Jump to content

Recommended Posts

Posted
Its due an upgrade but I would have to put a strong case to the business manager to get it replaced.

 

So what are you waiting for? Ubiquity is not the only wireless provider without ongoing cloud costs....but it is widely used....and there are cloud options if you really must. My guess is that a 2012 investment is not yet end of life in a Business Manager's view....but even 5 years worth of £2500 would buy 30 or so of the top end "HD" Ubiquity access points - and more than twice that of "n" access points which you probably have now. The other option is to go back to Fortinet pointing out that the kit is now old - and the warranty they offer is not useful - because you don't really want o maintain kit of that heritage and negotiate a smaller annual payment. Point to Meraki's current offer that are offering 10 years of cloud for the price of 5 and ask them for a 3 year deal to match until they are end of life.

 

MIght be worth getting a small number of new access points and start reducing Fortinet's annual costs - which will at least make them wake up to the fact you are serious about reducing costs and that their gravy train isn't going to last forever unless they start giving you value for money.

I would get rid of Meru tomorrow to be honest, and our latest annual support and warranty is due at the end of August so now is the time to decide.

I`ve never liked Meru (just my personal opinion), I came from a ruckus setup in my last school which was great.

I hate the Meru GUI, whilst the support is quick we find it very difficult to deal with the support engineers. (to the extent where we ask them to communicate over email rather than phone call!)

 

Thank you for your views im going to look in to a number of option in the next week or so.

 

Is it possible to get hold of a Unifi AP to trial?

Posted
Licence costs £0.00

AP range from £80 each to £300 each depending on features etc. PM me if you want to see some screen shots

Thanks,

What AP`s are you using?

Posted

I`ve never liked Meru (just my personal opinion), I came from a ruckus setup in my last school which was great.

I hate the Meru GUI

 

In fairness - I will point out that the MERU single channel architecture is not without some merit. Its often dismissed - in disbelief - that a single channel solution might offer better throughput than conventional wireless deployment...but in dense wireless environments it can be effective...and you can still layer additional channels if it bothers you that you are not using all the spectrum. So if you have 30 laptops all streaming Video then expect most premium wireless solutions to start buffering and spluttering long before a MERU system. And it "may" offer a way of using wide 80 or 160 MHz channels - although in reality there is little feed back from schools to suggest that there is any benefit with "ac"...and I have always wondered if the chips sets don't actually allow MERU to do what they did with earlier "n" chip sets. which may have lost them that edge in the market.

 

And I agree - the interface is awful. A true example of how "NOT" to build a user interface. I still drool over the meraki interface everytime I see it until looking at the price gives a reality check.

 

You may find a supplier that is happy to lend you Unifi kit - but given that they are so cheap and the profit margin not nearly so lucrative you will probably need to buy one. You could buy a wave 1 AP just to get an idea .....and probably sell it on ebay for the same price as you paid for it if you didn't want to keep it. Of course in luxury market suppliers will beat a path to your door and knock the door down if they think they are going to hook you into annual contracts.

Posted

 

Is it possible to get hold of a Unifi AP to trial?

 

What for? They're cheap as chips :) Just buy one, even if it's a basic £80 one and install the controller on your desktop PC to get a feel for it. THe controller will run on windows, linux, in the cloud, locally...

Posted
Sorry to hijack this thread but this post seems relevant to us at the moment. We have a requirement whereby our Wi-Fi system needs to be able to give public access & staff access to a sports centre that we have so the public would need to sign in or authenticate in some way, we also want to rent out whole blocks to various business's giving them Wi-Fi access, we also have boarding pupils from over seas and we will have a secondary school and a further education establishments. All of this will need to be segregated off and each has its own requirements i.e. speed, different signing in methods, RADIUS in some cases. In short it needs to be very flexible. Prior to me starting here they purchased some Ubiquiti Unifi stuff but from what I can see this cant meet all of these requirements, so I am thinking more of an enterprise system is required, would you agree or am I doing a disservice to Ubiquiti?
Posted
I'm still learning the more advanced unifi configs but we have a primary school where we have a normally wireless SSID for school and a public one on a different vlan. The public one requires accepting the T&C's. we don't have any throttling of bandwidth in their yet.
Posted
There's plenty of scope for that @jertsy - radius is easy enough as is segregation, differing speeds & rate limits, vlans etc. It probably could tick all of your boxes however in a more complicated setup like that, and certainly if you wanted to do anything auditing wise then other enterprise solutions may indeed suit better.
  • Thanks 1
Posted
I'm still learning the more advanced unifi configs but we have a primary school where we have a normally wireless SSID for school and a public one on a different vlan. The public one requires accepting the T&C's. we don't have any throttling of bandwidth in their yet.

