Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

SuperfluousAdjective

Members
  • Posts

    51
  • Joined

  • Last visited

Everything posted by SuperfluousAdjective

  1. I don't have experience with Netgear or 3com access points, but the first thing I would look into would be SNMP or scripting a bounce of their connected switchports. Your switches may even have a power save mode which will turn off designated ports at defined times to reduce power consumption. This will in effect bounce he WAPs as well.
  2. We have used Meraki with positive results. They are very popular in our area due to their discounts and everyone we have spoken to about their installation has been extremely satisfied. We have talked to people who yanked out vendors like Cisco and replaced with Meraki because they didn't like the nickel and diming/costs associated with controllers and licensing. Meraki is up front with their costs, offer exceptional education discounts and their controller is very intuitive and powerful. The product is not stagnant at all. The cloud controller is updated frequently. They have been pushing out their mobile device management which we find to be very useful. They also have good BYOD support which is a growing trend. I have to admit though having an internal or VM controller like what Aerohive offers is very appetizing.
  3. We have Extricom and it has been the bane of our existence. It doesn't work well and was incredibly expensive. We could have had all new Cisco 3602i access points installed with Clean Air licenses for half the cost of a comparable Extricom install. In our case we needed two 16 port "switches" or "controllers" @ $7,000 USD each and the software to make them work as a single channel cohesive unit was an extra $10,000 USD. Even if we didn't use all the ports, we were still out an incredible amount of money for wasted space. That's $24,000 USD for 32 ports before even getting to any access points. Even with an education discount it was incredibly expensive. And then the access points (or radios) were ~$900 each on top of the controller costs. And this did not include a license for "True ReUse" which severely limits the device density that can be utilized. Maintenance/license costs just to call for support and no additional licenses was twice as expensive as a cloud controller based solution including the annual cloud controller fees. Not to mention the fact that it just doesn't work very well. When using a dense assortment of devices the system fails and drops connections. We have had issues of access points dropping out and not communicating with the controller. Link lights not working on the controller randomly making trouble shooting difficult. Firmware was supposed to fix, but the web gui still shows activity on all ports, even when no access point is plugged in. If an AP goes down, the GUI doesn't really show it at a glance either. Their claim that they are "not impacted by co-channel interference" is obviously as flatly false on the face as it is in practice. The concept of Extricom is that the switch/controller is essentially a combination of the access point and the controller. The "access points" are not traditional access points. They are "dummy" devices that act as remote radios for the controller. They are essentially radio extensions of the controller and connectivity is fully managed by the controller. All access points are configured to run on the same channel and all "access points" or radio points are simply extensions of the controller. So if you have a mobile VOIP device and you connect to the wireless the idea is that you can walk around your building (assuming you spend $10,000 USD for the cascading software between controllers) and your wireless device doesn't know it is communicating with a new access point. The client never has to re-authenticate with a new AP or change channels. So in theory, if the controller does its job right, you don't lose a packet and you have seamless roaming. This is their "channel blanket." The downside is that wireless is essentially a hub network. Only one device within range of other devices can communicate (send OR receive) at the same time. If two transmissions are received simultaneously the frame will be not be accurate and is discarded for retranmission. The wireless protocols have functionality built in so that when devices pick up a transmission it will wait to try to send, but it is far from perfect and becomes a major factor in any wireless deployment. Collisions or "co-channel interference" becomes more prominent in a single channel architecture if left unmitigated. If you have two classrooms of kids within range of each other using the wireless they will all be on the same channel creating more interference. This is a major problem for single-channel architectures so they come up with ways to reduce the interference. Extricom has "True ReUse" which if I understand it correctly simply tries to time the radios on their access points so that they are broadcasting without stepping on each other. I don't believe it does any client side tricks (you'd have to read their whitepapers if they have any). Most of your traffic is downstream traffic from the radios, so if you can time the transmissions between your radios that are in range of each other so that they won't step on each other you can improve your throughput and decrease your collisions. If you run out of capacity on the channel you have to buy a whole new round of access points/controllers and make a whole new wireless system on a different channel. If you're looking at a single channel system I would seriously consider Meru over Extricom. They have a more complete product and they are a much larger company. I've called Extricom USA 3 times over 3 days and each time the same receptionist picked up and fowarded me to a phone that rang to voice mail (during normal business hours for the time zone). I left voice mails, but never received a call back. I also left two emails on the contact form of their website of which they never responded to. The fourth call I was transferred to someone who didn't even have the courtesy of putting me on hold while he finished up a personal conversation on his cell phone for the next few minutes, but at least he spoke with me, eventually. The organization seems to be a complete cluster. Years later they still seem to be stuck in "startup" mode.
