Buy Once, Cry Once

This is a house, not a datacenter. I bought a full TP-Link Omada stack because it was half the price of UniFi, because TP-Link sells more routers in America than anyone else, and because business-grade kit in a home lab should be overkill by definition. Every one of those was true. None of them meant what I thought they meant.

What Was Actually In The Rack

For the record, and because "I bought Omada" is not specific enough to be useful to anyone, this is what was actually in the rack and on the ceilings.

ER605 Omada gigabit VPN router. The gateway, and the whole network's bottleneck.
OC200 Hardware controller. Later moved into a VM.
TL-SX3016F 16-port 10G. SFP+ only, no copper ports.
TL-SG3428XMP 24-port gigabit PoE+, L2+ managed, 10G SFP+ uplinks.
3 x EAP773 Wi-Fi 7 access points, ceiling mounted.
3 x POE380S 10G PoE++ injectors, one per access point. The 10G switch has no PoE. One failed.
10-15 x TL-SM5310-T 10G BASE-T RJ45 SFP+ modules. All eventually dead.

Look at that list for a second longer than I did when I bought it. The switching is the top of the Omada range. The gateway is the bottom of it. An ER605 is the entry-level Omada router, and it is sitting in front of two 10G switches doing all the routing between VLANs at gigabit.

That mismatch turns out to explain most of what follows. Nearly every feature I ended up missing lives on the gateway rather than the switches: firewall rules between VLANs, local DNS, the mDNS repeater. I spent my money on the part of the network that was already going to be fine and economised on the part that does all the thinking. The switches never really let me down. The ER605 is where the complaints live, and I picked it.

That is not a cheap pile of hardware. It was cheaper than the equivalent UniFi build, which was why I bought it, and it is worth keeping in mind through what follows that this was the high end of the Omada line rather than the budget end of it. Whatever went wrong here, it did not go wrong because I bought the cheap switches.

What Everyone Actually Wants

Before the brand argument, it's worth saying what anyone shopping in this category is actually trying to buy. The list is much the same in every thread on the subject, and none of it is exotic.

Central command and control

One controller, one interface, every switch and access point in it. Provision a VLAN once and have it appear everywhere. Push firmware from one place. See which device is on which port without walking to the rack. This is the entire reason to buy managed gear instead of a pile of unmanaged switches, and it's the first thing people list.

10G Ethernet

Not for the internet connection, which nobody has at 10G. For moving things between machines: backups to the NAS, restoring a VM image, copying a dataset without going to make coffee. The moment there's a file server in the house, the LAN becomes the bottleneck and gigabit starts to feel small.

PoE everywhere

Ceiling-mounted access points and cameras with one cable instead of a cable and an outlet. It's the difference between a clean install and an extension lead in a loft.

VLANs that actually separate things

Put the IoT devices somewhere they can't see the laptops. Give guests internet and nothing else. This is the one everybody wants and the one that quietly generates most of the work, because segmentation is easy and making segmented things still cooperate is not.

Roaming that doesn't drop calls

Walk from one end of the house to the other on a video call and have the handoff between access points be invisible. Consumer mesh mostly does this. It's table stakes.

Rules between segments

Once the VLANs exist you immediately need exceptions: the phone should reach the printer, Home Assistant should reach the IoT network, nothing should reach the management interface. A firewall you can reason about, in other words.

Local name resolution

Reaching machines by name rather than by memorised IP. Trivial to state, and as it turned out, the single gap that caused me the most architectural grief.

Stability, above all of it

Set it up, then never think about it again. Everything above is negotiable. This one isn't, and it's the one that decided this story.

Is a 10G, VLAN-segmented, centrally managed network overkill for a house? Possibly. Probably, if I'm honest about it.

But that framing has never quite matched what I was after. I didn't want the network to be impressive. I wanted it to be finished: to work, to stay working, and to stop being a thing I had opinions about. Overkill is often the cheapest route to boring, and boring was the actual goal.

