pirran Posted February 23, 2016 Posted February 23, 2016 I've just updated a thread on our Unifi Radius setup, I've dumped a load of screenshots with some details which might be useful for anyone reading about Unifi kit (or wireless in general I guess). http://www.edugeek.net/forums/wireless-networks/159690-setting-up-ubiquiti-unifi-wifi-radius.html
Blue_Cookeh Posted February 23, 2016 Posted February 23, 2016 @Blue_Cookeh - between 27 and 35 devices connected to an AP with almost all of them on 5Ghz and authenticating using 802.1x back to a windows radius server. Today after updating the controller and firmware (hadn't updated since before xmas) we ran a test with 32 laptops all streaming youtube and bbc iplayer, no problems to report so far. The kids are back in tomorrow so I should get more feedback this week. Changes made - I've now assigned manual channels to the APs as we're not running ZHO and I'm pretty sure the auto function wasn't doing a lot for channel selection, I mapped it out nicely. RSSI has now been set to -15 which is obviously a bit low, i'm just being cautious. Any other ideas? Does anyone run zero hand off in a secondary with a lot of devices? I got he impression this could cause some performance issues with the unifi kit. All suggestions welcome! THanks again. I know you didn't ask for primary but...! We're running ours on ZHO simply because we have a couple of Avaya WiFi phones (coupled with UniFi's outdoor AP & sector antenna to get coverage over our playing field) and we can walk around our site without any dropouts at all. UniFi definitely isn't the best or most intuitive out there, but it's been fantastic on our budget. We've ramped up our device count significantly this year and haven't got any issues. Netbooks, phones, iPads, all sorts are hung off our system.
pirran Posted February 23, 2016 Posted February 23, 2016 Sounds good, do you mind if I ask how many APs you have vs device count connected? I could really do with ZHO but have been a bit scared of running it on the Unifi kit (we run it on our current Cisco gear). Ta
pirran Posted February 26, 2016 Posted February 26, 2016 little update: I've modified the RSSI values on the AP's (new firmware and controller) so this has been done through the GUI. I've currently set this to -15dbi which is very very low, after a quick wander around it seems that I'll definitely have to adjust it. From documentation it looks like -25dbi is a good place to start? It's been a few years since I looked at wireless surveying, what I'm surprised at is how quickly signal drops off within the same room (2.4Ghz). 30dbi under an AP to 55dbi within the same classroom, no obstructions. I think we're going to need to mount new APs in the centre of ceilings, our old kit with adjustable antennas seemed to cope a little better being wall mounted. I've also found it's very easy to assume that existing wireless systems are 'ok' in areas where they really aren't. There's so many dead spots(v.low signal) around the school that existed prior to my arrival and persons have just worked around them for years. I'm starting to think that the expensive pre-existing cisco system doesn't cover a wider area per AP after all. We're definitely going to have go down a single AP per classroom = 30 students BYOD, 1 teacher byod + school owned devices = 62 devices connected minimum, we're pretty much one2one throughout the school. It seems that even if we go with Ruckus that 'may' support 120 concurrent devices, that's going to be pushed over x2 classrooms! to get 5Ghz into each classroom I'm guessing we need to have a single AP per room.
DrCheese Posted January 22, 2018 Author Posted January 22, 2018 Just resurrecting this thread as with a new building on the Horizon (Which will naturally need wifi) I'm still stuck on this - I use Unifi at home and I love it but I'm struggling to find any "large" organisation that uses it. I'm forever seeing UniFi Points in the catering industry (Pubs/Nightclubs etc) but those obviously have different requirements than a school that needs robust wifi. Basically I don't want to put these points into our new building & then have problems with them which will get slapped back with "Should have bought Enterprise" >.< - Is anyone using them in a *Large* deployment (i.e 60+ points?) & if so, how is it working out?
