On-Site Agent update (optional; the v2.9.0 Agent, unchanged in v2.9.1 and v2.9.2): if you skipped v2.9.0, its Agent reads a UniFi Cable Internet's signal levels. It only matters on a site with a UCI, for the Agent on your UniFi Gateway. Open Settings - Multi-Site, expand your site, and press Run It for Me under the upgrade command, or run the upgrade command yourself. If you updated on v2.9.0-preview9, or on v2.9.0 or v2.9.1, you're set.
AP Telemetry on UniFi gateways with built-in Wi-Fi, client renames and fixed IPs without a trip into UniFi Network, Firmware Rollout of builds before your own Console is offered them and more control over when Autopilot runs, Channel Recommendation applying its own plan, fixes for ISP Health's Loaded Latency, for devices polled through an On-Site Agent, for an Express adopted as an AP, for the JVM GC Thrash health check, and for installs built from source, plus PostgreSQL on SSD for UniFi Network 11.0.81 and UniFi OS 6.0.11 EA support in Performance Tweaks. See the v2.9.1 release notes and the v2.9.0 release notes for what's new in v2.9.0+.
AP Telemetry
- UniFi gateways with built-in Wi-Fi - the AP Agent now deploys to the UDM, UDW, UDR, UDR7, UDR-5G-Max, UX, UX7, and UCG-Industrial, whether a UX or UX7 is your gateway or in AP mode, so clients on their radios get the same live telemetry as clients on your access points. A gateway deploys with your Gateway SSH credentials, and a UX or UX7 in AP mode falls back to them when your Device SSH login is refused (#1221, thanks @tempeduck for verifying the agent on a UX7).
- Fix: a missing AP Agent binary retried without end (installs built from source) - when the build had no AP Agent binary for an access point, Network Optimizer logged into that AP over SSH and wrote an Audit Log entry on every retry, and the AP Telemetry status kept showing an older error. It now says the binary is missing and backs off between retries (#1203, thanks @dpackham for the report).
- Running natively on Linux from source? The update steps in the Native Deployment Guide now rebuild the AP Agent and every other helper binary on each update, so a release that adds one is never missed. Docker, the MSI, and the macOS installer already include them.
Client Performance
- Rename a client or set its fixed IP without opening UniFi Network - click the pencil beside a client's name or IP, here or in Wi-Fi Optimizer - Client Stats (Site Admin), and the change goes straight to your UniFi Console. Only that field is written, so the client's other settings stay as they were; clearing the name brings back the one UniFi picks, and clearing the fixed IP removes the reservation and turns off its Local DNS Record, as UniFi Network does.
Firmware Rollout
- Roll out a build before your Console is offered it - Deploy Firmware by URL takes a Ubiquiti download link, and Deploy Known Firmware picks from every build your sites have seen, by device, model, or build. That includes an Early Access build installed on one site going to a site that isn't on Early Access. Plan Rollout Now installs exactly that build, including rolling device firmware back; UniFi OS and UniFi Network only move forward, and install over Gateway SSH.
- UniFi OS builds shared between sites (Multi-Site) - once one of your Cloud Gateways is offered a UniFi OS build, every site with the same hardware on that channel (or a more aggressive one) can roll it out too, over Gateway SSH. A newer shared device build now also replaces an older one the Console offers.
- Scheduling - set a preferred day and hour for Autopilot, and tick Flexible to let it move up to 3 hours to a quieter hour. On a site with more than 3 UniFi devices, Autopilot stays out of Sunday 5 PM to Monday 9 AM. A scheduled rollout can now Advance 24h or Set Time, and a soaking one can End Soak Early so you can plan the next one right away.
- Turn off UniFi's own auto-updates - the warning about UniFi updating on its own schedule names only what the rollout covers, and Turn Off switches those schedules off for you. The UniFi Network application and UniFi OS need a Console connected with an account rather than an API key.
- Rollout wizard - each device in the preview has an Exclude button, so you can leave it out without going back to the first step.
- Fix: Autopilot settings changed in the wizard were ignored - on a site that had run Autopilot before, turning Autopilot on from the wizard kept it planning from its earlier settings. What you set in the wizard now takes effect.
- Fix: rollback and SSH retry failed on access points and switches - the SSH upgrade command never ran on UniFi access points and switches, so a rollback, or a retry after a device ignored its upgrade, could not install over SSH. Both now do.
- Fix: a UniFi Network update that did not install read Completed - when the Console refused a UniFi Network update and the install over Gateway SSH failed too, the rollout's report read Completed. It now shows Failed, with the reason.
Wi-Fi Optimizer
Channel Recommendation
- Apply Recommended Channels - Channel Recommendation can now move your access points to its plan for you, never two that hear each other at the same time, and shows each radio landing on its new channel. Like spectrum scans, it needs Network: Full (Site Admin in older versions) on the UniFi account Network Optimizer signs in with or an API Key.
- Fix: a stale-scan prompt that Re-scan could not clear (AP Telemetry) - on an access point running the AP Agent, every spectrum scan was dated 1970, so the Channels tab could ask for a re-scan that never made the prompt go away. The scan's age now reads as unknown.
Site Health Score
- Fix: an access point with no clients pulled Client Satisfaction down - UniFi scores an idle access point -1, and that counted as a real score, so a site with no Wi-Fi clients showed -1. It now counts as no score.
Dashboard
- Fix: a power loss read as an old firmware upgrade - when a UniFi OS console lost power, the restart reason on its Dashboard device card could name a firmware upgrade from weeks before (seen on a UX7 adopted as an AP). That old upgrade no longer explains a later restart (#1221, thanks @tempeduck for the report).
