Live data from Hacker News

How we solved our office Wi-Fi problems

triplebyte.com

111–120 of 252 posts

Re: How we solved our office Wi-Fi problems

#111
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

I've always so far heard a lot of good for ubiquiti on HN.

What would you suggest instead?

Re: How we solved our office Wi-Fi problems

#112
post #108

Earlier quoted context omitted.

You could say the opposite I guess. I'm AMAZED at the number of people that bother hardwiring everything they can for no reason when they have no interference issues. Why go to all the effort of hardwiring every laptop at every desk? If someone's using a laptop and moving around the office, why cable every desk when you can have gigabit wifi wherever you are?

Because gigabit wifi turns to 50mbps when the office gets big enough. There is only so much spectrum to use. Plus if you're already connecting monitors when you have your laptop at your desk the Ethernet adapter can be part of the dock.

When the office gets big enough, you reduce transmit power and add more access points so that there's enough spectrum to cover each desk.

Aruba Networks equipment was used at my alma mater, and is also used by $dayjob. I've also had good experiences with employers using Cisco Meraki.

Re: How we solved our office Wi-Fi problems

#113
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

Which network vendor has better security updates? Can you point to a specific example of them not fixing a security issue that was addresssd by others?

How would you compare Microtik to Ubiquiti?

Re: How we solved our office Wi-Fi problems

#114
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

[deleted]

Re: How we solved our office Wi-Fi problems

#115
post #36
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

For the cost, I'd agree that Ubnt gear is quite good. I use it at home, and rarely have any problems. That said, I'd like to provide one caveat: In my experience, they tend to not do great in very noisy RF environments. Twice now I've deployed Unifi APs in offices with RF spectra similar to what the OP has going on, and we had nothing but problems. In each case, we ripped out the Ubnt gear, replaced with equivalent R…

As a counterpoint, we run Ubiquiti gear at large conferences (NAB in Vegas, IBC in Amsterdam). Thousands of people, hundreds of WiFi networks - pretty much a nightmare.

At NAB we're often the only booth with functional WiFi. Not using anything special really, just well configured UniFi mesh APs.

Re: How we solved our office Wi-Fi problems

#116
post #56

It’s only sort of passively mentioned in the article but I am AMAZED at the number of people who don’t hardwire everything they can. Obviously phones are out, but why not hardwire every laptop when it’s at the desk? If someone’s using a actual desktop computer like an iMac then what’s the point of Wi-Fi? Clear up the signal space and get a 100% reliable and ultra fast connection.

We're about to move ~800 people into a new office and we're going Wi-Fi only when we do. Several reasons:

- Cost avoidance. Hard wiring a new fitout is expensive, and in our case costs $200k for the structured cabling alone (ignoring the switch port cost, and the fact that we'd be deploying Wi-Fi anyway for roaming)

- Better roaming experience. USB3 docking made the desk experience better for staff but USBC has made it worse again, to the point that we get all kinds of random crap happening when roving from wired to wireless. This could (and will eventually be) fixed with some attention, but when we were considering Wi-Fi only for the office, mitigating this issue was a nice bonus.

- Reduced end-user network requirements. With most end-user applications being moved behind a web interface, the trend is for far lower fat-client throughput requirements. I don't see that changing any time soon despite the additional bloat being introduced to a lot of web front-ends. There are still special cases that do have high throughput requirements (raw media work, mostly) but it's a fraction of the user base.

- ROI on existing wireless infrastructure. We have significant investment in a proven enterprise wireless infrastructure (Aruba) that we can extract far more value out of by bumping up access point density and attaching all clients onto.

- Competing nonsense avoidance. In my sector, fibre to the desk is the current load of bollocks that we're being railroaded into adopting. I've side-stepped that whole debacle by shifting us entirely across to something we had to deploy anyway - Wireless.

- It fits a theme. We're doing wireless stuff in a ton of other places at the same time: Wireless bluetooth headsets for telephony. Wireless screen casting (Miracast, Airplay and Chromecast) for meeting presentation. Wireless bluetooth conference phones for audio conferencing. If I could nail some kind of bluetooth webcam for vid conferencing, I probably would push for that that too.

- We have the underlying capabilities to effectively support wireless-only, such as dedicated network staff with appropriate skills (Wi-Fi is it's own specialist subject aside from conventional networking) and the right investigative/monitoring tools (in our case, Spectrum analysis, heatmapping, air monitoring and such all come out of the Aruba mobility controller/Airwave systems we already operate.

