Skip to Content

UniFi & Networking Guides

Ubiquiti EFG Enterprise Fortress Gateway: Complete Australian Guide (2026)

Specifications, security architecture, session capacity, VPN throughput, redundancy and complete deployment design for Ubiquiti's enterprise UniFi gateway.

In one paragraph: the Ubiquiti EFG (Enterprise Fortress Gateway) is a 1U rack-mount UniFi security gateway built for large, security-sensitive networks. It inspects traffic at 12.5 Gbps using the 95,000+ signature CyberSecure Enterprise tier, tracks one million concurrent sessions at 71,000 new sessions per second, performs SSL/TLS inspection on up to 10,000 concurrent sessions, and supports 5,000+ users and 500+ UniFi devices. It connects at 25 Gbps via SFP28, and its two hot-swappable power supplies mean a failed PSU can be replaced without taking the network down. It has no built-in camera recording — it is a dedicated gateway designed to pair with separate switching and storage.

IDS/IPS: 12.5 Gbps
Signatures: 95,000+
Sessions: 1,000,000
Users: 5,000+
PSUs: 2× hot-swap

What the EFG is — and who it is for

Most UniFi gateways are all-in-one consoles: they route, they switch a little, they record cameras, and they host the UniFi applications. The Enterprise Fortress Gateway takes a different approach. It is a purpose-built security gateway that concentrates its silicon — an 18-core ARM v8.2 processor — on inspecting traffic and tracking sessions, and leaves switching and recording to dedicated hardware.

It is aimed at organisations where the network is genuinely critical: campuses and schools, hotels and accommodation, hospitals and clinics, multi-site retailers, managed service providers, apartment buildings and large offices. The common thread is not raw bandwidth so much as consequence — sites where an hour of downtime is expensive, and where encrypted traffic needs real inspection rather than a firewall looking at the outside of the envelope.

Quick qualifier: if you have fewer than about 1,000 users, no compliance requirement around encrypted traffic inspection, and you would rather have one box that also records your cameras, a Dream Machine will serve you better and cost less. The EFG earns its keep at scale and under obligation.

Full specifications

CategorySpecification
IDS/IPS throughput12.5 Gbps
Threat signatures95,000+ with CyberSecure Enterprise
Concurrent sessions1,000,000
New sessions per second71,000
SSL/TLS inspection10,000 concurrent sessions
Max. clients / simultaneous users5,000 / 5,000+
Managed UniFi devices500+
Default WAN ports(1) 25G SFP28 + (1) 2.5 GbE RJ45
Max. WAN ports5
25G SFP28 ports2 (25G / 10G / 1G)
10G SFP+ ports2 (10G / 1G)
2.5 GbE RJ45 ports2 (2.5G / 1G / 100M / 10M)
Processor18-core ARM v8.2 at 2 GHz
RedundancyShadow Mode (VRRP) gateway failover; (2) hot-swappable PSUs
Power supplies(2) hot-swappable 150 W CRPS
Power inputUniversal AC 100–240 V, 7 A max, 50/60 Hz
Max. power consumption82 W
Heat dissipation280 BTU/hr
Form factor1U rack mount
Dimensions442.4 × 43.7 × 325 mm
Weight6.5 kg
EnclosureCNC aluminium, SGCC steel
Display1.3" touchscreen (LCM)
ManagementEthernet, Bluetooth
ESD/EMP protectionAir ±8 kV, contact ±4 kV
Operating temperature0 to 40 °C
Operating humidity5 to 95% non-condensing
CertificationsCE, FCC, IC, Anatel, SRRC

Security architecture in detail

Intrusion detection and prevention

The EFG runs IDS/IPS at up to 12.5 Gbps against a signature set of 95,000+ rules on the CyberSecure Enterprise tier. For comparison, the CyberSecure tier used by the Dream Machine range carries 55,000+ signatures. The extra rules cover a broader range of exploit attempts, command-and-control patterns, malware families and protocol abuses.

SSL/TLS inspection

This is the EFG's most consequential capability and the one worth understanding properly. The overwhelming majority of internet traffic is now encrypted with TLS. A firewall that cannot look inside that encryption can see the destination and the volume, but not the content — so signature-based detection has very little to work with.

The EFG can decrypt, inspect and re-encrypt up to 10,000 concurrent TLS sessions. That turns intrusion prevention, content policy and malware detection into something that actually applies to real traffic rather than the small unencrypted remainder. If your organisation has an obligation to demonstrate inspection of encrypted traffic — common in health, education, finance and government-adjacent work — this is the specification that matters.

