Jump to content

Recommended Posts

Posted

Hi All,

 

We're in the process of procuring a new Wi-Fi 7 solution for our School. We're currently a Ruckus site and have had great experiences with them, and have no reason to not select them again - except price.

 

We've had a Cambium quotation pitched - I've had the demo of the management UI and it looks good.

 

I am looking for real world feedback from Schools who are currently using Cambium - and in particular any comparisons against Ruckus.

 

Cambium have quoted X7-35X APs, and Ruckus have quoted R575 (due to be released in the summer). We currently running Ruckus R510, with the Virtual Smartzone controller. There's about £3.5k between the quotes (~55 APs) which is enough of a saving to warrant serious consideration.

 

For context we are a secondary School of approx 850 pupils.

 

Thank you 🙂

Posted

No help to you at all really, but we're having Cambium AP's and some switching installed starting next week.

 

The reseller's engineers have been very impressed with the training and product from Cambium, but we've yet to properly try it ourselves in anger.

  • Like 1
Posted

I use Cambium, they're great, you can pay extra for the Pro cloud features, but that's mostly for apartment blocks and people selling access. There's only 2 access levels on the admin interface, Admin or Read Only, so not great if you need more, but apart from that, no problems

  • Like 1
  • Thanks 1
Posted

Hi, I use cambium across the trust.

 

The AP's are solid, the only thing that we have found is that if you go for an AP in every room you need to plan to turn off the 2.4 band on 50% of the AP's due to channel utilization and interference from other AP's.

 

We have had a couple of issues and cambium support have been good. 

 

We have the full CnMaestro licence currently but we can change that down after our 5 years so that we can continue to manage it.

 

I haven't used Ruckus before but I've previously used Unifi, Meraki and Aruba for the big names and I would say they give the Aruba and Meraki a run for their money without the licence issues you face with them.

  • Like 2
Posted

We have Cambium that was supplied and configured by Redway Networks a couple of years back.  

 

Superb kit for the price point, we've essentially had zero wi-fi issues since having it installed.

 

I would like a bit more reporting and proper access to logs but this does involve buying the cnMaestro Pro licenses to get this (and more), but the free version works well enough for us.

 

Pete

 

  • Like 1
Posted (edited)

We had a Cambium system throughout school on 6E but then we were eligible for CtC and it all got swapped out for Aruba.

 

I wish we still had the Cambium system!!

 

EDIT - If anyone wants to buy 50 access points I'm here..

Edited by ITGuyNW
  • Like 1
Posted

Just about to have it installed by Redway as part of our CtC project. Having used Aruba extensively before as well as Ruckus, I have a strong preference already for what I've seen with Cambium. We're Unifi currently.

Our install is pretty much the 35s everywhere with a couple of 55's in high density areas, with them paired up in exam locations. 

  • Like 1
Posted

We've deployed a large number of APs and cnMatrix switches (Supported by Redway) and have been very pleased with both the hardware and the support. Happy to answer any questions based on our experience.

My only criticism is that I'd like to see the Pro licensing tier broken down into more flexible options. With the number of devices we have, the cost was difficult to justify. That said, the free version is still very capable and has provided everything we need.

  • Like 1
  • Thanks 1
Posted

We had a network based on 47 x X7-35X APs installed last summer, and I've got no complaints. We're a primary with a flat network and still using PSK / PPSK as our authentication, so it's a pretty simple setup. We don't use their switches, only because we already had our own in place.

 

The UI takes a little while to get to know your way around, but then which of these UIs doesn't. We're on the free tier, which really adds to the saving. The only thing I wish I had from the paid tier was client history logs - ie, a history of client data so I could track missing client devices to their last known location / AP. Used to have that in a previous system and found it useful, but the free tier only gives you current locations and no history.

 

No regrets here, and made a good saving over the other options we looked at.

  • Like 1
  • Thanks 1
Posted
20 hours ago, notalot said:

Hi, I use cambium across the trust.

 

The AP's are solid, the only thing that we have found is that if you go for an AP in every room you need to plan to turn off the 2.4 band on 50% of the AP's due to channel utilization and interference from other AP's.

 

We have had a couple of issues and cambium support have been good. 

 

We have the full CnMaestro licence currently but we can change that down after our 5 years so that we can continue to manage it.

