github Ozark-Connect/NetworkOptimizer v2.8.0

4 hours ago

On-Site Agent update (one time for this release): the measured per-client WAN accounting below needs the v2.8.0 Agent on your UniFi Gateway, and the switch-port naming fix needs it on any Agent that does your SNMP collection. Everything else works with the Agent you have. Open Settings - Multi-Site, expand your site, and press Run It for Me under the upgrade command to have the app run it over SSH, or run the command yourself. Your enrollment is kept, and the app prompts you when an Agent is behind. If you updated on v2.8.0-preview8, you're set.

Network Optimizer can read Wi-Fi data straight from your access points now, and most of this release follows from it: live client data twice a second, a Roam button that moves a client between access points while you walk test, Wi-Fi Optimizer issues graded by what the radios actually measure, and traffic that never crossed the gateway so UniFi Network never counted it. The other half is the WAN: a Bandwidth Hogs card that says who is eating it right now and who ate the most this month, measured at the gateway by the On-Site Agent rather than estimated. And if you run UniFi Network's new Mesh MLO STR, the backhaul's links and their combined rate are on the AP cards, the 2D / 3D LAN Flow Map, and speed test traces.

This is the short version. The v2.8.0-preview notes have the detail, and each preview links back to the one before it.

AP Telemetry

A new Settings tab that pushes a small agent to each access point over SSH and reads Wi-Fi data from the radios themselves, not only through the UniFi Console. Everything below marked AP Agent needs it. It is opt-in: without it, everything marked AP Agent stays as it was on v2.7.3.

  • Ephemeral by design - the agent lives in memory on the access point, comes back on its own after a reboot or firmware update, and turning the feature off removes it everywhere. Every request to it is signed.
  • U6 and U7 access points (32-bit ARM); an aarch64 access point is refused with a message rather than half-working. (#1182, thanks @cypherstream and @keith-richard and others for testing on U6.)
  • Running natively on Linux from source? You build the AP Agent binary yourself; the Native Deployment Guide has the step. Docker, the MSI, and the macOS installer already include it.

Client Performance

Now a top-level menu item under Monitoring. It covers wired clients as well as Wi-Fi and has outgrown being a Wi-Fi Optimizer sub-item.

  • Live client data straight from the access point, twice a second (AP Agent) - half a second to two seconds ahead of WiFiman, measured side by side, and it follows a client across a roam instead of stalling on the handoff. Wi-Fi 7 MLO clients show each link.
  • Wired clients name their switch and port, with link speed and that port's errors and drops, where before the page just said "Wired". Needs monitoring configured.
  • Live Throughput on the Speed tab - a five-minute live chart of the device's download and upload; run a speed test and watch it climb. With an On-Site Agent on the Gateway it also shows how much of that is internet traffic and how much is local.
  • Roam (AP Agent) - move the client to another access point or band on demand. Useful on a walk test, when you need the device on the access point you are testing rather than wherever it is clinging. Only offered for clients we have already seen roam successfully.
  • Data tab - what the device actually used, on the internet and on your LAN, so a NAS copy your Console never sees is counted, and the internet side broken down by application. WAN usage is measured at the Gateway when the On-Site Agent runs there. The longer ranges read from an hourly rollup that builds itself in the background, so expect InfluxDB to be busier for a few hours after upgrading.
  • A client selector in the header - search by name, MAC in any shape, vendor, or words in any order.

Wi-Fi Optimizer

Client data comes from the access points first, with the UniFi Console filling in whatever they don't cover. That fixes Band Steering, whose list of steerable clients was always empty.

  • Acknowledge hides a Health Issue but keeps it scored, like Security Audit, and a fixed channel, TX power, or width you set yourself is an Info-level check with a hint, not a correction.
  • Issues graded by what the radios measure (AP Agent) - Raised Noise Floor, High Radio Utilization that says whose airtime it is, Sticky Clients, High Latency Despite Good Signal, and Unused Width. Co-Channel Interference catches overlapping 320 MHz radios on different channel numbers, and covered APs feed RF Environment their own scan tables, seconds old instead of minutes.
  • Channel Recommendation - Pin holds a radio where it is and the plan works around it. With the AP Agent the plan reads the real 320 MHz block off the radio instead of guessing, and can propose a narrower or wider width from what clients actually used this week and how busy the air is. After a move, the new channel is measured against the old one and the card shows interference before and after, and a channel full of 1x1 phones no longer reads as slow.
  • Mesh MLO STR - each backhaul link on its own row in Mesh Uplink and Mesh Child, the pair's combined rate on the 2D / 3D LAN Flow Map and speed test traces, and channel checks that treat the pair as one link rather than a conflict. Classic single-link mesh is unchanged.
  • Fix: the Signal Map heatmap read 5 to 10 dB stronger than measurements, open air included. It models what a device will report now. Interference checks and channel recommendations are unaffected.

Monitoring

Live View - Bandwidth Hogs

A new card above the second map: who is using the WAN right now, and who used the most of it over the last day, week, or month. Every client with a real share, biggest first, each linking to its Client Performance page. Scrub the maps and the list follows.

  • Measured at your Gateway - needs an On-Site Agent on your UniFi Gateway. With one, every client's WAN figure is measured at the source: live, in playback, and in the Data view. Without one the WAN split is a best guess when clients are busy locally at the same time. The Agent counts bytes per client and nothing else: no destinations, no ports, no per-flow records leave your Gateway. Gateway CPU impact is under 1% on UXG-Fiber and UCG-Fiber. Run It for Me in Settings - Multi-Site installs or upgrades it over SSH.

