# Network Optimizer for UniFi: self-hosted Wi-Fi scoring, security audits and ISP health

> Network Optimizer is a self-hosted C# application that audits UniFi networks, scores Wi-Fi health, recommends channels and runs centralized speed tests. It is aimed at homelab operators and MSPs, and its free tier stops at three sites.

**Ozark-Connect/NetworkOptimizer** — Self-hosted optimization, monitoring (NMS), and security audit tool for UniFi Networks. Includes Wi-Fi Optimizer for wireless health scoring and channel optimization, advanced DNS/VLAN/firewall security checks, config optimization suggestions, centralized WAN and LAN speed test server w/ L2 tracing, CM, ONT, SFP, 5G modem stats +more.​​​​​​​​​​​​​

- Repository: https://github.com/Ozark-Connect/NetworkOptimizer
- Website: https://ozarkconnect.net/network-optimizer
- Stars: 1,027 · Forks: 35
- Language: C#
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/ozark-connect-networkoptimizer

## What Network Optimizer adds on top of a UniFi console

A UniFi console already shows clients, traffic and device health. Network Optimizer's pitch is that the console only tells you so much: client stats arrive on the console's own schedule, roams are reported after the fact, and traffic that never crosses the gateway is invisible. The project wraps that data in scoring and recommendations. The Wi-Fi Optimizer grades health issues, Channel Recommendation proposes channel and width changes, and Security Audit runs DNS, VLAN and firewall checks that the console does not perform on its own.

The audience is narrow and clearly stated. The README addresses people running an MSP with client networks, a few business locations, or a home network plus sites they keep an eye on. Multi-site management from one server is a first-class feature, not an afterthought. If you have a single UniFi gateway and no interest in scoring or auditing, the console is probably enough and this adds a service to maintain.

## How the on-site agent and the single HTTPS tunnel work

The recommended way to bring a remote site online is a lightweight on-site agent that dials home to your self-hosted server over one outbound HTTPS tunnel. Nothing inbound is required, there is no port forwarding, and the README states it works behind CGNAT. The agent proxies that site's probing, SNMP, UniFi Console access and device SSH over the tunnel, and each site's data is kept separate. The agent is described as roughly 50 MB in practice, small enough to run directly on the site's UniFi gateway.

Sites already reachable over a site-to-site VPN can be onboarded with no agent at all. That path still gives security audits, Wi-Fi and channel optimization, performance tweaks, Adaptive SQM, WAN steering and SNMP device health. What it does not give you is the monitoring and performance layer: ISP Health, path discovery, latency and loss, and speed tests. Those need the agent, or a site the VPN does not reach.

AP Telemetry is a separate, opt-in mechanism. A small agent is pushed to each access point over SSH, runs in memory, survives reboots and firmware updates, and is removed everywhere when the feature is turned off. It supports U6 and U7 access points. The README claims signal and rates update twice a second, and that a laptop copying files to a NAS shows its real throughput where UniFi Network reported it idle because nothing crossed the gateway. Those are the project's own claims; nothing here was measured independently.

## Installing Network Optimizer with Docker and running a first audit

The README links a Quick Start section for Linux and Docker, and a separate deployment guide under docker/DEPLOYMENT.md. The repository ships a docker/ directory and a NetworkOptimizer.sln solution file, so the container image is the intended path. Windows downloads are also published on the releases page. The exact compose file is not reproduced in the README excerpt, so read docker/DEPLOYMENT.md before writing your own.

Once the service is reachable, the first useful action is a security audit, because it needs no agent and no speed-test server. Add your UniFi console credentials in the web interface, then run Security Audit first and Wi-Fi Optimizer second. If you want ISP Health, path discovery and speed tests, install the on-site agent next; the agent guide at src/NetworkOptimizer.Agent/README.md walks through that installation.

Licensing is configured under Settings > Application > Licensing. Personal, non-commercial use on up to three sites needs no key and nothing phones home. Commercial use or more than three sites requires a key, and activating one makes an outbound HTTPS request to licensing.ozarkconnect.net, so allow HTTPS on port 443 to that hostname if you run strict egress rules. The README states that a licence server outage never disables your sites because entitlements are cached and verified locally.

## Where Network Optimizer stops being the right tool

The licence boundary is the first constraint. Free use covers personal, non-commercial deployments on up to three sites. An MSP with a book of client networks is explicitly commercial and needs a key, which means contacting the maintainer by email for a licence or trial. That is a manual step, not a self-service checkout, and it is worth knowing before you build a workflow around it.

