Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. Really surprised to hear of switches "losing" ports - and needing to restart switches - especially from HP that I would regard as a brand that is big enough to want to protect its name. We have seen this kind of behaviour with netgear - which perhaps as a reputation for being budget will not be so surprising to some. However with dozens of switches in place over a large campus I can't say it happens as often as once a year. Nearly always there has been some physical problem with the cabling/sockets/plugs and an error count on that port in the logs until that problem is fixed (usually recrimping or reterminating the ends)....so I'd be interested to know if find its the SAME ports which tend to stop working...and whether you take a look at the logs/packet error status. But we have had the odd PC with a network socket that stops working and had to use a pci card...so ports can fail.
  2. Yes...most of it you rather it was not doing...like constant telemetry back to Microsoft and..."pushing" stuff to you - and updating apps in the background rather than when you might choose ....
  3. Meru at least did have a good foothold in the UK education market (maybe not in the world market, education or otherwise)...perhaps that is what was meant. This foothold was partly because it was pedalled by RM...and perhaps that is why it may not longer so successful (if it ever was). It was installed throughout Northern Ireland at one time....or pretty nearly. Not sure I would have used the expression counter intuitive... you understand the restrictions of 2.4GHz - with its three non overlapping channels (and only 2 if you use a wider 40MHz channel) - which would normally require you to reduce the transmit power - and the fact that a strong signal to noise ration is required to get the high QAM rates which essentially requires you to turn the power up and have a lot more than 2 or 3 access points to cover an area....you then have the problem of co-channel interference...which Meru's system does its best to do away with..and was pretty good at it..the result was that it was extraordinarily effective using that band. ..but today - with 5GHz, a lot more channels, and much greater density (no longer just one trolley of laptops moved around...but devices in every classroom)...it no longer offers the benefits it once did because you need to be using all the channels to get the required throughput. Perhaps if you have most of your client devices capable of operating at 160MHz channel widths...in which case it may be capable to showing some gains. And just to stab them in the back - I'm not convinced that the current "ac" chip sets allow them to do things in the same way as you can't masquerade the MAC address of the APs so clients seamlessly roaming between APs is not so well done. Now if they modelled their marketing like Unify...pile them high and sell them cheap...AND had a technical edge perhaps they would wipe the competition off the plate. There have been reports - in these forums - of some pretty unsuccessful Meru implementations...but that might not be the fault of the product....as indeed the best products can perform badly if poorly set up.
  4. I don't think there is anything really decent - even when it does cost an arm and leg. Partly its because firewall and filtering (and SSO and reverse proxy) all need to be closely integrated these days - because things like "allow Spotify" would require that you make changes in both what would be a traditional firewall and a separate traditional web filter. ...And filters will need to smarten up considerably - and be capable of DNS filtering and reporting ...because mobile apps and https are increasingly difficult to filter and report on with certificate pining and the like. I know some advocate all these things need to be separate and managed separately - but I think that belongs to a era that has passed by...but sadly even the most expensive firewall/filters seem to be struggling to provide what users need..(actually I'm not sure they have bothered finding out what users need...) Still with mobile operators giving away 20GB or more of data every month students won't want to use WiFi - or a desktop PC - because they will get much better throughout on their own device...and probably unfiltered too.
  5. Well either you bought some rubbish Meraki kit or lacked the financial wisdom of testing Unify first ....Could probably have bought a whole unify system for just the money you spend on support...exactly the same wireless chip sets ... same microcode.... OK - I accept the web management system is fantastic...but once you get bored with fiddling months will go by without using it.
  6. ...I certainly think that SSD makes a very noticeable difference...more so than with Win 7.
  7. Because? What do you think is wrong with a smoothwall? (I have a list of things...just wondering if your list might match some of my niggles...)
  8. Meraki = Rolls Royce solution. Schools need the Ford Mondeo solution....works fine...goes much the same speed....(or so close you'd never notice the difference). Don't expect a solution provider to come knocking at your door to sell you the Unify kit...because they make almost nothing out of the sales...
