Live data from Hacker News

How we solved our office Wi-Fi problems

triplebyte.com

131–140 of 252 posts

Re: How we solved our office Wi-Fi problems

#131

Earlier quoted context omitted.

Which network vendor has better security updates? Can you point to a specific example of them not fixing a security issue that was addresssd by others? How would you compare Microtik to Ubiquiti?

> Which network vendor has better security updates? I'd imagine pretty much any network vendor doing business in the enterprise sector (e.g. HP, Cisco, Juniper, Dell, etc, etc) > Can you point to a specific example of them not fixing a security issue that was addresssd by others? I haven't looked recently, but when I last updated my ER-X I noticed that the latest available packages included a large number that were n…

Cisco has not been having a good year, https://www.bleepingcomputer.com/news/security/hardcoded-pas...

Ubiquiti EdgeRouter Lite (not ER-X) is apparently supported by vanilla OpenBSD.

Re: How we solved our office Wi-Fi problems

#132
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

Ubiquiti is not suitable for a business environment

I'd say that Ubiquiti is perfectly suited for a small business environment -- definitely a big step up from discrete consumer Asus routers throughout the office with no central management (and probably haven't been patched since the day they were installed).

Ubiquiti may not be suitable for a mid to large sized business, but for up to a ~100 person office or so, they come in at a great price point and have decent performance and manageability.

Re: How we solved our office Wi-Fi problems

#133

Earlier quoted context omitted.

Which network vendor has better security updates? Can you point to a specific example of them not fixing a security issue that was addresssd by others? How would you compare Microtik to Ubiquiti?

> Which network vendor has better security updates? I'd imagine pretty much any network vendor doing business in the enterprise sector (e.g. HP, Cisco, Juniper, Dell, etc, etc) > Can you point to a specific example of them not fixing a security issue that was addresssd by others? I haven't looked recently, but when I last updated my ER-X I noticed that the latest available packages included a large number that were n…

The downside of the vendors you listed (and Cisco) is they require a support contract for software updates. If you lack said contract, you do not receive security updates.

Imo ubiquiti works fine for smaller offices. If you don't have enough people to justify an IT org it makes sense.

Re: How we solved our office Wi-Fi problems

#134
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

> All channel management will be by the devices working together, they can throttle down power if they are causing each other interference.

UniFi does not do this. At all. The Auto settings are the same as basically every other commodity AP out there -- look for the least noisy channel at boot, transmit full power, allow any client to remain associated regardless of signal strength.

UniFi has an ok tool for on-demand RF scans. It has all the appropriate knobs to tweak for optimizing coverage and encouraging devices with weak signal to associate with a better AP. But you have to do all of that yourself. Manually. Trial-and-error. There's absolutely no magic there.

Re: How we solved our office Wi-Fi problems

#135

Earlier quoted context omitted.

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

_Thank you_. I'm constantly astonished to see folks extolling UBNT gear for anything other than WISP purposes (where it admittedly fits a price profile that's unmatchable). Read about the first ~10 months of the ES16-XG DAC support issues. Read about how EdgeRouters could never approach even 40% of line rate with fq_codel running. Read about how they lied about the future of the mFi line for 8+ months before abandoni…

Or $1000 switches that fail outside of warranty with no replacement power supplies available. https://community.ubnt.com/t5/UniFi-Routing-Switching/Failed...

Re: How we solved our office Wi-Fi problems

#136
UniFi is already mentioned elsewhere in the comments already, so this whole post is likely redundant. If you're at the level of cobbling together consumer routers, even flashed to DD-WRT/Tomato/whatever, change. If someone your team is Cisco certified from a previous life as a network engineer, and insists you use Meraki kit and pay the fees, well, you're in SF and paying SF salaries anyway, so probably just go for it.

If you run a full UniFi stack, you can view your entire topology in the dashboard--it'll tell you which switch port or access point/SSID a client is connected to. Here's my home topology:

https://imgur.com/MnJwHiB

Note that most switches are double-uplinked for 2000Mbps throughput, and there's a 10-gigabit core router. 10gbe isn't nearly as expensive as you might think, especially for very small teams. It is possible to get access points to deliver 500-700Mbps speeds, too--that's going to depend a lot more on your device's radios than anything. See speed benches for UniFi kit at: https://goo.gl/RL4kkW

This guide doesn't cover VLANs, but it probably should mention they exist. Any IOT or networked camera type devices that don't need Internet access shouldn't be allowed egress, and VLANs are an easy way to implement network segregation. You almost certainly want a guest network too, both wired and wireless.

Re: How we solved our office Wi-Fi problems

#137

Earlier quoted context omitted.

> Which network vendor has better security updates? I'd imagine pretty much any network vendor doing business in the enterprise sector (e.g. HP, Cisco, Juniper, Dell, etc, etc) > Can you point to a specific example of them not fixing a security issue that was addresssd by others? I haven't looked recently, but when I last updated my ER-X I noticed that the latest available packages included a large number that were n…

The downside of the vendors you listed (and Cisco) is they require a support contract for software updates. If you lack said contract, you do not receive security updates. Imo ubiquiti works fine for smaller offices. If you don't have enough people to justify an IT org it makes sense.

