Jump to content

Recommended Posts

Posted
We did the switch from Meru this year. Really wouldn't look back. I replaced 50aps with 41 (mostly AC Pros but some in wall pros too)

Finding it much easier than meru I was also getting APs for like £116 each. And they were the pros

 

We are Meru which is 6 years old now and is something we are looking at replacing. Which Meru APs did you replace? Did you replace switches too? I've had a quick look and our POE switches will not support the these new APs.

  • Thanks 1
Posted
How many SSIDs did you guys have?

We have 2 SSID's

One with Radius that has 3 different vlans defined (school laptops/ staff BYOD, pupil BYOD) and 1 guest Wi-Fi (Unif Guest portal, isolated from rest of network, 4th VLAN)

 

One thing to be aware of is you can't have a radius controlled VLAN and a static one in the controller.

Posted
Currently have: BYOD, Pupil, Staff, Guest, ICT, School, Junior-iPads, Utilities.

 

BYOD will replace Pupil, Staff, ICT in future

Posted
We are Meru which is 6 years old now and is something we are looking at replacing. Which Meru APs did you replace? Did you replace switches too? I've had a quick look and our POE switches will not support the these new APs.

We replaced the AP320s with Unifi AC-Pro APs, they use the standard PoE.

 

No switch replacement yet, changes Cisco ports to trunk with a native VLAN. Was running both side by side while migrating

  • Thanks 1
Posted
We replaced the AP320s with Unifi AC-Pro APs, they use the standard PoE.

 

No switch replacement yet, changes Cisco ports to trunk with a native VLAN. Was running both side by side while migrating

 

Maybe I was looking at the wrong info about the PoE we have the same Meru APs.

 

We've got over 60 APs around our building and a couple external ones too.

Posted
What is the cost difference please? Are you saving much?

I can only go on what we paid six years ago for the ruckus (25 7363’s and a ZD3000) which was nearly £25k and today the 20 ac pros, 23 ac edu’s, five ac mesh, five US-8-60w switches and 2 NSM5s which was a little over £7k.

 

We’ve spun up a new server for the unifi, one for radius and another for freePBX (so we can tannoy to the EDUs from our voip system) but these didn’t cost us anything per se.

 

Reducing SSIDs is what we are doing this year, but dynamic VLANs? Tell me more and why? [emoji1][emoji1303]

Using radius you can dynamically assign a VLAN based on various parameters, but we’ll do it based on security group. Except in the case of our school owned WiFi machines which will be achieved based on their domain membership.

 

So users will sign into our WiFi, and depending on if they are admin, staff or post 16 they’ll be assigned a different vlan. This will segregate their traffic, allow slightly different access lists on our switch and obviously filter the internet accordingly. Machines will to be assigned a vlan which will allow them to connect to the network in the same manner as wired clients.

 

How many SSIDs did you guys have?

 

I think we’ve seven now... hope to leave just three.

  • Thanks 1
Posted

 

Using radius you can dynamically assign a VLAN based on various parameters, but we’ll do it based on security group. Except in the case of our school owned WiFi machines which will be achieved based on their domain membership.

 

.

 

What is the benefit over static port assigned VLANs?

Posted
We’ve still be putting Ac-lites in primaries - with Ac-pro in certain areas.

 

What the difference between the ac-pro and ac-lites? Do they support standard Poe?

Posted
What is the benefit over static port assigned VLANs?

 

The single SSID really.

 

I think it was Meraki who released a white paper explaining that more than four SSIDs is a bad idea - it creates a lot of interference broadcasting all the SSIDs on multiple APs.

 

Having a single SSID for 95% of my clients seems sensible. All our domain connected pcs, all our byod devices can just connect to ‘school wifi’. Guest will connect to a guest network though so we can use the captive portal and issue vouchers.

 

The only other ssid we may need is one for our cashless catering.

Posted
What the difference between the ac-pro and ac-lites? Do they support standard Poe?

 

Lite's use Unifi's own PoE standard, so if you do not get them with their injectors, you need the in line step down for them to work.

 

The Pro and ProHD and all the in wall ones use standardised PoE, so they will work for a straight swap with other APs most of the time.

Posted
Lite's use Unifi's own PoE standard, so if you do not get them with their injectors, you need the in line step down for them to work.

 

The Pro and ProHD and all the in wall ones use standardised PoE, so they will work for a straight swap with other APs most of the time.