The rest of the stack

  • Application-aware firewall with deep packet inspection
  • VLAN segmentation and inter-VLAN firewall policy
  • DNS filtering and content filtering by category
  • Country-based traffic rules and threat management
  • Client isolation and guest portal support
  • Full traffic visibility and per-client analytics in the UniFi Network application

All of it is managed from the same UniFi interface as your switches, access points and cameras — with no per-feature licensing on the core stack.

Sessions, users and why the numbers matter

Three published figures describe the EFG's scale, and they measure different things:

FigureValueWhat it limits
Simultaneous users5,000+How many people and devices can be connected at once
Concurrent sessions1,000,000How many simultaneous connections can be tracked
New sessions per second71,000How fast connections can be set up — burst capacity

The third figure is the one people overlook. Think of a school at 8:50 am: 1,500 devices wake up within a few minutes and each opens dozens of connections to sync mail, push notifications and cloud services. That is a burst of hundreds of thousands of new sessions in a short window. A gateway with a low session-setup rate does not fail dramatically — it just feels slow for ten minutes every morning, and nobody can explain why the bandwidth graph looks fine.

Rule of thumb: allow roughly 100–200 concurrent sessions per active device. A 1,000-device site therefore wants a gateway comfortable with 100,000–200,000 sessions; the EFG's one million gives substantial headroom for growth and for IoT-heavy environments.

What 12.5 Gbps actually means in practice

The 12.5 Gbps figure is IDS/IPS throughput — traffic inspected with intrusion prevention switched on, which is the demanding case. A few practical implications:

  • Your internet service is not the constraint. Even a 10 Gbps business fibre service fits inside that budget with inspection enabled.
  • Internal routing is where it gets used. Inter-VLAN traffic — cameras writing to a recorder, staff pulling from a NAS, backups running between segments — passes through the gateway when it crosses VLANs, and that can dwarf internet traffic.
  • Headroom protects the experience. Running a gateway near its inspection ceiling produces latency and jitter long before it produces obvious failure.

If your requirement genuinely exceeds this — sustained multi-tens-of-gigabits with inspection — the UDM-Beast publishes 25 Gbps, though on the 55,000-signature tier and without hot-swappable power. That trade-off is covered in our UDM-Beast vs EFG comparison.

VPN and multi-site throughput

Ubiquiti publishes per-protocol VPN throughput for the EFG, which makes it unusually straightforward to design a multi-site network against real numbers:

VPN typeThroughputTypical application
Identity Endpoint (One-Click VPN)1.2 GbpsStaff remote access with UniFi Identity
Teleport1.2 GbpsZero-configuration remote access
Site Magic (SD-WAN)1.1 GbpsAutomatic site-to-site mesh between UniFi sites
WireGuard980 MbpsModern, high-performance tunnels
IPsec580 MbpsInteroperating with third-party firewalls
L2TP280 MbpsLegacy client VPN
OpenVPN180 MbpsLegacy interoperability

Site Magic deserves particular mention for Australian multi-site organisations. It builds a site-to-site mesh between UniFi gateways automatically, without manual tunnel configuration at each end — so adding a new branch is a matter of adopting its gateway rather than a night of IPsec troubleshooting.

Ports and connectivity

The EFG's port layout reflects its role as an edge device rather than an access switch:

  • (2) 25G SFP28 — each also runs at 10G and 1G. One is the default WAN; the other typically becomes the LAN uplink to an aggregation or core switch.
  • (2) 10G SFP+ — additional fibre or DAC connectivity at 10G or 1G.
  • (2) 2.5 GbE RJ45 — one is the default secondary WAN; useful for a copper internet service, a failover link or management.
  • Up to 5 WAN ports can be configured for multi-WAN failover and load balancing.

Note what is not there: a bank of access ports. The EFG is not intended to have workstations plugged into it. It hands off to switching, which is where your endpoints live.

High availability and power redundancy

Two independent mechanisms protect availability:

Dual hot-swappable power supplies

The EFG ships with two hot-swappable 150 W CRPS modules. Either can fail — or be deliberately removed — while the gateway continues running on the other. Replacement happens from the front of the rack with no shutdown, no maintenance window and no outage. Feed the two supplies from separate circuits or separate UPS units and you also survive a circuit failure, not just a component failure.

Shadow Mode (VRRP) gateway failover

A second UniFi gateway can run in Shadow Mode as a standby. It stays synchronised with the primary and assumes the gateway role automatically if the primary becomes unavailable — protecting against a whole-unit failure, not just a power supply failure.

Designing for a service-level obligation? The combination of dual hot-swap PSUs plus a Shadow Mode standby unit is what lets you commit to uptime targets with UniFi hardware. It is the single clearest reason to choose an EFG over a Dream Machine.

