Jump to content

Recommended Posts

Posted (edited)

We are a school of 45 staff and 300 students. Now that we are looking to go BYOD path like many other schools, we need a solid wireless network. The current wireless is based on 8 Cisco APs without a wireless controller. So as part of the network upgrade this year, I will be buying new Access Points to cover the whole school. So what are people using and are you happy with it. If not what do you recommend. I am looking at Cisco, Aruba, Xirrus, Meru, Aerohive, Ruckus and Meraki as the options. As far as I know Meraki and Aerohive are cloud managed. I have had an online meeting with Meraki guys and it seems to be pretty good but I haven't compared it with others. They are also sending me a trial unit so it should be here in a week or so. What features should I be looking for in the device. So should I go with the latest cloud managed or should I just stick with the traditional ones. I would also like to know the models if you recommend a particular vendor.

On a different note, I had couple of consultants visit our school this week and after looking at the buildings(old and thick walls) they recommended to use wireless even for the faculty as it might be the cheaper and easier option. The current cabling is Cat5 and very poor quality so we won't be able to get more than 100mb speed with it. Also there are no network diagrams and it will be very time consuming to draw one. So do you think wireless is an option for staff. Or is it not recommended due to security, reliability, speed or other reasons.

Please ask if you require any more information.

Thanks in advance.

 

P.S- Here is the original thread.

http://www.edugeek.net/forums/hardware/111470-help-me-design-our-network.html

Edited by san_narula
Posted
I think whichever system you buy into, you'd need at least two VLANs - one for school equipment and another for BYOD, as essentially for the most part these devices just need web access.
Posted

I too looked at Meraki and Aerohive but eventually went for the Aerohive through a company called LAN3, once in and configured to your requirements it just works, we have had IPads, Andriod and windows wireless devices all hung off them.

 

Superb piece of kit and not that expensive as you will find out as they do bundle deals,

 

I would think that Meraki are the same but I had to make the choice farly rapidly due to IPad workshops being pushed out on schedules nothing more.

 

I do hope this has helped?

Posted

We currently have ruckus and allow anything with wifi to connect to the system, we dont have vlans in yet but am looking at for a summer job.

 

The Meraki stuff looks very interesting with the option to control down to app level from the AP not having to rely on web filter/firewall at the core.

Posted
What about Ubiquiti Unifi - plenty of people on here already using it, I've just started using it at one clients office, and you can do standard separation or VLAN, depending on your requirements, you can even break it down to a point where the Guest/BYOD WiFi uses a PayPal gateway to make it an income generator too, or just simply offer vouchers (like a cafe kind of thing) so that you still have an amount of control over peoples access.
Posted

Running a ruckus system here with 4 VLANS. The last 3 SSIDs are configured through the smoothwall.

Main Domain

Staff

Students&Post16

Guest

 

I have an instruction guide on here on how mine is setup (for smoothwall config). Was very easy to do. Ruckus kit just looks after its self.

Posted
Aerohive primarily sell their solution as cloud based but they do a VM based controller that you can host on your own hardware on site
Posted

Too much emphasis on the Wifi system rather than the BYOD management.

 

Before choosing a wifi vendor make sure that your underlying infrastructure is ready to support BYOD scenarios. Almost any Wifi vendors AP will bridge your client to your wired infrastructure you can do that for £50 or less but once connected how do you steer them through the minefield of Authentication, Subnets, Proxies, Firewalls and Filters...

 

You can spend 30k on a wifi system and still not be able to deliver BYOD as the rest of your network is ill prepared for it.

 

We are seeing an upsurge of MDM Solutions being pushed as a post wifi install solution to these issues as after spending $$$$'s getting BYOD client on line they find they have nothing to control them with !

Look at the whole project not just the Wifi element and of course, I will second the Unifi option as a radio source.

  • Thanks 2
Posted
Too much emphasis on the Wifi system rather than the BYOD management.