  4. Are you running VirtualCell? Not all devices work properly with VirtualCell/VirtualPort. Try turning off VirtualCell for testing to see if that helps. If it does check the model of your wireless NIC and go directly to the manufacturer's website to see if there is an update. PS I just looked up the hardware for the L300. It has the Intel 3945 which has had known problems with Meru. You're not the only person with this problem. Solution is to update the driver and disable all power-saving modes. Once updated you have to go into the device manager and configure the nic with these changes: http://www.cites.illinois.edu/sites/default/files/wireless/CSC_TECHNOTE_3945_TWEAK.pdf When wireless NIC drivers are created they are often done so with multichannel in mind. Seeing the same MAC address over and over again confuses it, especially when doing its background scans. Also, with battery operated devices they will often use battery saving features which may not be compatible with Meru as they break from the standards protocols. You'll experience a loss of battery life on an already dated battery, but it should work. Meru techs may have a better solution for your hardware as this workaround is a few months old.
  5. Thank you for the update. I wasn't aware of the change. I'll have to look back at your product offering for the next wireless build-out we do and see how it compares to the Aerohive solution. I personally prefer a distributed or cloud based controller solution. As far as the five year costs we recently received many quotes on a wireless deployment of about 200 APs from many vendors. An Aruba bid was made using AP105 access points and a controller. Five year cost was about 35% more expensive than the comparable Meraki MR16. This obviously is dependent upon region, hardware vendor, level of educational discount and many other factors so I assume the price differential we received is not the same across the board. But for us the difference we saw was very great. Even if you fully removed the Aruba controller from the quote the 10 year cost (assuming pricing doesn't change) on Meraki would be cheaper than the 5 year cost of Aruba (with no controller costs). They are pushing some pretty heavy educational discounts around here. A lot of districts in this area have been going with them lately. We called about 6 of them before deciding on Meraki and all of them were very pleased with the product. Not a single negative statement other than one client who wasn't using key caching would have liked to see better roaming performance.
  6. Not exactly because each AP is only responsible for itself and some functions are managed by the controller, they will just continue to operate as is until new instructions are given. Things like channel selection and power changes for interferance management is down while no access to the controller. And since each AP is responsible only for itself it becomes a distributed overhead. Whereas with Aruba there is one AP assigned to both control and manage all other APs in the network, albeit with a silly limit of 16. There is no distribution of resources. This is similar to what Aerohive tried in the past. They killed the program because it sucked. The feature set you can provide is lacking and the limit of the number of APs is annoying and expensive when you hit the wall. Turns out it is just more beneficial all around to put a controller in the cloud or distribute the management among the APs.
  7. The Aruba IAP series is fine if that is what you are looking for. The lack of advanced features and 16 AP limit is a huge hindrance for us and takes the product line out of the enterprise market and into the small/medium business market as far as I'm concerned. Your entire network is also limited to the CPU of a single access point (with a 16 AP limit which tells you there are problems there). Ultimately if you want a true enterprise wireless network you have to buy a controller from them. We actually received a bid from Aruba and they came out considerably higher for their mid-level access points compared to the top level Merakis we put in. Meraki offers pretty steep educational discounts (think 50% or more). The controller/license fee includes warranty and support.. 24/7/365 next day shipment of any failed product. Their controller/license/warranty fee was actually cheaper than a lot other bids we received that had the added cost of a controller (only one, no redundancy). The cloud controller also includes a lot of great reporting/monitoring features common in other controllers as well as Apple mobile device management and some other really useful features we make use of in our network. We didn't choose Meraki because they had a cloud based controller, although it was a nice to have. They have some interesting features in their cloud controller that we make use of. They performed well in our tests and their price was extremely competitive. We don't expect to have any wireless system for more than 5 years so investing in a controller doesn't seem to make a lot of sense. With these it is just a 1-1 swap. The Cat6 lines are run, the mounts