Why I Talked Myself Into It

Every thread I read before buying said the same thing: get UniFi. Every thread also had someone pointing out that Omada does the same job for noticeably less money, and that the people insisting otherwise were paying a brand tax. I found that argument persuasive, which in hindsight is the most interesting part of this story.

The reasoning I actually used was market share. TP-Link is not a small company selling a curiosity. Depending on how you count, they held roughly 36.6% unit share of the US consumer router market in 2024, something close to 65% of the home and small-business segment, and around 80% of retail mesh. There is no way, I thought, that the market leader ships something outright bad. Too many people would notice.

The flaw in that took me a year to see. TP-Link's dominance is in consumer routers, the box you buy at Best Buy and never log into again. Omada is a completely different product line aimed at a completely different buyer, and it inherits the brand's scale without inheriting its focus. The market share I was reasoning from measured a business that has very little to do with managed VLANs, controller software and SFP cages. I checked the right number and drew a conclusion it couldn't support.

Underneath the price and the market share sat a third assumption, and it's the one I'd defend hardest at the time. This gear is built for businesses. Omada is sold to offices, schools and small enterprises with real users and real uptime expectations, and I was pointing it at a house. Whatever it can handle in a thirty-person office, it can handle across three floors and a family. I wasn't buying at the limit of the product. I was buying miles inside it.

And the last piece of the rationalisation was me. I do this for a living. VLANs, routing, packet captures, reading a config until it confesses. If something went sideways I wasn't going to be stuck on hold with support, I'd just fix it. That felt like a genuine advantage at checkout, the thing that let me take the cheaper option safely, and I want to flag it early because it turns out to be the most expensive belief on this page.

And the phrase I ignored was one I'd used myself, about other people's tools, for years. Buy once, cry once. Pay the higher number a single time, hurt once, and stop thinking about it. The alternative is to pay less and then keep paying, in evenings.

The Part That Was Fine

In fairness to Omada, the first stretch was fine, and I want to be honest about that rather than retroactively hating a thing I chose.

Unboxing to a working managed network took an afternoon. The switches came up, the APs adopted, VLANs tagged the way I expected, and the controller drew a topology map that was accurate. For a fraction of the UniFi price I had 10G uplinks, PoE where I needed it, and a single pane of glass that mostly told the truth.

For months, nothing happened. That's the highest compliment you can pay network gear. I moved on to other projects and stopped thinking about it, which is exactly what I'd bought it to let me do.

The problems didn't arrive as a failure. They arrived as a slow accumulation of things I couldn't do, and things I had to work around, until the workarounds were the system.

Then The Bad

Roughly in the order they became my problem.

The OC200 got slower every year

The OC200 hardware controller is the cheap on-ramp to Omada, and it is underpowered for what the software became. Page loads went from instant to sluggish to painful, and it correlated with controller versions rather than with my network growing. This isn't just me: TP-Link's own forums have people describing an OC200 that became progressively unusable across firmware upgrades, with the blunt community assessment that the hardware "is simply too limited" for current controller releases. The recommended fix is to buy an OC300. Paying twice for the controller was not the plan.

Self-hosting the controller traded one problem for another

So I did the obvious thing and moved the controller into a VM, which is free and removes the hardware bottleneck. It also means the network's brain now lives on the hypervisor, which is a dependency I had specifically been trying to avoid. Adopting devices, provisioning changes, and anything the controller owns are all downstream of a machine I reboot for unrelated reasons. It works. It's just one more thing that has to be up.

"No RJ-45 ports... no problem"

That was my actual thought process reading the datasheet, and I was really wrong. The 10G switch, a TL-SX3016F, is SFP+ only. Not "mostly SFP+ with a couple of copper ports". There is no RJ-45 data port on it at all. Every 10G device I own is a machine with a copper port, so every one of those links needed a TL-SM5310-T 10G BASE-T module to bridge the gap. I priced the modules in, decided that was fine, and moved on. Ten to fifteen of them died in service.

