github Ozark-Connect/NetworkOptimizer v2.9.0

2 hours ago

On-Site Agent update (optional): v2.9.0's Agent reads a UniFi Cable Internet's signal levels (see Monitoring below). It only matters on a site with a UCI, for the Agent on your UniFi Gateway. Open Settings - Multi-Site, expand your site, and press Run It for Me under the upgrade command, or run the upgrade command yourself; the app offers the update either way. Everything else in this release works with the Agent you have.

Health Checks you write yourself: pick a device, a command to run on it, what counts as a problem, and what to do about it. The first template catches UniFi Network stalled in garbage collection on a Cloud Gateway and restarts it.

Also in this release: UniFi Cable Internet and a Channel Spectrum in Cable Modem Stats, an Active Alerts card on the Dashboard, IPv6 in the Security Audit, and a round of Adaptive SQM fixes (one redeploy covers them).

What you missed on v2.8.x

If you're upgrading from v2.8.0, the six patches since then carried some significant work:

  • Adaptive SQM - Congestion Profile Learning - learns your line's own congestion curve from a week of brief speed tests taken while the WAN is idle. Upload Strength shapes upload too on Fixed LTE/5G, Starlink, and Fixed Wireless.
  • Security Audit - Missing Port Lock recommends UniFi Network's new Lock Port to UniFi Device, and two new rules alert you when a scheduled audit turns up new findings.
  • Wired clients online and offline by the port - on a switch you monitor over SNMP, Client Performance and the Live View maps use the switch port to catch a wired client that UniFi Network's client list gets wrong.
  • Firmware Rollout - a scheduled rollout skips anything already updated, and holds alerts for everything a switch upgrade cuts off.
  • Multi-Site - UniFi Console certificate validation through an On-Site Agent.
  • Performance Tweaks - Fan Control Tuning works on UniFi OS 6.0.x EA (redeploy it there).

See the v2.8.6, v2.8.5, v2.8.4, v2.8.3, v2.8.2, and v2.8.1 release notes for the full detail, and v2.8.0 for the full v2.8 feature set.

Monitoring

Custom Health Checks

  • Health Checks - keep an eye on what UniFi Network doesn't: stability of an SFP GPON/XGS-PON ONT, a device with a known issue on a particular switch port, AP radio flakiness, gateway memory leaks, or even a site-to-site WireGuard tunnel that stops handshaking. Open a device on the Devices card, give it a command to run over SSH, what counts as a problem, and what to do about it (alert, restart a service, kill a process, or reboot). Checks are charted on Device Stats.
  • UniFi Network JVM GC Thrash - the first template, for Cloud Gateways: when UniFi Network stalls in garbage collection (routing fine, UniFi Console unresponsive), the template restarts UniFi Network (#1224, thanks @jakerobb for the request and idea).

Cable Modem Stats

  • UniFi Cable Internet (UCI) - channel power, SNR, and FEC errors (DOCSIS 3.1 OFDM and OFDMA too), the modem's own event log with T3 and T4 timeouts marked on Cable Modem Signal History, and alerts for them: all things UniFi Network doesn't show for a UCI. It needs the On-Site Agent on your UniFi Gateway, and a UCI appears here by itself once that Agent is updated (#260, thanks @twodarek for the request, @b52src for pointing us at robry84's uci-inform-exporter, and robry84 for working out the format).
  • Sagemcom F3896LG (Virgin Media Hub 5, Ziggo SmartWifi) support (#1223, thanks @JPWTCK for the traces).
  • Channel Spectrum - every channel from your modem's latest poll, placed by frequency: downstream power colored by SNR, with the channels carrying uncorrectables marked, and upstream power against the 51 dBmV ceiling. Tilt, a notch, or ingress in one part of the band shows up at a glance, on every cable modem Network Optimizer supports (it shows the data from the latest poll).

Cellular Stats

  • Inseego FX gateways (FX4100) - carrier, RSRP, RSRQ, SNR, and the serving cell (#1237). The gateway doesn't report its band or neighbor cells, and a 5G NSA connection shows as its LTE anchor.
  • Zyxel 5G and LTE CPEs (NR7101, NR7102, NR7301, NR7302, NR7303, NR5103E, NR5103 v2, NR5307, FWA505, FWA510, FWA710, LTE3202, LTE5398, LTE7490) - RSRP, RSRQ, SINR, the 5G NR leg alongside the LTE anchor, the active band, and neighbor cells where the firmware lists them (#1212, thanks @Mirabis for the request, the references, and testing on an NR7302).

Live View

  • Fix: playback lost detail for Wi-Fi clients sharing a radio - on sites running the AP Agent, only one client per access point radio kept its fine-grained throughput. Every client does now, from the upgrade on.

Network Performance

  • Fix: ISP Health's Investigate on the charts only worked once - following it (or a Packet Loss or Loaded Loss link) again after leaving Network Performance opened the charts without jumping to the loss event.
  • Fix: Upstream Path Discovery could pick a transit router that answers by a different route - those are left out now, marked Different route in the review.

