on the automatically discovered UDM Pro.
  6. Complete the setup wizard.

Steps two and four are required with some ISPs (i.e., Comcast) to release the public IP address from the previously connected router. When I unplugged the UDM and connected the UDM Pro, I wouldn’t get an IP address assigned from Comcast via DHCP.

Rebooting the modem fixed that.

Once I had that figured out, the rest of the setup took less than five minutes to complete.

Migration from UDM to UDM Pro

UDM Pro Dashboard
UDM Pro Dashboard.

Since I already had a UniFi controller as part of the existing UDM, I wanted to migrate my configuration and swap out the UDM with the UDM Pro.

The issue I ran into was that both my existing UDM and the UDM Pro (by default) use 192.168.1.1 as their IP address on the LAN side. That led to an IP address conflict that confused both the UniFi mobile app and my MacBook.

So if your existing LAN uses the 192.168.1.0/24 network range, I recommend connecting your computer directly via ethernet to the UDM Pro and avoiding any physical connection between the UDM Pro and your existing network. 

In my case, that meant disabling Wi-Fi on my MacBook Pro and unplugging the ethernet cable I had used to connect the UDM Pro with my other UniFi switch. 

If you prefer using the mobile app, I recommend disconnecting from your existing Wi-Fi and relying on Bluetooth instead to finish the UDM Pro setup.

I found it to be more convenient using Safari on my MacBook Pro to complete the configuration wizard.

Once the UDM Pro was configured and had rebooted, I logged back into the UniFi management portal (via https://192.168.1.1).

Your browser will likely show you a dialog warning you about the self-signed SSL certificate on the UDM Pro. You can safely ignore that warning and later replace that certificate, if you like.

Once I had logged into the UniFi portal, I restored the UDM Pro’s configuration using a backup I previously exported from the UDM.

How to Download a Backup of the Configuration

UniFi - Backup and restore
UniFi – backup and restore.

If you have never done it before, you can easily download a backup of your existing UniFi Controller configuration by following these steps:

  • Log in to the UniFi portal.
  • Click on the settings wheel on the lower left of the menu.
  • Scroll down to “Controller Settings” and click on “Backup.”
  • Select “Settings only” in the dropdown menu and click on the download link.

How to Restore a Backup File

Restoring a previously downloaded backup or settings file is just as easy as downloading it. Right above the download section you used before, you’ll find a “Restore From Backup” area with a “Choose File” link.

Just click on it and select the backup file you downloaded.

When you do that, the UDM Pro is supposed to load the backup and then reboot, restoring its configuration.

That’s exactly what I did, because I wanted to make the new UDM Pro an exact copy (settings-wise) of my existing UDM.

Unfortunately, while the upload of the backup file went through without a hitch, the UDM Pro got stuck upon reboot and, after several minutes, ended up in “diagnostic mode.”

I reset the UDM Pro to factory settings several times and tried to restore a backup, but it always failed, leaving the UDM Pro in an undefined state and non-operational.

At first, I thought the UDM Pro couldn’t restore a backup from a UDM because the hardware is much different. But based on the information I found in the UniFi community forums, it appeared as if others had been successful with such a migration.

I didn’t want to waste a ton of time and ultimately decided to set the UDM Pro up from scratch and manually transfer the configuration data.

How I Manually Migrated the UDM to the UDM Pro

UniFi - How to forget a previously adopted device
UniFi – how to forget a previously adopted device.

Fortunately, I only own four UniFi access points, four UniFi switches, and a dedicated Cloud Key for UniFi Protect. So re-adopting all of those devices on the UDM Pro wasn’t a major effort.

If I had dozens or hundreds of devices, I would have spent more time figuring out why the backup didn’t restore.

On a high level, here’s what I did:

  • Take screenshots of the most important configuration settings of the UDM.
  • Write down what switch ports had “special” profiles assigned.
  • Remove all access points and switches from the UDM by using the “forget” option.
  • Unplug the UDM and connect the UDM Pro to one of the UniFi switches.
  • Manually configure the UDM Pro by leveraging the screenshots.
  • Adopt access points and switches on the UDM Pro.
  • Manually update switch port settings to match what they previously were.

