Jump to content

Recommended Posts

Posted

PLAN A

We have taken over an adjacent small building and need to expand the network. We had an extortionate quote for a fibre link. I had the ideas of going to our ISP (EXA) and asking for another broadband connection and having a static route so it appears as a subnet so it appears on our LAN.

 

There won't be alot of devices in the new building and it may even be empty a lot of the time.

 

PLAN B

EXA haven't come back to me yet but could I use any ISP (£50/mth for Daisy FTTC (not leased line) and buy a router with a VPN client on it and create a site to site VPN between the sites?

 

For home working we already use EXA's IPsec VPN.

 

How can i do NAT and DHCP relay etc.

 

I am thinking of getting a pfsense hardware router which features a IPsec client. E.g. https://shop.netgate.com/products/2100-base-pfsense

 

We need to have cloud based VOIP and filtered internet working via EXA.

 

We will also have a Wifi AP and 1 copier using PaperCut.

 

There will be 5 people max working from this building.

Posted
Do you have line of sight between the buildings? You could use a wifi point to point link. If it's only for 5 people to use occasionally this would more than suffice.
  • Thanks 3
Posted
Do you have line of sight between the buildings? You could use a wifi point to point link. If it's only for 5 people to use occasionally this would more than suffice.

 

Yes we do have line of sight. I did think about WiFi p2p but was worried that poor weather would affect it and it might end up being nearly as expensive as fibre.

 

https://store.ui.com/products/ubb-xg seem pricey but they do cheaper one too.

 

https://www.4gon.co.uk/ubiquiti-airmax-powerbeam-c-193_981_935.html Anyone used these?

  • Thanks 1
Posted
I have 2 sites both with Exa, both with Fortigate firwalls, set up a site to site IPSec vpn on them, works great

 

If they were both EXA why did you need the VPN? Can't they do an internal static route? Or is the VPN their way of doing this?

 

Also did they configure the DHCP helper and NAT for you or was this all on your own?

  • Thanks 1
Posted

We used Siklu radio links to link our main building and the 6th form across the road after a tractor took out the cable strung across the road... been very happy with them, but its a very short link (~35m) and we had special 'short link' firmware installed to help. It's a 1 gig link and handles all the 6th form traffic including VOIP etc. it was expensive (£5k), but highways and the Electricity company wouldn't let us put a new cable across the road, so we were stuck.

 

In other areas when we've needed a point to point link, we've used Ubiquity Nanobeams (link here) and have been suprised how well they work for the price (we paid about £70 for each end). We thought for £140 for a link, they were worth a punt! We've now got 3 sets of them running in various 'hard to get a cable installed' places.

Posted
Yes we do have line of sight. I did think about WiFi p2p but was worried that poor weather would affect it and it might end up being nearly as expensive as fibre.

 

https://store.ui.com/products/ubb-xg seem pricey but they do cheaper one too.

 

https://www.4gon.co.uk/ubiquiti-airmax-powerbeam-c-193_981_935.html Anyone used these?

 

We used an older version of these (we moved onto 1 site 8 and a half years ago now) but had them running over a link with line of sight about a mile across the town with zero issues for 2 and a half years. Think the link speed back then was around 100meg, but for a nursery with about 5 computers in it worked perfectly.

  • Thanks 1
Posted

The MAT I used to work for had a couple of their primary schools connected via P2P Wireless radios. One had UBNT equipment, a couple of the others had Cambium.

 

It worked reasonably well over the distances involved (about half a mile for one of the schools, a mile for another and about three miles for the third) for a long time but they got progressively worse as time went on. One of them was point almost directly at Canary Wharf and I think that we were getting a lot of interference from that. Another slowed down to the point of uselessness because we think that the airwaves were getting more congested and that there was interference from domestic wireless networks.

 

They can work well, but if you're in a built-up area you may want to use one which uses a 6GHz radio to avoid that.

  • Thanks 1
Posted (edited)

P2P WiFi link is going to be a whole less hassle than having to setup and manage a VPN for the short distance. Save yourself a lot of hassle.

 

And you should be able to carry over the same vlan if necessary so you don't have any routing issues between the 2 sites.

Edited by Davit2005
  • Thanks 2
Posted
If they were both EXA why did you need the VPN? Can't they do an internal static route? Or is the VPN their way of doing this?

 

Even if it's the same provider it's over a public network. The internal boundary ends at the router.

Posted
+1 for a wireless point to point link. They can operate on a 60Ghz frequency with a very focused beam (with a 5Ghz backup) giving very little interference and +1Gbps speeds.
  • Thanks 1
Posted
If all sites are with the same provider can they not open up IP site to site access? All our schools in the trust use same provider but full bidirectional IP access between them so they don't go via public networks/internet, just through the exchanges private network.
Posted
We used Siklu radio links to link our main building and the 6th form across the road after a tractor took out the cable strung across the road... been very happy with them, but its a very short link (~35m) and we had special 'short link' firmware installed to help. It's a 1 gig link and handles all the 6th form traffic including VOIP etc. it was expensive (£5k), but highways and the Electricity company wouldn't let us put a new cable across the road, so we were stuck.

