Placement of UniFi controller

I’m looking into being a small datacenter footprint with Uniquiti hardware. EFGs for edge firewalls and MLAG switches. For core firewalls a pair UDM Beasts. This is all still high level planning but the one piece I’m not clear on is where the controller runs. Does it run on all the firewalls or do I pick a pair of firewalls? Can all the gateways be managed by another controller?

You’re close, but the controller model works a little differently with UniFi gateways.

Each UDM (including the UDM Beast/Enterprise Fortress Gateway family) runs its own UniFi Network application locally and manages the switches, APs, and other UniFi devices adopted into that site. The gateways themselves are not managed by another UniFi Network controller.

So if you have multiple independent firewall pairs, each pair would have its own management instance. They don’t all register to a central UniFi Network controller.

If you’re looking for a single pane of glass across multiple sites or gateways, that’s done through UniFi Site Manager, which gives you centralized access and monitoring, but each gateway still hosts and manages its own UniFi Network application.

so if i understand you correclty, each pair of firewalls i bring up will have their own network controller?

For example:

Edge gateways connecting to the gateway: These two will run the controller

Core firewall gateways connecting multiple vlans: These two will run the controller

DMZ/Extranet gateways: These two will run the controller

And site magic links all these controllers into a single pane of glass?

Yes, that’s essentially correct.

Each HA gateway pair hosts its own UniFi Network instance and manages the devices adopted into that site. So if you build separate edge, core, and DMZ environments as independent gateway deployments, each would have its own management instance.

For example:

  • Edge gateway HA pair → manages the edge switches/APs for that site.

  • Core gateway HA pair → manages the core switches for that environment.

  • DMZ gateway HA pair → manages the DMZ devices.

Those are separate management domains they don’t share a single Network controller.

For centralized access, Site Manager ties them together into a single pane of glass so you can access and monitor each site from one account. It doesn’t merge them into one controller; it just gives you one place to manage all of your individual UniFi sites.

I have a question though. Why are you planning multiple UDM-based gateways in the same datacenter? That’s not a typical UniFi deployment. If your goal is to have separate edge, core, and DMZ firewalls all managed from a single Network controller, the UXG/Enterprise Fortress Gateway platform (externally managed) may actually be a better fit than multiple UDM-based gateways. That could change the recommendation depending on what you’re ultimately trying to accomplish.

. Why are you planning multiple UDM-based gateways in the same datacenter? That’s not a typical UniFi deployment.

Its typical in the large datacenter space im working within where there are segmentations based on purpose of the device. Extranet firewalls have nothing to do with Edge firewalls as one would handle cross connect and VPN clients while the Edge is just internet.

But you did bring up a very good alternative. the UXG line. I take it you mean here: Ubiquiti Store

I take it the other solutions like UDMs are more for a campus solution style and not datacenter?

That makes sense. Segmented edge, core, and extranet/DMZ firewalls are a pretty standard design in larger datacenter environments.

And yes, I was referring to the UXG/Enterprise Fortress Gateway line.

I wouldn’t necessarily say the UDM platform is for campus and the UXG platform is for datacenters. The bigger difference is the management model.

A UDM is an all-in-one appliance, it is both the gateway and the UniFi Network controller. That’s great for a single site because everything is self-contained.

A UXG is controller-managed. It doesn’t host the UniFi Network application itself, so you can have a dedicated UniFi Network controller managing multiple gateways, switches, and APs. If your goal is to have multiple security zones (edge, core, DMZ, etc.) while keeping management centralized, the UXG architecture is generally a better fit.

So for the type of environment you’re describing, I’d probably lean toward the UXG family over multiple UDMs. It gives you much more flexibility in how you structure management without ending up with a separate controller for every gateway deployment.

thank you so much for the details here. You provided a great deal of clarity Appreciate it @xMAXIMUSx

1 Like

One thing to note with the UXG line is their updates and features lag a bit behind the other ones with the built in controller. Also you can have one UniFI controller but you can have only one UXG per site meaning in that controller you would be switching between each site. I would go with the Beast models as they are built on the latest platform.

1 Like