 

You can also use the unifi or (recommended) the edgeswitches - that will do both 24v and 48v PoE+. They’re actually decent switches. But it might prove better value to go for the AC-Pro if you have existing PoE switches.

Posted (edited)
Lite's use Unifi's own PoE standard, so if you do not get them with their injectors, you need the in line step down for them to work.

 

The Pro and ProHD and all the in wall ones use standardised PoE, so they will work for a straight swap with other APs most of the time.

 

Last I heard, Ubiquiti had planned to release v2 versions of some of their 24V units (such as the AC-Lite) which were supposed to support 802.3af/A out of the box but still be backward compatible with existing 24V injectors.

 

EDIT: In fact this forum posting on their site seems to confirm that: https://community.ubnt.com/t5/UniFi-Wireless/Updating-PoE-Standards-on-the-UniFi-Product-line/td-p/1999465

Edited by MrEprise
Posted
Last I heard, Ubiquiti had planned to release v2 versions of some of their 24V units (such as the AC-Lite) which were supposed to support 802.3af/A out of the box but still be backward compatible with existing 24V injectors.

 

Yep, they are phasing out the 24v and moving to 48v I think. Certainly the 48v AC lites are readily available now. We put some of the early ones in last August - but did find a couple of 48v switches didn’t really work well. Ended up going to back to a ubiquiti edgeswitch.

  • Thanks 1
Posted (edited)
Last I heard, Ubiquiti had planned to release v2 versions of some of their 24V units (such as the AC-Lite) which were supposed to support 802.3af/A out of the box but still be backward compatible with existing 24V injectors.

 

EDIT: In fact this forum posting on their site seems to confirm that: https://community.ubnt.com/t5/UniFi-Wireless/Updating-PoE-Standards-on-the-UniFi-Product-line/td-p/1999465

 

Can confirm, we got UAP AC Lites over the Summer holiday and they were 802.3af compliant, and backwards compatible with Ubiquiti's janky standard. The UVC-G3 cameras are now also shipping as 802.3af compliant whereas they weren't before.

 

I can't wait for April, I'll be ripping out all our first generation UAPs for more AC Lites, meaning no more inline PoE adapters cluttering up our cabs! \o/

Edited by Blue_Cookeh
  • Thanks 1
Posted

Does anyone know if you can add a man in the middle certificate on Unifi? We have a SSL cert that currently we have to install whenever a new device is added to our WIFI, its OK for School owned WIFI devices but any guests I would just like to give them guest access and off they go.

I guess this could be by using a Captive portal?

Posted

You'll have to manually add the certificate to any BYOD devices no matter what wireless system you're using. You could use a HTTP captive portal (Ubiquiti will support this) with a customised landing page that provides a download to the certificate with install instructions.

 

Personally I don't like doing HTTPS inspection on BYOD networks so we control access with voucher codes (only to stop the kids connecting) and just let the browser display an error page on blocked HTTPS websites. I believe products like Ruckus' CloudPath and Aruba's ClearPass provides this sort of more user friendly functionality, though.

  • Thanks 1
Posted
Can you add proxy details to a guest portal so these wouldnt have to be inputted on to the device for guests?

 

You can use WPAD which will work for most apple and windows devices. Sadly Android doesn't support it though and the user must manually configure a proxy.

  • Thanks 1
Posted

Regarding PoE compatibility.

 

If your current switches only run at PoE/802.3af and you need to upgrade to 802.3at for your WAPs (or any other PoE device for that matter), you could use a midpsan device that will upgrade the power. The midspan will sit between both the switch and the WAP. It will upgrade the power to the newer standard at the same time as passing the data backwards and forwards.

 

https://www.microsemi.com/product-directory/rack-mountable-midspans/4798-pd-9024-pd-9012-pd-9006

  • Thanks 1
Posted
You can use WPAD which will work for most apple and windows devices. Sadly Android doesn't support it though and the user must manually configure a proxy.

 

Are you saying Android doesn't support it via the Ubiquiti guest portal or Android in general doesn't support wpad? I've not set up the Ubiquiti guest access but in general Android supports wpad

Posted
Are you saying Android doesn't support it via the Ubiquiti guest portal or Android in general doesn't support wpad? I've not set up the Ubiquiti guest access but in general Android supports wpad

Everything I have read says Android doesn't support wpad. Are you saying you have it working with Android devices?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...