How we solved our office Wi-Fi problems
triplebyte.com
triplebyte.com
Am I missing something, or did they buy consumer routers to use as access points?
Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each other, to help hand off clients between them. All channel management will be by the devices working together, they can throttle down power if they are causing each other interference. I cant even begin to list all the different benefits with a single set of settings vs devices that dont work together. Even an asus aimesh network would likely be better. Youre asking for a troubleshooting nightmare.
You can either pay a couple hundred a year for the management interface, or $80 for an on prem tiny little stick that hosts it. (paying for the cloud hosted one, has its benefits, and is my recommendation.)
Access Point - https://unifi-hd.ubnt.com/
POE Switch - https://www.ubnt.com/unifi-switching/unifi-switch-poe/
Management Interface - https://www.ubnt.com/unifi/unifi-cloud-key/ OR Cloud Management https://unifi.ubnt.com/
Router - https://www.ubnt.com/unifi-routing/usg/
You should never need to track down or log into individual devices to configure them.
I dont mean to be a complete ballsack, but isnt it weird for a company thats mission is matching talent to problems, to fail to find the talent to adequately address their problem, and to be giving authoritative (mis)advice on something they are not remotely domain experts in. It doesnt seem like the best advertisement.
That said, this is the KIND of post companies should be making when their seo expert says to use keywords. Good job writing about improving the internals of your company, and not just what your company does. Write a V2 of this post once you upgrade, and rename the old one, "How we Created (and then mitigated a Device Management and Troubleshooting Nightmare)
Unfortunately because they're primarily in the business of slapping a slick web interface on Vyatta they don't have the skill required to debug the hardware acceleration. They don't have a single clue how to get RADIUS to work with their fork of Vyatta. And their support is fine for a home lab situation.
And let's not speak of the chronically overheating stuff.
Some-time wireless installer here, I bring a snippet of anecdata.
A recent client had the full Unifi experience for an outdoor network, including 3x EdgeSwitch XP (formerly known as ToughSwitch) in a single IP65-rated, largely airtight enclosure.
The network would go offline on summer afternoons. It was overheating, those models run hot and are not recommended for low ventilation areas, but they weren't convinced.
I fitted a thermometer, went back three days later and checked the logs. The temperature peaked at 143 Celsius.
Every day, cut out. When it cooled down, it worked again. This continued for about two months, then they failed.
Most electronic devices say operate between x and y degrees and if in full sunlight the temp may have exceeded y, which in a device that generates heat itself led to runaway overheating?
Either way plastic could melt at that temp and you'd definitely burn your hands touching it. Pretty crazy.
I assume the soldered innards failed, though I never did open it up to check properly.
This sounds like unrealistic expectations and a poorly designed implementation.
But that's exactly what "anecdote" means already, why change it?
I'd say that Ubiquiti is perfectly suited for a small business environment -- definitely a big step up from discrete consumer Asus routers throughout the office with no central management (and probably haven't been patched since the day they were installed).
Ubiquiti may not be suitable for a mid to large sized business, but for up to a ~100 person office or so, they come in at a great price point and have decent performance and manageability.
Just because patches are available, doesn't mean that someone's going to take the time to apply them. Having a central management console makes this much easier. Upgrade one node, make sure it works, then roll out to the rest of the nodes one by one with one click.
They run an embedded Mongo DB on their UniFi hardware that (at least in the deployment I've inherited) requires occasional direct interventions[1] to keep running. That's just one example of the many baffling/wrong things they do.
I know Mongo gets quite a bit of undeserved hate, but it really just doesn't seem suitable for this use case.
[1] https://help.ubnt.com/hc/en-us/articles/360006634094-UniFi-S...
We have dozens of WAPs under management across the city and state, and I've never seen any of the issues you guys are talking about. We don't have issues with database crashing or overheating. The wap controllers are configurable for automatic firmware updating, so I don't know what the issue is with patching. They definitely support wpa-e/radius because I've configured it and we use it in my my office.
A personal goal of mine is to buy a unifi wap and a modem (already have a router and firewall) and divorce from ISP equipment altogether. Then I can start posting on /r/homelab :)
Sure, and problems with RADIUS auth have been well documented. How much of the not seeing issues is simply a matter of users assuming your setup (or their phones or computers) is flakey? Issues with Mongo are also pretty well documented.
https://www.google.com/search?q=ubnt+mongo+issue
> The wap controllers are configurable for automatic firmware updating, so I don't know what the issue is with patching.
The issue with patching is that Ubnt is in a bad position. They're on their own completely to create and issue patches even for stock packages. That's just what happens when you distribute EOL'd software. So, sure, it's not that hard to apply patches* from Ubnt but it's a lot more work for Ubnt to generate these patches — and last I checked they were pretty well behind with the excuse of "there are no known exploits for ABC in the wild".
* Let's not forget the ER-X bootloader for which end users are entirely on their own. Ubnt has a patch but hasn't applied it to the devices they ship. It's just lazy and sloppy.
(I'll see myself out...)
My experiences aren't wrong, of course, but it's an apples to oranges comparison. My IT MSP is only small to medium sized businesses (as I think all IT MSPs are since Enterprise level environments don't contract out it and hire their own department - this is an educated guess). We do very little Enterprise work and have no single client with more than 300 users.
However, I will defend my position and consumer grade ubiquitis on a (significant) technicality. Higher models beyond what my company sells are not cost effective. Buying higher grade waps at no less than double the price is more expensive than just running cables. If you WANT to make everyone get 200mbps wifi, you will pay for it, but that's a convenience you pay for, not a requirement. UAP-AC-Pros are perfectly capable of handing out up to 50mbps pipes to multiple endpoints without huge (or even medium) upfront capital investments, overheating or DB problems. In my opinion, just run cat6 lines. Itll be cheaper than spending thousands on Enterprise waps for only 30 people.
