Jump to content

Recommended Posts

Posted

OK. Unifi is great but I have one large criticism.

 

It's a pile of s*** when you don't just have a flat network.

I keep reading up on it and there are multiple workarounds, the majority aren't helpful, including daft suggestions like moving DC's, DHCP servers etc.

 

Is there something simple I'm missing?

 

Everything's vlanned up, servers on one, wifi clients on another, AP's and switches on one subnet (not vlanned, just on default obviously)

 

The gist seems to be you can't have the controller on a separate vlan/subnet from the points which is ridiculous. Any help available on this? Ubiquiti's site is clear as mud.

Posted
OK. Unifi is great but I have one large criticism.

 

It's a pile of s*** when you don't just have a flat network.

I keep reading up on it and there are multiple workarounds, the majority aren't helpful, including daft suggestions like moving DC's, DHCP servers etc.

 

Is there something simple I'm missing?

 

 

Must be..

 

We have standard and pro APs setup to offer multiple SSIDS in multiple VLANS - our NM didn't seem to have much of a problem, and reckons these are a whole lot simpler to configure to do that than the procurve stuff we had before..

Posted (edited)
This isn't about SSID's in vlans though - that is easy. It's about actually getting the points to speak to the server in the first place! I'm sure as f*** not putting DHCP on our servers VLAN. Edited by synaesthesia
Posted

Use RADIUS to achieve Dynamic VLAN assignment? AP's are on a single network, clients get shifted to the relevant network upon connecting.

 

Points will always speak to the server providing there is a default gateway setup, and the point knows the servers address.

Posted (edited)

Just had to do that, annoyingly. Will give them statics afterwards. Seems very OTT for such a simple job.

One question furthermore;

I assume the "gateway" in the AP's options is for the networking gateway? (i.e. in this case that vlan's gateway address) and absolutely NOT the IP of the unifi controller?

Edited by synaesthesia
Posted

Nope, this is still not playing ball.

 

So, as I type this I have 3 unifi points connected and speaking to my controller. To do this, I enabled DHCP on that vlan to get them an IP address. That enabled the controller to see them and allow me to set them up.

 

I have given them a static IP, which is fine. However, clients don't get an IP as they're not on the right VLAN.

Move them to the right vlan and no connectivity. The core switch can ping them (whcih is what they're currently plugged into). Routing is working.

The controller is sitting on the servers vlan (100).

The default management vlan across the site is vlan 1.

The wifi clients vlan is 105.

 

If it matters, the cores are HP Procurve 5406. Currently, the APs on the Servers VLAN ping fine.

If I do as the documentation clearly states and UNTAG them for vlan 1 whilst TAGGING them for vlan 105, I can no longer speak to them.

 

The servers are absolutely able to speak to other devices on VLAN1.

They are able to speak to other devices on the WiFi vlan.

They are however unable to speak to the unifi APs.

 

They have 2 ssids both tagged in the controller options for vlan 105.

 

Nothing speaks to anything.

I'm stuck.

Posted

OK - this is how I have our Ruckus system working at this end.

 

Lets use port 1 as the AP, port 24 as the uplink to my core switch.

 

APs are on the networks VLAN (15 in this example)

Clients are put onto VLAN 200 and VLAN 300 by RADIUS

 

Port 1 is untagged to the local network VLAN 15

Port 1 is tagged to VLAN200 and VLAN300

Port 24 is tagged on VLAN15, VLAN200 and VLAN300

Recieving port on the core switch is tagged on VLAN15, VLAN200 and VLAN300

 

All of these networks have default gateways?

The APs default gateway is the gateway of the VLAN it's connected to?

Posted
Your clients are going to be put on the same network as the AP as it stands - there is nothing telling them otherwise if you are not using something like RADIUS to change the VLAN.
Posted
RADIUS shouldn't come into it. It wouldn't actually matter if the clients are in teh same network as the AP as long as they got the right address, but nada. The controller doesn't even speak to the AP.
Posted

The controller needs to be on a vlan with the APs for managment. This vlan must be untagged on the AP ports.

For SSIDs you need the AP ports tagged for those vlans. Your ports that the APs are plugged into will need to support VLANs and have them available on the switch.

 

The APs do not send traffic via the controller for unifi afaik. I assume the APs gateway is for the vlan you are using for management/unifi server.