  9. ...and keep in mind that many (possibly all?) of the "ac" APs require 802.11at PoE to deliver full functionality. They all claim to be 802.11af "compatible" - but have to disable the second Ethernet port (...not the end of the world of course)...or limit the number of transmit streams (...more of an impact...) if they don't get the higher power levels delivered by 802.11at capable switches....and some of those switches only have limited numbers of ports which operate at the higher power levels.
  10. I think you only get the poe injector when you buy single AP. When you buy the multi packs ...which are more economic...you don’t get the injector.
  11. PPSK....never could see the point of it. Why invent a further way of identifying users when they could use their AD logon with radius....and then smoothwall can report by logon name without having to use captive portals or some additional method. And yes, I’m sure Aerohive works well...as does ruckus...Aruba..meraki..fortinet and unify. When you want WiFi, get some kit in to test it under a real work load...compare their management functionality...and of course compare pricing.
  12. I have a very similar policy. Don’t pay for warranty. Buy second hand ...but still current generation switches and modules...sometimes for the cost of peanuts...keep several spare switches...although can’t remember last time I used one..and use Lags everywhere to protect against module or fibre failures. Schools don’t need rolls Royce solutions.
  13. I use integrated graphics with a large 4K monitor....seems fine. Not sure that 4K offers anything much in the way of real advantages...especially not for a class display ....
  14. This is the kind of support for Unify that I keep hearing...they have a marketing disruptive model...."pile em high a and sell them cheap" comes to mind...although the 4x4 HD units are not that cheap they are half the price of those of competitors...and of course no on going annual charges or subscription - nor a compulsion to use expensive cloud management... But despite positive comments - my advice - which I repeat in these groups regularly..is don't take anyone's word for it...get some kit in and test it (and test it in a demanding environment). There are lots of different circumstances and deployments that might not make it the right solution.... Given the acute shortage of money in some schools I am often surprised by how many continue to pay out annually or upgrade and extend their existing system without any real evaluation of what is available.
  15. ...hmmm... you would need an internet connection to use MS office apps...probably others too....not least of all because you would almost certainly decide to store user data in the cloud - rather than locally on a device where is can be vulnerable...loss/breakage of device...resets...etc.
  16. Seems an ideal opportunity to evaluate the competition. If you have never seen the meraki cloud interface..it’s worth a look...and unify offers good value for money with no subscription. I’d you are moving from “n” to “ac” and expect higher data rates keep in mind that higher QAM rates need a really good signal to noise ratio, nearly always requiring APs in the same room as clients..which might make you revise your deployment. Don’t stay with a vendor because “it’s easy” because too often vendors rely on this..and you get neither the best product nor the best price. Nearly all the vendors will lend you kit to test...because it’s a massively lucritive for them...except unify, because they are cheap enough to buy and resell..you’ll get much the same price as you pay of them on eBay.
  17. Is this a radius authentication....LDAP..... or simple WPA2 key? If one ofthe former..have you tried with a separate SSID on a simple WPA2? There should be logs somewhere - both in Win10 ...and Unify.... Do use certificates to validate against the APs? ...just shooting in the dark really....As I am often heard to say about problems...there is nothing wrong...except it doesn't work.
  18. So in addition to "logon" profile traffic...how much internet traffic are these using typically. Do you have a 1G internet connection? If so I'd definitely be using some LAGs between switches....costs a lot less than replacing switches.... And it sounds as if you are working towards "ac" which will help ...without those clients capable of supporting if of course. I'd be focussing on one area and aiming for the Wow factor that internet and logon times are much better there...possibly increasing the number of APs...and then when they start asking why is it better in that block/corner - you can explain that given the funds it can be like that everywhere....
  19. ...we bought the RM CC4 package for Creative suite...now upgraded to support 64 bit....just works out of the box....