Why they died is physics, not a bad batch

I assumed I'd bought bad modules. The truth is worse, because it means the failure was designed in. 10GBASE-T runs continuous DSP to cancel crosstalk and echo across four copper pairs, so a copper module draws 2.5 to 3.0 watts against the 0.6 to 1.0 watts an optical SFP+ uses, and nearly all of the difference becomes heat. Now populate a 16-port cage row with them. That's forty-plus watts concentrated into a bay that typically has no fan pointed at it, in a rack, in a room that already ran warm. The recommendation for copper modules is to leave gaps between them in a checkerboard, which is advice that makes an SFP+-only switch substantially less useful than the port count suggests.

An all-fibre switch is a commitment, not a spec

The lesson generalises past TP-Link, and I'd give it to anyone reading a switch datasheet. An SFP+-only switch is excellent if your endpoints take fibre. If they take copper, you have not bought a 16-port 10G switch. You have bought a 16-port switch that needs sixteen power-hungry adapters to do its job, and their combined heat is now your problem. UniFi sells all-SFP+ switches too and the physics are identical there. I'd have been better served by fewer copper 10G links and actual fibre where it mattered.

And it has no PoE either, so add an injector per access point

The other thing the TL-SX3016F doesn't do is power anything. The three EAP773 access points hang off it, and each one needed the full chain: a TL-SM5310-T to turn an SFP+ cage into copper, then a POE380S 10G injector to put power on the run, then the cable to the ceiling. Three transceivers, three injectors, three power bricks and six extra patch leads, to light three access points, all of it fanning out from a switch I bought because it looked like the tidy option. One of the injectors failed outright, which by that stage barely registered as news.

Firmware updates were something to be survived

A firmware update should be boring. On Omada it was an event I scheduled for a weekend. Sometimes it went cleanly. Sometimes a device came back not properly managed, and the fix was to forget it, factory reset it, and re-adopt it from scratch. That is an annoyance on a switch sitting in a rack. It is a different thing entirely on one of the three ceiling-mounted EAP773 access points, where "factory reset" means a ladder, finding the recessed button, and holding it while balanced above a stairwell. I started putting off updates, about the worst outcome there is for network gear, and I was putting them off for ergonomic reasons rather than technical ones.

No local DNS, which turned into a circular dependency

The ER605 had no usable local DNS, so the answer was Pi-hole. Pi-hole is excellent and I'd run it anyway. But it runs as a VM, on the hypervisor, and the moment DNS for the entire house depends on that hypervisor, taking the hypervisor down means taking the internet down for everyone in the building. So now I either run redundant Pi-hole instances to make DNS highly available, or I hand DNS to something external like Cloudflare and lose the local resolution I wanted in the first place. A missing checkbox in the router turned into an availability design problem.

Firewall rules that couldn't express what I wanted

Once you have VLANs you want rules between them, and this is where the gap between "has VLANs" and "is a firewall" shows on an ER605. Basic inter-VLAN policy that I'd consider table stakes was either absent, awkward, or split across the controller and the gateway in ways that made the effective policy hard to reason about. I found myself keeping a text file of what I believed the rules were, and when you're doing that, the UI has failed.

mDNS was the one that broke me

Segmenting the network is what VLANs are for, and mDNS is how everything in a modern house finds everything else. AirPlay, Chromecast, printers, the TV, HomeKit. Omada does have an mDNS repeater, and getting the ER605 to actually forward what I needed between the VLANs I had was a running battle: feature support that depends on which device type you're configuring, and behaviour that varies with controller and router firmware versions. There is a whole genre of forum thread about this. I contributed to several. Nothing makes a segmented network feel less worth it than explaining to someone why the speaker isn't in the list.

Read that list back and the pattern is obvious. Not one of these is a defect. There's no RMA to file, no bug to report, no support case that ends with a fix. It's a product that does the advertised things and stops precisely where a home network stops being simple, which is a much harder thing to notice from a spec sheet and a price comparison.