What the EFG does not do

An honest guide should be as clear about limits as capabilities:

  • No camera recording. Ubiquiti publishes no NVR storage for the EFG. Cameras need a separate recorder — see the ENVR.
  • No PoE. No device draws power from the EFG; access points and cameras are powered by your switch.
  • Only two copper ports. This is not a switch, and it should not be treated as one.
  • No integrated WiFi. Access points are separate — see the UniFi AP range.
  • Rack-only form factor. 1U, actively cooled, 6.5 kg — it belongs in a rack or comms room.

Designing a complete EFG deployment

An EFG is the centre of a system rather than the whole of one. A typical complete design looks like this:

1. The gateway

The EFG at the edge, with the internet service on the 25G SFP28 or 2.5 GbE WAN, and a second unit in Shadow Mode if you need whole-unit redundancy.

2. Core / aggregation

On larger sites, a Pro XG Aggregation switch terminates 25G uplinks and links the access layer, servers and storage.

3. Access switching

PoE switches feed the endpoints — the Pro XG 24 PoE for 10 GbE with 90 W PoE+++, or the Enterprise 48 PoE for 48 ports of 2.5 GbE PoE+.

4. WiFi

Access points sized to density — the UniFi E7 for high-density enterprise areas, with the full range in our access point guide.

5. Cameras and recording

An ENVR with surveillance-rated drives, plus cameras such as the AI Turret. Optionally an AI Key for site-wide AI detection.

6. Management

The UniFi applications run on the gateway; for very large multi-site estates a Cloud Key Enterprise gives a dedicated management server.

Real deployment scenarios

A secondary school (1,200 students, 90 access points)

The morning burst is the design driver — thousands of devices associating within minutes. The EFG's 71,000 new sessions per second and one million session table absorb it, SSL/TLS inspection supports content filtering obligations for minors, and dual PSUs mean a failed supply does not end the teaching day. Paired with Enterprise 48 PoE switches and E7 access points in halls and libraries.

A 180-room hotel

Guest devices churn constantly, each guest expects instant WiFi, and the property cannot take an outage at check-in. Shadow Mode plus dual PSUs protect availability; VLAN segmentation separates guest, staff, back-of-house, PMS and camera networks; Site Magic links sister properties.

A managed service provider

An EFG at each significant client site, all visible from one interface, with Site Magic meshing them at 1.1 Gbps and a Cloud Key Enterprise providing dedicated on-premises management for thousands of devices across the client base.

A logistics warehouse and office

Heavy inter-VLAN traffic between scanners, WMS servers and cameras; 24-hour operation means no maintenance window. Hot-swappable PSUs and Shadow Mode failover matter more here than headline internet speed.

Rack, power and environment

  • Rack space: 1U, 325 mm deep — shallower than most servers, fits comfortably in a wall-mount comms cabinet as well as a full-depth rack.
  • Power: universal AC 100–240 V, up to 7 A, drawing a maximum of 82 W. Feed the two supplies from separate circuits where possible.
  • Cooling: 280 BTU/hr, actively cooled. Rated 0–40 °C, which is worth checking against an unairconditioned comms room in an Australian summer.
  • Weight: 6.5 kg — use rack rails or a shelf, not just the front ears, in a deep cabinet.
  • Setup: a 1.3-inch touchscreen and Bluetooth management make initial configuration possible without a laptop at the rack.

How it compares to other UniFi gateways

EFGUDM-BeastUDM-Pro-Max
IDS/IPS12.5 Gbps25 Gbps5 Gbps
Signatures95,000+55,000+55,000+
Concurrent sessions1 millionNot publishedNot published
Users5,000+7,500+2,000
Built-in NVR40× 4K15× 4K
Hot-swap PSUsYes (2)
Copper ports2× 2.5 GbE8× 10 GbE8× 1 GbE + 1× 2.5 GbE

Read the full head-to-head in UDM-Beast vs EFG, and see how the near-identical UXG Enterprise fits in our rack-mount gateway comparison.

Frequently asked questions

What is the Ubiquiti EFG Enterprise Fortress Gateway?

The EFG is a 1U rack-mount UniFi security gateway for large networks. It inspects traffic at up to 12.5 Gbps with 95,000+ threat signatures on the CyberSecure Enterprise tier, tracks one million concurrent sessions at 71,000 new sessions per second, performs SSL/TLS inspection on up to 10,000 concurrent sessions, supports 5,000+ users and 500+ UniFi devices, and includes two hot-swappable power supplies. It uses an 18-core ARM v8.2 processor and connects via 25G SFP28, 10G SFP+ and 2.5 GbE ports.

How many users can the EFG support?

Ubiquiti rates the EFG for 5,000 or more simultaneous users and 500 or more managed UniFi devices such as access points, switches and cameras. Its one million concurrent session table and 71,000 new sessions per second give substantial headroom for device-dense environments.