  20. 1100 wireless clients....Oh! Is it too late to tell you that I would have strongly discouraged that.....wireless and laptops are not a suitable replacement for computer suites.... ...but perhaps they are tablets/BYOD/Chrome book stuff- so perhaps all will be well.....but if you are hoping to get multiple sets or laptops to work - possibly in neighbouring classrooms (does each student have one?)....then this can be a really difficult problem - wirelessly speaking.... If they are laptops taken out of a cabinet - then laptops need to be booted BEFORE the start of the day...so that WSUS, virus updates etc and GPOs all deploy fully before a student gets their hand on one...because that will take a load of bandwidth away at the start any lesson otherwise. If they are students own devices - STRONGLY encourage them to switch on and logon as early as possible - and not to wait until the laptops are required. Even if these clients have "ac" wireless ...I'm guessing nobody bothered looking at the type of wireless card...and guess they are 1x1 with a speed of 433Mb/s. And even if you have acw2 MuMIMO or even 2x2 stream devices you are only going to get 20% more in practice...not the higher figures you see in all the advertising blurb... So in reality...by the time you take into account that this is UDP speed not TCP ....and that client desnisty prevents you using wide channels...you are talking a little over 100Mb/s in real world - wired data terms. And ...this is 100Mb/s to ALL of those clients in a room - not to EACH of them. User experience is not going to tbe great. No changes to switches is going to solve this. Of course if you clients are not "ac"...but "n"...and the access points are out in the corridor so you don't get any of those higher spatial stream datarates...and if the same access points covers more than one room..then ....time to see management and tell them they have badly advised and its not going to work without a lot more investment...in both infrastructure and the clients.
  21. I find that most clients boot faster, logon etc with a 1Gb connection to desktop...as it’s rare for a whole room to boot to logon at exactly the same time.... I’d split a single core switch to 2 switches in a stack and use teamed/ LAG connections to edge switches...splitting the server team between them. This would allow a core switch to fail..and all the edge switches to continue working...and give you some overhead in capacity ready for when you get that 1Gb internet connection. Doesn’t surprise me backbone is 20% max as unless you gave loads of SSD storage even getting data out of a SAN can struggle to fill a single 1Gb link.
  22. ...really, I dont know where to start with such dogmatic, and largely ignorant and poorly informed information. First..”you get what you pay for...” well you might...and you might not. There is absolutely no guarantee that the more you pay gets you a better product. Never has...never will.... that’s not to say that unify is better....or just as good...it’s just that price alone means nothing. “All reputable benchmarks...” Most of the one’s I’ve see are extrodinarily biased. Most wireless systems have an edge in a particular environment. For Meru’s ...now fortinets single channel architecture ..it might be streaming to a larger number of clients...for Ruckus it might be their their beamflex giving a better signal through a wall to get a higher QAM connection....for Aerohive ..it might be their autonomous capability to work intelligently after loosing contact with a controller...for meraki it might be their brilliant user interface. But if you want all of it...you won’t get it...not for any price. For unify...the USP is value for money. It’s the Mondeo car solution for schools. Is it as good as a Rolls Royce?..No. but it doesn’t cost as much as a rolls royce.. and yet does a perfectly good job. 40 to 50 users per AP is going to pretty awful with all APs. A single collision domain with that number of clients has a significant impact on overall throughput....well compared to “gigabit” rates you might have believed from the advertising. Every AP uses one of two types of hardware chipsets ...and both chip sets come with their own microcode firmware which has been granted 802.11 certification. This cannot be changed by a wireless vendor...although I agree ..they can do a lot to help get the best out of what is intrinsically a difficult and limited transport medium with management software. And keep in mind that wireless clients are significantly better today..and for example do roaming just fine without help from the AP...and power control to reduce the size of the collision domain etc. Poor AP positioning and deployment can be more detrimental than choice of AP. Achieving the high data rates of acw2 for example needs a very strong signal to get the spatial separation of MIMO and high QAM rates. Typically no more than 3m or so in open space. Put a wall in the way or even bodies...and most of the benefits of acw2 disappear for all APs ...expensive or not. My mantra..always ..is not to take anyone’s word for this...get some test kit it...test it under load....will unify deliver what some of the more expensive APs do? Probably not...but I had to get stop watch out to measure the difference ...well..a timer in the code actually...