We could never fix it and switched over to google appliances. We rarely have over 20 people in the office.
I found it weird that the UniFi line of products and the EdgeMAX line of products while very similar in terms of specs and their target markets, use completely different remote management systems (UniFi vs. UMNS).
While some really folks like their management GUI, I found that once you wanted to do anything not bog standard with it, you were on your own. I had to SSH into both devices and enter EdgeOS (Vyatta) commands for even relatively simple things like disabling NAT on the ER4 or configuring mutual TLS with OpenVPN. With IpSec there are so many different possible parameters that the GUI just didn't have enough widgets to cover them all.
I found the USG security gateway too underpowered for my purposes. I wanted a device I could use for IDS/IDP as well as a dedicated VPN. With hardware offloading disabled (which you need for IDS/IDP) the throughput of the USG is limited to around 130 Mbps.
Using IpSec on the USG (ESP:AES-128-SHA1) I was able send (encrypt) data at 70 Mbps and 56 Mbps on receive (decrypt). Don't even think about using OpenVPN with this device, as it's single-threaded and can't take advantage of any crypto offload -- only managing around 14 Mbps of throughput.
If you are using the USG for a VPN you can get much better performance with WireGuard. I managed to get 90 Mbps encrypt, 111 Mbps decrypt with it, which is likely good enough for a lot of folks.
The EdgeRouter4 was faster, but it had a weird issue with IpSec. I was able to get it to encrypt at 631 Mbps, but only decrypt at 229 Mbps. On encrypt (send) I could see that the CPU was 376% utilized (it has 4 cores) with most of that spent dealing with software interrupts. On decrypt (receive) it only 167% utilized -- so something was wrong there.
The EdgeRouter4's OpenVPN single core performance was more than 3x faster than the USG, clocking in at 43 Mbps, and best with WireGuard at 636/597 Mbps encrypt/decrypt.
I used iperf3 on a remote host on my simulated WAN for measuring throughput like:
iperf3 -c host_behind_router -P4 -t120 # decrypt
iperf3 -c host_behind_router -P4 -R -t120 # encrypt
Ultimately I found the whole dance of having devices being adopted by the controller software and then being provisioned by it to be tedious and unnecessarily faffy -- especially considering how often I had to drop into EdgeOS to get things done.https://unifi-xg.ubnt.com/usg-xg-8
https://www.ubnt.com/unifi-routing/unifi-security-gateway-pr...
What would you suggest instead?
At some level, you really do get what you pay for. They are great for people who want to set up a "homelab" without learning anything about actual networking, though.
Tell you what. I used to have a Mikrotik CRS125 switch in my home office, and by default if you have a set of ports where one has no VLAN assigned, and the others have untagged VLAN assignmnets, any broadcast traffic on the untagged port(s) without a VLAN leaks to the ports with an untagged VLAN. This isn't well documented in the manual, and to fix it you either disable "Invalid VLAN Forwarding" (I think) and/or move said ports without a VLAN to a VLAN.
https://community.ubnt.com/t5/UniFi-Wireless/UniFi-AC-AP-iss...
Never really trusted their other product lines.
How would you compare Microtik to Ubiquiti?
I'd imagine pretty much any network vendor doing business in the enterprise sector (e.g. HP, Cisco, Juniper, Dell, etc, etc)
> Can you point to a specific example of them not fixing a security issue that was addresssd by others?
I haven't looked recently, but when I last updated my ER-X I noticed that the latest available packages included a large number that were not up-to-date with the latest available security fixes.
One of the problems is that the version of Debian that the hardware (MIPS) Ubnt uses is end-of-lifed on the old version of Debian that EdgeOS is based on. Where most vendors could simply track the official Debian repositories, Ubnt is stuck rolling their own packages. If Ubnt has finally moved on to an officially supported version of Debian then this is less of an issue.
This is one of those I wish I had a better solution moments. For the home user this may not pose a challenge, but in a business environment I'd say that it's probably worth spending the big bucks on a vendor with a better track record. That's not to say there aren't other bad vendors, but it is to say that Ubnt gear does not belong outside of a home lab.
I haven't evaluated Mikrotek because the Ubnt stuff works well enough (but certainly not great) for me in the two locations I've got it deployed.
Ubiquiti EdgeRouter Lite (not ER-X) is apparently supported by vanilla OpenBSD.
The issue has more than one dimension. Apart from them being nice and auditing now, there is still the fact that their internal processes have allowed (and probably encouraged) stashed passwords in such a manner that 6 of them has been found in a really short time. Unless your process is total garbage you don't end up with 6 backdoor passwords like that without knowing it.
So for any company that prides themselves with having a device in the middle of LOTS of networks, its a very poor track record to figure out security and backdoors don't really mix in 2018.
The ER-L is what I spoke of when I referred to the chronic overheating problems. From a different reply to my comment it sounds like there may be other Ubnt devices that suffer the same fate. The ER-L also has issues with reordering UDP packets.
Imo ubiquiti works fine for smaller offices. If you don't have enough people to justify an IT org it makes sense.
Disagree, and not just because of the GPL violations and security issues. There are enough subtle bugs (e.g. data corruption with hardware acceleration) and design flaws (e.g. overheating) that you are setting yourself up for intermittent bugs (a.k.a. trouble) if you don't have someone well versed in diagnosing network issues. It's powerful enough to do fun things in a home lab, but it's way too complex for a professional setting where there's nobody around with the skills to troubleshoot it.
Enterprise gear is expensive, yes.
EdgeOS is a Vyatta fork. Has Ubnt abandoned EdgeOS? It's been a few months since I've looked, but the version of Debian that's being used was end-of-lifed on MIPSLE hardware a while back so security updates are entirely incumbent upon Ubnt. There is no upstream support.
