19 ms·
How we solved our office Wi-Fi problems
- compumike 8y agoWe had internal debates about different SSIDs for 2.4 vs 5 GHz, but in the end, this is the optimal configuration we landed on. I was also surprised by how slow S3 was with a single download connection, but really fast when using aria2 to parallelize the download.
- lathiat 8y agoI use either axel or lftp’s pget (works on SFTP) all the time. Being in Australia the 200-400ms latency means I frequently wont get full speed otherwise.
- brian-armstrong 8y agoPutting 2.4 and 5 onthe same SSID is a recipe for sadness. OSX does very poorly at deciding which band it should be on, and 2.4 is largely useless in most of SF. OSX also tends to be pretty sticky. The worst is that it uses RSSI as its metric rather than SNR.
- sbradford26 8y agoI know that at least with my Ubiquiti access points I simply set them to prefer 5G and they will move clients over to that. I have had limited issues with roaming and such with that enabled.
- basch 8y agoThe recommended setting for Band Steering is Balanced I believe. Probably depends on how many clients are connecting.
- kalleboo 8y agoYeah what I've done (at home) is use separate SSIDs, everything connects to 5 GHz, and 2.4 GHz is only for legacy devices without 5 GHz support.
- teeray 8y ago> Use fast DNS servers I use GRC's DNS Benchmark tool[1] for this whenever I set up DHCP somewhere, and the results are sometimes surprising. If you're on a *nix or macOS, it runs well under Wine. [1] https://www.grc.com/dns/benchmark.htm https://www.grc.com/dns/benchmark.htm
- compumike 8y agoYes, I just used dig's reported timings: dig triplebyte.com @1.1.1.1 | grep 'Query time' ;; Query time: 2 msec dig triplebyte.com @8.8.8.8 | grep 'Query time' ;; Query time: 21 msec but could imagine doing a more thorough benchmark like the one you linked if my results weren't so dramatically different!
- geek_at 8y agowow didn't think it was this much of a deal but can confirm dig triplebyte.com @1.1.1.1 | grep 'Query time' ;; Query time: 5 msec dig triplebyte.com @8.8.8.8 | grep 'Query time' ;; Query time: 35 msec
- PascLeRasc 8y agoThis is great if you're at home or there's no IT team like in the article (a dream come true!) but if you're in a more corporate network these kinds of tools will usually ping NSFW servers. I also prefer namebench (https://github.com/google/namebench https://github.com/google/namebench) since it runs at the command line.
- basch 8y ago>Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed Am I missing something, or did they buy consumer routers to use as access points? Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each other, to help hand off clients between them. All channel management will be by the devices working together, they can throttle down power if they are causing each other interference. I cant even begin to list all the different benefits with a single set of settings vs devices that dont work together. Even an asus aimesh network would likely be better. Youre asking for a troubleshooting nightmare. You can either pay a couple hundred a year for the management interface, or $80 for an on prem tiny little stick that hosts it. (paying for the cloud hosted one, has its benefits, and is my recommendation.) Access Point - https://unifi-hd.ubnt.com/ https://unifi-hd.ubnt.com/ POE Switch - https://www.ubnt.com/unifi-switching/unifi-switch-poe/ https://www.ubnt.com/unifi-switching/unifi-switch-poe/ Management Interface - https://www.ubnt.com/unifi/unifi-cloud-key/ https://www.ubnt.com/unifi/unifi-cloud-key/ OR Cloud Management https://unifi.ubnt.com/ https://unifi.ubnt.com/ Router - https://www.ubnt.com/unifi-routing/usg/ https://www.ubnt.com/unifi-routing/usg/ You should never need to track down or log into individual devices to configure them. I dont mean to be a complete ballsack, but isnt it weird for a company thats mission is matching talent to problems, to fail to find the talent to adequately address their problem, and to be giving authoritative (mis)advice on something they are not remotely domain experts in. It doesnt seem like the best advertisement. That said, this is the KIND of post companies should be making when their seo expert says to use keywords. Good job writing about improving the internals of your company, and not just what your company does. Write a V2 of this post once you upgrade, and rename the old one, "How we Created (and then mitigated a Device Management and Troubleshooting Nightmare)
- comboy 8y agoThe above may sound like an Ubiquiti ad, but I've tested a few top specs routers about 2 years ago and settled with unifi for my home installation. I needed a good coverage and reliability for my home automation, e.g. when I switch lights on/off I want a consistent few milliseconds latency.