And here's where being able to fix things stops being an advantage. I could diagnose every one of these. I did diagnose every one of these. I wrote mDNS repeater rules that worked, kept a firewall policy file that was accurate, built the Pi-hole redundancy the missing DNS forced on me, and re-adopted access points off a ladder. Each fix was satisfying in the moment and each one was me subsidising the product with my own time.

Someone without my background would have hit the first or second of these, concluded the gear was wrong for them, and returned it inside a month. My skills didn't protect me from a bad purchase. They let me absorb it, for about a year, one evening at a time. The capability I counted as insurance turned out to be the thing that delayed the decision.

Every single complaint on that list, I had read before buying. All of it was in the threads I'd decided were brand loyalty. The commenters weren't being snobs. They were being specific, and I filed specific as biased because the alternative cost more.

And Then Washington Weighed In

Then the decision got taken partly out of my hands, which I did not expect when I was choosing a switch.

In August 2024 the House Select Committee on the Chinese Communist Party asked the Commerce Department to investigate TP-Link, and Commerce, Defense and Justice all opened investigations. In November 2024 Microsoft reported a botnet, CovertNetwork-1658, built largely from compromised TP-Link routers and used by Chinese state-sponsored actors against Azure customers. Researchers had already found TP-Link-specific malicious firmware aimed at European government targets in 2023. Through 2025 an outright ban on TP-Link sales in the US was reported as a live possibility.

I want to be careful here, because this is the part where it's easy to be unfair. Being investigated is not being convicted. The specific botnet exploited consumer routers, not Omada switches. TP-Link has disputed the characterisation, and reasonable people note that a company's US arm restructuring away from its Chinese parent complicates the story further.

But I wasn't ruling on national security. I was deciding what to buy next for a network that runs my house. And the honest calculation is that a vendor facing a possible sales ban in my country is a vendor whose firmware pipeline, warranty and long-term support I can't confidently plan around. Not because I'd concluded anything about the accusations, but because uncertainty of that kind is itself a cost, and I'd already spent a year paying costs I hadn't budgeted for.

It also reframed the market share argument I'd started with. That 65% of American homes and small businesses running TP-Link was the thing I'd read as reassurance. Regulators were reading exactly the same number as concentration risk. Same fact, opposite conclusion, and theirs was better reasoned than mine.

Buying It Twice

I bought UniFi. The thing everybody told me to buy at the start, at roughly twice the price, about eighteen months later than I should have.

Dream Machine Pro Max Gateway, controller and NVR in one. Replaces the ER605 and the OC200, and quietly added cameras.
USW Pro XG 8 PoE 8-port 10G PoE++. Native RJ-45. No transceivers.
USW Pro XG 48 PoE 48-port 2.5G PoE++ with 10G uplinks. Replaces the TL-SG3428XMP.
3 x U7 Pro XGS Wi-Fi 7 access points, one per floor. Replaces the EAP773s.

The controller stopped being a component

The change I least expected is the one I notice most. On Omada the controller was a thing I maintained: an OC200 that got slower every year, then a VM that made the network depend on the hypervisor. The Dream Machine Pro Max is the gateway and the controller, so there is no separate box to outgrow and no VM to keep running. Two of my Omada part numbers collapsed into one, and the management plane stopped being a component I think about at all.

Local DNS came back inside the network

This is the one that fixed an architectural problem rather than an annoyance. With name resolution handled at the gateway, Pi-hole becomes something I run because I want ad blocking, not something the house depends on for basic function. I can take the hypervisor down for an afternoon and nobody notices, which was never true before. The circular dependency is gone, and it went away by buying a router that does what routers have done for twenty years.