Posted

My Ruckus controller isn't on the same VLAN as my APs in my setup - they are all gatewayed up and work fine across VLANs.

 

Example -

Controller is on VLAN 2 (10.0.2.x/24 - gateway 10.0.2.1)

APs 1-5 are on VLAN 5 (10.0.5.x/24 - gateway 10.0.5.1)

APs 6-10 are on VLAN6 (10.0.6.x/24 - gateway 10.0.6.1)

APs 11-15 are on VLAN7 (10.0.7.x/24 - gateway 10.0.7.1)

 

My core / routing switch is a 5412xl (12-module version of OP) and APs can talk to controller as all VLANs route through the core switch.

Posted

Right, here's a nice easy diagram of our rough setup (there's more to ours i.e. there's a pair of routing cores, dhcp server is on the other but it matters not)

 

unifi.jpg

 

*Everything* other than the UAP's work.

 

Switch to switch speaks via vlan1. Works fine.

Switch to standard AP is untagged 105. Works fine. Vlan 105 has ip helper address pointing at the right dhcp server etc, addresses allocated without problem.

Switch to UAPs is the obvious issue. Untagged 105 like the standards is a no-go, and untagging them on vlan 1/tagged 105 also. They only work when untagged to vlan 100 (servers) but then obviously can't give out the right IPs.

 

I don't understand why these would be any different to any other standard AP. The understanding is simple enough for a standard one, treat it like an switch as that's all it is - uplink is the cable to switch, client connections (access ports) are wireless. Difference would be, a standard non-vlan aware AP would be like a hub or unmanaged switch. Untagged to the uplink switch on the relevant vlan (which would be 105). However these would be more like a managed switch, which need untagging to vlan 1 and tagging for 105 - as that's the tag they are configured to give the traffic from clients (the same tag stripped from the traffic going to).

 

That isn't difficult. So:

 

1) Is my understanding of these points flawed

2) Are these points just being a pain in the ballbag for the sake of it, flouting standards by doing so

3) Is something drastically wrong with them?

Posted
Are you using the dns record so they know the address of the controller? seeing as you aren't untagging them in the same vlan as it, they won't get adopted if they can't find it.
Posted

The UAPs must have a L3 connection to the controller. That's it.

 

Make sure you have the controller correctly configured first and test by adopting a point attached to the same LAN as the controller.

Set the VLAN assignment to SSID later.

 

Our controller isn't even in the same country.... We use a hosted one on Amazon AWS and don't have any issues connecting them up.

 

We just plug them in and let them get an IP address from whatever LAN they connect to.

Then using L2 discovery SSH into them and set the inform URL to http://mycontrollerIP:8080/inform

As long as the AP has a clear route to the controller it will appear for adoption.

Adopt it.

Configure the Wireless SSIDs and assign the appropriate VLAN

The physical port will be untagged on the UAPs hardware LAN and Tagged on all SSID VLans.

Controller can see UAP and Vice Versa.

 

Works for me and I have hundreds of them working flawlessly, now Im just waiting for my .AC one to turn up next week and gigabit Wifi is on the menu. :)

Posted

Yeah, been looking at those. What sort of prices are those rocking up at? We can't afford to work with much hence we're going for the standards (3 pack for ~150 quid) but going from the bog standard AP's we're used to it's a huge step up.

 

I'm going to approach it with a clear head on Monday, it's been a long and broken week so I suspect things are getting overcomplicated in my mind.

Posted
The UAP-AC will first arrive at around £220 each but I expect them to settle to £199 when they arrive in sensible quantities.
Posted

The weekend did the trick :) All up and running with absolutely no fuss. It's likely it was just a matter of time (waiting for changes to take effect rather than changing IP, yanking cables and wondering why things failed to work).

 

I'm getting older, the patience is growing :)

Posted
OK. Unifi is great but I have one large criticism.

 

It's a pile of s*** when you don't just have a flat network.

 

Glad to hear you got it sorted and that it wasn't anything to do with Unifi. Hope that now you have it all singing and dancing we will hear of your successes with it as opposed to your pitfalls. ;)

 

Unifi rocks, as I'm sure you will see for yourself.

Posted

Well we've had much success with it already, it's just how it works on L3 setups. Just another step to add on to another AP really.

 

It's a piece of cake to set up otherwise and can be installed by a monkey. No offence of course, but for it's cost and apparent reliability along with features you only get from fully managed systems I don't think it can be touched!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...