- intsunny 8y agoI really wish MacOS would allow you to choose which band or BSSID to connect to. Every so often I have to physically drag my laptop to the superior AP and restart wifi to get my laptop to stop connecting to the bad AP.
- zlynx 8y agoI believe Ubiquity has an option to force clients off of individual APs when their signal falls too low. Bad for WiFi at distance but good for roaming within an office.
- basch 8y agoThe setting is a mbps setting. If the negotiated rate falls below X, disconnect.
- rconti 8y agoNah it's RSSI-based.
- basch 8y agothats not how they visually expose the setting in the gui. you choose a transmission rate floor, not a power amplitude minimum. https://i.imgur.com/imKDQ14.png https://i.imgur.com/imKDQ14.png there is also a minimum RSSI, but its a per device setting, not a per site setting. https://i.imgur.com/Z6Jsxjl.png https://i.imgur.com/Z6Jsxjl.png Fast Roaming and 802.11 Data Rate Control are the way I would set this setting, vs trying to pick a manual dBm.
- gnu8 8y agoDial down the transmit power on your more distant AP so your laptop won’t think it’s the closest one.
- exabrial 8y agoPro tip: Keep your router/managed switch configurations in source control as text files.
- tradertef 8y agoBiggest issue I have with the solution proposed is the recommendation to avoid DFS channels. These channels are much more "cleaner" as adoption is less due to added cost caused by extra design and certification. Radars are pretty static and does not come and go (especially weather radars), so the router does not need to move from channel pretty much. False alarm can be an issue but if one has a decent quality router, it should not be very often. Furthermore, after a radar detection (false alarm or actual), routers can switch to non-DFS channels and and start operating immediately.
- zamadatix 8y agoWith the caveat that some clients really have trouble with DFS channels. Generally not a problem if you're refreshing your office with new wireless though.
- akurilin 8y agoIf you're based in SF and want to have a high quality boutique IT shop work with you, without hiring IT staff yourself, then I can't recommend https://www.boxit.net/ https://www.boxit.net/ enough. I was managing consumer grade routers for the company since its inception until we switched to Aruba APs (which are awesome <3) and then eventually to an office with a real firewall, several APs, and a switch for 100+ cabled desks. The folks at BoxIT were a real life-saver at that stage, both for the initial setup and proactive monitoring of your network's health over time. Having your staff spend brain cycles on this stuff isn't the best ROI IMO. The one thing to watch out for is VoIP in SF office buildings. Our APs conflict with about 300 other APs in the area, so getting reliable VoIP for your sales people over WiFi is not even worth trying. We got lucky and inherited an office where the previous company learned that the hard way and wired every nook and cranny with ethernet.
- Serow225 8y agoThank you!!
- jpm_sd 8y ago> There’s no IT team at startups Uh, what? Are you nuts? Hire somebody.
- jmuguy 8y agoI work for an MSP servicing small businesses, Triplebyte sounds like one of our clients. I guess since they're developers they think IT is optional and they can save on costs (and/or their time is worth less than ours, which I doubt). And then later those decisions come home to roost and it costs more to pay some company like ours to come in and do things properly. I mean hell with modern wifi like Ubiquiti or Meraki you shouldn't even have to think about half the stuff in this article.
- deleted 8y ago[deleted]
- mmt 8y ago> Hire somebody. This is easier said than done, even if they're convinced it's worth the money. Not only are startup founders faced with the usual problems associated with hiring competent technical people (ironically a problem the OP is attempting to help), but this would be hiring someone whose competence they'd be much less qualified to evaluate. This effect can be seen in "DevOps" (as a title) postings from startups that emphasize Dev (programming against a cloud API and/or "automate everything!"). That kind of redefinition is much harder to do convincingly for office IT.
- jonny_eh 8y ago> Don’t put 5 GHz on its own band. Uhh, do they mean "don't put 5 GHz on its own SSID"?
- compumike 8y agoThanks -- fixed!