> If you don't have enough people to justify an IT org it makes sense.

Disagree, and not just because of the GPL violations and security issues. There are enough subtle bugs (e.g. data corruption with hardware acceleration) and design flaws (e.g. overheating) that you are setting yourself up for intermittent bugs (a.k.a. trouble) if you don't have someone well versed in diagnosing network issues. It's powerful enough to do fun things in a home lab, but it's way too complex for a professional setting where there's nobody around with the skills to troubleshoot it.

Enterprise gear is expensive, yes.

Re: How we solved our office Wi-Fi problems

#138

Earlier quoted context omitted.

I just finished installing the G3AFs (outside) and G3 Flexes (inside) at my house, and I crimped the outside ends. For my outdoor cameras, I used outdoor rated cat6 solid. It's a little harder to work with, and I had to buy a spool of 1000 feet because the 500 feet spools were out of stock when I needed them. Are you using back boxes? I think it would be extremely hard to use keystone and patch cables given how littl…

I'm not using boxes, I'm putting them under the eaves, mounted to the plywood. I drilled a hole just big enough to fit the keystone through (1"? 1.25"? I forget), then I put the keystone on it, put a grounded patch in that, and pushed it up inside the hole. Then I mount the ring and plug the camera in, and mount the camera. The cable runs are in the attic. This is all the G3 Dome, they didn't have anything else when…

For the G3/AFs, you feed the wire into the mount, which is tight especially if you're not aiming straight ahead (which I assume few people are doing). The Flex gives you more leeway, but because the cameras are inexpensive, the wall mounts for them are reflective of the cost savings, which means "not great".

The motion sensing is quite sensitive and there's no machine learning behind the analysis like there is with Nest. I prefer the Unifi Video's motion sensing set up over that of Zoneminder which I was using before.

I find myself creating less-sensitive motion sensing zones where I know there are plants/trees that are going to blow plus where they might cast shadows.

The "before" and "after" settings for motion detection are pretty important if you think your footage is getting cut off at the beginning or the end of the clip. I use a setting of 5 seconds.

Since I came from crappy wifi IP cams, I've been very happy with my setup.

I'm currently using an inexpensive NUC as my Unifi Controller and NVR. I have four cameras recording on motion sensing (the others are for monitoring only). The only time I have issues is when I run Duplicati in the background to backup the video files to a NAS. Duplicati is a bit of a pig, but I'm not a Linux expert, and Duplicati was familiar and easy to set up.

From everything I've seen and heard, Nest is great, but I find the subscription fees to be excessive, but ymmv based on your own needs.

Re: How we solved our office Wi-Fi problems

#139
post #123
post #12

Earlier quoted context omitted.

The above may sound like an Ubiquiti ad, but I've tested a few top specs routers about 2 years ago and settled with unifi for my home installation. I needed a good coverage and reliability for my home automation, e.g. when I switch lights on/off I want a consistent few milliseconds latency.

I installed Ubiquiti at home and it was a terrible experience. I really wanted it to work, but my wife teased me long enough about my "professional grade" installation that I gave up. She was right. The biggest issue was range, which was much worse than what I got with I had with a traditional consumer access point (I had a TP-Link Archer C7.) It was not even close. The handover didn't work very well either. Much old…

The problem with UniFi is people read about how great it was for someone who somewhat haphazardly flung a few APs around their house and lived happily ever after... and for many it's just not going to work out that way.

A lot of work can go into making WiFi work well.

With multiple APs you've got to adjust the Transmit power (defaults to Auto, which means High, which is generally bad). For good roaming, increasing the minRSSI is critical. 5G and 2.4G have very different propagation characteristics so they need to be optimized individually. With several APs you may even want to disable 2.4G on some of them.

Band Steering may or may not play nicely with the devices you have. Some devices have trouble if they can see many APs advertising the same SSID -- Ring Doorbells are notorious for not being willing to associate to an SSID at all if many APs are advertising the same SSID.

At my old house I got away with one AP placed centrally in the attic and another in my detached garage. At my new house, at about 2.5X the size, I'm running 5 APs and it has taken me a solid month of fiddling to get my devices consistently associating to the best AP and roaming appropriately.

Re: How we solved our office Wi-Fi problems

#140
post #112
post #108

Earlier quoted context omitted.

Because gigabit wifi turns to 50mbps when the office gets big enough. There is only so much spectrum to use. Plus if you're already connecting monitors when you have your laptop at your desk the Ethernet adapter can be part of the dock.

When the office gets big enough, you reduce transmit power and add more access points so that there's enough spectrum to cover each desk. Aruba Networks equipment was used at my alma mater, and is also used by $dayjob. I've also had good experiences with employers using Cisco Meraki.

Even a single AP, single client, 160 MHz AC wave 2 2x2 connection in clear airspace has less max theoretical throughput than a gigabit hardware (1.7 vs 2).

What makes a sane high density 5 GHz office design with 40 MHz channels (theoretical 400 mbit/s, real usually ~200-300) work is that office workers don't actually need that decent of a connection, just a guarantee voice jitter won't be >10 ms and that throughput will be "fast enough".

Post reply on HN