Live data from Hacker News

How we solved our office Wi-Fi problems

triplebyte.com

41–50 of 252 posts

Re: How we solved our office Wi-Fi problems

#41
post #36
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

For the cost, I'd agree that Ubnt gear is quite good. I use it at home, and rarely have any problems. That said, I'd like to provide one caveat: In my experience, they tend to not do great in very noisy RF environments. Twice now I've deployed Unifi APs in offices with RF spectra similar to what the OP has going on, and we had nothing but problems. In each case, we ripped out the Ubnt gear, replaced with equivalent R…

I've had similar issues with Ubiquiti in a noisy RF environment. The 2.4GHz spectrum was extremely saturated and people were frequently dropped whenever they were on it. Thankfully, the neighbors aren't using 5GHz too much--I just turned off 2.4GHz for our own WiFi and it seems to have solved the issue. Still, very annoying and took a long time to figure out.

Re: How we solved our office Wi-Fi problems

#43
post #40

Earlier quoted context omitted.

You can also 'cloud' host a unifi controller on a VM somewhere and set up the APs for "layer 3" management, where when you originally provision them you tell each AP to register to a specific hostname. It's all done over TLS. Each AP just needs to be able to get a DHCP lease, default route out to the internet, and to resolve hostnames. A small Unifi controller can run on a $10/month VM if you don't want the 'cloud ke…

I agree with this, I don't even use a VM somewhere I just run it on a system I already had at home and point a lot of other sites at it L3, no issues in a few years. Obviously it depends on the kind of uptime and home setup you've got, but the take home should be that running a Unifi controller doesn't inherently have to cost anything, not even for L3 adoption. There is zero cloud tie-in needed, or even colo/VPS or w…

My home unifi controller doesn't even 'run' 99.9% of the time, it's not necessary to have the controller online once the APs are provisioned. It's just a debian stretch virtualbox VM that lives on my laptop, with its virtual ethernet interface bridged to the laptop's physical interface. I bring it up on the same L2 fabric as the APs if I need to make any changes, and then suspend it again.

Re: How we solved our office Wi-Fi problems

#44
post #36

Earlier quoted context omitted.

For the cost, I'd agree that Ubnt gear is quite good. I use it at home, and rarely have any problems. That said, I'd like to provide one caveat: In my experience, they tend to not do great in very noisy RF environments. Twice now I've deployed Unifi APs in offices with RF spectra similar to what the OP has going on, and we had nothing but problems. In each case, we ripped out the Ubnt gear, replaced with equivalent R…

I've had similar issues with Ubiquiti in a noisy RF environment. The 2.4GHz spectrum was extremely saturated and people were frequently dropped whenever they were on it. Thankfully, the neighbors aren't using 5GHz too much--I just turned off 2.4GHz for our own WiFi and it seems to have solved the issue. Still, very annoying and took a long time to figure out.

Yes, we actually considered that. Unfortunately in our use case, there were many 2.4GHz-only IOT-type devices that needed to be on the network, so we couldn't turn off 2.4GHz. It helped a bit when we turned down the 2.4GHz Tx power - that seemed to encourage more devices to jump over to 6GHz, but even that didn't solve the problems altogether.

I'm not an RF design engineer, but for this type of equipment, I do feel like there's some truth to "you get what you pay for". It's plain to me that the Ruckus APs have superior RF front-ends that are better able to deal with the noise. They're more expensive than Ubnt for sure, but that extra cost was very much worth it for us, to avoid the frequent disconnects that the users were having to deal with.

Re: How we solved our office Wi-Fi problems

#45
post #29

> There’s no IT team at startups Uh, what? Are you nuts? Hire somebody.

I work for an MSP servicing small businesses, Triplebyte sounds like one of our clients. I guess since they're developers they think IT is optional and they can save on costs (and/or their time is worth less than ours, which I doubt). And then later those decisions come home to roost and it costs more to pay some company like ours to come in and do things properly. I mean hell with modern wifi like Ubiquiti or Meraki you shouldn't even have to think about half the stuff in this article.