 

I haven't used Ruckus before but I've previously used Unifi, Meraki and Aruba for the big names and I would say they give the Aruba and Meraki a run for their money without the licence issues you face with them.

 

I have around 30 APs across the site, and in two classrooms that are quite far apart we were experiencing connectivity issues, with very little signal available in those rooms.

As a quick fix, I unplugged the APs in those classrooms. Most devices then connected to the neighbouring APs, which improved things, although we're still seeing a few connectivity problems.

Did you disable 2.4GHz on the APs either side of the affected classrooms? If so, how did you determine which APs should have 2.4GHz turned off?

  • Like 1
Posted

Good question - raises another. Is there a need for 2.4 these days other than some older devices? 

Can the signal strength on 2.4 be changed? - for instance on UniFi you could set the transmit strength to low and enable minimum RSSI.

  • Like 1
Posted
Just now, JazzFlute said:

 

 

I have around 30 APs across the site, and in two classrooms that are quite far apart we were experiencing connectivity issues, with very little signal available in those rooms.

As a quick fix, I unplugged the APs in those classrooms. Most devices then connected to the neighbouring APs, which improved things, although we're still seeing a few connectivity problems.

Did you disable 2.4GHz on the APs either side of the affected classrooms? If so, how did you determine which APs should have 2.4GHz turned off?

 

We laid them out on the floor plan (we have scale drawings) then very unscientifically went through and best guessed 50% of them with local site knowledge of the building structure.

 

Along with this we set the  auto power settings for all aps to 

 

Max Power : 19

Min Transmit Power : 8

Minimum Neighbour : 2

Cell overlap : 50 

 

We had a long call a while ago about the settings and these are a starting point. Without a spectrum analyser its all best guess.

  • Like 1
Posted
1 minute ago, notalot said:

 

We laid them out on the floor plan (we have scale drawings) then very unscientifically went through and best guessed 50% of them with local site knowledge of the building structure.

 

Along with this we set the  auto power settings for all aps to 

 

Max Power : 19

Min Transmit Power : 8

Minimum Neighbour : 2

Cell overlap : 50 

 

We had a long call a while ago about the settings and these are a starting point. Without a spectrum analyser its all best guess.

 

Without bringing anyone in, I think I'll just disable 2.4GHz on the APs closest to the two problematic classrooms and see how it goes. I imagine it's going to be a bit of a trial-and-error process.

The wireless network was originally installed by professionals as part of the CTC funding project, but we've had issues with these two classrooms from day one. It's probably due to the fact that we have an AP in every classroom, which may be causing interference and overlap in those areas.

  • Like 1
Posted

Thank you to everyone who has responded. The overwhelmingly positive support of Cambium has been really reassuring, and we have decided to go with them for our new deployment 🙂

  • Like 2
  • Thanks 1
Posted

It's been reassuring for us too, as when I asked earlier in the year I only got a couple of replies so was a bit worried. Our install starts in a couple of weeks with Virtue, the cablers are in now.

  • Like 1
Posted
On 17/07/2026 at 09:28, JazzFlute said:

 

Without bringing anyone in, I think I'll just disable 2.4GHz on the APs closest to the two problematic classrooms and see how it goes. I imagine it's going to be a bit of a trial-and-error process.

The wireless network was originally installed by professionals as part of the CTC funding project, but we've had issues with these two classrooms from day one. It's probably due to the fact that we have an AP in every classroom, which may be causing interference and overlap in those areas.

you could try turning the power down slightly if you think it might be interference, in regards to max and min power try not to have this too far apart usually no more than 7 difference. it just stops the AP having to change quite so often. 

 

If still having issues raise it with Cambium, to say the support is included for free ive found it pretty good. 

  • 3 weeks later...
Posted

Hi All,

 

I was just wondering - those of you who replied to say you are using Cambium - are any of you using a splash page for your student BYOD Wi-Fi, sending RADIUS auth to NPS and then RADIUS accounting packets to SmoothWall (or another web filter) to apply filtering policy?

 

This is the only bit we're struggling to get working correctly and I wondered if anyone has any tips to share 🙂

 

Thanks

Andy

Posted (edited)
1 hour ago, smarties11 said:

Hi All,

 

I was just wondering - those of you who replied to say you are using Cambium - are any of you using a splash page for your student BYOD Wi-Fi, sending RADIUS auth to NPS and then RADIUS accounting packets to SmoothWall (or another web filter) to apply filtering policy?