 

We have something similar at present, its fairly basic stuff but obviously I need to be sure it can grow and adapt as we require it.

Posted
Weirdly I only just discovered that the whole 2.4GHz 1,6,11 channel thing was just for N.America, and have reset ours to 1,5,9,13 as https://en.wikipedia.org/wiki/List_of_WLAN_channels suggests. Just a few clicks on Cisco WLC.

 

Then I noticed it wasn't programmed to use the Extended UNII-2 channels for 5GHz.

 

Wait. you must NOT use channels 1,5,9 and 13. I don't know who or when the Wiki article was written - but its poor advice.

 

it MIGHT have been possible in the early days of "g" wireless to get away with squashing in 4 channels, but that was because it did not use orthagonal whatever mejig so the usage of the 20MHz channel width was very low at the edges of the spectrum of the channel.

 

Even since "n" came out you get much more complete use of the 20 MHz channel - including at the edges. - and spacing 1,5,9 and 13 will produce overlap and co-channel interference. There have been some learned and impressive mathematical papers produces by Cisco amongst others on using 4 channels and they all agree that the co-channel interference using 1,5,9 and 13 will more than destroy any advantages of the extra channel.

 

So Sorry - you are stuck with 1,6 and 11.

 

you MIGHT....if your school is isolated and has no neighbouring housing go with channels 1,7, and 13 which would give you better channel spacing - but you would need to be absolutely certain no one is going to use 1, 6 or 11 anywhere on site (or on a peer to peer link to a projector or whatever).

 

So no. Absolutely no. You must not use 1,5,9, and 13. No vendor/supplier should advise that.

Posted
Prior to me starting here they purchased some Ubiquiti Unifi stuff but from what I can see this cant meet all of these requirements, so I am thinking more of an enterprise system is required, would you agree or am I doing a disservice to Ubiquiti?

 

Ubiquiti supports all the standard enterprise features. If you can't do it Ubiquiti...then you can't do it with anything else either.

 

Yes you need your wireless for any BYOD segregated using VLANS. Ubiuity access points wont do that. No access point does that. You will need smart switches to so it - possibly ubiquiti ones, but most vendors have ranges of switches that will do VLANS.

 

Yes - you will probably link it to your active directory using a radius server. Some access points can run as a radius server for other access points...we run radius on smoothwall - there are lots of ways to do radius. SOme access points - including Unfi - I think will authenticate directly with AD.

 

You will need to think carefully about guest access - and how you make it available - because students will use it in preference to AD authentication - especially if its not filtered or monitored. (And you MUST monitor it by username to satisfy the prevent strategy). Again monitoring and filtering is not a feature of access points but is probably something you already have a facility for.

 

Ubiquiti has guest features which allow registration etc....but there would be no way to prevent a student using it. I suspect you would require "guests" to signup or to be given an account from a database of accounts already set up in AD and record their details. You couldn't automate this.

  • Thanks 1
Posted
Ubiquiti has guest features which allow registration etc....but there would be no way to prevent a student using it. I suspect you would require "guests" to signup or to be given an account from a database of accounts already set up in AD and record their details. You couldn't automate this.

 

You can generate expiring codes that can be given to guests and set it so that you can't go further than a landing page unless you input the code.

Posted
Ubiquiti supports all the standard enterprise features. If you can't do it Ubiquiti...then you can't do it with anything else either.