Does the EFG record security cameras?

No. The EFG has no built-in NVR storage - it is a dedicated gateway. For camera recording you pair it with a UniFi recorder such as the ENVR, which handles up to 210 HD or 70 4K cameras across 16 hot-swap drive bays, or with a Dream Machine at smaller sites.

Does the EFG have PoE ports?

No. The EFG provides no Power over Ethernet. Access points, cameras and door readers are powered by a PoE switch such as the USW-Pro-XG-24-PoE or USW-Enterprise-48-PoE.

What is SSL/TLS inspection and why does it matter?

Most internet traffic is encrypted, which means a firewall that cannot decrypt it can only see where traffic is going, not what it contains. The EFG can decrypt, inspect and re-encrypt up to 10,000 concurrent TLS sessions, so intrusion prevention, malware detection and content policy apply to real traffic rather than only the small unencrypted remainder. This is often a compliance requirement in health, education and finance.

What is the difference between CyberSecure and CyberSecure Enterprise?

They are Ubiquiti's threat signature tiers. CyberSecure provides 55,000+ signatures and is used by the Dream Machine range including the UDM-Beast. CyberSecure Enterprise provides 95,000+ signatures and is used by the EFG, which also publishes SSL/TLS inspection capacity.

Does the EFG have redundant power supplies?

Yes - two hot-swappable 150 W CRPS modules. Either can be replaced from the front of the rack while the gateway keeps running, with no outage or maintenance window. Feeding them from separate circuits also protects against a circuit failure.

Can I run two EFGs for high availability?

Yes. The EFG supports Shadow Mode (VRRP) gateway failover, where a second gateway runs synchronised in standby and automatically takes over the gateway role if the primary fails. Combined with the dual hot-swap power supplies, this covers both component and whole-unit failure.

What VPN throughput does the EFG deliver?

Ubiquiti publishes 1.2 Gbps for Identity Endpoint One-Click VPN and Teleport, 1.1 Gbps for Site Magic SD-WAN, 980 Mbps for WireGuard, 580 Mbps for IPsec, 280 Mbps for L2TP and 180 Mbps for OpenVPN.

What switch should I use with an EFG?

Because the EFG has only two 2.5 GbE copper ports, endpoints connect through a separate switch. Common pairings are the USW-Pro-XG-24-PoE for 10 GbE access with 90 W PoE+++, the USW-Enterprise-48-PoE for 48 ports of 2.5 GbE PoE+, and the USW-Pro-XG-Aggregation to terminate 25G uplinks on larger sites.

Does the EFG require a licence or subscription?

No. The UniFi Network application and the core security stack run on the hardware with no licensing or per-device subscription fees.

Is the EFG suitable for a small business?

Usually not - it is over-specified for most small sites and expects separate switching and recording. Under roughly 1,000 users, without a requirement for encrypted-traffic inspection or hot-swap power redundancy, a UDM-SE or UDM-Pro-Max is generally the better and more economical choice.

How much rack space and power does the EFG need?

One rack unit, 442.4 x 43.7 x 325 mm, weighing 6.5 kg. It accepts universal AC 100-240 V at up to 7 A, draws a maximum of 82 W and dissipates 280 BTU/hr, rated for 0 to 40 degrees C ambient.

Where can I buy the Ubiquiti EFG in Australia?

ARC IP Networks supplies the EFG in Australia as an authorised Ubiquiti reseller, with genuine Australian stock, full manufacturer warranty, GST tax invoices and fast Australia-wide shipping or free Melbourne warehouse pickup. View the EFG or call 1300 100 440 for project pricing and design assistance.

Buying the Enterprise Fortress Gateway in Australia

ARC IP Networks is an authorised Ubiquiti reseller in Australia. We hold deep local stock across the UniFi range, so most orders ship the same or next business day from Australian warehouses — not on a four-week wait from an overseas grey-market seller.

  • Genuine Australian stock with full manufacturer warranty and local RMA support
  • Competitive pricing — our prices are monitored against the Australian market daily
  • Fast Australia-wide shipping, or free pickup from our Melbourne warehouse
  • GST tax invoice on every order, with trade accounts available
  • Volume and project pricing for integrators, schools, MSPs and enterprise rollouts

Our team can size a complete EFG deployment for your site — gateway, switching, access points, recording and drives — and quote it as one project. Talk to our team on 1300 100 440, email info@arcip.com.au, or read more about buying from an authorised Ubiquiti reseller in Australia.

UDM-Beast vs EFG: Hyperscale Throughput or Enterprise Resilience?
25 Gbps vs 12.5 Gbps, 55,000 vs 95,000 threat signatures, built-in switching and NVR vs hot-swap power redundancy — the two flagship UniFi gateways compared.