Monitoring
ISP Health
- Fix: one WAN speed test could set Loaded Latency on its own - only some of your WAN speed tests counted toward it, so a single test that read high set the figure even when your latency monitoring saw a clean line at that moment. Every WAN speed test that filled the line now counts, and one your latency monitoring contradicts is left out.
- Fix: Loaded Loss and Loaded Latency missed most scheduled WAN speed tests - a speed test's load often read as a one-off spike and was thrown out, so the loaded figures could come from a single test. Load during a recorded WAN speed test now always counts.
On-Site Agent
- Fix: a device that redirected was reached from the wrong network (Multi-Site Agent) - on a site whose devices Network Optimizer reaches through its On-Site Agent, a cable modem, ONT, cellular modem, or Starlink that redirected a request had the redirect followed from the server's own network instead of the site's. It could land on a different device or the wrong port, and Netgear CM2050V and CM600 login never worked on such a site. Every connection, redirects included, now stays inside the site.
Monitoring Interfaces
- Fix: an Alias IP in Monitoring Interfaces was unreachable from an On-Site Agent on the gateway (multi-WAN) - on a multi-WAN site whose On-Site Agent runs on the UniFi Gateway, the agent could not reach a device on a non-primary WAN through its Alias IP: the traffic left through the primary WAN instead. If a device was unreachable through a Monitoring Interface via your gateway's On-Site Agent, press Deploy on that interface in Monitoring - Setup.
Custom Health Checks
- Fix: Custom Health Checks on an Express adopted as an AP ran on your gateway - a check on an Express (UX, UX7) adopted as an AP ran its command, and any remedy, on the site's gateway instead of on the Express. Both now run on the Express itself.
- Fix: UniFi Network JVM GC Thrash kept failing after UniFi Network recovered - after UniFi Network restarted, the check kept reporting the old process's pauses, so its alert and its restart remedy kept firing. Checks still on the original command are updated for you (#1259, thanks @jimstrang for the report). If you changed that check's command, add it again from its template to pick up the fix.
Performance Tweaks
- PostgreSQL on SSD - UniFi Network 11.0.81 moved from MongoDB to PostgreSQL, so on a UCG-Fiber or UCG-Max this tweak replaces MongoDB on SSD, with daily SSD backups and weekly eMMC copies. Deploying it retires MongoDB on SSD first by copying the newest MongoDB data back to the eMMC, and UniFi Network stops for a minute or two while that runs (#1251, thanks @KittyFarts for raising it and testing the offload on hardware, and @jimstrang for the gateway findings and the PR that hardened the offload and added its backups).
- Fix: removing MongoDB on SSD reported success when its copy back to eMMC failed - it now checks each step, keeps whichever copy is newest, and shows the error instead.
- UniFi OS 6.0.11 EA on the UCG line - supported, verified against the UCG-Fiber 6.0.11 firmware image.
Security Audit
- Firewall: Missing Firmware Download Access now checks
dl.ui.com- Ubiquiti serves firmware fromdl.ui.comas well asfw-download.ubnt.comandfw-update.ubnt.com, so a rule allowing onlyubnt.comhosts is now flagged. If this issue appears after updating, adddl.ui.comto that rule, orui.com(which covers it, the same wayubnt.comcovers the other two).
WAN Speed Test
- Fix: no WAN speed test from the server on native x64 installs - the Native Deployment Guide only built the speed test binary for the gateway, so a WAN speed test run from the server reported "UWN speed test binary not found". The build and update steps now include the server's own binary.
UniFi Console Connection
- Fix: a changed password locked the UniFi Console account - after the account's password was changed on the Console, Network Optimizer kept signing in with the old one until the Console locked the account, and then the new password could not be saved either. It now waits several minutes between retries of a rejected password, and saving the new one in Settings connects right away.
- Fix: switching between an API key and a username and password could switch back - a moment after the new sign-in was saved, the live connection could reconnect with the old one, while Settings showed the new one. It now reconnects with what you saved.
Fixes
- Coming back to Network Optimizer on a phone or tablet put you back at the top of the page - when Network Optimizer reloads on resume, the page now opens where you were scrolled. The reload after a Network Optimizer restart keeps your place too, on desktop as well.
- An Express adopted as an AP that refused your Device SSH login - when an Express (UX, UX7) adopted as an AP refuses the Device SSH login, LAN Speed Test, Custom Health Checks, reboot reasons, Network Tools, the Wi-Fi Optimizer's Re-pair Uplink, and Firmware Rollout's SSH retry now use your Gateway SSH credentials for it instead of failing (#1221, thanks @tempeduck for spotting the refused login).
Installation
Windows: Download the MSI installer below
Docker (Upgrade):
docker compose pull && docker compose up -dmacOS (native, recommended for accurate speed tests vs Docker Desktop):
git clone https://github.com/Ozark-Connect/NetworkOptimizer.git && cd NetworkOptimizer && ./scripts/install-macos-native.sh
# or if you already have it cloned
cd NetworkOptimizer && git pull && ./scripts/install-macos-native.shProxmox:
bash -c "$(curl -fsSL https://raw.githubusercontent.com/Ozark-Connect/NetworkOptimizer/main/scripts/proxmox/install.sh)"
# or if you just need to update
pct exec <CT_ID> -- bash -c 'cd /opt/network-optimizer && docker compose pull && docker compose up -d && docker image prune -f'For other platforms (Synology, QNAP, Unraid, native Linux) or new installations, see the Deployment Guide.