Which offerings are on OpenWRT?
Their Unifi APs have option of a LEDE based firmware option, but think it is just beta at the moment. You can choose between the LEDE version and the regular version.
Ars' article[1] was the thing that pushed me over the edge and don't regret it at all. Rock solid APs, central management, isolated vlan+ssid just for IoT, just all around good. Was about $300 to get all setup and outstripped all my "pro-sumer" gear by miles.
[1] https://arstechnica.com/information-technology/2018/07/enter...
The very start of a strong network is a solid Dynamic DNS + DHCP setup. The only IPs that should be static are the router's.
In a small office, using your firewall/router is not a bad choice to DNS+DHCP. For companies < 100 and WAN connections <1gig pfsense is perfect.
Segment your APs and servers etc into different VLANs with distinct IP pools, bonus point for different subdomain. This allows your to firewall it off to prevent prying eyes. It also means that if something were to get into your VPC, and then over the VPN, they can't fiddle with your APs quite so easily.
As for ethernet always buy in cables, but get good sockets and patch panels. It is worth the money to hire a wireman/woman to do that for you. Unless you've been practising its a long boring slog, time you should be spending doing your real job....
Ubiquity again is a solid choice for wifi. I've deployed ~50 to cover 1800 person office. Beware, the non "pro" versions of the APs don't use proper PoE, so you'll be stuck either using their injectors(ok for small places) or buying their switches.
SOme of the pro APs have built in speakers (https://www.ubnt.com/unifi/unifi-ap-ac-edu/) which might be fun. They have proper PoE too, so you can use a real switch.
I agree though, all my APs run on DHCP.
I would love at least a gateway/cloud key combo to simplify things. The separate switch doesn't bother me as much though.
Had to modify it to mount bind a shared cert location.
I'm currently commandeering a R-Pi as a controller, but I tend to misplace it when it gets pulled into other projects.
I installed an Amplifi AP/Router at my parent's house. It works absolutely phenomenally for their use case, but is basically plug and play. The Ubiquiti gear is worlds more configurable.
The gen2 cloud keys don't do that, although the gen2 plus model merges the cloud key and NVR appliance into one device.
The fact that I can run VPN/Wireguard/Basic Network apps on my router is fantastic. If I ever get tired of the range (which is only an issue in my garage on the other side of the house), I'll simply get another AP.
The biggest issue was range, which was much worse than what I got with I had with a traditional consumer access point (I had a TP-Link Archer C7.) It was not even close.
The handover didn't work very well either. Much older UniFi products used Qualcomm wifi chipset which had excellent hand-over, the later versions used Broadcom which didn't have that yet.
I replaced everything with Eero, which just worked.
The AmpliFi product line of Ubiquiti supposedly offers similar features as Eero, but that didn't exist yet when I made the switch.
A lot of work can go into making WiFi work well.
With multiple APs you've got to adjust the Transmit power (defaults to Auto, which means High, which is generally bad). For good roaming, increasing the minRSSI is critical. 5G and 2.4G have very different propagation characteristics so they need to be optimized individually. With several APs you may even want to disable 2.4G on some of them.
Band Steering may or may not play nicely with the devices you have. Some devices have trouble if they can see many APs advertising the same SSID -- Ring Doorbells are notorious for not being willing to associate to an SSID at all if many APs are advertising the same SSID.
At my old house I got away with one AP placed centrally in the attic and another in my detached garage. At my new house, at about 2.5X the size, I'm running 5 APs and it has taken me a solid month of fiddling to get my devices consistently associating to the best AP and roaming appropriately.
This! I thought the UAPs sucked until I played with transmit power and especially min RSSI.
I’ve been using the UniFi line for about a year now, covering the whole property and house in rock-solid WiFi. It took a few hours of walking around with a laptop and tinkering with settings/placement but I couldn’t be happier now.
At work I have a two sites of Unifi with cloud keys and an edge router. All visible on one management screen and super easy to configure.
Fabulous kit. Make sure you take a backup of the cloud key btw, they can get corrupted by a power interruption, and then you have to install from scratch. You can do this from the browser.
I wanted to caution people who are choosing Mikrotik at home. A lot of network engineers find their interface a bit weird, and by default they have way too much open on their public interfaces. I have seen one in the process of being brute-forced from ssh, that was installed by a qualified Mikrotik installer. If you want to plug and play the Unifi routers are a better option. Many have packet inspection features built in too.
If you have truly symmetric 1 Gbps full duplex at home maybe you need the capabilities of an RB4011. But you should learn how to lock down its WAN facing interface.
The ubnt EdgeOS based devices are based on a fork of Vyatta. Ubiquiti hired most of the Vyatta software development team years ago when Brocade acquired Vyatta (the corporation). Ultimately they are little tiny Debian based boxes, since that's the foundation vyatta was built on.
Home/Offsite - https://www.ubnt.com/unifi-routing/usg/
Office - https://www.ubnt.com/unifi-routing/unifi-security-gateway-pr...
Large Office - https://unifi-xg.ubnt.com/usg-xg-8 (sweet 1U screen!)
$110, and same management interface as the AP's and switches. As you can tell, im prioritizing all-in-one management very heavily. One, managed, cloud, location for all my devices (minus sdwan, hosted by that vendor.) But the USG can do Auto IPSEC, so if you have 5 of them, you can tell all 5 to automatically keep connections to each other open. I havent fully tested a complex mesh of USG's yet, but id like to. It's getting close to even sdwan being expensive, compared to what these things can do.
One of the things I like the least about the Unifi management interface, is having to edit each site separately. If i want to make a router or ap/ssid change, I have to open each site.
