Live data from Hacker News

How we solved our office Wi-Fi problems

triplebyte.com

51–60 of 252 posts

Re: How we solved our office Wi-Fi problems

#51
post #50

Earlier quoted context omitted.

Yes, it should. Assuming you're running your unifi controller on a public ipv4 /32 somewhere on the internet (at some commodity VM host), it's entirely up to you how you want to lock down access to it. Some people do leave the TLS1.2 web browser admin control panel login exposed, but on a non standard port, other people set up iptables ACLs to only allow traffic from a certain IP range, other people set it up so that…

>more in favor of having the unifi controller on the same premises as the APs But when your premise is MANY sites across the country, and you are using a single controller, only ONE site gets the controller on prem, OR you have many controllers running. >Big difference between like $700-900/year and $120/year. At the end of the day, it comes down to what my time is worth doing other things (not how much im paid, but…

> But when your premise is MANY sites across the country, and you are using a single controller, only ONE site gets the controller on prem, OR you have many controllers running.

yes, totally agree, in that sort of scenario with many premises you would set up your own internal L3 management of the APs, in your own management VRF, in RFC1918 IP space.

Re: How we solved our office Wi-Fi problems

#52
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

This a thousand times. The very start of a strong network is a solid Dynamic DNS + DHCP setup. The only IPs that should be static are the router's. In a small office, using your firewall/router is not a bad choice to DNS+DHCP. For companies Segment your APs and servers etc into different VLANs with distinct IP pools, bonus point for different subdomain. This allows your to firewall it off to prevent prying eyes. It a…

Looks like the UAP-AC-EDU is PoE+

I agree though, all my APs run on DHCP.

Re: How we solved our office Wi-Fi problems

#54

> Don’t put 5 GHz on its own band. Uhh, do they mean "don't put 5 GHz on its own SSID"?

I thought it was considered and GOOD idea to put the 5 GHz and 2.4 GHz APs on different SSID is because some clients won’t connect to the faster one automatically. Or maybe it was because all traffic slow down to the lowest level.

Is that no longer an issue? Or maybe these aren’t problems as long as the 2.4 and 5 access points are physically separate.

Re: How we solved our office Wi-Fi problems

#55
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

If you're in a position where you have a small number of AP's (less than 5) the ubiquiti product may appear to be overkill.

Re: How we solved our office Wi-Fi problems

#56
It’s only sort of passively mentioned in the article but I am AMAZED at the number of people who don’t hardwire everything they can.

Obviously phones are out, but why not hardwire every laptop when it’s at the desk? If someone’s using a actual desktop computer like an iMac then what’s the point of Wi-Fi? Clear up the signal space and get a 100% reliable and ultra fast connection.

Re: How we solved our office Wi-Fi problems

#57

Earlier quoted context omitted.

I use Unifi AP at home and a Fritzbox router. At work I have a two sites of Unifi with cloud keys and an edge router. All visible on one management screen and super easy to configure. Fabulous kit. Make sure you take a backup of the cloud key btw, they can get corrupted by a power interruption, and then you have to install from scratch. You can do this from the browser. I wanted to caution people who are choosing Mik…

The vast majority of peoples' houses don't have WAN connections that need the capabilities of the higher-spec mikrotik routers anyways. An RB3011 or RB4011 is overkill for a residential cablemodem or VDSL2 based last mile service, in terms of pps and Mbps capacity, and NAT pps ability. The ubnt ER-X ($48) is good for up to about 700 Mbps of traffic, and comes with sane defaults. If you have truly symmetric 1 Gbps ful…

Why an edge router over unifi, for smaller setups (Triplebyte is what, 30 office people?)

Re: How we solved our office Wi-Fi problems

#58
post #6

>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each…

I wish OpenWRT came with easy-to-configure out of the box fast roaming and a centralized configuration solution. It’s otherwise excellent, and my home network based on OpenWRT works quite well.

Re: How we solved our office Wi-Fi problems

#60
post #57

Earlier quoted context omitted.

The vast majority of peoples' houses don't have WAN connections that need the capabilities of the higher-spec mikrotik routers anyways. An RB3011 or RB4011 is overkill for a residential cablemodem or VDSL2 based last mile service, in terms of pps and Mbps capacity, and NAT pps ability. The ubnt ER-X ($48) is good for up to about 700 Mbps of traffic, and comes with sane defaults. If you have truly symmetric 1 Gbps ful…

Why an edge router over unifi, for smaller setups (Triplebyte is what, 30 office people?)

I wouldn't recommend an edgerouter for a small office, maybe something a bit more serious. I was describing what I'd recommend for a residential/personal small home office setup. Mine is basically a 32x8 capable DOCSIS3.0 cable modem that is a dumb L2 bridge to the cable ISP's CMTS, an ER-X router, a managed mikrotik fanless L2 switch for the LAN, and several $79 UAP-AC-Lite (802.11ac not wave2, 2x2 MIMO, dual band APs).
Post reply on HN