 

In other areas when we've needed a point to point link, we've used Ubiquity Nanobeams (link here) and have been suprised how well they work for the price (we paid about £70 for each end). We thought for £140 for a link, they were worth a punt! We've now got 3 sets of them running in various 'hard to get a cable installed' places.

 

Thanks everyone for their valued input. Can anyone recommend a installer of PtP Wireless in the Midlands?

Posted
If all sites are with the same provider can they not open up IP site to site access? All our schools in the trust use same provider but full bidirectional IP access between them so they don't go via public networks/internet, just through the exchanges private network.

 

This is tunnelled and is essentially a VPN. My old job we have over 20 sites on an MPLS network like this. Worked well.

Posted
Thanks everyone for their valued input. Can anyone recommend a installer of PtP Wireless in the Midlands?

Where in the Midlands? I imagine (coming from Worcs) that County Infrastructure may be able to do what you're looking for?

  • Thanks 1
Posted

Last place I worked at had what I vaguely recall were UniFi point-to-point radios.

 

Dead simple to set up, was probably 300yds and worked a treat, same boat as yourselves by the sound of it; few VLANs, MFD and some VoIP phones. Radios were PoE and weatherproof. Definitely no sweat and basically treated like a trunk switch-to-switch just with two radios rather than a cable going to and fro.

  • Thanks 2
Posted
PLAN A

We have taken over an adjacent small building and need to expand the network. We had an extortionate quote for a fibre link. I had the ideas of going to our ISP (EXA) and asking for another broadband connection and having a static route so it appears as a subnet so it appears on our LAN.

 

There won't be alot of devices in the new building and it may even be empty a lot of the time.

 

PLAN B

EXA haven't come back to me yet but could I use any ISP (£50/mth for Daisy FTTC (not leased line) and buy a router with a VPN client on it and create a site to site VPN between the sites?

 

For home working we already use EXA's IPsec VPN.

 

How can i do NAT and DHCP relay etc.

 

I am thinking of getting a pfsense hardware router which features a IPsec client. E.g. https://shop.netgate.com/products/2100-base-pfsense

 

We need to have cloud based VOIP and filtered internet working via EXA.

 

We will also have a Wifi AP and 1 copier using PaperCut.

 

There will be 5 people max working from this building.

 

A basic broadband connection with a VPN capable box on the end would work - I'm sure EXA can quote you an FttC connection that would do the job? A Sophos XGS with base licence on an FttC would work cheap as chips too - you'd just need Exa to agree to terminate the VPN. I'm not sure why people saying that a VPN is harder to manage or more expensive than a P2P Wireless link. You have to get it surveyed, installed, supported, and unless it's licenced (£) you'll have the risk of interference. Needs to be at height to stop something crossing the 'link' and if the internet in the main school goes down, you lose both sites.

  • Thanks 1
  • 3 months later...
Posted (edited)

Looking at this again, sorry for bump.

 

I enquired with Exa and they quoted me nearly as much as a new school connection for FTTC. There will only be <5 people working from this annexe! Need something barebones cheap. Was thinking of getting Daisy Business Broadband and use pfSence NetGate to direct all traffic to the VPN.

 

I tested this out from home connection and unfortunately pfSense assumes IPsec peer to peer tunneling. I haven't been able to work out what of the myriad of options I can use on the pfSense

 

I wanted to make use of Exa's remote access VPN using FortiGate but the only credentials they supplied were:

 

Remote Gateway

Preshared key

Account (in form of e-mail address)

Password

 

They were able to accommodate an iOS client by disabling "perfect forward secrecy" on their gateway end for our school. So perhaps they would help me out but think that a permanently on VPN may be misusing this facility. Also a permanently connected VPN would be more vulnerable to attack with a short password and short preshared key.

 

pfSense seems only capable of connecting to a IPsec tunnel or a OpenVPN for NordVPN etc it does not seem geared up for remote access type VPNs.

 

I may contact EXA again and ask if they can setup VPN tunnel rather than remote access type tunnel which would be more secure and also technically possible.

Edited by Alis_Klar
  • Thanks 1
Posted
@Alis_Klar - I have read through the post thread and there may be some options we can suggest for you to achieve the end goal you are looking for. If you would like to discuss these, just drop me a direct message with yours details and the school you work at I will get in touch.
  • 1 month later...
Posted

Hi,

 

Just to update, went with MikroTik Cube pre-configured pair. They basically work out of the box although their documentation is DIRE! Which would be ok but the user interface (RouterOS) is very confusing. https://mikrotik.com/product/wireless_wire_cube_pro

 

These work at 60GHz (802.11ay) and fall back to 5GHz Wifi in bad weather. I had trouble finding out the max eirp of the MikroTik from their specs so they can be used without a 60GHz OfCom licence as they're below 40 dBm eirp. See https://www.broadbandbuyer.com/advice/4527-60ghz-ehf-ofcom-licensing/

 

Not tested the 5GHz fallback in snow yet but although MikroTik have poor documentation their stuff seems rock solid.

 

Problem I had was I changed the wifi password from the default one and it broke the Wifi link (60GHz link was unaffected) and couldn't work out how to fix it. I used their support and they advised that resetting the units restored the pairing from factory.

 

I was worried it might fully wipe the config but support were correct.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...