They used to. Since about a year or so ago, the public interface is so completely locked down by default that I've heard people wondering if they've bought defective units (because they're trying to access management through eth1.)
SEO at its finest.
UniFi does not do this. At all. The Auto settings are the same as basically every other commodity AP out there -- look for the least noisy channel at boot, transmit full power, allow any client to remain associated regardless of signal strength.
UniFi has an ok tool for on-demand RF scans. It has all the appropriate knobs to tweak for optimizing coverage and encouraging devices with weak signal to associate with a better AP. But you have to do all of that yourself. Manually. Trial-and-error. There's absolutely no magic there.
Well, with the one exception which is the Cloud Key. I’ve yet to see it run for more than 24 hours before soft rocking and requiring a total re-setup of the network.
For those who have never touched a Ubiquiti, configuring it could be a little iffy . I normally advise setting up DHCP 43 advertisement on the router before trying to setup the access points.
But seriously, this stuff scales.
As long as you aren't exposing the device itself to the internet, you should be safe from most exploits if your LAN is semi-trusted.
What are your considerations for not choosing Ubnt for routing?
- When it comes to SFP, UBNT's wired gear is unreliable. See https://community.ubnt.com/t5/EdgeRouter/EdgeRouter-X-SFP-le... for an example.
- My only experience with UBNT's support was exceptionally poor. When I ran into the above issue, I was using a third party SFP module and support stonewalled me, saying I had to buy one of their modules. They wouldn't loan me one or guarantee a refund if the module didn't resolve the issue. Unsurprisingly, buying their module didn't help at all (though they finally let me RMA the equipment).
Mikrotik's gear has been solid for me. Zero problems whatsoever.
quick question - why do you need windows/wine for mikrotik ? we use the cli commands through the web console.
in fact we dont have windows in the office. granted you may be doing something more advanced than us, but curious to know.
If you buy the APs individually, they come with power injectors, if you buy a 5 pack, they dont and its easier to home run back to a single switch. Less things to get unplugged.
https://blog.mikrotik.com/security/winbox-vulnerability.html
Or if you happen to have your own hardware on premises a unifi controller on debian can be a really small Xen VM that runs at an average load of 0.02, your xen or KVM hypervisor can be as small as an Intel NUC stuck to a plywood board on the wall of a telecom room in the building.
Unifi absolutely has flaws and missing parts that are easy to run into if you push into more powerful aspects of networking, but overall it's a delightful foundation, and critically to me was the feature of zero online dependencies. I feel like that's the Net at its best, a smooth progression from your own random kit all the way up to multi region failover hosting or whatever but purely based on bandwidth/uptime/maintenance/cost considerations, never any permanent ties. Can centralize/decentralize/move around/selfhost/colo/contract out at will. Unifi can match where you're comfortable with, is has pleasant pretty safe defaults, and they're great about long term updates and support. At the end of the day I can forgive a lot over that, particularly given the contrast it is with so many other offerings.
That's also a good point, the reliability is solid and things won't fall apart even without a controller. That said the controller is necessary for certain nice extras like stats, guest portal, etc. Granted the average HN crowd may have other appliances or systems to manage that, and plenty of people do use a controller locally installed on a notebook purely to adopt and setup APs and then never worry about it again, but given how cheap the minimal VM needed would be or Ubiquiti's local "cloudkey" (worst name ever, has nothing to do with the cloud, it's just a stick computer dedicated for this), I think it's worth considering having a controller running if someone was going that way anyway. Might as well have the management console up all the time. My only point was that running it is highly, highly flexible.
UniFi Cloud Controller
$299.00/year for up to 10 devices
$498.00/year for up to 20 devices
$697.00/year for up to 30 devices
+ $199.00/year per 10 additional devices
When I include my time, one less things to break or be misconfigured, one less vendor involved, etc... $299+ a year is worth it vs $120 a year + AWS/Azure, but if youre trying to do it on the cheap, I agree with you.
Does the Unifi mobile app work with the setup you described?
You can easily control 50 to 100 ubnt APs on the cpu, ram and disk resources of a $10/month VM. Big difference between like $700-900/year and $120/year.
However I am more in favor of having the unifi controller on the same premises as the APs, or at least in the same metro area network as the APs, in your own private network. Just throwing the L3 management option out there for people who truly want 'cloud' hosted everything.
But when your premise is MANY sites across the country, and you are using a single controller, only ONE site gets the controller on prem, OR you have many controllers running.
>Big difference between like $700-900/year and $120/year.
At the end of the day, it comes down to what my time is worth doing other things (not how much im paid, but the opportunity cost of me managing management interface infrastructure, stability, and resources. Unifi cloud, for lack of a better phrase, just works.)
yes, totally agree, in that sort of scenario with many premises you would set up your own internal L3 management of the APs, in your own management VRF, in RFC1918 IP space.
That said, I'd like to provide one caveat: In my experience, they tend to not do great in very noisy RF environments. Twice now I've deployed Unifi APs in offices with RF spectra similar to what the OP has going on, and we had nothing but problems. In each case, we ripped out the Ubnt gear, replaced with equivalent Ruckus APs (with their cloud controller) and haven't had a single problem.
I admit this is not a large sample size, but thought it worth mentioning.
I'm not an RF design engineer, but for this type of equipment, I do feel like there's some truth to "you get what you pay for". It's plain to me that the Ruckus APs have superior RF front-ends that are better able to deal with the noise. They're more expensive than Ubnt for sure, but that extra cost was very much worth it for us, to avoid the frequent disconnects that the users were having to deal with.
At NAB we're often the only booth with functional WiFi. Not using anything special really, just well configured UniFi mesh APs.
https://www.reddit.com/r/openwrt/comments/515oea/finally_got...
Is this still valid? If so, it seems quite doable if your already comfy SSHing into your router.