- MBCook 8y agoI thought it was considered and GOOD idea to put the 5 GHz and 2.4 GHz APs on different SSID is because some clients won’t connect to the faster one automatically. Or maybe it was because all traffic slow down to the lowest level. Is that no longer an issue? Or maybe these aren’t problems as long as the 2.4 and 5 access points are physically separate.
- slantyyz 8y agoI think it depends on the use case. I set up extra SSIDs for specific bands on my Unifi equipment to force some wifi gear (IP cams that have since been retired) to always connect to the closest AP.
- jrockway 8y agoSoftware has been written that will forcibly disconnect a 5GHz capable client that is found using 2.4GHz. How widely deployed this is, I don't know. Avery did a talk about it (and other things) a couple years ago: https://apenwarr.ca/diary/wifi-data-apenwarr-201602.pdf https://apenwarr.ca/diary/wifi-data-apenwarr-201602.pdf
- Dylan16807 8y agoWhat's the point of using one SSID for both frequencies if you make roaming between them impossible?
- falsedan 8y agoSupporting clients with 2.4-only devices without distributing two sets of credentials & avoiding a 5Ghz use accidentally picking the wrong creds.
- qwerty456127 8y agoCool! Building big-office/building-size WiFi networks had always been such a huge pain... Thank you for sharing your experience!
- mciancia 8y ago> connection requires only 8 of the 16 physical connections to be made successfully. A working 1000BASE-T (gigabit) connection requires all 16 of 16! Small error here, should be 4 of 8 and 8 of 8, respectively ;)
- sokoloff 8y agoThe sentence you copied started with an important qualifier: "Counting both ends of a cable," > If you’re new to making cables However, IMO if you're making your own patch cables, you're so far on the wrong side of what's reasonable that I don't know what else to say. Punching down horizontal cabling to jacks makes sense; there's no other choice. Making patch cables is an enormous waste of resources.
- MBCook 8y agoIt’s only sort of passively mentioned in the article but I am AMAZED at the number of people who don’t hardwire everything they can. Obviously phones are out, but why not hardwire every laptop when it’s at the desk? If someone’s using a actual desktop computer like an iMac then what’s the point of Wi-Fi? Clear up the signal space and get a 100% reliable and ultra fast connection.
- deleted 8y ago[deleted]
- lolc 8y agoYou got a wifi problem? I'll bring the cable.
- slantyyz 8y agoDon't forget the dongle too.
- kraftman 8y agoYou could say the opposite I guess. I'm AMAZED at the number of people that bother hardwiring everything they can for no reason when they have no interference issues. Why go to all the effort of hardwiring every laptop at every desk? If someone's using a laptop and moving around the office, why cable every desk when you can have gigabit wifi wherever you are?
- maxyme 8y agoBecause gigabit wifi turns to 50mbps when the office gets big enough. There is only so much spectrum to use. Plus if you're already connecting monitors when you have your laptop at your desk the Ethernet adapter can be part of the dock.
- cbhl 8y agoWhen the office gets big enough, you reduce transmit power and add more access points so that there's enough spectrum to cover each desk. Aruba Networks equipment was used at my alma mater, and is also used by $dayjob. I've also had good experiences with employers using Cisco Meraki.
- maerF0x0 8y agoAnyone have a recommendation of a company in the Bay area that solves this issue for startups? Someone I can just call, have onsite and get my people back to work in <5 business days?
- samstave 8y agoIll do it.
