Ubiquiti UniFi EFG Enterprise Fortress Gateway Firewall Appliance
Ubiquiti EFG UniFi Enterprise Fortress Gateway Firewall Appliance
Ubiquiti UniFi EFG Enterprise Fortress Gateway Firewall Appliance is a 25G Cloud Gateway with 500+ UniFi device / 5,000+ client support, 12.5 Gbps IPS routing, and complete high availability.
Key Features
- Runs UniFi Network for full-stack network management.
- Shadow Mode High Availability with automatic failover provides uninterrupted connectivity (VRRP).*
- 12.5 Gbps routing with IDS/IPS.
- Licence-free, real-time inspection of encrypted packets with NeXT AI Inspection (SSL/TLS decryption).
- Two (2) 25G SFP28, two (2) 10G SFP+, and two (2) 2.5 GbE RJ45 ports (all LAN/WAN remappable).**
- Two (2) included hot-swap PSUs for power redundancy.
- Features a 1.3″ touchscreen.
- Includes 90 days of Professional Phone Support (via Ubiquiti).
Specifications
Mechanical
Dimensions
- 442.4 x 43.7 x 325 mm (17.4 x 1.7 x 12.8 in.)
Weight
Enclosure materials
- Aluminium CNC, SGCC steel
Hardware
Processor
- 18-core ARM v8.2 at 2 GHz
System memory
Management interface
Networking interface
- LAN:
- 1 x 25G SFP28 port
- 2 x 10G SFP+ ports
- 1 x 2.5G RJ45 port
- WAN:
- 1 x 25G SFP28 port
- 1 x 2.5G RJ45 port
Power method
- 1 x Universal AC input, 100—240V AC, 7A Max., 50/60 Hz
Power supply
- 2 x Hot-swappable 150W CRPS
Supported voltage range
Max. power consumption
ESD/EMP protection
- Air: ± 8kV, contact: ± 4kV
LCM display
Button
Operating temperature
- 0 to 40° C (22 to 104° F)
Operating humidity
Certifications
Gateway Features
Performance
- Redundant WAN with failover and load balancing
- WiFi QoS with UniFi APs
- Application, domain, and country-based QoS
- Application and device type identification
- Additional internet failover with LTE Backup
- Internet quality and outage reporting
Next-generation security
- Application-aware firewall rules
- Signature-based IPS/IDS threat detection
- Content, country, domain, and ad filtering
- VLAN/subnet-based traffic segmentation
- Full stateful firewall
Advanced networking
- Licence-free SD-WAN
- WireGuard, L2TP and OpenVPN server
- OpenVPN client
- OpenVPN and IPsec site-to-site VPN
- One-click Teleport and Identity VPN
- Policy-based WAN and VPN routing
- DHCP relay
- Customisable DHCP server
- IGMP proxy
- IPv6 ISP support
Capacity
UniFi devices
Client devices
Concurrent sessions
New sessions / sec
SSL/TLS inspection concurrent sessions
Client devices
- 80,000+ (with Enhanced Threat Updates, not included)
Routing Throughput
Firewall
IDS/IPS
VPN Server Single User Throughput***
UniFi Identity
Teleport
WireGuard
OpenVPN
L2TP
Site-to-Site VPN Single Tunnel Throughput***
Site Magic
OpenVPN
IPsec
VPN Client Single Tunnel Throughput***
WireGuard
OpenVPN
LEDs
Ethernet
SFP+
CRPS
- Off: No AC power present
- Steady white: AC power and DC output active
- Flashing white: AC power present
- Steady red: AC power lost/failure events
- Flashing red: Warning events
Software
Mobile app
- UniFi iOS:Version 10.16.2 and later
- UniFi Android: Version 10.17.2 and later
*Limiting to 5,000 concurrent sessions is recommended if the gateway is passing significant traffic. This can be achieved by restricting which VLANs and domains pass through NeXT AI Inspection, such as only including search engine and LLM queries on employee devices.
**Measured with iPerf3 on DHCP WAN. Performance may be reduced with PPPoE depending on ISP implementation.
***Measured with iPerf3.
Standard Warranty: 2-Years