SNMP

  • Fix: duplicate SNMP polling with two On-Site Agents - only one polls now, preferring the agent off the gateway, so make sure it can reach your devices over SNMP.

Dashboard

  • Active Alerts - your three most severe unresolved alerts, with Acknowledge and Resolve right on the card (Site Operator and above). View All opens the rest.

Security Audit

  • Your IPv6 gets audited too - on networks with IPv6, isolation, internet blocking, and DNS blocking that only hold over IPv4 show up as their own finding "over IPv6". Blocking DoH by address now needs the providers' IPv6 addresses too.
  • Pi-hole bypassed over IPv6 - a network that hands out a Pi-hole or other LAN DNS server over IPv4, but the gateway over IPv6, is flagged, since devices with IPv6 usually ask the IPv6 server first. IPv6 DNS servers you set by hand, on networks and WANs, and IPv6 DNAT rules for DNS are checked too (#180, thanks @cdheiser for the report).
  • Fix: IPv4-only and IPv6-only firewall rules were judged as covering both - a rule in one family could raise a false Firewall: Rule Order Issue or Firewall: Ineffective Allow Rule against the other, or make a network read as isolated, internet-blocked, or DNS-protected while IPv4 still got through (#1231, thanks @Sub-lime-time for the report).

Client Speed Test

  • Fix: a test from an IPv6 address showed as WAN - Test History showed the raw address, labelled WAN and traced out through the gateway. With Gateway SSH set up, it now names the device and traces it on your LAN, as for IPv4 (#568, thanks @ekobres for the report).

Adaptive SQM

  • Fix: the download shaper could drop to 0 Mbit after a firmware upgrade - the rate scripts relied on a package that a UniFi OS upgrade removes, and the gateway doesn't always get it back. Redeploy Adaptive SQM once after updating (the Adaptive SQM page prompts you); the calibration fix below arrives with the same redeploy.
  • Fix: redeploying a learned profile failed - a profile that shapes upload failed with "Failed to deploy 20-sqm-.sh" (#247, thanks @LOOHP for the report and logs). A failed deploy now shows the gateway's reason.
  • Fix: a false "Smart Queues was just enabled" - it held back deploying after switching sites (Multi-Site), or after the page failed to load the WANs.
  • Calibration comes straight back after a firmware upgrade - the Ookla speed test now lives on the gateway's persistent storage, so an upgrade no longer leaves calibration off until the next reboot or redeploy. UniFi's own speedtest package is left alone too (#1093, thanks @Jason-Morcos).

Performance Tweaks

  • UniFi OS 6.0.10 EA on the UCG and UXG lines - supported (live-verified on a UXG-Fiber).
  • Fix: Gateway SSH mistakenly pointed at a CloudKey could reboot it - the Performance Tweaks status check no longer touches a CloudKey's hardware: it only reads the SFP+ SGMII+ patch's registers where that patch is deployed. The Gateway SSH connection test now fails on a CloudKey, and saving warns (#1200, thanks @Bagomojo for the report and @Confenet for tracking it down).

Client Performance

  • Fix: Device Not Found for a device UniFi Network knows - when UniFi Network's client list leaves out a device or its current address, Client Performance now falls back to UniFi Network's second active-clients list. With Gateway SSH set up, it also finds a device you're browsing from over IPv6 (#1094, thanks @Jason-Morcos).

Data Usage

  • Fix: LAN totals came up short for many Wi-Fi clients - on the longer ranges (and in Bandwidth Hogs' LAN + WAN view), only one client per access point radio was counted each hour. The last 30 days are recounted after you upgrade: you'll notice increased InfluxDB CPU/HDD usage while this one-time recount runs.

Alerts & Schedule - Rules

  • Fix: Gateway: High CPU and Gateway: High Memory ignored their Threshold % - they alerted at a fixed 70% (CPU) and 95% (memory). They use the Threshold % you set now (#1232, thanks @Sub-lime-time for the report).

Fixes

  • Also fixed: Threat Intelligence logging a warning on every poll on a CloudKey, where UniFi Network doesn't serve traffic flows (#1200).

Installation

Windows: Download the MSI installer below

Docker (Upgrade):

docker compose pull && docker compose up -d

macOS (native, recommended for accurate speed tests vs Docker Desktop):

git clone https://github.com/Ozark-Connect/NetworkOptimizer.git && cd NetworkOptimizer && ./scripts/install-macos-native.sh
# or if you already have it cloned
cd NetworkOptimizer && git pull && ./scripts/install-macos-native.sh

Proxmox:

bash -c "$(curl -fsSL https://raw.githubusercontent.com/Ozark-Connect/NetworkOptimizer/main/scripts/proxmox/install.sh)"
# or if you just need to update
pct exec <CT_ID> -- bash -c 'cd /opt/network-optimizer && docker compose pull && docker compose up -d && docker image prune -f'

For other platforms (Synology, QNAP, Unraid, native Linux) or new installations, see the Deployment Guide.

Don't miss a new NetworkOptimizer release

NewReleases is sending notifications on new releases.