Yes you need your wireless for any BYOD segregated using VLANS. Ubiuity access points wont do that. No access point does that. You will need smart switches to so it - possibly ubiquiti ones, but most vendors have ranges of switches that will do VLANS.

Yes - you will probably link it to your active directory using a radius server. Some access points can run as a radius server for other access points...we run radius on smoothwall - there are lots of ways to do radius. SOme access points - including Unfi - I think will authenticate directly with AD.

You will need to think carefully about guest access - and how you make it available - because students will use it in preference to AD authentication - especially if its not filtered or monitored. (And you MUST monitor it by username to satisfy the prevent strategy). Again monitoring and filtering is not a feature of access points but is probably something you already have a facility for.

Ubiquiti has guest features which allow registration etc....but there would be no way to prevent a student using it. I suspect you would require "guests" to signup or to be given an account from a database of accounts already set up in AD and record their details. You couldn't automate this.

Has the Ubiquiti stuff really improved that much since this report was done? (http://habitech.s3.amazonaws.com/PDFs/RUC/Ruckus_vs_Ubiquiti_April_2015.pdf)?

 

Last I checked, it had relatively poor channel switching, and the throughput was significantly lower. Plus it simply doesn't have an effective dynamic power level system (ie. with a controller based system, the controller has the "big picture" and adjusts individual AP's power levels to suit the RF environment).

 

It doesn't have the same features as a proper managed solution, but it will work in smaller environments. The guest functionality you mention is sub-par compared to, say, Ruckus, where guest passes are issued by an authorised user.

Posted
The guest functionality you mention is sub-par compared to, say, Ruckus, where guest passes are issued by an authorised user.

 

Don't know about the rest, but this can also be delegated in the newer Unifi Controller.

Posted

Another key point about annual licences is that you get support.

 

For that £2500 if something goes wrong at 4:30pm and engineer will work with you to put it right before the morning.

 

Where as with unifi, it's basically peer to peer forums only.

 

I've worked with both meraki and Meru on issues and with their 24/7 support staff and students never knew that we'd had outages.

Posted
Wait. you must NOT use channels 1,5,9 and 13. I don't know who or when the Wiki article was written - but its poor advice.

 

it MIGHT have been possible in the early days of "g" wireless to get away with squashing in 4 channels, but that was because it did not use orthagonal whatever mejig so the usage of the 20MHz channel width was very low at the edges of the spectrum of the channel.

 

Even since "n" came out you get much more complete use of the 20 MHz channel - including at the edges. - and spacing 1,5,9 and 13 will produce overlap and co-channel interference. There have been some learned and impressive mathematical papers produces by Cisco amongst others on using 4 channels and they all agree that the co-channel interference using 1,5,9 and 13 will more than destroy any advantages of the extra channel.

 

So Sorry - you are stuck with 1,6 and 11.

 

you MIGHT....if your school is isolated and has no neighbouring housing go with channels 1,7, and 13 which would give you better channel spacing - but you would need to be absolutely certain no one is going to use 1, 6 or 11 anywhere on site (or on a peer to peer link to a projector or whatever).

 

So no. Absolutely no. You must not use 1,5,9, and 13. No vendor/supplier should advise that.

 

Must not is overstating it, "should monitor the effect of it with actual data" might be a better idea.

Posted

It doesn't have the same features as a proper managed solution, but it will work in smaller environments

 

Exactly what is meant by a "proper managed solution"? It's surprisingly feature rich to be honest. Ultimately, and this is always a test worth applying, it works. Lots of schools use ie it successfully and on relatively large scale. It's not really surprising as all access points from every vendor use identical chip sets and ... fir that matter ...the same "micro code" to allow it to meet the 802.11ac spec.

 

Unify' controller is feature rich.

 

I agree power management is not what some other AP s give you, but few clients have power control, and turning down the power on an AP but not on the clients doesn't give you the control over cell size you would really like. 802.11h is rarely implemented on clients anyhow and along with TPC, Ciscos proprietory DTPC has not been shown to be significant in real world implementations.

 

 

I've known a school advised to rip out ubiquity, because of wifi shortcomings, only for the expensive replacement to have exactly the same sluggish domain laptop logins in the classrooms from access points far to sparsely spaced outside in corridors.

