Jump to content

nicklowe

Members
  • Posts

    14
  • Joined

  • Last visited

Everything posted by nicklowe

  1. Hi Norphy, To check for high CPU or low memory, initially check: show cpu detail show memory detail If there is a rebooting issue, initially check for the AP determined reason: show system _reboot-info The output of these would usually determine the next troubleshooting steps. Cheers, Nick
  2. Hi Norphy, To understand configuration push issues with Aerohive, you collect and observe the following via SSH (preferable) or the RS232 console: console page 0 _debug capwap cli debug console Then, attempt to push a config and observe the output. It usually becomes apparently from that what the issue is. Also check what you see from: show capwap client If roll back occurs because connectivity is subsequently lost because of something in the config change, this can be checked for via: show config rollback If there are space issues on the AP, this can be checked for by reviewing: show system disk-info Cheers, Nick
  3. Hi Norphy, When you tested the AP120s with a PoE+ injector, where did you place this, by the switch or by the AP? If there is an issue with the cabling causing power-related reliability issues, and to determine this one way or the other, this would need to be placed by the AP with a short patch lead and not by the switch. There is an issue with the AP120 if the metal bracket is screwed up excessively tightly where it can cause a short on the back of the PCB. These are both potential causes that are worth precluding while troubleshooting your issue with your partner and Aerohive. Best, Nick
  4. Aerohive for a public/independent, secondary school (boarding) with the whole campus covered with 213 APs. Very happy! It was an ongoing project from mid-2011 to relatively recently, setup is comprised of about a 50/50 mix of AP330s (3x3:3 802.11n) and AP230s (3x3:3 802.11ac Wave 1).
  5. This will almost certainly be an issue with your configuration and nothing to do with bugs/issues in HiveOS, Aerohive's firmware. Which model(s) of AP do you have deployed? It is bad practice to use a CWP as you are doing. Have you considered using PPSKs or 802.1X for your staff/students? I would be very happy to help you get things working if you ping me via a PM. Have you also considered seeing if it is possible to transfer your support from AIT to a company like LAN3?
  6. Have you tried observing what is going on with a packet capture from another wireless device in range in monitor mode? You should be able to observe the EAPOL / EAP exchange to see if the device can successfully authenticate to the network. And if not, what is actually going on. You can use Wireshark on the RADIUS server to capture the traffic there too for analysis. There is also tracing that can be performed via netsh on the client which could help you out. If you're using a machine digital certificate, it is, as far as I am aware, unrelated to the validity of the machine's domain password. Nick
  7. Be careful to pin down what you mean. If there is nothing performing the function of what a physical controller does, it is not enterprise class hardware as you lose features necessary for such environments. With a company like Aerohive or AirTight they do it in protocol between their APs in a distributed fashion, it's actually far superior than having a physical controller.
  8. I am curious what has made you choose Meru? I would personally have avoided them because they use an single channel architechture (SCA) and looked strongly elsewhere. Aerohive, Aruba, Ruckus etc.
  9. I would go with AC for a new deployment if the price differential isn't too high as the chips are a generation newer and exhibit better performance characteristics. Are you looking at 3x3:3 802.11n APs or something else? For what it is worth, I am an Aerohive fan due to the controllerness nature of their product as it is instead done in protocol in a distributed way between the APs. Ruckus have the best antenna technology and are a great choice though!
  10. Hi, You're right, of course it does not mean that we will follow, but as that article mentions, this is being considered in concert with the other regulatory bodies, the UK included. Historically, we have always followed. Nick
  11. No, it's not the future... More frequency is likely to come on tap in the next year or two worldwide following the FCC's lead: Revolution Wi-Fi: Wi-Fi May Get A Capacity Boost, Thanks to the FCC SCAs should, of course, be avoided where possible due to the inherent co-channel interference issues they cause. For what it is worth, I am an Aerohive fan due to the controllerness nature of their product as it is instead done in protocol between the APs in a distributed fashion. Ruckus have the best antenna technology and are a great choice too. Meru are not a choice I would make precisely because of their SCA approach.
  12. nicklowe

    Proxy

    Have you tried configuring the proxy server to be transparent rather than requiring explicit configuration? In general, proxies are considered by many to be an anachronism and poorer practice these days where not used in a reverse proxy role, especially as the highest bandwidth consumers are typically not cached. The best way to filter is in-line via the default gateway address that a client has.
  13. Be careful! It could easily be considered to be professionally negligent to deploy it with a certificate shared among all devices in a school if that is what you intend. Nothing would be achieved over just using a PSK. Ensure that you are using one certificate per device with individual enrolment, don't reuse credentials. A primary purpose of WPA2-Enterprise is to get away from this aspect of WPA2-Personal. It's a massive accountability, auditability and security nightmare waiting to happen otherwise. Think about what would happen if you needed to revoke it, and the logistical steps required to correct and resolve it redistributing credentials. You should have a certificate server per school to generate a certificate derived from that sites root on a per-device basis where you don't have federation.
  14. Mustang, Strongly agree that a proper site survey is important and necessary whoever you go with! Meraki and Aerohive do use the same OEM to physically build their APs at the moment, Senao Networks in China and use QCA (Atheros) chips for wireless. (I suspect that this many change somewhat down the line with Cisco's acquisition of Meraki.) The boards are built to custom designs and requirements however, so you can't draw too much inference from who manufacturers them. Software engineering, the main differentiator with all vendors these days, is in house for both companies. I have had good success with HiveOS and HiveManager 6.1r3 that has recently been released. Have you upgraded yet and exercised your use cases? (We have a network of around 100 HiveAP 330s.) Every vendor has their share of bugs and issues with their products, this is why testing what you want to do as well as you can is so important before purchasing. Nick
×
×
  • Create New...