Enterprise Fortress Gateway

Good Morning!

Trying to find some information about the EFG…

Does the Gateway have a VPN Client baked in to be able to connect to a third party vpn provider?

Similar to the Firewalla Appliances… VPN Client – Firewalla

Only information I could find was below, which makes it seem like it may be possible.

VPN Client Single Tunnel Throughput

WireGuard 980 Mbps

OpenVPN 180 Mbps

Measured with iPerf3.

Hello! Thanks for posting on r/Ubiquiti!

This subreddit is here to provide unofficial technical support to people who use or want to dive into the world of Ubiquiti products. If you haven’t already been descriptive in your post, please take the time to edit it and add as many useful details as you can.

Ubiquiti makes a great tool to help with figuring out where to place your access points and other network design questions located at:

If you see people spreading misinformation or violating the “don’t be an asshole” general rule, please report it!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

It does have a client to server connection possible, wireguard or openvpn, as do (I think) all the UI gateway devices, its part of the Network Application. I myself connect to NordVPN full time. It allows routing to the VPN eg Can send domains/IP’s/Devices to the VPN connection.

Appreciate the insight!

Does it have Teleport?

Thanks. Out of curiosity, do you have any personal opinions on how the EFG stacks up against other next gen firewalls? Are you using their add on service with the EFG?

Only really used Drayteks (A HA pair of 3910’s) in past, I like them, but they hard work. I went UI to complete my Unifi chain, with all my other network kit being Unifi.

So, you’re running an EFG in a home environment? If you’re not comfortable answering that, I understand.

Yep sat at home in good old UK!! I will be the first to admit its totally over the top (money wise), but I look at it this way, the network apps, apart from the SSL inspection bit and a few more IPS categories (if you pay for them), its basically the same as the UDM-SE I had before it. I paid for the horsepower. I have to use pppoe on the two fibre WAN connections I have, one is 2Gb other is 1.6Gb, I wanted IPS on high/blocking, VPN client connected, DPI, content filter all running and still get full speed. Its the pppoe that sucks the life out of the unifi gateways, and with this thing I achieve that.

Thanks for sharing. Cheers, from the other side of the pond!

I know this thread is old, but I am also looking into EFG for PPPoE. So you confirm that it can do 2Gb w/ PPPoE? Do you have any idea how hard its being hit by it and what the theoretical maximum might be?

Cityfibre 2Gb/1Gb connection to Aquiss, full IPS/IDS on, DPI on, VPN Wireguard Server, Teleport Server & Nord VPN Client all running and connected. Network of 9 switches, 5 AP’s, 29 Protect cameras/devices and about 60 clients.

This is to Usenet servers downloading a 10Gb test file. Bouncing off 230MBps over SABNZBD on the single pppoe 2Gb connection (max cpu at 60%). Using domain based routing I can utilise both my pppoe connections (2Gb & 1.6Gb) over different usenet providers and I get about 370MBps, it does appear to start to struggle at those speeds on two pppoe connections. But equally at those speeds, who cares!! The UDM-SE couldnt do half of that with nothing turned on.

Edit: Bit more testing, if I turn IDS/IPS off it hits 401MBps on the two pppoe, at about 80% cpu, which is about as fast as those two will go just about.

Very helpful, thanks. That sounds quite a bit better than even the UDM-PRO-MAX which has the same CPU clock speed. Since PPPoE is single threaded, I wouldn’t intuitively expect that to be the case.

Perhaps having more cores allows fewer conflicts with non-PPPoE tasks. Or the newer chip just has a higher IPC or something.