Re: How we solved our office Wi-Fi problems

#46
post #36
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

For the cost, I'd agree that Ubnt gear is quite good. I use it at home, and rarely have any problems. That said, I'd like to provide one caveat: In my experience, they tend to not do great in very noisy RF environments. Twice now I've deployed Unifi APs in offices with RF spectra similar to what the OP has going on, and we had nothing but problems. In each case, we ripped out the Ubnt gear, replaced with equivalent R…

My company do a lot of Ruckus deployments and they are brilliant, they have a radio built in just for spectrum analysis so each point can choose the perfect channel, none of this manual setting stuff.

Re: How we solved our office Wi-Fi problems

#47
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

I use Unifi AP at home and a Fritzbox router.

At work I have a two sites of Unifi with cloud keys and an edge router. All visible on one management screen and super easy to configure.

Fabulous kit. Make sure you take a backup of the cloud key btw, they can get corrupted by a power interruption, and then you have to install from scratch. You can do this from the browser.

I wanted to caution people who are choosing Mikrotik at home. A lot of network engineers find their interface a bit weird, and by default they have way too much open on their public interfaces. I have seen one in the process of being brute-forced from ssh, that was installed by a qualified Mikrotik installer. If you want to plug and play the Unifi routers are a better option. Many have packet inspection features built in too.

Re: How we solved our office Wi-Fi problems

#48
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

This a thousand times.

The very start of a strong network is a solid Dynamic DNS + DHCP setup. The only IPs that should be static are the router's.

In a small office, using your firewall/router is not a bad choice to DNS+DHCP. For companies Segment your APs and servers etc into different VLANs with distinct IP pools, bonus point for different subdomain. This allows your to firewall it off to prevent prying eyes. It also means that if something were to get into your VPC, and then over the VPN, they can't fiddle with your APs quite so easily.

As for ethernet always buy in cables, but get good sockets and patch panels. It is worth the money to hire a wireman/woman to do that for you. Unless you've been practising its a long boring slog, time you should be spending doing your real job....

Ubiquity again is a solid choice for wifi. I've deployed ~50 to cover 1800 person office. Beware, the non "pro" versions of the APs don't use proper PoE, so you'll be stuck either using their injectors(ok for small places) or buying their switches.

SOme of the pro APs have built in speakers (https://www.ubnt.com/unifi/unifi-ap-ac-edu/) which might be fun. They have proper PoE too, so you can use a real switch.

Re: How we solved our office Wi-Fi problems

#49
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

I use Unifi AP at home and a Fritzbox router. At work I have a two sites of Unifi with cloud keys and an edge router. All visible on one management screen and super easy to configure. Fabulous kit. Make sure you take a backup of the cloud key btw, they can get corrupted by a power interruption, and then you have to install from scratch. You can do this from the browser. I wanted to caution people who are choosing Mik…

The vast majority of peoples' houses don't have WAN connections that need the capabilities of the higher-spec mikrotik routers anyways. An RB3011 or RB4011 is overkill for a residential cablemodem or VDSL2 based last mile service, in terms of pps and Mbps capacity, and NAT pps ability. The ubnt ER-X ($48) is good for up to about 700 Mbps of traffic, and comes with sane defaults.

If you have truly symmetric 1 Gbps full duplex at home maybe you need the capabilities of an RB4011. But you should learn how to lock down its WAN facing interface.

The ubnt EdgeOS based devices are based on a fork of Vyatta. Ubiquiti hired most of the Vyatta software development team years ago when Brocade acquired Vyatta (the corporation). Ultimately they are little tiny Debian based boxes, since that's the foundation vyatta was built on.

Re: How we solved our office Wi-Fi problems

#50
post #34

Earlier quoted context omitted.

Does the Unifi mobile app work with the setup you described? If you are outside the network? Do you use a vpn client to connect your phone back inside the network?

Yes, it should. Assuming you're running your unifi controller on a public ipv4 /32 somewhere on the internet (at some commodity VM host), it's entirely up to you how you want to lock down access to it. Some people do leave the TLS1.2 web browser admin control panel login exposed, but on a non standard port, other people set up iptables ACLs to only allow traffic from a certain IP range, other people set it up so that…

>more in favor of having the unifi controller on the same premises as the APs

But when your premise is MANY sites across the country, and you are using a single controller, only ONE site gets the controller on prem, OR you have many controllers running.

>Big difference between like $700-900/year and $120/year.

At the end of the day, it comes down to what my time is worth doing other things (not how much im paid, but the opportunity cost of me managing management interface infrastructure, stability, and resources. Unifi cloud, for lack of a better phrase, just works.)

Post reply on HN