All of the above steps took around 30 minutes to complete, so that wasn’t a big deal. I have a fairly simple configuration consisting of:

  • Three Wi-Fi networks (main, IoT and guest).
  • VPN server.
  • Threat detection and deep packet inspection.
  • Dedicated VLAN for guests and IoT devices.
  • Bandwidth limitation for devices in the IoT group.
  • Some switch ports are tagged with the IoT VLAN via configuration profiles.

After swapping out the UDM for the UDM Pro, it took a few minutes for all my devices to re-appear in the UniFi management portal so I could adopt them. So don’t get nervous if you don’t immediately see all of your devices.

Once I completed the configuration and was satisfied that everything was working properly, I cut the power to all light switches and other IoT devices so they could reconnect to the access point with the strongest signal.

I’ve noticed that most IoT devices, and particularly HomeKit-enabled light switches, stay connected to an access point with a weaker signal even when one with a stronger signal becomes available. Power-cycling those light switches is often the quickest way to fix that — especially if they become unresponsive.

Migration of UniFi Protect

UniFi Protect Cameras
Manually migrating my four cameras took less than 10 minutes.

In addition to my network configuration, I also wanted to migrate UniFi Protect from the UniFi CloudKey Gen 2 to the UDM Pro. 

To use Protect on the UDM Pro, you need a hard disk drive to store your video footage. So before I installed the UDM Pro in my server rack, I inserted a 4TB NAS drive into the drive bay of the UDM Pro.

On the UDM Pro, UniFi Protect is an app you can install via the UDM Pro landing page (https://192.168.1.1). 

On the bottom of that page you can see a settings icon. Click on it and it redirects you to a device-specific page that has an “Applications” section. 

UDM Pro applications
UDM Pro applications.

Using the app section, you can install additional apps, such as Protect, Access and Talk (Beta). I don’t use Access or Talk, but I installed the Protect app.

Given my experience with restoring backup files, and considering that I have only four UniFi surveillance cameras, I decided to go the manual route again.

So I logged into my UniFi Protect portal and removed all four cameras from the Cloud Key. Once done, I reset the Cloud Key to its factory settings and adopted the cameras via the Protect app running on the UDM Pro.

UniFi Dream Machine Pro vs. UniFi Security Gateway Pro (USG Pro)

UniFi Security Gateway Pro 4
UniFi Security Gateway Pro 4.

UniFi recently also launched the UniFi Security Gateway Pro, a rack-mountable and more powerful successor to the USG I used to have.

I don’t have any hands-on experience with the USG Pro 4 yet, so the information below is simply based on the spec sheet of the enterprise gateway router.

USG Pro 4UDM Pro
Form factorRack applianceRack appliance
LAN ports2 gigabit8 gigabit (switched)
10 Gbps ports02
WAN ports(2) 1 Gbps [ethernet/fiber combo)(1) 1 Gbps, (1) 10 Gbps with redundancy
Power over Ethernet ports00
Wi-FiN/AN/A
CPUDual-core 1 GHz, MIPS64 with hardware acceleration for packet processingQuad ARM Cortex-A57 core at 1.7 GHz
System memory2 GB4 GB
IDS/IPS throughput250 Mbps3.5 Gbps
UniFi ControllerN/ABuilt-in
Application supportN/AProtect, Access, Talk
Power supplyStandardRedundant (support for PSU failover)
MSRP$344.00$379.00
Comparison of UniFi Security Gateway Pro 4 and UniFi Dream Machine Pro.

Based on my personal requirements, the two most striking differences between the USG Pro and the UDM Pro are the IDS/IDP throughput and the built-in UniFi Controller software.

In other words, if you have an internet connection with more than 250 Mbps bandwidth and you want to take full advantage of the network security features UniFiOS offers, you need the UDM Pro or the UniFi XG Server. 

If you choose the USG Pro, you also need a separate Cloud Key or controller software because Ubiquiti didn’t build that into the appliance.

