Jump to content

Recommended Posts

Posted

Hi all,

 

One thing I've not recently looked at is our WIFI setup, as we run Unifi exclusively and to be fair, it's always sat there and done its job.

 

with the advances of technology, I'm tempted to put in a bid for new kit but want to weigh up if it's worth it or not.

 

Unifi seem to change their products more frequently these days (and not always for the better)

 

So, we have a couple of U6 Pro units, the majority are NANO HD (now discontinued) and a few AC Pro stragglers, which do make up a majority of the older building.

 

We're also still using WPA-Personal for our keys (not interested in Radius) so is there a new fromat we should be using?

 

Thoughts Welcome

 

https://eu.store.ui.com/eu/en?category=all-wifi

Posted

Obviously hands down Radius 802.1x is going to be a better choice. Most other methods have workarounds, but one PSK shared is sooner or later going to be leaked.

 

You could look at MPSK or similar (different manufacturers label it differently) essentially one PSK per device, it is not as good as full blown 802.1x but it gets around one shared PSK. Unifi to my knowledge have not yet got a solution for per device PSK although using NPS you could potentially set something up but it will be an admin chore.

Posted (edited)

The only reason I can think of is if any part is not supported so not getting security or functionality. So a rolling program of replacements so they never fall out of EOL could be set up.

 

EDIT: & definitely move away from one key to be shared by all.

Edited by TechMonkey
  • Thanks 1
Posted
Hi, obviously everyone will have their own opinion on which Wifi system to use and why, but if you are happy with your unifi setup you would probably want to look at a rolling replacement to upgrade to the U6 Pro or enterprise across your environment. The U6-Pro also meet the DFE recommended standards for Wifi being Wifi 6 so you can use that as a bargaining tool to get the cash for new APs (Thats what I did so we could begin our rolling replacements). They will adopt into your current environment so it wouldnt be a case of breaking or adapting your entire network, however WPA1 I have always been told is unsecure and WPA2 or 3 is recommended. I went for 2 as some much older devices dont like WPA3 but Radius is the better option in general. If you use a Cloud Key or Dream Machine to manage your APs you can setup Guest and Staff Networks and apply AUPs which helps to meet the new KSCIE regulations as you can seperate your traffic slightly and obviously block any devices you know havent been provided your key. Hopefully that helps?
Posted

Unifi is fine - We're just slowly replacing our NanoHD Pro's (WiFi 5) with U6-Pro's (WiFi 6) - Don't have any of the 6E points yet as need 2.5gb backhaul to really work.

There's nothing really in more expensive WiFi systems that I miss or really need.

 

We have 3 wifi networks on ours

 

School - This runs certificate-based radius auth for school-owned devices. If a device isn't on the domain, it doesn't get on. This is managed via NPS.

 

Staff/Students - THis is a 802.11x smoothwall based wifi for staff/students own BYOD devices

 

Visitor - This is just a PSK that we change often for visitors. We used to just put them on the staff/student one but ran into issues with third parties not being able to install our MITM certificate.

  • Thanks 2
Posted
Hi all,

We're also still using WPA-Personal for our keys (not interested in Radius) so is there a new fromat we should be using?

 

Problem with WPA-Personal keys these days is the ability on both Apple and Android devices to share this key with others - which we found out to our peril last academic year.

 

Radius 802.1x all the way.

 

We replaced our aging HP Wi-Fi system with a Cambium Networks solution over summer - all cloud managed, no on-going licensing and comparable prices to UniFi kit. It's been bloody brilliant so far.

 

Pete

  • Thanks 3
Posted (edited)
Yes, get off WPA-Personal - Might not be interested in Radius, but it's what you need to secure things properly.

 

Does that mean a quick change, or will everyone need to re-enter their password?

 

Capture.JPG

 

These are my options - I assume WPA2/WPA3 does both (?)

Edited by Warwick_Tech
Posted
Does that mean a quick change, or will everyone need to re-enter their password?

 

[ATTACH=CONFIG]69959[/ATTACH]

 

These are my options - I assume WPA2/WPA3 does both (?)

 

No, you'll need to do some research into NPS & setting that up - Don't change it randomly as you'll break everything :p (It's WPA2 Enterprise you'd want)

 

You can have machines authenticate via their Computer accounts - So as long as they have a machine account on the domain they'll connect

Although you really want to be using Computer certificate-based authentication with a PKI infrastructure to allow things like Device guard to work properly on Windows 11

  • Thanks 1
Posted

I work with a trust that had UniFi Ac-lites about 3 years ago and full UniFi switching. Never had an issue. Guest wireless in a Vlan (although they didn’t want the captive portal)

The only thing I’d look at would be some kind of radius - although they’re also looking to go ‘serverless’.

 

Some of the schools have gone for connect the classroom. I don’t really see the benefit they’re getting. At this stage it’s pretty much wireless infra only and the specs are only slightly better. I don’t think they’ll see much performance difference for day to day tasks with the devices they have. (They are using an alternative manufacturer and will end up with a mix of manufacturer in school as not all UniFi will be replaced).

Posted

I did radius on UniFi very early on. Very little was documented about it which made it a challenge, but I managed to find a blog which told me how to set the 'Called Station ID' which was the stumbling block for me.

 

Our current setup is UniFi, and we do radius here as well. If anyone would like to know, our 'Called Station ID' for our setup is

..-..-..-..-..-..:SSID

(replace 'SSID' with the actual SSID name) and that seems to be working for us. I imagine it'd work with any setup but it's UniFi that now passes this to radius as MAC_Address:SSID which is not what it used to do (or at least not based on how I had to set it up before.)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...