…or download it (no cost), put it on a desktop/laptop running Windows, macOS or Debian/Ubuntu, and use it when it's needed.
Or save more and put it in a Pi. If you have no idea what your doing it’s a great intro into the world of networking, ssh, Linux and docker, Ansible etc. But yes, this loses the cloud features.
Before I got deeper in the Unifi ecosystem, I just ran the controller on Windows when I needed to (when I only ran 2 APs -- in that case, you only needed an always-on controller if you wanted to run the captive portal).
An office of 30 people sharing 3 APs will encounter problems even if those same APs would have worked just fine for a family of 4 living in the same space.
I've even found this to be true in a residential setting with consumer APs, where reducing the number of devices (by plugging into wired ethernet things that don't often move, such as media players and printers) tends to improve range and throughput for others, without adding more APs.
I'm not suggesting that there's necessarily value in "managed", but your parent comment was about the Ubiquiti product being overkill, which is a much broader statement.
The GP certainly advocates for management, but that's neither the primary value delivered by the overall product, nor the majority cost (even with a single AP). IIRC, this may not hold for competitors, such as Ruckus, where even the lowest-end "controller" is quite pricey.
> wifi should function without the need to phone home.
AFAIK, Ubiquiti's products can be run standalone, only requiring management software for initial configuration.
This is correct. I only power on the controller VM when I want to make a change. I do think a few features, like the captive portal require the controller to be online.
I know it's not a common setup, but some of the ISPs that do fiber to high-rises offer that.
On the cable termination part: I've (mostly) stopped crimping cables because I've had too many go flaky and don't have 4-5 figure testing equipment. One thing I'll add is that there are ends for solid conductor and stranded, make SURE you have the right ones for the cable you are using.
These days I always just put on keystone ends and then use commercial patch cables from there. I've had very good luck. I'd recommend against the advice to use a screw driver to punch them down, the Leviton ones I prefer you just put the cap on and they punch down themselves. The random ones I get from Ace Hardware have a little punch tool included.
One additional recommendation I have is to put 5GHz radios in each space. 5GHz has more spectrum, and less interference, but it penetrates drywall significantly worse. But that's a good thing, because it cuts down on interference from your neighbors.
Beware of microwave ovens, baby monitors, cordless phones (last 2 more in residential areas). They can be intermittent interference, and won't show up on the non-commercial spectrum analyzers. Our 2.4GHz used to go out when we'd run our brand new microwave. But it would also go out at other times, possibly when a neighbor ran theirs? 2.4GHz penetrates buildings quite well, which kind of sucks.
My credentials: https://www.tummy.com/articles/pycon2012-network/
I just redid a lot of the ethernet wiring in my house, and it's super easy compared to how I did it 10+ years ago.
If you use EZ-RJ45 jacks (the only way to go, imo), it's super easy to get cables working properly the very first time. The wires feed through the jack so you can verify wire order before crimping.
I spent less than $200 on the tools I used to do my wiring:
* EZ-RJ45 crimper
* RJ45 cable tester with probe and toner (this was easily the most important tool I bought)
* Punchdown Tool
* An adjustable Cat 5 stripper
Out of the several cables I did, I only had one with problems, I wired one end backwards (it was before I had my morning coffee), and it was quickly "debugged" with my cable tester.
I've installed a few (and have a few more to install) of the Ubiquiti cameras, and I've been using keystone at the end and then patch cables. That has worked well, but I'd be tempted to just crimp the outside end. I'd have to see how the shielding works with the crimping, that gear is all on shielded cable per spec. Shielded plenum rated cable is kinda spendy...
For my outdoor cameras, I used outdoor rated cat6 solid. It's a little harder to work with, and I had to buy a spool of 1000 feet because the 500 feet spools were out of stock when I needed them.
Are you using back boxes? I think it would be extremely hard to use keystone and patch cables given how little room the cameras have for running the cables, especially the G3AFs with the shielded cables if you are not using back boxes.
This is all the G3 Dome, they didn't have anything else when I bought the cameras. I thought about putting a G3AF mounted from the upper eaves to get another view, but haven't done that yet. That'll be a bit more of a project.
I'm fairly happy with the setup, but it's kind of a bit flaky. The motion detection fires all the time, with wind blowing trees or the like. Then it'll sometimes cut off in the middle of a recording when it seems like it should be detecting motion. I've been wanting to put an SSD in their little appliance, or just migrate that appliance to a Ubuntu host of my own, but haven't done that yet. The hardware seems solid, but the software seems flaky.
A coworker has the Nest cams and those seem to be a bit less flaky. I may need to reevaluate this before I go further in, and it's been a year, maybe there's something else I should look at.
The motion sensing is quite sensitive and there's no machine learning behind the analysis like there is with Nest. I prefer the Unifi Video's motion sensing set up over that of Zoneminder which I was using before.
I find myself creating less-sensitive motion sensing zones where I know there are plants/trees that are going to blow plus where they might cast shadows.
The "before" and "after" settings for motion detection are pretty important if you think your footage is getting cut off at the beginning or the end of the clip. I use a setting of 5 seconds.
Since I came from crappy wifi IP cams, I've been very happy with my setup.
I'm currently using an inexpensive NUC as my Unifi Controller and NVR. I have four cameras recording on motion sensing (the others are for monitoring only). The only time I have issues is when I run Duplicati in the background to backup the video files to a NAS. Duplicati is a bit of a pig, but I'm not a Linux expert, and Duplicati was familiar and easy to set up.
From everything I've seen and heard, Nest is great, but I find the subscription fees to be excessive, but ymmv based on your own needs.
Solid core is generally for premise wiring (PVC jacketed in walls, PTFE-jacketed through ducts); stranded is typically for patch cables. If you try like the first place I worked at in the mid-90's trying to put stranded ends on solid-core wire, breaking of tools and unreliable cables will make.