Frequently Asked Questions

My decommissioned UniFi Cloud Key Gen 2
My decommissioned UniFi Cloud Key Gen 2
After making changes to my configuration, my internet speed is suddenly super slow. What could be the reason?

There could be dozens of reasons for slow internet speed. In my case, I made an error enabling smart queues. Instead of 30,000 kbit/s, I set it to 3,000 kbit/s, which limited my upstream to 3 Mbit/s instead of 30 Mbit/s.

My ISP modem and home office are on opposite sides of the house. Can I install two UDMs in the same network to connect these two locations?

A reader recently asked me if he could use two UDMs — one connected to the ISP modem and one in his home office (where he needed additional switch ports). He couldn’t use ethernet between those two locations, and figured he could use two UDMs to solve that problem “wirelessly.”

Unfortunately, you can’t install two UniFi controllers in the same managed network — at least not as far as I know. The reader ended up buying the AmpliFi Alien Mesh Kit to address his use case.

When I got the UDM Pro, I thought about ways to reuse the no-longer-needed UDM, and I hoped I could use it in my office as an additional access point. Unfortunately, that doesn’t work as UniFi doesn’t allow you to adopt the extra network controller.

Does the UDM Pro support PoE?

No! That’s the only thing I don’t like about the UDM Pro — it doesn’t have any Power over Ethernet (PoE) ports. I’m hoping that a future version will get that upgrade.

How do you set up the UDM Pro?

That’s easy. The UDM Pro has a Bluetooth chip built-in, so you can use your mobile phone (in combination with the UniFi mobile app) to set it up.

Alternatively, you can use a computer and web browser to walk through the configuration wizard.

What hard drives does the UDM Pro support?

The UDM Pro doesn’t come with a hard drive. However, you can add pretty much any 2.5-inch or 3.5-inch HDD. I used one of my 3.5-inch 4 TB NAS drives that I had laying around.

In case you’re wondering, you could also use an SSD as long as it has a SATA interface — but it would be overkill to do so because you won’t need the fast read/write speeds solid state disks offer.

How many access points (APs) can the UniFi Dream Machine Pro support?

At least 16 but the exact upper limit is unclear because Ubiquiti couldn’t complete their internal testing due to COVID-19.

The UDM Pro can also support at least 24 UniFi Protect devices.

I’ll update this section when I get new test results from Ubiquiti.

Ubiquiti UniFi Dream Machine Pro – Wrap-Up

The UDM Pro has two redundant WAN ports
The UDM Pro has two redundant WAN ports.

I’m incredibly happy with my UDM Pro because I love its simplicity. Plus, the UDM Pro helped me consolidate my networking infrastructure while making it more capable and powerful at the same time.

The only thing the UDM Pro is missing is PoE ports. I still own two older eight-port UniFi switches that support PoE, and I use one of them in my server rack to power UniFi access points and security cameras. So the lack of PoE ports in the UDM Pro is not a big deal for me. 

However, if I just started out with UniFi, I would appreciate not having to buy a separate (PoE-enabled) switch to power my UniFi cams. 

What do you think about the UDM Pro? Let me know by leaving a comment below!

58 thoughts on “UniFi Dream Machine Pro Review”

  1. Hi Michael,

    I am considering swapping my network gear (currently pfSense and Mikrotik devices) for UDM and ubiquiti switches – while looking up information on the UDM your article is one of the best resources I stumbled upon – thanks!

    Although I have some additional questions for which I have been unable to get straight answer for, even from ubiquiti support. As it seems you have hands-on experience, perhaps you happen to know the answers to my questions holding me from ordering the UDM device. :)

    I would really like to have all network services running on the network gear itself, to allow reboots etc for other hosts without interruptions and for ease of configuration – so:
    Does UDM (non-pro) automatically register DHCP leases (including static leases) to DNS service? Allowing me to access my devices by hostname without any further manual configuration.

    I occasionally like to try and test security solutions I would like to be able to use port-mirroring – does UDM include such feature?

    Thanks
    Holger

    Reply
    • Hi Holger!