are installed. APs hung. When we want to do a refresh we just pull the old down and upgrade to the new... preferably again without a controller. With the way networking is progressing I can't imagine wireless controllers will be around much longer. There isn't much point to it. Wireless management will move to the cloud, virtual appliances or they'll become internal. But the days of buying a hunkin box to manage access points are numbered. I never said running without connection to a controller was a massively special feature. I was just saying that you were wrong when you said you can't authenticate to the network if a Meraki AP loses its connection to the controller. That's false. Nowhere did I state that Aruba or Ruckus did not provide useful features or a fine product. Although, after you brought up the Aruba Instant AP line I do stand by my statement that it is meant more for a small branch office and not an enterprise environment.
  8. This is false. The cloud controller just sends updates of network policy changes to the WAPs. Users continue to stay connected, new users can authenticate, users can roam between WAPs, layer 7 firewall policies/traffic shaping on the WAPs continues to run, and VPNs continuing running. The data traffic is processed internally in the WAP. The cloud provides a management interface and a means for the APs to get updates. If you have an outage at a data center some services in the cloud controller may be done temporarily, but everything critical continues to run on site as it was before the controller went down. Your local controller (if no HA unit) going down would cause far greater issues and far more downtime. Whereas with Meraki your data is replicated within the data center itself and then to another data center as well. Less opportunity for downtime. If your internet connection goes down you're out of luck anyway. Local traffic and authentication will continue to operate. We haven't had an outage with Meraki, but I have done testing while setting up ACLs on the VLANs and it works like a champ without access to the cloud controller. You can't tell the difference except for the lack of internet, which you'd have anyway. Most people don't have redundant wireless controllers anyway so the point of failure is greater. I build my network to be as redundant as possible, but if there is an ISP outage the last thing I'm worried about is creating new wireless policies.
  9. The controller adds functionality and an interface to manage the WAPs. The APs themselves have enough RAM to store their configuration so if the link to the controller goes down very little functionality is lost until it comes back up. You just can't make changes to the configuration of the network or use their online services. But they have redundant data centers across the globe. Keeping controllers in house or in the cloud will be a long debate for any facet of networking. But more and more applications have been moving to the cloud such as Google Apps for Education, Live @ Edu. If you had your own internal mail server you could keep mail services up for your organization, but the idea of managing an extra server, backing it up locally, managing that, power, etc.. it is often easier and cheaper to just do it in the cloud. In many cases it also adds functionality to what you could have internally because it is a shared resource and shared funding. Plus it saves you a lot of headache. Who wants to manage and maintain an Exchange server? That said, a wireless controller is something I would happily put in the cloud.
  10. This really depends on your environment and needs. If you're torn between the two options you may want to even consider using both. It's not necessarily an either or scenario. Using both is great for VDI environments as well as allowing roaming profiles without dealing with migration of large amounts of user data with each new logon.
  11. You can't do this without having access to the core switch. The vlan will need to be created there. Don't forget to trunk your links.
  12. We inherited Extricom here. It is the bane of our existence. It doesn't work properly, firmware is a joke, radio strength seems weak. Simple things like link lights not working on their controllers to connected devices. Radio strength being very weak compared to other wireless solutions in our environment. Coverage seems to be twice as strong when placing a Meraki or third party device directly on top of the Extricom access point to do a 1-1 comparison. Throughput and coverage was more than doubled. I would save yourself the headache.
  13. Well good luck to you. Don't forget to make sure nobody else on the WAN is using that IP space in any way. 10.0.0.0-10.0.255.255 is a large IP space to move yourself into.
  14. You're confusing me a little with your Class A/C comments. That's old school terminology which may or not reflect what you are actually describing. So to be clear, you currently have a 192.168.x.x /24 and a 10.0.0.0 /24 network? Your problem is that you are running out of IP space on the 10.0.0.0 network due to some new developments. A /16 would work for what you are looking to do, but that is a large broadcast domain. It really depends on your network and the protocols you're running, but you typically want to keep the number of hosts per VLAN under 250 if you can. If wireless is "going in" I would put that on a separate VLAN from the start. This will allow customization for performance and security. Depending on your system, it may be a pain to modify the access points down the road. If you need to get your network up and running without configuring new VLANs the setup in your post will work locally. However, make sure any routing changes are carried over to the WAN.
×
×
  • Create New...