There's cheapo Chinese cable tester kits on eBay, AliBaba and Amazon that do a good-enough impedance at GbE spectrum testing to not have to spring for a Fluke "will-survive-nuclear-winter" "official" tester. Backfilling connectors with epoxy is another idea to avoid corrosion... as long as it doesn't affect the impedance or dielectric values much. No-snag boots, axial aligned label zipties are also a big help. Barcode label and floorplan everything.
Finally, always test every cable with iperf3 (two laptops or one laptop w two ethernet ports) and reject for reworking/replacment any cable with abnormal latency or bandwidth figures.
PS: our head-office networking guy was awesome; worked 10% time just to keep benefits since his wife was GOOG's first admin.
Obviously phones are out, but why not hardwire every laptop when it’s at the desk? If someone’s using a actual desktop computer like an iMac then what’s the point of Wi-Fi? Clear up the signal space and get a 100% reliable and ultra fast connection.
I'm AMAZED at the number of people that bother hardwiring everything they can for no reason when they have no interference issues.
Why go to all the effort of hardwiring every laptop at every desk?
If someone's using a laptop and moving around the office, why cable every desk when you can have gigabit wifi wherever you are?
Aruba Networks equipment was used at my alma mater, and is also used by $dayjob. I've also had good experiences with employers using Cisco Meraki.
What makes a sane high density 5 GHz office design with 40 MHz channels (theoretical 400 mbit/s, real usually ~200-300) work is that office workers don't actually need that decent of a connection, just a guarantee voice jitter won't be >10 ms and that throughput will be "fast enough".
PING 10.0.3.1 (10.0.3.1): 56 data bytes
64 bytes from 10.0.3.1: icmp_seq=0 ttl=64 time=0.737 ms
64 bytes from 10.0.3.1: icmp_seq=1 ttl=64 time=0.636 ms
64 bytes from 10.0.3.1: icmp_seq=2 ttl=64 time=0.701 ms
64 bytes from 10.0.3.1: icmp_seq=3 ttl=64 time=0.633 ms
...
--- 10.0.3.1 ping statistics ---
8 packets transmitted, 8 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 0.516/0.644/0.737/0.075 ms
Wifi:
PING 10.0.3.1 (10.0.3.1): 56 data bytes
64 bytes from 10.0.3.1: icmp_seq=0 ttl=64 time=6.713 ms
64 bytes from 10.0.3.1: icmp_seq=1 ttl=64 time=3.508 ms
64 bytes from 10.0.3.1: icmp_seq=2 ttl=64 time=2.425 ms
64 bytes from 10.0.3.1: icmp_seq=3 ttl=64 time=2.127 ms
64 bytes from 10.0.3.1: icmp_seq=4 ttl=64 time=4.057 ms
...
--- 10.0.3.1 ping statistics ---
22 packets transmitted, 22 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 1.429/3.769/16.722/4.054 ms
Depending on what you're doing, this can make a HUGE difference.
Despite my skepticism, I've seen that, in the typical office setting, wireless latencies can vary much higher. It stands to reason that, no matter how well-engineered, it's still a shared medium, which means that congestion or interference caused by a neighbor can ruin someone's VoiP call during the time it's happening.
Is there a site you can point to that details the protocol's latency-sensitivity?
If something like bulk file transfer is at issue, a ping test with sizes closer to the MTU (e.g. 1480 bytes) would be a closer simulation of those latencies.
> Over cable I'd say it's at least twice as fast
That could be be because of the bandwidth difference, if wireless isn't 802.11ac (or if the cable isn't 100Mb/s).
Is it also the case that copying a single file of comparable size doesn't show the same speedup?
- Cost avoidance. Hard wiring a new fitout is expensive, and in our case costs $200k for the structured cabling alone (ignoring the switch port cost, and the fact that we'd be deploying Wi-Fi anyway for roaming)
- Better roaming experience. USB3 docking made the desk experience better for staff but USBC has made it worse again, to the point that we get all kinds of random crap happening when roving from wired to wireless. This could (and will eventually be) fixed with some attention, but when we were considering Wi-Fi only for the office, mitigating this issue was a nice bonus.
- Reduced end-user network requirements. With most end-user applications being moved behind a web interface, the trend is for far lower fat-client throughput requirements. I don't see that changing any time soon despite the additional bloat being introduced to a lot of web front-ends. There are still special cases that do have high throughput requirements (raw media work, mostly) but it's a fraction of the user base.
- ROI on existing wireless infrastructure. We have significant investment in a proven enterprise wireless infrastructure (Aruba) that we can extract far more value out of by bumping up access point density and attaching all clients onto.
- Competing nonsense avoidance. In my sector, fibre to the desk is the current load of bollocks that we're being railroaded into adopting. I've side-stepped that whole debacle by shifting us entirely across to something we had to deploy anyway - Wireless.
- It fits a theme. We're doing wireless stuff in a ton of other places at the same time: Wireless bluetooth headsets for telephony. Wireless screen casting (Miracast, Airplay and Chromecast) for meeting presentation. Wireless bluetooth conference phones for audio conferencing. If I could nail some kind of bluetooth webcam for vid conferencing, I probably would push for that that too.
- We have the underlying capabilities to effectively support wireless-only, such as dedicated network staff with appropriate skills (Wi-Fi is it's own specialist subject aside from conventional networking) and the right investigative/monitoring tools (in our case, Spectrum analysis, heatmapping, air monitoring and such all come out of the Aruba mobility controller/Airwave systems we already operate.
There are risks to doing this, and you want to run a solid proof-of-concept ahead of committing your organisation to it. But that's achievable, and there's no reasons a sufficiently mature organisation that's trying to work more flexibly can't treat wireless as a first-class connectivity option.