- basch 8y agodo you mean strategy/planning/design/bestpractice or troubleshooting and implementation? the former can get complicated if you dont scope right, which is why business analysts and enterprise architects exist. just because youre a startup, doesnt mean you dont want to explore where components can be reused, how many places you need to log in to manage your company, how things compliment and overlap each other, and which vendor you should use for which service. good foresight and some lucky guesses can make your life easier later. when you buy three kitchen sinks, and they all offer payroll services, you have to pick which is authoritative. same with file services, corporate planning, financial forcasting. where do you want to put your portfolio management, in something dedicated like clarizen, smartsheet, or wrike; somewhere simplistic like or asana or trello, with finance like anaplan. now that anaplan is on the table, it might change how you feel about adaptive insight. now you might need to replace your gl. losing adaptive insight for anaplan might push you away from workday and towards ultimate, because of the ownership structure (not at all a technical decision.) ten cascades later, you are asking yourself aryaka+hyperv+qumulo+simplivity+ruckus+salesforce+gsuite+adaptiveinsight+workday or velocloud+esxi+nasuni+nutanix+ubiquiti+anaplan+dynamics+office365teams. your either or's become complex and intertwined. you might think some of these decisions are just "IT/technical" but at the the end of the day every decision cascades into another, changing the scope of the next decision. if my somewhat silly rant didnt make my point: too often companies want to outsource decision making that belongs in the c suite, that can give them a competitive edge, if done right, in house by magicians. you lose your magic and secret sauce by going with what everybody else does. its akin to whatsapp being erlang based vs going with metoo ruby. or how newspaper publishers have an edge when they also develop the hosting platform and license to others (vox chorus, gizmodo kinja, wapo arc, say tempest, bi viking, vs wordpress.) https://www.wsj.com/articles/why-do-the-biggest-companies-keep-getting-bigger-its-how-they-spend-on-tech-1532610001 https://www.wsj.com/articles/why-do-the-biggest-companies-ke... http://www.niemanlab.org/2018/09/newsonomics-the-washington-posts-ambitions-for-arc-have-grown-to-a-bezosian-scale/ http://www.niemanlab.org/2018/09/newsonomics-the-washington-...
- slantyyz 8y agoWhile it doesn't really matter whether you use EIA-586-B or EIA-586-A so long as you're consistent, I've been told that EIA-586-A is the standard in Canada. addendum: Re crimping RJ45 - the better way to do terminations is to use the EZ-RJ45 pass-through plugs like the ones made by Platinum Tools. You need a special crimper, but it's night and day easier. If you're using AWG23 Cat 6, you also need to make sure your plugs can handle those wires (not an issue with the Platinum Tools plugs).
- linsomniac 8y agoHoly crap, that is awesome! I might start crimping my own cables again! Nah, but still good to know.
- jahabrewer 8y agoOnly thing I've found annoying about passthrough plugs is it's easy to not quite cut the wires flush with the end of the plug. This can make the plug not seat fully. At least, this is true for me. Maybe I did it wrong.
- slantyyz 8y agoI think this depends on which crimper you use. I used a cheapo crimper from China I bought off Amazon (I wasn't doing enough terminations to justify Platinum Tools' top of the line crimper which cost more than 2x what I paid) and it was leaving maybe a mm or less of wire hanging off, because of the crappy tolerances. On the other hand, I saw some videos on Youtube of people using other cheap crimpers, and they were getting clean flush cuts. Luck of the draw is a big thing when you get the cheaper tools. Originally I thought that 1mm or less was preventing my plugs from seating fully but on further inspection I found that the locking lever on my plugs weren't consistently locking. I made the mistake of not using the matching Platinum Tools strain relief boots for my plugs, which actually have a piece of plastic that pushes the locking lever up a little more to ensure a more secure mating between the plug and port.
- windowsworkstoo 8y agoTypically the cable manufacturer will have a recommendation but in AU I pretty much exclusively use B unless the manufacturer of the cable being used requires A for some reason (like, they spool the strands a certain way, so you might get less AXT with A vs B or some such)
- linsomniac 8y agoGenerally pretty solid advice. I say that as someone who is known for solving tough wireless problems. :-) On the cable termination part: I've (mostly) stopped crimping cables because I've had too many go flaky and don't have 4-5 figure testing equipment. One thing I'll add is that there are ends for solid conductor and stranded, make SURE you have the right ones for the cable you are using. These days I always just put on keystone ends and then use commercial patch cables from there. I've had very good luck. I'd recommend against the advice to use a screw driver to punch them down, the Leviton ones I prefer you just put the cap on and they punch down themselves. The random ones I get from Ace Hardware have a little punch tool included. One additional recommendation I have is to put 5GHz radios in each space. 5GHz has more spectrum, and less interference, but it penetrates drywall significantly worse. But that's a good thing, because it cuts down on interference from your neighbors. Beware of microwave ovens, baby monitors, cordless phones (last 2 more in residential areas). They can be intermittent interference, and won't show up on the non-commercial spectrum analyzers. Our 2.4GHz used to go out when we'd run our brand new microwave. But it would also go out at other times, possibly when a neighbor ran theirs? 2.4GHz penetrates buildings quite well, which kind of sucks. My credentials: https://www.tummy.com/articles/pycon2012-network/ https://www.tummy.com/articles/pycon2012-network/
- slantyyz 8y ago>> I've (mostly) stopped crimping cables because I've had too many go flaky and don't have 4-5 figure testing equipment. I just redid a lot of the ethernet wiring in my house, and it's super easy compared to how I did it 10+ years ago. If you use EZ-RJ45 jacks (the only way to go, imo), it's super easy to get cables working properly the very first time. The wires feed through the jack so you can verify wire order before crimping. I spent less than $200 on the tools I used to do my wiring: * EZ-RJ45 crimper * RJ45 cable tester with probe and toner (this was easily the most important tool I bought) * Punchdown Tool * An adjustable Cat 5 stripper Out of the several cables I did, I only had one with problems, I wired one end backwards (it was before I had my morning coffee), and it was quickly "debugged" with my cable tester.
