Jump to content

Recommended Posts

Posted
I wondered if anyone had any tips for deploying a large amount (200+) of U6-Pros, we will be installing over the summer. It's been about 4 years since I have done this personally. Any tips for keeping track of which one is going into each room etc. Any config changes needed. This will be across three sites connected by VPN, with the controller running on a Windows box.
Posted

I'm doing 50+ of these over summer so will be keeping an eye on this thread. I'm having a little problem with getting the controller setup correctly to work with our Radius Profile and VLANs so if anyone has experience there I'd love to pick their brain a little.

 

As regard what you said - I'm planning on creating reservations for them in DHCP with a note to say what room they're in and then naming according to the room in the Console.

  • Thanks 1
Posted

We use a Clearpass for Radius Authentication and it queries AD on our primary DC. The Access points send the Radius request to the Clearpass device just fine and the authentication part works, the user gets onto the WiFi but they have a wrong IP address (they get an IP on our management VLAN).

 

Based on whether the user is Staff or Student they should get assigned a specific VLAN and based on their VLAN they should get an IP in a particular one of our DHCP Scopes. When I look at the request in our Radius Server, it is handled correctly and returns the correct VLAN ID for a staff / student.

 

I'm guessing that as the request comes back to the AP/Controller it should then relay/assign the DHCP based on the settings defined for that network. (This is the part that seems to be going wrong)

I have the controller set up with the correct underlying networks for each SSID and I'm pretty sure I've got the details of the networks themselves correct.

 

My guest Profile uses a different network and that one seems to work just fine.

Posted

Hmm, I am no RADIUS expert, we are using basic NPS on Windows.

 

So things I setup today to get this working:

 

Within NPS the RADIUS client setup for the AP IP or the subnet the AP's are in.

 

Connection policy setup in NPS based on AD group.

 

VLAN tagged on the port the AP is connected to, we are using HP switches so this is needed.

 

Network configured within the unifi controller, VLAN ID only no subnet etc needed.

 

Profile configured within the controller with the relevant secret added and the IP of the RADIUS server.

Posted

My main advice with Unifi is always, Don't run the controller on Windows! it's fine for a few APs but I wouldn't consider using it for anything like 200 APs.

 

I would suggest looking at this for guidance on installing on linux:

https://community.ui.com/questions/UniFi-Installation-Scripts-or-UniFi-Easy-Update-Script-or-UniFi-Lets-Encrypt-or-UniFi-Easy-Encrypt-/ccbc7530-dd61-40a7-82ec-22b17f027776

 

The script also lets you update just by entering:

 

sudo apt update

sudo apt upgrade

 

You could also look at hosted options, We run a few instances in Digital Ocean for some of our customers, which works well and doesn't cost a fortune either.

Posted

Cannot help with that larger deployment or number of sites but using the controller on a Linux VM will so much easier to update.

 

I’m also using Windows NPS for radius - it is setup using dynamic VLAN assignments, so depending which AD groups the users are in determines which VLAN they use.

Posted

Yep we run ours on Ubuntu, around 70 odd APs.

 

Unifi use the MAC address the same as the serial number so if you scan the serials and pre decide which rooms/areas they are going in you should be able to easily rename on the controller.

Posted

Also we tend to get them all added to the controller prior to physical installation, then name them in the controller with their proposed location and attach matching label to the AP.

 

Finding the AP that hasn't adopted or been discovered by the controller without this can take a lot of wandering around. Occasionally you get one that just doesn't want to play ball and needs messing around with through SSH, especially those that have been sat in boxes with older firmware. (should be less of a problem with the U6 Pros)

  • Thanks 2
Posted

I would recommend a Cloud Key Controller per site, rather than all on one. You can still manage this using one account.

 

Separately, can you even source Unifi Pro 6's? Everywhere in the UK has no or limited stock!

  • Thanks 1
Posted

We did this up to a point.

 

Cloud keys are great until you have to upgrade 20+ remotely immediately and 25% fail meaning hour long drives.

 

On the other hand, if anyone wants 20 controllers at half price I'm your man!

Guest Guest
Posted
Our controller is running on Windows and we've had no issues, we only have 32 access points though
Posted
Our controller is running on Windows and we've had no issues, we only have 32 access points though
We are running 200+ on Windows with no issues.
Posted
I did think about a cloud key, but we have plenty of server space. Yeh managed to get hold of 210, sitting in our store room ready to go.

 

I guess my thinking is why would you need to amend three separate sites simultaneously? You can also stage upgrades at a smaller site, then the larger sites.

 

I've done both - Windows Server and Cloud Key. I just find Cloud Key more polished, one less VM to manage and less issues with the controller service being unavailable.

 

The original white one is 32Bit Gen1 (so avoid this), the black ones are 64Bit Gen2, so you want these. Alternatively a hosted controller on a VPS is another alternative, but you pay x amount per month of course. Most do controller upgrades for you.

Posted
I guess my thinking is why would you need to amend three separate sites simultaneously? You can also stage upgrades at a smaller site, then the larger sites.

 

I've done both - Windows Server and Cloud Key. I just find Cloud Key more polished, one less VM to manage and less issues with the controller service being unavailable.

 

The original white one is 32Bit Gen1 (so avoid this), the black ones are 64Bit Gen2, so you want these. Alternatively a hosted controller on a VPS is another alternative, but you pay x amount per month of course. Most do controller upgrades for you.

Cheers, I think I will see how we get on. We have three sites, I have turned on multi site within the controller. And we will setup each academy in its own site. We should be able to easily move if things don't work. Appreciate the advice tho!
  • 4 weeks later...
Posted

Update we have around 120 access points up so far, not under load but the controller seems to be fine!

 

Been a fun couple of weeks, up and down ladders, in false ceilings and generally very hot! Tomorrow is mounting points onto concrete ceilings, SDS at the ready!

Posted (edited)

Naming convention is good policy. Also a physical map of where they are and what patch panel ports and switch port they go back to especially with bigger deployments. We have 2400 (not Unifi) Aps on our site they all are labeled with the building and floor and in rooms are labeled with the room number. This way we can quickly reboot an AP if there are issues or locate to replace.

 

Unifi lets you import maps and place APs and if possible that would be a great idea.

 

I'd also go for a cloud key for management rather than looking after a OS whatever that may be, I've done Linux before now but you have to consider a lot of stuff before upgrading the controller software i.e. the Mongo DB.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...