There are risks to doing this, and you want to run a solid proof-of-concept ahead of committing your organisation to it. But that's achievable, and there's no reasons a sufficiently mature organisation that's trying to work more flexibly can't treat wireless as a first-class connectivity option.

Re: How we solved our office Wi-Fi problems

#117

Earlier quoted context omitted.

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

Note that nearly all of Ubiquiti's offerings are running modified OpenWRT, with a handful running a fork of VyOS which happens to be Debian plus some packages.

> Note that nearly all of Ubiquiti's offerings are running modified OpenWRT, with a handful running a fork of VyOS which happens to be Debian plus some packages.

EdgeOS is a Vyatta fork. Has Ubnt abandoned EdgeOS? It's been a few months since I've looked, but the version of Debian that's being used was end-of-lifed on MIPSLE hardware a while back so security updates are entirely incumbent upon Ubnt. There is no upstream support.

Which offerings are on OpenWRT?

Re: How we solved our office Wi-Fi problems

#118
post #7

I really wish MacOS would allow you to choose which band or BSSID to connect to. Every so often I have to physically drag my laptop to the superior AP and restart wifi to get my laptop to stop connecting to the bad AP.

Dial down the transmit power on your more distant AP so your laptop won’t think it’s the closest one.

Re: How we solved our office Wi-Fi problems

#119

Earlier quoted context omitted.

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

Which network vendor has better security updates? Can you point to a specific example of them not fixing a security issue that was addresssd by others? How would you compare Microtik to Ubiquiti?

> Which network vendor has better security updates?

I'd imagine pretty much any network vendor doing business in the enterprise sector (e.g. HP, Cisco, Juniper, Dell, etc, etc)

> Can you point to a specific example of them not fixing a security issue that was addresssd by others?

I haven't looked recently, but when I last updated my ER-X I noticed that the latest available packages included a large number that were not up-to-date with the latest available security fixes.

One of the problems is that the version of Debian that the hardware (MIPS) Ubnt uses is end-of-lifed on the old version of Debian that EdgeOS is based on. Where most vendors could simply track the official Debian repositories, Ubnt is stuck rolling their own packages. If Ubnt has finally moved on to an officially supported version of Debian then this is less of an issue.

This is one of those I wish I had a better solution moments. For the home user this may not pose a challenge, but in a business environment I'd say that it's probably worth spending the big bucks on a vendor with a better track record. That's not to say there aren't other bad vendors, but it is to say that Ubnt gear does not belong outside of a home lab.

I haven't evaluated Mikrotek because the Ubnt stuff works well enough (but certainly not great) for me in the two locations I've got it deployed.

Re: How we solved our office Wi-Fi problems

#120

Earlier quoted context omitted.

I did a look at those EZ-RJ45 ends when another replied about them in this thread and notice that they are rated for solid or stranded, which I think would help. They look pretty good. I've installed a few (and have a few more to install) of the Ubiquiti cameras, and I've been using keystone at the end and then patch cables. That has worked well, but I'd be tempted to just crimp the outside end. I'd have to see how t…

I just finished installing the G3AFs (outside) and G3 Flexes (inside) at my house, and I crimped the outside ends. For my outdoor cameras, I used outdoor rated cat6 solid. It's a little harder to work with, and I had to buy a spool of 1000 feet because the 500 feet spools were out of stock when I needed them. Are you using back boxes? I think it would be extremely hard to use keystone and patch cables given how littl…

I'm not using boxes, I'm putting them under the eaves, mounted to the plywood. I drilled a hole just big enough to fit the keystone through (1"? 1.25"? I forget), then I put the keystone on it, put a grounded patch in that, and pushed it up inside the hole. Then I mount the ring and plug the camera in, and mount the camera. The cable runs are in the attic.

This is all the G3 Dome, they didn't have anything else when I bought the cameras. I thought about putting a G3AF mounted from the upper eaves to get another view, but haven't done that yet. That'll be a bit more of a project.

I'm fairly happy with the setup, but it's kind of a bit flaky. The motion detection fires all the time, with wind blowing trees or the like. Then it'll sometimes cut off in the middle of a recording when it seems like it should be detecting motion. I've been wanting to put an SSD in their little appliance, or just migrate that appliance to a Ubuntu host of my own, but haven't done that yet. The hardware seems solid, but the software seems flaky.

A coworker has the Nest cams and those seem to be a bit less flaky. I may need to reevaluate this before I go further in, and it's been a year, maybe there's something else I should look at.

Post reply on HN