 

Before choosing a wifi vendor make sure that your underlying infrastructure is ready to support BYOD scenarios. Almost any Wifi vendors AP will bridge your client to your wired infrastructure you can do that for £50 or less but once connected how do you steer them through the minefield of Authentication, Subnets, Proxies, Firewalls and Filters...

 

You can spend 30k on a wifi system and still not be able to deliver BYOD as the rest of your network is ill prepared for it.

 

We are seeing an upsurge of MDM Solutions being pushed as a post wifi install solution to these issues as after spending $$$$'s getting BYOD client on line they find they have nothing to control them with !

Look at the whole project not just the Wifi element and of course, I will second the Unifi option as a radio source.

 

Totally agree that you have to plan the core and edge network switches, we ended up installing HP 2920 at the edge for our Ruckus wireless to be installed in the summer. Took 5 months for planning and decision making!!

 

Ruckus is great as they currently do the AP and controller bundles, great value..

Posted
Running a ruckus system here with 4 VLANS. The last 3 SSIDs are configured through the smoothwall.

Main Domain

Staff

Students&Post16

Guest

 

I have an instruction guide on here on how mine is setup (for smoothwall config). Was very easy to do. Ruckus kit just looks after its self.

 

 

Hi timbo343

I tried to find your instruction guide but couldn't. Can you post the link?

Posted
Too much emphasis on the Wifi system rather than the BYOD management.

 

Before choosing a wifi vendor make sure that your underlying infrastructure is ready to support BYOD scenarios. Almost any Wifi vendors AP will bridge your client to your wired infrastructure you can do that for £50 or less but once connected how do you steer them through the minefield of Authentication, Subnets, Proxies, Firewalls and Filters...

 

You can spend 30k on a wifi system and still not be able to deliver BYOD as the rest of your network is ill prepared for it.

 

We are seeing an upsurge of MDM Solutions being pushed as a post wifi install solution to these issues as after spending $$$$'s getting BYOD client on line they find they have nothing to control them with !

Look at the whole project not just the Wifi element and of course, I will second the Unifi option as a radio source.

 

 

Actually we are refreshing our whole IT Infrastructure so I am trying my best to make sure that the network is prepared for BYOD. I will start a new discussion thread on how to achieve that but atm I am mainly working on deciding on hardware which is BYOD ready, that's why I have asked people about the wireless systems they are using.

Actually it will be interesting to know how many and what VLANs/SSDs others are using for both wired/wireless networks.

Posted

One of the most common challenges is the Proxy config, how do you get visitors online and through your Proxy with zero intervention? PAC files, Proxy Auto config, Transparent proxy?

I cheat, we have a dedicated VLAN and a second WAN interface with a dedicated line for the visitors. Everything else is routed through the main gateway. Super simple.

Posted
One of the most common challenges is the Proxy config, how do you get visitors online and through your Proxy with zero intervention? PAC files, Proxy Auto config, Transparent proxy?

I cheat, we have a dedicated VLAN and a second WAN interface with a dedicated line for the visitors. Everything else is routed through the main gateway. Super simple.

 

So do you mean there is no filtering for the Guest VLAN at all.

Posted

No, we use a second wan interface on the firewall which has its own dedicated Filter settings we just don't have any issues with proxies.

Everyone on the Guest VLAN gets :-

Captive Portal

Individual Voucher based authentication (so we know which guest had which voucher)

Redirected start page (to push traffic stats on web site for sponsors)

URL Filtering and Application control (No Porn, live streaming or P2P access etc..)

Bandwidth Control ( we cripple phones so they get enough for email, twitter etc)

 

Being able to packet capture your guests at the firewall is interesting... Nothing is safe ;)

Posted
No, we use a second wan interface on the firewall which has its own dedicated Filter settings we just don't have any issues with proxies.

Everyone on the Guest VLAN gets :-

Captive Portal

Individual Voucher based authentication (so we know which guest had which voucher)

Redirected start page (to push traffic stats on web site for sponsors)

URL Filtering and Application control (No Porn, live streaming or P2P access etc..)