Live View - 2D / 3D LAN Flow Map

  • Per-client Wi-Fi traffic UniFi Network cannot show (AP Agent) - UniFi Network counts what crossed the gateway, so a client copying to a NAS read as idle. Reading the access point measures what is actually on the air, live and in playback, and every Wi-Fi client shows signal bars on the 2D map.
  • Double-click (or double-tap) a client to open it in Client Performance, or a switch or gateway for its Port Statistics. On the 2D map a WAN globe opens that WAN's ISP Health report.
  • UniFi Building Bridge pairs - both units, the wireless span with its band, signal, rates, and throughput, and the far building's gear behind it, which used to hang off nothing. Built against a captured site rather than my own, so if yours draws oddly, tell me.
  • Port Statistics for switches without SNMP - read from UniFi Network instead, so a USW-Flex-Mini shows up in Port Statistics, on the maps, and in its wired clients' totals.
  • Fix: a spare WAN showed up in the WAN pills after a UniFi Network update. It stays out of the way until it actually comes up (#1183, thanks @bondskin).
  • Fix: a mesh AP that re-pairs moves to its new parent - it stayed drawn on the old one, with the old link speed, while that parent was down for a firmware upgrade.

SFP Stats and ONT Stats

  • PON error totals - cumulative BIP, HEC, FEC, BWmap, allocations lost, GEM drops, FCS errors, TX drops, and buffer overflows, with columns hidden when nothing reports them. PLOAM Uptime next to PLOAM State.

Firmware Rollout

  • Firmware Rollout is now a top-level menu item with its own icon, no longer tucked under Config Optimizer.
  • A device that comes back on its old firmware gets a second try over SSH rather than failing on the spot. Some devices burn the reboot without installing the image.
  • A UniFi OS build promoted to Official is offered again - a console on Early Access or Release Candidate is only told about newer pre-releases, so a build vanished the moment it graduated.
  • Fix: a UXG gateway upgrade no longer alerts on itself - its reboot raised a WAN outage and an offline alert per device behind it.
  • Fix: devices behind an upgrading switch or AP no longer alert - only the device being flashed was kept quiet, so a switch uplinked through that AP raised Device Offline.
  • Also fixed: a healthy device failed over a brief blip in the post-upgrade check; a Release Candidate plan carrying an Early Access build; and a waiting plan offering a downgrade after Re-plan.

Performance Tweaks

  • UniFi OS 6.0.5 EA on the UXG line, and UXG-Max support with Fan Control Tuning and Logging Offload. UCG ceiling unchanged.

WAN Steering

  • Fix: nothing steered on UniFi OS 6.0.5 EA - it changed how the gateway marks a WAN's traffic, so our rules landed in bits it no longer routes on, and after any edit stopped applying at all. The app now reads the layout off your gateway, so 5.x and 6.x both work. The page will ask you to redeploy once.
  • Running natively on Linux from source? Rebuild the WAN Steering binary before that redeploy; the Native Deployment Guide has the step. Docker, the MSI, and the macOS installer rebuild it for you.

Alerts & Schedule

  • A wedged radio raises an alert (AP Agent) - judged against the radio's own history rather than its neighbors, because on U7 hardware 6 GHz resets continuously while 2.4 and 5 GHz sit at zero.

Fixes

  • Settings fields sent stale or empty values when you clicked a button without leaving the field first - a Local Account connection test failing with correct credentials typed was the report (#1177, thanks @djmaxwell1975); every text field on the page had the same gap.
  • Security Audit: isolation by firewall rule is judged in rule order - an allow ahead of the block used to still read as isolated. First match wins, as on the console. The firmware access check also needs both Ubiquiti hosts now, not any ubnt.com substring.
  • A device going offline sent two notifications, one from ICMP monitoring and one from UniFi device state. Whichever fires first wins.
  • Input hardening from a private security review: values that reach gateway commands and InfluxDB queries are validated, alert channel configs are no longer returned to Viewers by the API, and an agent tunnel can only act on its own connections. The only Gateway attack surface was an admin injecting into their own Gateway, or an authenticated Viewer doing so via Network Tools TCP ping. Thanks @Optic00.
  • Also fixed: Wi-Fi signal colors disagreeing between pages and going flat above -57 dBm on 6 GHz; a switch port changing names after an SNMP hiccup, splitting its history (needs the Agent update where the Agent does SNMP); a device that crashed during a commanded restart reported as an abrupt stop; and ECS-24S, ECS-48S, ECS-Core, Enterprise NAS, and Travel Router Long-Range showing as raw model codes.

Installation

Windows: Download the MSI installer below

Docker (Upgrade):

docker compose pull && docker compose up -d

macOS (native, recommended for accurate speed tests vs Docker Desktop):

git clone https://github.com/Ozark-Connect/NetworkOptimizer.git && cd NetworkOptimizer && ./scripts/install-macos-native.sh
# or if you already have it cloned
cd NetworkOptimizer && git pull && ./scripts/install-macos-native.sh

Proxmox:

bash -c "$(curl -fsSL https://raw.githubusercontent.com/Ozark-Connect/NetworkOptimizer/main/scripts/proxmox/install.sh)"
# or if you just need to update
pct exec <CT_ID> -- bash -c 'cd /opt/network-optimizer && docker compose pull && docker compose up -d && docker image prune -f'

For other platforms (Synology, QNAP, Unraid, native Linux) or new installations, see the Deployment Guide.

Don't miss a new NetworkOptimizer release

NewReleases is sending notifications on new releases.