Live data from Hacker News

How we solved our office Wi-Fi problems

triplebyte.com

211–220 of 252 posts

Re: How we solved our office Wi-Fi problems

#211

Earlier quoted context omitted.

Software has been written that will forcibly disconnect a 5GHz capable client that is found using 2.4GHz. How widely deployed this is, I don't know. Avery did a talk about it (and other things) a couple years ago: https://apenwarr.ca/diary/wifi-data-apenwarr-201602.pdf

What's the point of using one SSID for both frequencies if you make roaming between them impossible?

Supporting clients with 2.4-only devices without distributing two sets of credentials & avoiding a 5Ghz use accidentally picking the wrong creds.

Re: How we solved our office Wi-Fi problems

#212
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

I have a full UniFi setup in my home office/house and it is glorious. It Just Works! Well, with the one exception which is the Cloud Key. I’ve yet to see it run for more than 24 hours before soft rocking and requiring a total re-setup of the network.

I need a wireless bridge and am a bit overwhelmed with the various Unifi offerings. Can you recommend a setup?

Re: How we solved our office Wi-Fi problems

#213
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

This a thousand times. The very start of a strong network is a solid Dynamic DNS + DHCP setup. The only IPs that should be static are the router's. In a small office, using your firewall/router is not a bad choice to DNS+DHCP. For companies Segment your APs and servers etc into different VLANs with distinct IP pools, bonus point for different subdomain. This allows your to firewall it off to prevent prying eyes. It a…

The UAP-AC-LITE used to be only 24V passive PoE but has supported real 802.3af PoE for a while now.

Re: How we solved our office Wi-Fi problems

#214

Earlier quoted context omitted.

Same as this , except with one change. For the router, use the (cheaper and more powerful) Mikrotik Routerboards. We don't use a Poe switch - we just use cheap Poe adapters and connect directly to the routerboard. For those who have never touched a Ubiquiti, configuring it could be a little iffy . I normally advise setting up DHCP 43 advertisement on the router before trying to setup the access points. But seriously,…

I'm currently using Mikrotik happily for AP and router needs, but considering switching to a Ubnt setup for ease of management that does not depend on Windows/Wine and without having to write my own configuration management tooling. As central management is somewhat lacking. What are your considerations for not choosing Ubnt for routing?

Windows? The MT RouterOS web interface works very well in both Chromium and Firefox on Linux for me.

Re: How we solved our office Wi-Fi problems

#215

Earlier quoted context omitted.

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

Yup. The network engineer in me would never recommend Ubiquiti for any scenario. Maybe it works for WISP because of the price point; I'd have to be convinced. They run an embedded Mongo DB on their UniFi hardware that (at least in the deployment I've inherited) requires occasional direct interventions[1] to keep running. That's just one example of the many baffling/wrong things they do. I know Mongo gets quite a bit…

My IT MSP solely sells and supports unifi WAPs, and I have no idea what you're talking about.

We have dozens of WAPs under management across the city and state, and I've never seen any of the issues you guys are talking about. We don't have issues with database crashing or overheating. The wap controllers are configurable for automatic firmware updating, so I don't know what the issue is with patching. They definitely support wpa-e/radius because I've configured it and we use it in my my office.

A personal goal of mine is to buy a unifi wap and a modem (already have a router and firewall) and divorce from ISP equipment altogether. Then I can start posting on /r/homelab :)

Re: How we solved our office Wi-Fi problems

#216

Earlier quoted context omitted.

Fine, I'll say it: Ubiquiti is not suitable for a business environment. They don't have a good track record of pushing out security fixes. They've blatantly violated the GPL (and introduced security vulns in the process). Their "enterprise" features don't work well (e.g. hardware acceleration, WPA+Radius). Depending on what you buy the PoE may be non-standard passive or it may not. Unfortunately because they're prima…

I've heard great things about Ubiquiti's products, so I recently evaluated both their USG security gateway and EdgeRouter4 products using only wired gigabit ethernet. I found it weird that the UniFi line of products and the EdgeMAX line of products while very similar in terms of specs and their target markets, use completely different remote management systems (UniFi vs. UMNS). While some really folks like their mana…

You were using the $100 USG?

https://unifi-xg.ubnt.com/usg-xg-8

https://www.ubnt.com/unifi-routing/unifi-security-gateway-pr...

Re: How we solved our office Wi-Fi problems

#217
post #134
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

> All channel management will be by the devices working together, they can throttle down power if they are causing each other interference. UniFi does not do this. At all. The Auto settings are the same as basically every other commodity AP out there -- look for the least noisy channel at boot, transmit full power, allow any client to remain associated regardless of signal strength. UniFi has an ok tool for on-demand…

yeah, I knew that and forgot thinking there was some kind of magic. too bad i cant edit these comments. by bad.

Re: How we solved our office Wi-Fi problems

#218

Earlier quoted context omitted.

Yup. The network engineer in me would never recommend Ubiquiti for any scenario. Maybe it works for WISP because of the price point; I'd have to be convinced. They run an embedded Mongo DB on their UniFi hardware that (at least in the deployment I've inherited) requires occasional direct interventions[1] to keep running. That's just one example of the many baffling/wrong things they do. I know Mongo gets quite a bit…

My IT MSP solely sells and supports unifi WAPs, and I have no idea what you're talking about. We have dozens of WAPs under management across the city and state, and I've never seen any of the issues you guys are talking about. We don't have issues with database crashing or overheating. The wap controllers are configurable for automatic firmware updating, so I don't know what the issue is with patching. They definitel…

I have an office with a few of those and they are not great and do overheat. I am quite surprised you having been exposed to a great number of them never had an issue.

Re: How we solved our office Wi-Fi problems

#219
post #148
post #38

Earlier quoted context omitted.

Haven't the Mikrotiks had lots of serious vulnerabilities recently?

Those that weren't updated for a year.

There was a 0-day winbox bug this year that was being actively exploited in the wild. They definitely have their share of security issues, and more are likely to come since they write their own versions of httpd, sshd, smbd, etc instead of using well tested open source versions.

As long as you aren't exposing the device itself to the internet, you should be safe from most exploits if your LAN is semi-trusted.

Re: How we solved our office Wi-Fi problems

#220
post #194
post #185

Earlier quoted context omitted.

I sincerely question the value of a managed wifi system for less than 5 hotspots, I also am even more dubious of the need for a cloud service. wifi should function without the need to phone home.

> I sincerely question the value of a managed wifi system I'm not suggesting that there's necessarily value in "managed", but your parent comment was about the Ubiquiti product being overkill, which is a much broader statement. The GP certainly advocates for management, but that's neither the primary value delivered by the overall product, nor the majority cost (even with a single AP). IIRC, this may not hold for com…

> AFAIK, Ubiquiti's products can be run standalone, only requiring management software for initial configuration.

This is correct. I only power on the controller VM when I want to make a change. I do think a few features, like the captive portal require the controller to be online.

Post reply on HN