The other big gotcha with wireless is catering adequately for guest devices. In more permissive environments (such as ours), catering for 3 devices per staff member is a good starting point.
You also have to decide how/if you want to prioritize corporate over guest traffic, and that's not as straightforward as it first looks.
We're fortunate that our user base (800) is spread over a significant floor area, and four separate large floors. We're also pretty much alone in our space, so less outside interference to handle. It was far worse at my last organisation (also Aruba), where not only were we surrounded by very noisy neighbours but we also had far higher floor density, coupled with the navy docking right next to the building which would regularly wipe out our wireless, site-wide, for random amounts of time.
I was managing consumer grade routers for the company since its inception until we switched to Aruba APs (which are awesome <3) and then eventually to an office with a real firewall, several APs, and a switch for 100+ cabled desks. The folks at BoxIT were a real life-saver at that stage, both for the initial setup and proactive monitoring of your network's health over time. Having your staff spend brain cycles on this stuff isn't the best ROI IMO.
The one thing to watch out for is VoIP in SF office buildings. Our APs conflict with about 300 other APs in the area, so getting reliable VoIP for your sales people over WiFi is not even worth trying. We got lucky and inherited an office where the previous company learned that the hard way and wired every nook and cranny with ethernet.
The configuration is done through a hosted dashboard that also provides monitoring. We're in a heavily regulated field, and the Meraki dashboard provides a lot of evidence for compliance audits. It also enables us to remotely control devices (e.g. lock, wipe, locate) and ivestigate issues when integrated the Meraki MDM solution.
We did have to tune the bitrate for wireless.
We also cannot setup redundant VPN tunnels to AWS (Meraki only supports one tunnel for non Meraki VPNs), so we have to do manual faiilover. This is my biggest gripe with Meraki. We are investigating adding a Cisco ASA to handle site-to-site VPN to AWS with redundant tunnel support.
I use GRC's DNS Benchmark tool[1] for this whenever I set up DHCP somewhere, and the results are sometimes surprising. If you're on a *nix or macOS, it runs well under Wine.
I also prefer namebench (https://github.com/google/namebench) since it runs at the command line.
* check whether a range of domains are censored by the DNS
* lookup a bunch of domains and ping them to check whether the DNS server is returning properly localized addresses using EDNS - Cloudflare DNS is a good example of one that was not (at least a few months ago)
dig triplebyte.com @1.1.1.1 | grep 'Query time'
;; Query time: 2 msec
dig triplebyte.com @8.8.8.8 | grep 'Query time'
;; Query time: 21 msec
but could imagine doing a more thorough benchmark like the one you linked if my results weren't so dramatically different! dig triplebyte.com @1.1.1.1 | grep 'Query time'
;; Query time: 5 msec
dig triplebyte.com @8.8.8.8 | grep 'Query time'
;; Query time: 35 msecRadars are pretty static and does not come and go (especially weather radars), so the router does not need to move from channel pretty much. False alarm can be an issue but if one has a decent quality router, it should not be very often. Furthermore, after a radar detection (false alarm or actual), routers can switch to non-DFS channels and and start operating immediately.
If you run a full UniFi stack, you can view your entire topology in the dashboard--it'll tell you which switch port or access point/SSID a client is connected to. Here's my home topology:
Note that most switches are double-uplinked for 2000Mbps throughput, and there's a 10-gigabit core router. 10gbe isn't nearly as expensive as you might think, especially for very small teams. It is possible to get access points to deliver 500-700Mbps speeds, too--that's going to depend a lot more on your device's radios than anything. See speed benches for UniFi kit at: https://goo.gl/RL4kkW
This guide doesn't cover VLANs, but it probably should mention they exist. Any IOT or networked camera type devices that don't need Internet access shouldn't be allowed egress, and VLANs are an easy way to implement network segregation. You almost certainly want a guest network too, both wired and wireless.
Uh, what? Are you nuts? Hire somebody.
This is easier said than done, even if they're convinced it's worth the money.
Not only are startup founders faced with the usual problems associated with hiring competent technical people (ironically a problem the OP is attempting to help), but this would be hiring someone whose competence they'd be much less qualified to evaluate.
This effect can be seen in "DevOps" (as a title) postings from startups that emphasize Dev (programming against a cloud API and/or "automate everything!"). That kind of redefinition is much harder to do convincingly for office IT.
* Most of my client devices are from Apple, and I easily got the best WiFi performance overall with 802.11ac-capable Airport Extremes, which is impressive given how relatively cheap they are. However, I'd like multiple SSIDs, and Apple gear can't do that (the guest network support doesn't count). Regardless, Apple is out of the game, so this isn't a long-term solution.
* The UniFi gear had terrible 802.11ac performance, even when my devices were in the same room as the WAP. At the time, I was using first-gen 802.11ac hardware from UniFi, so it's somewhat understandable, but the poor performance combined with 2 of the units failing within the first 6 months didn't leave a good impression.
* The Aruba Instant WAPs were reliable and got good performance (though not as good as the Apple WAPs), but I'm not a fan of their licensing. Without a support contract, it was possible to hunt down the latest firmware updates, but they didn't make it easy.
I recently bought a PC Engines APU3C4 with a mini-PCIe WiFi card and a couple of Chaohang antennas [1], and I'm contemplating build my own WAP. This would give me all of the configurability and tweaking that I want, and I could deploy it as just another piece of my personal little devops pipeline.
