Thank you. I’m coming from a cable provider router, so anything will likely feel fast
Basically, I left my home automation devices that need internet access in my main LAN group -- like those that use Spotify for streaming media or with which I still use their built in web interface. All others are isolated in the way described in that thread.
Edgerouter/Unifi are not designed for networking noob as you describe yourself, unless you like doing a lot of reading and have a working network you can rely on while you figure out the Ubiquiti stuff.
I had a Eero mesh in place while I was setting up my ER12 and NanoHD, and was really glad I did. I took down the Ubiquiti network a number of times while figuring things out (mostly due to VLAN setup goofs).
If I had been doing that on our primary network my family would have kicked me out of the house. Since getting set up, the ER12/NanoHD have been extremely reliable.
But I would not recommend a similar setup to someone unless they were the type who enjoy the process of reading/watching/learning and iterative activities.
There are a lot of very smart people on the Ubuiquiti forums who can help. On their forum I always felt like like a fifth grader talking to the cool high school kids. 
And AFAIK ER line doesn't include any family-friendly stuff so don't expect it to help you keep the kids safe online w/built-in tools.
Fair comment -- although to be fair, it isn't that hard either...after all, I managed it....lol. I'd say my ER3 was easy enough -- and if you avoid VLANS like the plague, well, it's easier than MikroTik...and frankly easier than finding DHCP in my last actiontec router from Verizon....lol.
On ease of use, the USG lineup would likely be easier than my ER3 for sure.
S.
Yea, I’m def going usg, probably that $30 4 port flex an one nano he to start
Same.
Not a network engineer by a long shot, but I don't think there is a great risk here by not separating the LANs.
Funny every time a read a router review they are all talking IoT support now. But and it's a big Butt they don't talk about security only about the number of devices that the router will connect. Every IoT device that needs to call back to the mother ship is a new attack surface into your network. If you are going to implement a "flat" network for IoT at least allow the consumer to see where the traffic for each device is going and allow them to create a rule to block the access. That would make consumer routers/ap's much more useful.
Maybe on pro-sumer routers...
No average/normal consumer is going to do any of that. Hell, they won't even make a separate IoT network at all.
Actually if they would just use some intelligence and notifications of unusual activities from a device it would be a start. A subset of of a IDS/IPS would be a good start. But you are right who would want to keep a router app on their phone for notifications and would the consumer even set it up if not given the option during initial setup.
I use adguard home dns, are some plugs call weird places
![]()
Exactly, I use a UDM pro for one of my networks Multicast DNS works really well with all usual Iot devices. HE homekit,homebridge,sonos even alexa and google when I use to use them.
I moved all my digital content off one of my NAS because that NAS also had backups of personal files, etc., from my other NAS. Didn't want that content on the same VLAN w/all my IoT devices (which includes Roku and ShieldTV). I wasn't using the NAS for transcoding or anything, so just moved it to a standalone HDD connected directly to my primary entertainment device, which is my ShieldTV.
Made me touch the switch next to me.
Hey, can a usg do separate dns per device? Like Pinole on certain devices without setting the dns on the actual device?
What company are you using for your ISP? I have AT&T fiber and there is a trick to avoid using their provided router/modem box. I had to get a USG so I could clone the MAC from the ISP box, and had to install a switch between the ONT (converts fiber to copper ethernet) and the USG to make it work. When the ONT is powered up I actually have to connect up the AT&T gateway for it to authenticate, and once it does then I can unplug it and power on the USG. The switch in between keeps the ONT thinking it is still connected. If it disconnects, then it has to re-authenticate. It sucks, but it works and I have everything on UPS devices so I haven't had to do this since I deployed my Unifi stuff about 6 months ago. If I would have kept their gateway in the mix, since there is no true bridge mode, then everything would have been double NAT, and I didn't want to do that. Some people keep it, I decided I didn't want their junk device in my way and consuming power. There are more ways to get around the gateway, but they are a lot more complex (and cost extra). Though, it avoids the issue of reconnecting their gateway on power ups, although I can live with this.
Though, I will say in roughly 6 months of having gone full Unifi, I have had my work VPN drop out 0 times since changing over. Before on the ISP box, it was maybe once a week. My wife has had the same situation as well, and now hers works great too. And for me, everything that has a ethernet jack is wired. Even the wife's work laptop. I can hit gigabit speeds on my main desktop still with the USG (I have threat detection turned off). That being said, the USG is dated, but it still works well. And the likelyhood of you running at full gigabit speeds is very low. I only have done it a couple times, when downloading large games and such.
Thank you. And Verizon Fios
The DNS settings on the UniFi controller are per-VLAN I have my USG hand out my PiHole IP as DNS to all its DHCP clients. Of course, you could manually override it on a per-client basis on the client-side config.
You may want to do some research with Fios as well. I believe I have seen it mentioned without a true bridge mode, but can't remember exactly. Just lookup Unifi on fios and see what people are saying. It may change the outlook on what you should buy to make it most compatible with your ISP.
I was originally thinking of getting the UDM (for throughput) but since it cannot clone MAC addresses, I had to opt for the USG. Though, I will say my overall network design in my home was better because I could put the USG in the basement, rather than where my ISP gateway was in the living room.
I have a new unused UDMPro available in the UK and I’m after some switches ideally 24 port series 2 and Router Next Gen Pro as I have now chosen the separate component routes. Maybe POE 16’s or 8’s Willing to cut a deal.
Also rather inconsequentially I'm after some camouflage covers for Flex cams