UniFi is the second constraint. Every feature described in the README depends on a UniFi console, UniFi access points or both. AP Telemetry supports U6 and U7 access points specifically, so older APs do not get the twice-a-second client view. There is no indication of support for switches, routers or access points from other vendors, and the security audit checks are written against UniFi's DNS, VLAN and firewall model.

The third constraint is operational. The agent model is what makes CGNAT sites work, but it also means the agent is a component you deploy and keep running on each site, either on the gateway or on a separate box. The README describes the agent as light, around 50 MB, but it is still software on your gateway. The README does not document rollback for a failed agent push or for an AP Telemetry agent that misbehaves, beyond stating that turning the feature off removes it everywhere.

## Network Optimizer compared with a general-purpose NMS

A general-purpose monitoring system such as Zabbix or LibreNMS takes the opposite approach. It is vendor-neutral: you add devices over SNMP, write or import templates, and build your own dashboards and alert rules. It will monitor a UniFi gateway alongside a MikroTik router and a Brocade switch, and it will keep doing so for a decade.

The trade-off is that a general NMS knows nothing about UniFi's specific data model. It will not score Wi-Fi health, recommend a channel width based on a week of client usage, or tell you whether high airtime utilization is yours or a neighbour's. Those judgements require reading the console's data the way Network Optimizer does. Conversely, Network Optimizer will not monitor your non-UniFi gear, and it will not replace a general NMS if your network is mixed-vendor.

If your whole network is UniFi and you want recommendations rather than raw graphs, Network Optimizer is the more direct fit. If you need one pane of glass across vendors, keep the general NMS and treat Network Optimizer as an addition scoped to the UniFi side. Running both is a legitimate configuration; the overlap is device health and SNMP, which both will report.

## Maintenance, releases and licence implications

The repository is not archived, and the last push was on 2026-09-10. Releases v2.8.3, v2.8.2 and v2.8.2-preview2 all landed within two days of each other in early September 2026, which indicates an active release cadence at that point. A renovate.json file at the repository root suggests dependency updates are automated, and the presence of a TODO.md and a CODING_STANDARDS.md suggests the project is maintained with some process.

Upgrade cost is mostly the container image plus, for agent sites, the agent on each gateway. The README does not describe a migration path between major versions, and it does not document rollback for the agent or for AP Telemetry. Plan to read the release notes for each version before upgrading a production site.

The licence is shown in the README badge as BSL 1.1, while the repository's licence field reports NOASSERTION. Those two signals disagree, so read the LICENSE file directly rather than trusting the badge. BSL 1.1 is a source-available licence with terms that typically change over time, and the README points to a pricing and licensing page for the commercial terms. This is not legal advice: if you intend to use it commercially, read the licence text and the pricing page, and contact the maintainer with specific questions.

## Conclusion

Adopt Network Optimizer if you run UniFi gear at a handful of sites and want Wi-Fi health scoring, channel recommendations and security checks in one self-hosted place. Skip it if you have no UniFi console, or if you need a vendor-neutral NMS that also covers switches and routers from other brands. Before committing, verify the licence terms on the pricing page against your own site count, confirm that HTTPS egress to licensing.ozarkconnect.net is allowed if you activate a key, and check the agent guide if any site sits behind CGNAT.

## FAQ

### Is Network Optimizer free to use?

Personal, non-commercial use on up to three sites is free and needs no key. Commercial use or more than three sites requires a licence key, configured under Settings > Application > Licensing.

### Does Network Optimizer work with UniFi equipment?

Yes. The project is built specifically for UniFi networks, reading data from a UniFi Console and, for AP Telemetry, pushing an agent to U6 and U7 access points over SSH.

### How do I install Network Optimizer?

The README points to a Quick Start for Linux and Docker and a deployment guide at docker/DEPLOYMENT.md. Windows downloads are also published on the releases page.

### Will Network Optimizer keep working if the licence server is down?

According to the README, a licence server outage never disables your sites, because entitlements are cached and verified locally. Activation itself makes an outbound HTTPS request to licensing.ozarkconnect.net.

### Can I manage several sites from one Network Optimizer instance?

Yes. Multi-site support is a core feature, and the recommended approach is the on-site agent, which dials home over a single outbound HTTPS tunnel and keeps each site's data separate.

## Sources

- [Issues](https://github.com/Ozark-Connect/NetworkOptimizer/issues)
- [Ozark-Connect/NetworkOptimizer on GitHub](https://github.com/Ozark-Connect/NetworkOptimizer)
- [Project website](https://ozarkconnect.net/network-optimizer)
- [README](https://github.com/Ozark-Connect/NetworkOptimizer/blob/main/README.md)
- [Releases](https://github.com/Ozark-Connect/NetworkOptimizer/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ozark-connect-networkoptimizer