 

My advice always is buy a couple Unifi APs and get meraki, fortinet, or whatever lend you some kit. Test them in a demanding environment. Will you prefer the meraki interface , absolutely. Will Aruba's beamforming give you a better data rate further away? Yes it will, but nothing like the significance their figures suggest. Will fortinet's single channel give you better video streaming in a dense environment? Yes it will. Would I like all of these things? Yes, I would...but you will need a stop watch to measure the differences...but when you look at the price and the fact that you get all the essential features with unify...its difficult to justify the cost of some vendors products ....and even more difficult to justify their annual maintenance charges.

Posted (edited)
Has the Ubiquiti stuff really improved that much since this report was done? (http://habitech.s3.amazonaws.com/PDFs/RUC/Ruckus_vs_Ubiquiti_April_2015.pdf)?

 

Last I checked, it had relatively poor channel switching, and the throughput was significantly lower. Plus it simply doesn't have an effective dynamic power level system (ie. with a controller based system, the controller has the "big picture" and adjusts individual AP's power levels to suit the RF environment).

 

It doesn't have the same features as a proper managed solution, but it will work in smaller environments. The guest functionality you mention is sub-par compared to, say, Ruckus, where guest passes are issued by an authorised user.

 

 

That report was written by Ruckus, so what do you expect? These large company are pooping their pants at the sight of Ubiquiti with their price vs featureset.

 

Guest passes can be authorized by an Administrator, as with any Wireless system the authentication can be pretty much anything you want thanks to Radius (although UniFi has guest tokens built in already). Also you shouldn't ever let your Wireless solution do automatic channel switching and power levelling, you should be doing that yourself to suit your RF environment, but even still I think Ubiquiti may have this built into their newer models (since they have monitoring radios).

 

My only qualm with Ubiquiti is the lack of "enterprise" support options, the hardware will perform superbly if configured properly by someone who knows Wireless and RF... the same as any Wireless vendor. I think all these enterprise-y managed solutions hide away the more advanced config behind management portals and automation, yet they usually do a pretty poor job of it... but just *good enough* to hide their shortcomings.

 

As with anything you'll find people who love/hate different stuff, from my point of view we've had no trouble what so ever with our (now aging) UniFi setup in the last 5-6 years, this is with Radius and multiple SSIDs/VLANs with all kinds of random devices.

 

Of course, I won't even go into how TERRIBLE the hardware was on our old Netgear system, but I think that's a given hehe

Edited by Blue_Cookeh
Posted

The only shortcoming I still have with Unifi is the 4 SSID limit.

There are times when maybe transitioning or without having to delve into setting up Unifi Groups where a few more SSIDs would be really handy.

 

I've recently been rolling out the new Mesh APs and these are incredibly versatile.

Posted
The only shortcoming I still have with Unifi is the 4 SSID limit.

.

 

Oh dear....you do NOT want to be using more than 4 x SSID....and if you can get away with 3 or 2 (or even 1) so much the better. Better to use RADIUS accounting based on user groups to allocate the user /device in the appropriate way.

 

The reason is that SSID broadcasts are always done at the slowest (possibly "b") rates and can take up a significant part of your high speed "ac" bandwidth.

 

I have seen tables and graphs showing how 4 x SSID can consume as much as 20% without sending any data at all! Yes - you can usually configure these beacons to be shorter and less often if you know what you are doing, but often they are left on their default setting even in an "enterprise" setup.

 

So its probably a good thing they limit you to 4 x SSID.

Posted

Just read many items...

1-5-9-13 is most definitely NO. We had a neighbour using Ch8 which killed two of our channel ranges with interference.

 

Ubiquiti, yes. Sold through Euro_DK based in Latvia (I think). Had good support for purchases. Also, look at their website [Euro dk] and see the other Ubiquiti offerings.....

I bought an outdoor Ubiquiti for under £100 and ran streaming video on a laptop at over 100 metres. Most impressed. Covers our whole yard at a secondary school. They run mesh etc... No brainier with the money we have now....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...