Blue_Cookeh Posted January 22, 2018 Posted January 22, 2018 There are entire school districts in the US that have deployed UniFi https://www.ubnt.com/casestudies/ We're now ripping out our old original UniFi access points... and replacing them with the AC Lite models
Katy Posted January 22, 2018 Posted January 22, 2018 Is anyone using them in a *Large* deployment (i.e 60+ points?) & if so, how is it working out? No, but almost did. We have replaced the entire junior school (which is far enough away from the rest to not interfere) so far - 21 Unifi AC Pros. We are hoping to replace the other building (60 APs) at some point in the future however it means spending money, and we don't really do enough wireless to justify it in the seniors. Enterprisey features such as 802.1X work fine, the "gotcha" is that the APs themselves talk directly to RADIUS so you need to add their management subnet (or individually add them all) to RADIUS. Compared with our old system (HP) where the controller does the talking to RADIUS. Only problem we have is the 4 SSID limit (claims to be 8 on the AC Pro but it means you get 4 on 2.4G and 4 on 5G) so we've had to be clever about how we arrange our 5 networks on them. Compared to our HP MSM460s, they are amazing. Speed test from my mobile on the Unifi gets 60Mbps during the day (on a 100Mbps line), the same test ran through the HP kit gets 13Mbps. (HP kit is running "n" band so no way it should be that slow really). We've gone from multiple daily complaints about class sets of laptops to the occasional one where it's either doing a huge update or it's user error (turned the wifi off on the laptop).
Blue_Cookeh Posted January 22, 2018 Posted January 22, 2018 Only problem we have is the 4 SSID limit (claims to be 8 on the AC Pro but it means you get 4 on 2.4G and 4 on 5G) so we've had to be clever about how we arrange our 5 networks on them. This isn't necessarily a bad thing. Extra SSIDs significantly impact performance. Meraki document this pretty well: https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/Multi-SSID_Deployment_Considerations You could look at using RADIUS VLAN tagging to keep devices on one SSID, but in their correct network.
Chris_ Posted January 22, 2018 Posted January 22, 2018 Basically I don't want to put these points into our new building & then have problems with them which will get slapped back with "Should have bought Enterprise" >.< - Is anyone using them in a *Large* deployment (i.e 60+ points?) & if so, how is it working out? We've got around 100 APs installed across our site. The UniFi wireless works well. What doesn't work well is the whole BYOD/RADIUS/802.1x Smoothwall authentication. I'm still working with the Ubiquiti support team to get this resolved as Smoothwall couldn't care less.
dapaulio Posted January 22, 2018 Posted January 22, 2018 This will solely depend on your number of devices connected and what you use it for. We have 82 pro / ac pro ap with ZHO across the site connected to gig switches servicing mainly BYOD and about 98 banked laptops and tablets All staff classrooms already have a wired computer in so not commonly used by the teachers throughout the day although the option is there. I too love unifi, and tbh can’t say we have had any major issues. And the minor issues outweigh the cost benefit difference. If you want a flawless service then opting for an enterprise solution may be the way forward but The way you use it in my opinion is the sole factor of choosing unifi over a very costly alternative.
dapaulio Posted January 22, 2018 Posted January 22, 2018 We've got around 100 APs installed across our site. The UniFi wireless works well. What doesn't work well is the whole BYOD/RADIUS/802.1x Smoothwall authentication. I'm still working with the Ubiquiti support team to get this resolved as Smoothwall couldn't care less. Exactly my point I was referring too with the minor niggles. We have vlan d our byod network routed straight out of our smoothwall with a smoothwall portal doing authentication which they log in to everyday. Works well but the portal certificate can be a bit of a pain. For some reason I cant get it to work. Smoothwall don’t care and unifi & edugeek community have come up with ideas but nothing as a ideal permanent solution. Smoothwall ingenious solution was to allow a http portal rather than https. Not sure I am comfortable with that solution. We have learnt to live with the certificate error in browser.
jthompson Posted January 22, 2018 Posted January 22, 2018 Not quite 60+ APs here but we're now up to over 40 UniFi AP-AC-Pros. About 700 clients. It's working well for us, with nothing to suggest that we should have spent more money on a different solution (we didn't trial anything else, tbf). Connections are stable, and we're not seeing and quirky stuff happening. There's also nothing to suggest that a much larger deployment of the sort you're thinking of would pose any further problems: I should imagine the controller would cope perfectly fine with a load more APs, given that it's not critical for the APs to actually function. We upgraded to UniFi from a mish-mash of standalone Netgear APs, so the bar was arguably not that high. Previously we would see a class of Windows laptops struggle to log in and work reliably (30 laptops in one room) but we don't seem to have those problems these days. 1
DrCheese Posted January 23, 2018 Author Posted January 23, 2018 ah thank you for the replies - I wasn't aware that there's a few school districts in America that are using them (Their stories page is mostly just home users!) I'm going to get a few at work and test them with our setup & go from there. I'd ideally prefer the wave 2 ones but they seem a bit pricy right now (There's a nano version coming) so will probably be the AC-Pros - Are you guys putting them one per room or spreading them out? I'm aware it doesn't have auto channel mapping (or at least, it didn't before) so I have to be careful with how I balance the channels...