      I’m using the UDM Pro right now and not the UDM anymore but I can tell you that the UDM Pro cannot do port mirroring, only the UniFi switches can do that. Regarding the DHCP to DNS question, I don’t know from the top of my head and I’m not using the built-in DHCP (I have delegated that responsibility to my Synology NAS).

      Cheers,
      Michael

      Reply
  2. Hey Michael,
    can you explain, why the IDS/IPS performance of the UDM pro is so much higher when compared to the normal UDM? UDM Pro is 4x faster… why? They both use the same CPU…

    Reply
  3. Hi,

    I am considering buying the Dream Machine Pro, but an important requirement is that it should capable of connecting 2 modems of different providers on the WAN ports.
    The traffic should be routable in a controlled way either to WAN1 or WAN2.
    No automatic load balancing needed, neither pure failover.

    So, with a UF-RJ45-1G module in the 2nd SFP WAN port, could I connect a second cable modem to the DMP in order to split the internet traffic in a flexible and a controlled way?

    Cheers,
    Filip

    Reply
  4. this is a fantastic article, thank you.

    I dont know if the IDS/IPS is much to really rave about given it uses Suricata, and I have noticed alot fo the things it reports are blocked by the firewall anyway?

    Make a change to your wifi config – the entire AP gets re-provisioned and your wifi is gone whilst it sends a change to the AP.

    Deep Packet Inspection (DPI) used is simply incorrect and wrong.

    Real time view of traffic rates for each client? Forget it with Ubiquiti. Wont do it, and this has been the top request for many years now.

    The thing works, but alot of the features a bug ridden, in my opinion.

    Reply
    • Hi Steve,

      Thanks for your reply!

      I’ve found both IPS/IDP and DPI quite useful.
      Sure, it sometimes blocks (IPS) stuff it shouldn’t but I haven’t had this happen very often.

      The fact that the AP re-provisions isn’t great but I don’t make changes so often that it becomes a real issue.

      Regarding missing features, I agree that some take forever or still haven’t materialized for reasons I don’t know. But based on my needs and requirements, the pros outweigh the cons by far.

      Reply
  5. Great Reviews, thanks!!!
    I thought about buying a Dream Machine, but the Pro Version seems much better: more CPU for DPI, 10GigE already available (as my ISP speed is less than 1G, can I use both SFP+ Ports for LAN Traffic?)…

    I will put the box into the cellar, so noise and missing WLAN is not a problem.

    Reply
    • Hi Oliver,

      I think one of the SFP+ ports is a dedicated WAN port but you can use the other for LAN traffic.

      Reply
      • sigh, OK… I hoped to save money on the 10G-Switch, 2 SFP+ ports would be enough right now. Anyway, thanks for your help.

        Reply
  6. Hi Michael,
    great review, many thanks for the detailed explanations. I am about to switch tu Ubiquity as our Meraki licenses are up for renewal and frankly, it’s a bit on the expensive side for a small office like ours. A question I haven’t quite foudn an answer to yet, are there any yearly licensing costs for software updates within the Ubiquity “world”, and if yes, how much are they approx. for a small set up like yours? Cheers!

    Reply
    • Hi Jonas!

      Thanks for the feedback! UniFi doesn’t have any licensing or maintenance fees. Your only cost is the hardware.

      Cheers,
      Michael

      Reply
  7. UDM Pro – Can it handle multiple IP addresses?
    I have the option to get multiple static IP addresses from my provider. Can the UDM Pro handle this (route multiple port 80s to different end-points, for example)? The USG series cannot (as far as I have been able to find).

    Reply
    • Hi Paul,

      I never tried that myself based on everything I’ve heard from other users, that’s not (yet) possible.

      Reply
    • Hi Paul,

      Yes. Even the basic USG can handle multiple IPv4 IPs on a single WAN connection, so the UDM Pro should be able to as well.

      Hoever, this requires you to manually edit json config files, put them on the controller, and hope you did not make any config/syntax errors. Also it requires a bit of understanding of IPv4 and NAT routing, setting up hairpins, so you can see devices on your other IPv4 WAN IPs from within your NAT routed network.