 

This is the only bit we're struggling to get working correctly and I wondered if anyone has any tips to share 🙂

 

Thanks

Andy

 

Currently RADIUS auth via NPS, Accounting to Fortinet (via agent) however still researching non expensive solutions to cloud auth via Entra.

 

Whats not working for you?

Edited by RobFuller
Posted

Also RADIUS auth via NPS server (which requires a certificate to be installed).   Only downside is the logs are not great unless you pay for the cnMaestro X license which also opens up better authentication methods I believe.    You also need that for Azure SSO authentication.

 

Ours was configured by Lee at Redway Networks.

 

Pete

 

 

 

Posted

@FragglePete @RobFuller

 

Thank you both!

 

Are you doing this with an 802.1X SSID or are you using OWE with a splash page (captive portal)?

 

We are trying to achieve the latter and it all works beautifully on a single AP but when you roam the client to the next AP, internet connection is lost. SmoothWall then sees the traffic from that client as unauthenticated. So there is an issue with the authentication/accounting packets when roaming. I have Lee at Redway and Cambium looking at it for us, just wondering if there was any knowledge here from someone who has achieved the same.

 

We are using full 802.1X radius to NPS and accounting to SmoothWall for our staff SSID and that roams fine. But reluctant to use this method for students as it's more complicated for them to sign in, and when users change passwords and forget to update wireless profile on all their devices it triggers our account lockout policies. Plus there's nothing to stop a sixth form student (BYOD allowed) signing in a lower school student (BYOD not allowed), a daily captive portal sign in hinders this.

 

The account lockout is already a bit of an admin burden on our staff SSID although we have them fairly well trained now!

 

Thank you ☺️

Posted

We don't use captive portals at all, just 802.1X authentication. It can be a bit of a pain on Android and Chrome devices, but otherwise it's worked well for us.

Like you say, once it's in place it's very reliable. We haven't had too many issues with account lockouts either, although our lockout policy isn't particularly aggressive. Since moving almost everything over to Entra ID and enforcing MFA for all users, we've found that provides a much better security trade-off. In terms of our risk versus disruption assessment, it's been the right balance for us.

Posted
44 minutes ago, RobFuller said:

 

We don't use captive portals at all, just 802.1X authentication. It can be a bit of a pain on Android and Chrome devices, but otherwise it's worked well for us.

Like you say, once it's in place it's very reliable. We haven't had too many issues with account lockouts either, although our lockout policy isn't particularly aggressive. Since moving almost everything over to Entra ID and enforcing MFA for all users, we've found that provides a much better security trade-off. In terms of our risk versus disruption assessment, it's been the right balance for us.

 

Hi Rob,

 

Thanks for your insights! If we can't get the captive portal working then I think we will likely go down a similar route. In addition to lockouts, we also enforce password changes every 45 days, so we'd likely need to consider not doing this anymore and being less aggressive on the lockout policy. As you say, with Entra / MFA these things are less important now, but I feel still a consideration for the case of an on-site brute force from another student etc. Appreciate your input, it's definitely some food for thought 🙂

Posted

Same here, just 802.1X authentication.  The captive portal is in place for users accessing the Guest Wi-Fi and we generate printed tokens handed out to visitors primarily.

 

Agreed that Chrome/Android devices are a pain to get enrolled on WPA3, so I give a rare hat tip to Apple for making their implementation really easy.  

 

Password lock outs can be problematic - we lock out accounts after 3 incorrect passwords and if users don't update the password on their device then their account is continously locked.  We get a notification from our DCs when a lock out occurs so we can usually deal with it quickly if need be.  Users are becoming more educated about it and we make a point of telling them when we do a password reset they need to update their mobile devices as well.

 

We monitor usage on Cambium to see if we have multiple devices assigned to one particular user, and can tell if they have devices logged in at multiple places across the site which would indicate password sharing has occurred.  We allow our Sixth Formers BYOD access and they have been known to share passwords to the lower school, who then shares it to their friends, etc, etc.  In these cases, BYOD access is revoked permanently.... no excuses.

 

Pete

 

 

  • Like 1
  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...