  23. RM here too...and Windows 7-10 (64bit) has been plain sailing...think early adopters had some issues which RM then addressed - and I guess that is partly why we think RM is (sometimes anyhow) is worth paying for. Some older machines - especially those with 2GB (we are largely 4GB or more) - are noticeably slower - and it seems to be mainly down to antivirus software (and Microsoft telemetry - which we have now disabled) taking significant percentages of CPU cycles. Can't imagine many home users left with Win7 so it increasingly looks dated...although functionally fine...(but then I thought there was nothing much wrong with Windows XP either...)
  24. Absolutely agree with this. Although the more functionality you start to use - you are increasingly tied into using that solution.
  25. OK. Once upon a time...in the distant past - when all we had was 3 channels of 2.4GHz (or may be only two channels if you used a wider 40MHz channel)...single channel architecture was ...fantastic actually - and really clever. And if any reader making a choice about wireless vendors doesn't understand it then its worth reading up on because its clever - and gets around some of the limitations imposed by co-channel interference and large numbers of clients in a single collision domain. Basically the APs are on the same channel - and at full power. And the chipsets virtualise their MAC addresses so that clients just see a single access point regardless of where they are - and if the management system decides to move clients to load balance - clients never know about it. And when you had a single laptop card wheeled between classrooms it was great. The trouble now is that all classrooms have the equivalent of laptop carts - either because there are mobile phones , or BYOD tablets, or indeed laptops and that gives you a bandwidth problem that can only be solved by breaking up that domain (collision domain that is...) by layering (to use single channel terminology) or different channels to use the conventional term. And when you do this - you start to lose many if not most of the advantages of the single channel solution. So you might decide you will run a single channel solution with a really high speed 160MHz or 80MHz channel width....but actually this will not work well in a really dense busy environment...and you get much better overall throughput using access points with narrower channels and smaller collision domains - particularly when some of the clients are older and can't take advantage of the wider channels so that significant bandwidth is wasted. So yes - for a single user you would get a really high speed - and even for single class of laptops the single channel solution works well....but start expanding that on a bigger scale and it starts to fall apart...and you would start to need lowering the transmit power to reduce the size of the collision domains to try to reuse some of the bandwidth. Add to that the fact that some of the chips sets don't cater for virtualised MAC addresses and the result is that single channel - although once a deal break - no longer offers schools what they are after. And you don't have the same set of problems with 5GHz because it doesn't go through walls that well...and there are lots more channels. And rather than using new wide channel "ac" access points - you might discover that putting a second "n" access point into rooms on narrower 20MHz channels might actually get you better results for the whole class than using wide channels. Some access points have configurable 5GHz or 2,4GHz to help you achieve this. Putting access points out side a classroom to serve multiple areas is unlikely to get you the best results..although I agree you can omit an access point from inner classrooms with some success if they can be covered by several other access points ...especially if that means you don't need to reuse a channel somewhere else and therefore run APs at higher power settings. ...and I think there are compromises...the solution which gives you the highest speed to a single client - is not generally the solution that will give you the highest overall bandwidth to a high density of clients in a building. And when you start to reuse channels - which can happen even with 40MHz channels especially as DFS channels often gives false detections...turning down the power will reduce co-channel interference and kepp your bandwidth up - but yes, at the expense of more remote clients getting a poor signal, As always don't take my word for this. I always advise everyone to get some test kit on site - several access points.. spread over several rooms...and hammer it with 30 or more laptops, We tried Meru (now Fortinet), Meraki, Aerohive and Unify...and within the range of errors produced by repeating tests found little real difference in actual throughput...but that was pre Wave 2 "ac" so perhaps things are different now. As I say - test it for your self - don't take my word for it...and don't be taken in by smooth talking vendors who convince you they have your best interest at heart...because they are after you money...lots of it...sometimes with annual charges as well....and if you can't tell the difference when testing...I'm pretty certain you won't see much difference when classes use it....
×
×
  • Create New...