      No, There is still no option to configure multiple IPv4 IPs on a single connection, via the Unifi GUI.

      Yes – the lack of this basic routing feature in the GUI is strange (if not ridiculous, considering it’s supposed to be enterprise level hardware/software), and has been asked for (and promised by Unifi) many times on the Unifi forums.

      Reply
  8. Thank you so much Michael for a thorough, insightful review and easy to understand explanations. Does UDM Pro work with the upcoming wifi 6 access points that are in EA now? I wanted to make sure that the controller is upgradable to whatever is needed by the access points and there is not any incompatibility with UDM Pro and future wifi 6 access point hardware. I have a need for an elongated coverage area to cover my longish home and a carriage house in the back. House is roughly 60ft long and the carriage house another 30ft or so. Initially I was thinking of two amplifi aliens separated by 40ft wired connection but I like security features of the unifi line and the scalability of adding more access point(s) if needed. Thanks.

    Reply
    • Hi Janak,

      I have one of the new Wi-Fi 6 APs and it works without issues in combination with the UDM Pro.

      Reply
  9. I have an orbi wifi 6 system right now. Would I be able to use the UDM pro between the cable modem and the orbis, and get the protection from the UDM pro, use it for routing, and set the orbis up as access points? I currently have one set to be a router and the other wired to it and in use as an access point. I have a 1 Gbps internet connection, but love the information and security provided by ubiquiti and I want my connection to remain fast.

    Reply
    • Hey Ryan,

      yeah, that should be possible as long as you can set the Orbi to bridge mode.

      Cheers,
      Michael

      Reply
  10. Hi Michael,
    Just for Info:
    because I liked to have a Raid-Mirror for storing the Videos of the Protect-App I tried the ICY DOCK “EZConvert Pro MB982SPR-2S R1″.
    This SATA SSD/HDD RAID Converter for two 2,5 ” Drives fits into the 3,5″ Slot and works without flaws in our UDM-Pro by combining two SSD’s to a RAID.

    Reply
  11. My UDM Pro is in the mail and in about to do the exact same upgrade. My only question is, could I just take the hdd out of my cloud key gen 2+ and put it in the UDM Pro and have all my old footage?

    Reply
    • Good question…I didn’t try that but it’s surely worth a try. Of course, there is a risk that the UDM Pro will reformat the drive and wipe out all of your footage :)

      Reply
  12. Thanks for the comparison. I just got into this UniFi gear and am considering replacing my gateway/fw with a unifi device. I was looking at both the USGpro4 and UDM pro and could really see many differences other than being able to use the video features of UDM pro. With the facts presented in your review/comparison I can see that the UDM pro clearly has much higher IDS/IPS throughput. I’d say it’s almost a different in a different class if you’re using that feature. Thank you for the info!

    Reply
  13. Hi Michael, thanks for the great article. I purchased a UDM Pro and was wondering if you are using your AT&T modem in bridge mode (between the UDM Pro and ISP).

    The UDM Pro is going to replace a Cisco router that is connected directly to my FiOS ONT. The configuration is fairly simple – I configured the outbound port on the router to get an address from the FiOS DHCP server and set up NAT translation. Can I do this with the UDM Pro or will I need to use a FiOS router in bridge mode?
    V/r
    Tim

    Reply
    • Hey Tim!

      Since writing my UniFi reviews, we moved and I had to switch back to Comcast and I’m operating the cable modem in bridge mode. The AT&T router doesn’t support true bridge mode.

      In your case, I see no reason why you couldn’t use the UDM Pro without the FiOS router.

      Reply
      • I don’t have a UDM Pro (yet), but I use a USG-Pro on FiOS without the FiOS router. You need the router for initial connection or if you want to connect to your DVR remotely (have never got that to work without the FiOS router and just make do without it or VPN in). Keep it around for troubleshooting (since Verizon won’t support if it is not connected), but otherwise it does not need to be there as a bridge. I have Fiber to ONT, ONT Ethernet to USG-Pro and SFP fiber from USG-Pro to PoE switch on separate UPS’s for additional electrical isolation; SFP was inexpensive enough.