However, I don't know much about the RF side of things. I'm aware there's a lot of black magic involved, but it's not clear to me how much performance and/or range I'm going to lose by piecing together COTS stuff versus a professionally-engineered solution from Ubiquiti et al. If anyone who's reading has built their own WAPs, I'd love to hear from you.
addendum:
Re crimping RJ45 - the better way to do terminations is to use the EZ-RJ45 pass-through plugs like the ones made by Platinum Tools. You need a special crimper, but it's night and day easier. If you're using AWG23 Cat 6, you also need to make sure your plugs can handle those wires (not an issue with the Platinum Tools plugs).
https://en.wikipedia.org/wiki/TIA/EIA-568
"ANSI/TIA-568 recommends the T568A pinout for horizontal cables... The standard also allows the T568B pinout, as an alternative, "if necessary to accommodate certain 8-pin cabling systems"... Many organizations still use T568B out of inertia."
At least, this is true for me. Maybe I did it wrong.
On the other hand, I saw some videos on Youtube of people using other cheap crimpers, and they were getting clean flush cuts. Luck of the draw is a big thing when you get the cheaper tools.
Originally I thought that 1mm or less was preventing my plugs from seating fully but on further inspection I found that the locking lever on my plugs weren't consistently locking. I made the mistake of not using the matching Platinum Tools strain relief boots for my plugs, which actually have a piece of plastic that pushes the locking lever up a little more to ensure a more secure mating between the plug and port.
Also don't be afraid to hire someone to do a wireless survey - or do it yourself. Someone will walk around with a laptop, and try to find wifi blackspots/hotspots, and can recommend adjustments to AP power and/or placement.
But then I still haven't had any luck setting up a WPA2 Enterprise config that works on all devices.
I thought that was the defacto-standard in office environments. It certainly is for EDU
I will also add to this, consider having all the APs on the same channel. My experience is that some OSs (I'm looking at you, Windows) don't roam properly if the following three things are not the same:
1. SSID
2. Authentication/Encryption
3. Channel
It does sound like the author has deployed consumer access points. For a proper office scenario centrally managed is the way to go. Finally, never use WPA2-PSK Personal in a work environment. Use proper back-end authentication such as Radius or MAC filtering, or a 'Register me via a captive portal' system with a central LDAP type user directory.
Using the same name for both didn't work
I was also surprised by how slow S3 was with a single download connection, but really fast when using aria2 to parallelize the download.
Should I try using a lower 5Ghz channel such as 36 or 40? Won't that decrease overall throughput? My understanding was the higher the channel number on 5Ghz, the theoretically higher the throughput.
Every so often I have to physically drag my laptop to the superior AP and restart wifi to get my laptop to stop connecting to the bad AP.
Bad for WiFi at distance but good for roaming within an office.
https://i.imgur.com/imKDQ14.png
there is also a minimum RSSI, but its a per device setting, not a per site setting. https://i.imgur.com/Z6Jsxjl.png
Fast Roaming and 802.11 Data Rate Control are the way I would set this setting, vs trying to pick a manual dBm.
And you can get more channels than 3, if you use 20Mhz channels, not the 22MHz channels by simply not using 802.11b. only use g&n and you get four channels.
And do use the DFS channels, exactly because people like this author are not there to congest the channel. Just make sure you have non-DFS too while the DFS AP is in listen mode.
So this article is very much not written by an expert.
where do you want to put your portfolio management, in something dedicated like clarizen, smartsheet, or wrike; somewhere simplistic like or asana or trello, with finance like anaplan. now that anaplan is on the table, it might change how you feel about adaptive insight. now you might need to replace your gl. losing adaptive insight for anaplan might push you away from workday and towards ultimate, because of the ownership structure (not at all a technical decision.) ten cascades later, you are asking yourself aryaka+hyperv+qumulo+simplivity+ruckus+salesforce+gsuite+adaptiveinsight+workday or velocloud+esxi+nasuni+nutanix+ubiquiti+anaplan+dynamics+office365teams. your either or's become complex and intertwined. you might think some of these decisions are just "IT/technical" but at the the end of the day every decision cascades into another, changing the scope of the next decision.
if my somewhat silly rant didnt make my point: too often companies want to outsource decision making that belongs in the c suite, that can give them a competitive edge, if done right, in house by magicians. you lose your magic and secret sauce by going with what everybody else does. its akin to whatsapp being erlang based vs going with metoo ruby. or how newspaper publishers have an edge when they also develop the hosting platform and license to others (vox chorus, gizmodo kinja, wapo arc, say tempest, bi viking, vs wordpress.)
https://www.wsj.com/articles/why-do-the-biggest-companies-ke...
http://www.niemanlab.org/2018/09/newsonomics-the-washington-...
I constantly run into this issue in my home network. Is solving it really just a matter of reconfiguring the routers to share she same SSID or is there more to it?
Small error here, should be 4 of 8 and 8 of 8, respectively ;)
> If you’re new to making cables
However, IMO if you're making your own patch cables, you're so far on the wrong side of what's reasonable that I don't know what else to say. Punching down horizontal cabling to jacks makes sense; there's no other choice. Making patch cables is an enormous waste of resources.
Uhh, do they mean "don't put 5 GHz on its own SSID"?
Is that no longer an issue? Or maybe these aren’t problems as long as the 2.4 and 5 access points are physically separate.
I set up extra SSIDs for specific bands on my Unifi equipment to force some wifi gear (IP cams that have since been retired) to always connect to the closest AP.
Avery did a talk about it (and other things) a couple years ago: https://apenwarr.ca/diary/wifi-data-apenwarr-201602.pdf
Clients do pretty stupid things, which is why the AP is the right place to control this sort of thing. (If you have more than 1 AP, then you have signal strength data from the other APs, and AP A can disconnect the client and force it to use AP B. This seems to work better than letting the client decide on its own.)
But I think since WiFi clients are so varied in their intelligence, the ideal thing is to build the roaming functionality into the AP... because at least you have the ability to fix it once and for all for everyone. Whether or not currently commercially-available hardware does that, I don't know.