Firewall rules I can read back

I no longer keep a text file describing what I believe the network policy is. The rules are expressible, they are in one place, and the order they evaluate in is visible. It isn't perfect, since Ubiquiti has its own opinions about rule placement that took a while to internalise, but I can answer "can the IoT VLAN reach the NAS" by looking rather than by testing.

mDNS across VLANs just works

Segmentation stopped being a thing I apologise for. The speaker appears in the list. The TV casts. The printer is findable from the phone. This was the single largest source of my evening time on Omada and it is now a setting I configured once and have not revisited.

Firmware updates are boring again

Devices update and come back adopted. I have not been up a ladder to factory-reset an access point since. That sounds like a small thing and it is the difference between running updates promptly and putting them off for months, which is a security posture, not a convenience.

Cameras became a thing I could just add

This one I did not buy it for, and it has turned into the upside I talk about most. The Dream Machine Pro Max has the NVR built in, so adding a camera is: plug it into a PoE port, watch it adopt, done. Same controller, same app, same credentials, footage recording to drives in a box I already own. No separate recorder, no second piece of software, no third vendor account, and no monthly fee to see my own front door.

And the 10G lesson stuck

The USW Pro XG 8 PoE has eight 10G ports and they are RJ-45. Copper, natively, straight out of the switch. Every one of those links used to need a TL-SM5310-T cooking away in a cage; now the port is just a port. I want to be clear that this is a spec I finally read properly rather than a virtue Ubiquiti invented, and they sell all-SFP+ switches too where the same physics would apply. It also does PoE++ on those same ports, so the three POE380S injectors went in a drawer along with their power bricks, and each access point became a single cable again. One switch now does what a switch, sixteen transceivers and a row of injectors used to do between them. And here is the part that actually stings. "Check whether the ports are copper, and whether they carry power" is not an insight. It is not advanced. It is the kind of thing I would catch in about five seconds reviewing somebody else's design at work, because at work there is a review, a budget line and someone asking why. At home there was none of that, and "it's not a datacenter, it's not a business" was enough for me to skip diligence I would never skip on a twelve-port office switch. Twenty years in the field didn't fail me here. I gave myself permission not to use it.

The honest accounting is worse than the difference in sticker price. Add a gateway, a 16-port 10G switch, a PoE switch, three Wi-Fi 7 access points, plus ten to fifteen dead SFP+ modules and the 10G injectors needed to power anything, plus the OC200 I was advised to replace with an OC300, plus a Dream Machine Pro Max, two UniFi switches and three U7 Pro XGS access points, and the hardware alone is well past what buying UniFi once would have cost.

Then add the part that doesn't appear on any invoice: a year of evenings on mDNS repeater rules, a text file tracking what I thought the firewall was doing, ladder trips to re-adopt access points after firmware updates, and the low background hum of knowing the network was the least reliable thing I owned. That time was the real price, and I paid it in the currency I have least of.

I'm not going to pretend UniFi is flawless, because it isn't, and I'd rather not write the mirror image of the posts I dismissed. Ubiquiti ships bugs. It has removed features people relied on. Its cloud posture makes some people uncomfortable for reasons I think are legitimate. There will probably be a version of this post about them one day.

But the specific things on my list are things it does, and it does them without me building scaffolding around the gaps. That's the whole difference, and it's not a small one.

The enterprise-grade reasoning was wrong in a way I still find interesting. Business kit is built for a business network: one flat purpose, a helpdesk, an IT person who owns it during working hours. A house is stranger than that. It has televisions, a printer somebody's phone needs to find, guests, a partner who does not care why the speaker vanished, and an expectation of working at eleven at night with nobody on call. My home lab was not a smaller version of an office. It was a harder problem in a different shape, and the gear that thrives in an office was never aimed at it.

The lesson was never "UniFi good, Omada bad." Omada is competent gear that stops where a home network stops being simple, and if my requirements had stopped there too I'd still be running it happily. The lesson is that I had a heuristic I trusted for other people's decisions and abandoned for my own the moment money was involved. Buy once, cry once. I bought twice, and cried the whole way through the middle.