        Reply
  14. Hi Michael –

    It seems like you’re pretty happy with the UDM Pro. I have been considering getting one to replace my USG, mostly for the improved IDS/IPS throughput so I can enable more IPS features without impacting the speed of my (gigabit) Internet connection.

    Based on a review and a thread I read, it seemed like it was very buggy and effectively still in beta (as-of earlier this year). Have you experienced any of the trouble documented in the below posts? Perhaps for those of us with less advanced requirements it’s fairly stable?

    Thanks!
    Tchad

    https://alexsguardian.net/2020/04/30/ubiquiti-udm-pro-usp-plug-review/

    https://community.ui.com/questions/UDM-Features-missing-from-UDM-and-or-controller/faa5646e-476b-41ae-8c3b-4ef418e88028

    Reply
    • Hey Tchad!

      I’m currently on firmware 1.7.2.2620 and haven’t experienced any major issues or limitations. But my use cases might be less advanced than some of those of other users. The only thing I’m missing is a more flexible VPN client config, but that’s about it.

      So I guess whether or not the UDM Pro is a good fit for you depends on your specific requirements.

      Hope that helps

      Cheers,
      Michael

      Reply
  15. A great article. The Unifi Security Gateway Pro is not a new device, I have had one for two years, its the big brother to the USG, another thing to bear in mind is that initially when IDS/IPS appeared the bandwidth was around 250Mbps, however with updates, I now get around 360Mbps with IPS and DPI on, (I’m on a cable modem 360/36 Mbps service, so it might actually have more bandwidth).
    One last thing, you can upgrade the RAM on the USG Pro, I have 4GB in there as I had a redundant stick available.

    Reply
  16. Hey Michael,

    How is the content filtering? I am planning to use this device with approx 8 Unifi AP’s for a Christian school, and just wondering how well the content filtering works, as they will want to block porn sites and possibly social media, etc. I know Unifi has not been great at CF in the past, so wondering if they have improved at all.

    Rob

    Reply
    • Hey Rob,

      content filtering is still in Alpha stage and relatively rudimentary. Right now, you can block security issues, make the network family safe and block adult content – see https://www.dropbox.com/s/omhhxavhn7ihdpm/Screen%20Shot%202020-08-12%20at%2008.01.53.jpg?dl=0

      You can also add your maintain a custom blacklist. So for what you’re trying to accomplish, it might be sufficient.

      Reply
    • You could consider purchasing a Firewalla Gold for better CF, powerfull and very user friendly. Keep in mind that Firewalla is a very different product.
      Regards…

      Reply
    • Personally, I use sophos XG ( inline Bridge mode) on X86 Hardware for content filtering. Free for home use and maybe charity use. It is corporate class content filtering / antivirus for everything behind it. I personally don’t like the beta stuff from ubiquiti myself IMO. It also ensures that the unify gear is just used for what it is actually good at.

      Reply
      • Great review and I am sold on the UDM Pro!

        Hey Kevin,

        So I currently have an XG 106 as well. How is your experience using the XG in bridge mode? I had tried this a while back with a USG 3p and could not get it to work so my usg has been gathering dust for the past year. I am thinking of changing over to the UDM pro to manage the network and then wanted to use my XG for lower level security – sandstorm, https decryption, detailed logging of urls, email scanning etc. the only reason I actually went with the 106 instead of free was for sandstorm.

        Thanks,
        Gary

        Reply
    • Hey Godfred,

      here is what I got from Ubiquiti:

      Unfortunately, due to Covid 19 constraints – we had to push back our proper tests for upper limits of just UniFi networking devices.
      However, can confirm UDM-Pro can handle 24 Protect Devices and 16 UniFi devices simultaneously. We plan on conducting more thorough tests as some restrictions lift.

      I’ll update the blog post when I get updated results.

      Reply
  17. Do you know if Ubiquiti is considering Time Machine support for the internal hard disk? I’d love to decommission the Time Capsule I use today and currently have unused support for it in the Asus router I’m decommissioning (but not using). It seemed to be table stakes in other routers, did not know if it was here, as well.

