Gongalong Posted January 24, 2013 Posted January 24, 2013 Hi folks, Our wireless system is currently a piecemeal set of D-Link WAPs (around 25). It isn't a managed solution, and each WAP operates independently. They're also mostly 802.11g. To add, they connect into the edge switches around the school, so aren't PoE. We're looking to upgrade it, and after recommendations for suppliers/manufacturers/models. The only changes we're looking to make are (a) improving bandwidth and (b) a dual SSID system that will create a separate network for visitors. My networking is pretty good, but I'm not at the level of switch management and complex TCP/IP setups. Any advice is much appreciated. TIA
Haptic Posted January 24, 2013 Posted January 24, 2013 Hi Gongalong, one word answer- Ruckus... Simply put you don't become the most widely deployed wireless solution within UK education without having a solid system, capable of handling with ease the ultra high density nature of classrooms, with unparallelled reliability and a nice straight forward management system. I will drop you a PM to discuss getting you some demo hardware so you can see for yourself. Thanks, Mark 2
Michael Posted January 24, 2013 Posted January 24, 2013 There's nothing wrong with individual WAPs configured correctly (on different channels) for Primary Schools. A managed solution can be considerably more, but as so little WAPs are in use it doesn't make any difference. At 25 WAPs I'd say you're borderline whether or not a managed system is better value for money or will deliver a better quality wireless network. I generally use HP or Cisco WAPs in Primary Schools, connected via PoE at gigabit, offering up to wireless N speeds. 1
Michael Posted January 24, 2013 Posted January 24, 2013 I forgot to add, on HP's and Cisco's, you can create multiple SSIDs (4 or so) with different security encryption and password if required. I'd generally recommend WPA2-PSK AES on individual WAPs. For guest SSIDs I'd probably recommend WPA-PSK AES, as someone always brings a device in which isn't quite up to scratch security wise. WPA is still secure to the best of my knowledge. 1
Gongalong Posted January 24, 2013 Author Posted January 24, 2013 I should add, for context, that we're a Comprehensive with around 1,200 students and 120 staff. All the teachers have laptops, so are currently the only users of wireless. The big potential change is that the students will go BYOD, so we could have another 1,200 users. Hence the system would need to cope with that! (On a Visitor SSID)
Gongalong Posted January 24, 2013 Author Posted January 24, 2013 Also, as mentioned above my network knowledge isn't exactly at expert level. For the Visitor/Guest SSID we'd have to issue IPs via DHCP of course. How would we separate traffic? Is a different IP range/subnet enough?
Michael Posted January 24, 2013 Posted January 24, 2013 If you went BYOD, you'd most certainly need at least double the amount of WAPs, so a managed solution would be the better choice and allow you to scale better. Optionally you can set up VLANs to separate traffic, but this isn't always necessary. If your servers and share permissions are configured correctly you have nothing to worry about. 1
psydii Posted January 24, 2013 Posted January 24, 2013 (edited) What services would you want to be offering to the BYODs? I'd be tempted to offer only via http/https and build the rest of your services around that limitation. You'd then be able to keep all the personal devices in (a) dedicated VLAN(s) away from your AD, SQL and other potentially exploitable services. 1200 users != 1200 devices. Consider that almost all users in a BYOD environment will have 1 Laptop and 1 Phone - That's twice the number of devices you just predicted. Some of your users will have laptop phone and tablet..... a wireless device that is not connected to your network is still on the air, taking up airtime. When you are building for site-wide high density-high throughput, physics takes over and the number of radios is the same from each vendor. A broad rule of thumb is a maximum of 30 active devices per wireless radio and 70 devices per collision domain. Some AP's have more radios than others, whether fewer APs with a high radio density, or more APs with fewer radios is better, is really down to your site's physical structure. You need to specify your requirements strongly. For example: Supporting 60 devices in every classroom simultaneously with a throughput of 3Mb/sec per device and average latency of <20ms. Supporting 300 devices with a throughput of 1Mb/sec and latency of <80ms in the communal areas <-this for example only - the spec above might not be achievable with today's technology. By giving clearly defined outcomes you have a baseline to evaluate the suitability and success of any vendor's implementation. Hope this gives you food for thought. Edited January 24, 2013 by psydii SPAG, Clarity, Minor addition capacity estimates. 1
SuperfluousAdjective Posted January 24, 2013 Posted January 24, 2013 (edited) Also, as mentioned above my network knowledge isn't exactly at expert level. For the Visitor/Guest SSID we'd have to issue IPs via DHCP of course. How would we separate traffic? Is a different IP range/subnet enough? You would have to create a new VLAN and a new DHCP scope. Within your VLAN you would have to add a helper address to your DHCP server. In order to do this you will need an enterprise grade WAP that can handle 802.1q encapsulation/tagging. From there you can create unique web filtering policies and access control lists if desired. To set up the helper config on a Cisco/HP Router/L3 switch just add this to your vlan interface configuration: ip helper-address Repeat for for each vlan or SSID you want to segment. Very simple. Only has to be done at your school's devices that are configured for L3 routing. Edited January 24, 2013 by SuperfluousAdjective 1
m25man Posted January 24, 2013 Posted January 24, 2013 As all of the above ... You are going to have to hone your networking skill sets as VLANs are essential as will be routing and firewall skills. There is no magic bullet, not even the mighty Ruckus can help you if you dont have the underlying infrastructure to carry your traffic. How are you going to get unauthenticated visitors through your private network and out of your county proxy without assistance?? Im afraid that your opening quote, "I'm not at the level of switch management and complex TCP/IP setups" will be your first hurdle. Step up to the plate and get learning or outsource the whole project to someone who can do it for you. 1
Gongalong Posted January 24, 2013 Author Posted January 24, 2013 I suspect the whole thing will be farmed out, as it's too risky a project to just learn on.
twin--turbo Posted January 24, 2013 Posted January 24, 2013 BYOD............ Optionally you can set up VLANs to separate traffic, but this isn't always necessary. If your servers and share permissions are configured correctly you have nothing to worry about. Apart from DOS Attacks, Brute force attempts, rouge IP's and other network nasties....Etc...... Rob
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now