Bandwidth Control ( we cripple phones so they get enough for email, twitter etc)

 

Being able to packet capture your guests at the firewall is interesting... Nothing is safe ;)

 

 

Dare to share how do you achieve all this.

Posted

Ruckus here for our BYOD but still in its infancy of use. We've not opened it to students yet but will be when our sixth form opens Summer 2014.

 

We have it sitting on a separate VLAN but you can setup Ruckus to keep the individual clients in full isolation mode and control what parts of other subnets it can access. We've allowed it access to our Frog and E-Mail server internally.

 

Pete

Posted

We are going from an HP WESM based wireless network to Meraki. 60 APs so far and loving the ease of the solution deployment. Pretty much fit and forget so if you do decide to go with Meraki you will not regret it.

 

However the secret to success is all in the planning.

 

You should be thinking about exactly what you are trying to achieve for each type of user. What level of access to what resource. How many devices are you supporting. What sort of content filtering.

 

You need to revisit your existing network and firewall design.

 

Wireless wise:

 

1) get an active wireless survey done with the APs you plan to use. You will end up with a list of exactly how wany APs you need and where they should go.

 

2) work out the cable runs from each AP to your distribution cabinets. Make sure you have enough POE ports in free to support all the APs. I would recommend gigabit POE to APs and gigabit backbone to core switch. So be prepared to buy some new switches.

Posted
You can buy the TP-LINK PoE Gigabit injectors, they need to be version 3 and Black, not the white ones, the white ones are 100mbps if you dont have PoE switches.
Posted
We are going from an HP WESM based wireless network to Meraki. 60 APs so far and loving the ease of the solution deployment. Pretty much fit and forget so if you do decide to go with Meraki you will not regret it.

 

However the secret to success is all in the planning.

 

You should be thinking about exactly what you are trying to achieve for each type of user. What level of access to what resource. How many devices are you supporting. What sort of content filtering.

 

You need to revisit your existing network and firewall design.

 

Wireless wise:

 

1) get an active wireless survey done with the APs you plan to use. You will end up with a list of exactly how wany APs you need and where they should go.

 

2) work out the cable runs from each AP to your distribution cabinets. Make sure you have enough POE ports in free to support all the APs. I would recommend gigabit POE to APs and gigabit backbone to core switch. So be prepared to buy some new switches.

 

This is sound advice, and infact if you get a basic switch that can be managed you can do an active survey with the Meraki AP when not connected to the cloud controller. I have just completed a survey today in this way and it worked very well.

Posted

Meru here. BYOD in its infancy. AD authentication (well, via RADIUS) against members of the BYOD group. Sign the form, become member of group, job done.

 

Separate VLAN, filtering on the core switch/router to keep them away from sensitive stuff, dedicated firewall/proxy rules to allow generic access to the internet with much tighter filtering than through the authenticating proxy. If users need greater access, they can enter the proxy details and get their authenticated access.

Posted (edited)
Actually we are refreshing our whole IT Infrastructure so I am trying my best to make sure that the network is prepared for BYOD.

 

Please don't take this the wrong way, and I realise you might be well aware of this, but you keep talking about being hardware being "prepared for BYOD" and "BYOD ready" and I'd be careful with that term. You need to define with the people who are asking you to make this happen what exactly you're both talking about when you talk about "BYOD ready".

 

Is there a standard spec for what a D that someone BYOs has to be able to do before you will support it?

Is there a "service level agreement" that specifies how far you'll have to go to support devices? What happens if you spec a network to work with "Shiny v1" today and someone brings in a nice new "Shiny v2" the following month and it doesn't work. Is that your problem or their problem?

What are the stakeholders hoping to achieve from this?

 

In a lot of ways, as long as you stick to a reputable vendor, what make of WAP you buy is the least difficult and least interesting part of the project - you wouldn't focus too heavily on what brand of switch your desktops were wired into as part of a project to give everyone access to a new VLE from the desktop - you'd spend more time checking that the VLE worked with your standard browser and thinking about what content users should be able to get to and how they'd get to it. Same here...

Edited by Roberto

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...