    Reply
  18. Hi Michael, Thanks for the review. I am now replacing my netgear router, for a Unifi network. I have like 30-40 wired devices, between computers, network streamers and IOT devices (using multiple 8 port switches). And I might have at any given time between 10-20 wireless devices. I just got 1Gig fiber connection from AT&T.

    My only concern is on the USG, as it really seems under powered. The UDM-pro is too big for my and it wont fit in my network cabinet. Even though the UDM could be a solution my cabinet is metal and the built-in WIFI in the UDM would be completely lost. Is there anything better than the small USG, that has more horsepower, but a smaller footprint than the UDM-Pro??

    Reply
    • Hi Roberto,

      The UDM should easily be able to handle the number of devices you have. Even with the IDS/IDP throughput limited to 850Mbps, I doubt that would become a bottleneck.

      But to answer your question, no I don’t think there is a more powerful appliance than the UDM that has a similar form factor.

      Cheers,
      Michael

      Reply
  19. I had to just say thank you very much for this breakdown.

    I am looking at the Unifi line to introduce to customers (vs. the much more expensive Sonicwall routing solutions) and from what you’ve presented the only router they will need in most circumstances is the UDM Pro, and then I will build the switches and AP’s from there.

    A huge help, thank you for taking the time!

    Reply
  20. Hi Michael

    Thank you for the great review

    In my house in Norway I curently use a Amplifi HD mesh setup (5 units). I consider buying a dream machine pro for added security. What limitations in UDM Pro functionality can I expect using Amplifi access points in bridgemodus vs. replacing Amplifi HD with regular Ubiquiti access points? Thanks for any advice on this matter.

    Reply
    • Hey Bjorn,

      If you combine the AmpliFi nodes with the UDM Pro, you won’t be able to manage them via the UniFi controller or do anything that’s related to Wi-Fi. Everything else, including IDS/IDP/Firewall should work – but I haven’t tested it myself to confirm.

      Cheers,
      Michael

      Reply
    • Hey Pete!

      No, we moved in January and I don’t have AT&T fiber at the new location. I’m back with Comcast… :(

      Reply
      • Hey Pete,
        I have AT&T fiber and I am using UDM Pro behind the AT&T gateway. What you have to do is set the AT&T Internal network to a different IP address range in my case, I changed to 192.168.2.254 and the UDM Pro came up without any issues.
        thanks,
        Ken

        Reply
  21. Hola Michael,

    I have to say I’m okay with the UDM-Pro. Ubiqiti needs to address a lot of issues when it comes to SPF+ connections. I use the WAN port 2 for access and they have yet to introduce or support iPV6. SPF+ port 11 is currently being used as an uplink to my switch and the experience has been less than good. So if anyone needs to use any of these SPF+ ports. Please do yourself a favor and research the firmwares and read the threads on the community board. This way you can set the right expectation. Hopefully the product can and will be polished up sooner rather than later. As I like the product and like their products.

    Reply
    • Hey Carlos,

      Thanks for the valuable feedback! I had some issues with SPF+ ports in the past (not on the UDM Pro) and never could make them work in tandem. Maybe those issues were related to what are describing. I have to dig into that again when I get a chance.

      Do you have any specific links I should check out?

      Cheers,
      Michael

      Reply
  22. Hey Michael!
    I’ve bought a UDM after reading your review and it’s a great machine.
    I’m hitting a weird issue tho: my wi-fi printers don’t work well with it. Every time I have to print, I need to disconnect the printers from wi-fi, reconnect them and reinstall them on my Mac.
    This is very weird and it never happened before with the previous router I had.
    Do you happen to have any suggestion about this?

    Reply
    • Hi Lorenzo,

      Do you have multiple SSIDs or are all devices on a single Wi-Fi network?

      I’ve had issues with my Wi-Fi printer and some light switches and solved it by enabled Multicast DNS (mDNS)

      Let me know if that doesn’t work and I’ll dig through my config so see what else I changed.

      Cheers,
      Michael

      Reply

Leave a Comment

[Fit In 40 Seconds]
[Fit In 40 Seconds]