dapaulio Posted January 23, 2018 Posted January 23, 2018 In my opinion it depends on your building structure. Parts of our main building is solid concrete therefore an ap has been designated in every room or if the rooms are clustered in away where demand may be greater. New builds however tend to be stud walls therefore you could probably get away with not putting one in every room. Our new build is three floors and the provisioning of ap works out like a star. Hope this makes sense eg... Ground floor room 1,3,5 First floor room 2,4 Second floor 1,3,5 Works well
synaesthesia Posted January 23, 2018 Posted January 23, 2018 We've got nearly 40 here and they're only the original standard APs. They're well spread out due to the lighter usage we have here but we've installed a couple of the Pro access points in higher use areas and they are immensely powerful. I couldn't recommend them enough. Testing with Radius has been particularly successful here although that's with internal authentication servers (on Windows) rather than Smoothwall.
jthompson Posted January 23, 2018 Posted January 23, 2018 We have about 1 AP for every 3 rooms or so, as a rough figure.
dapaulio Posted January 23, 2018 Posted January 23, 2018 We've got nearly 40 here and they're only the original standard APs. I would like to comment some advice about standards and not sure whether @synaesthesia agrees with me but my experience of the standards ap were pretty poor. Good for really low demand eg maybe in a home. Recommend pros over the standards. Standards use 24v Poe (non standard to most switches) so require a POe injector or compatible switch. Unlike the pros which support 48v poe offered by most Poe switches They also only support 10/100 as apposed to the pros which have gig uplinks. The pros also have a secondary port on them to attach another device eg a Poe camera. Not something I have implemented my self here but read it’s possible We had a small number of standards and I changed them all for pro ac
synaesthesia Posted January 23, 2018 Posted January 23, 2018 Absolutely agree; whilst the standards were all supplied with POE adapters and having a few toughswitches around, the POE wasn't an issue for us but for our light usage, £130 for 3 access points was a no-brainer, with the full knowledge we can adapt and improve over time without changing anything just by adding things in as and when needed. So when we found a few hotspot areas, equipped our 6th form with a laptop trolley etc, we added in the Pro AC points in those areas with no reconfiguration or reworking necessary, nor any costly additions to licenses (looking at you, Ruckus). Also we've added in a couple of external APs around the place, same applies they just went straight in. The Pro's do have a secondary port but they don't pass through PoE. We have an external we fitted to an access gate because the gate people couldn't be bothered to do a proper job of either implementing a modern wifi solution or use a decent camera, so we used the secondary port on the external AP to pass data through to a camera but it did need external power. Works very well Frankly I would recommend the pro's over and above anything, the price is still better than anything else out there and performance is excellent. 1
Katy Posted January 23, 2018 Posted January 23, 2018 We've gone 1 per room in a new build with the Pro ACs, don't notice any channel based problems and didn't have to do anything manually? So either it does it automatically or we were lucky. (We went 1 per room as although it's a new build, the internal walls are that thick chalky board stuff covered in tin foil with about 18 sheets of plasterboard either side, we found with our HP APs which were alternate rooms that the signal doesn't go through the walls very well)
AlanD Posted January 24, 2018 Posted January 24, 2018 This isn't necessarily a bad thing. Extra SSIDs significantly impact performance. Meraki document this pretty well: https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/Multi-SSID_Deployment_Considerations You could look at using RADIUS VLAN tagging to keep devices on one SSID, but in their correct network. Glad you said this, because I was thinking the same. Better to use a single SSID and use AD radius to allocate radio profiles accordingly. Yes, maybe a second one, for guests or testing....but the significant impact of broadcasting SSIDs needs to be really pruned back.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now