- linsomniac 8y ago
- TabTwo 8y agoOn moving day ..? They rented office space and did not check the infrastructure? Glad you guys got power and running water.
- GuyPostington 8y agoI run a pfsense + unifi network for the home and it's fantastic.
- keeperofdakeys 8y agoWhen you're deploying multiple APs you also want to turn down the broadcast power on them. If the signal of multiple APs overlap too much, clients won't roam onto the next AP in time. Also don't be afraid to hire someone to do a wireless survey - or do it yourself. Someone will walk around with a laptop, and try to find wifi blackspots/hotspots, and can recommend adjustments to AP power and/or placement.
- zamadatix 8y agoYep, and disable the lowest data rates, particularly if you have decent coverage. The AP is forced to send certain types of traffic at the lowest available data rate so everyone can hear it so you save a lot of airtime on that traffic but also clients will be more likely to roam because they can't "stick" to a far away AP at a really low data rate even if they wanted to.
- dhess 8y agoI've tried all kinds of WiFi gear over the past 5 years -- Apple, UniFi, Aruba Instant -- and all of them have been unsatisfactory in one way or another: * Most of my client devices are from Apple, and I easily got the best WiFi performance overall with 802.11ac-capable Airport Extremes, which is impressive given how relatively cheap they are. However, I'd like multiple SSIDs, and Apple gear can't do that (the guest network support doesn't count). Regardless, Apple is out of the game, so this isn't a long-term solution. * The UniFi gear had terrible 802.11ac performance, even when my devices were in the same room as the WAP. At the time, I was using first-gen 802.11ac hardware from UniFi, so it's somewhat understandable, but the poor performance combined with 2 of the units failing within the first 6 months didn't leave a good impression. * The Aruba Instant WAPs were reliable and got good performance (though not as good as the Apple WAPs), but I'm not a fan of their licensing. Without a support contract, it was possible to hunt down the latest firmware updates, but they didn't make it easy. I recently bought a PC Engines APU3C4 with a mini-PCIe WiFi card and a couple of Chaohang antennas [1], and I'm contemplating build my own WAP. This would give me all of the configurability and tweaking that I want, and I could deploy it as just another piece of my personal little devops pipeline. However, I don't know much about the RF side of things. I'm aware there's a lot of black magic involved, but it's not clear to me how much performance and/or range I'm going to lose by piecing together COTS stuff versus a professionally-engineered solution from Ubiquiti et al. If anyone who's reading has built their own WAPs, I'd love to hear from you. [1] https://www.amazon.com/gp/product/B01E29566W https://www.amazon.com/gp/product/B01E29566W
- kccqzy 8y agoI've heard multiple people saying Apple wireless APs perform so much better than others. I really wish someone could do a technical deep-dive and explain how Apple did it.
- matthew-wegner 8y agoUniFi is already mentioned elsewhere in the comments already, so this whole post is likely redundant. If you're at the level of cobbling together consumer routers, even flashed to DD-WRT/Tomato/whatever, change. If someone your team is Cisco certified from a previous life as a network engineer, and insists you use Meraki kit and pay the fees, well, you're in SF and paying SF salaries anyway, so probably just go for it. If you run a full UniFi stack, you can view your entire topology in the dashboard--it'll tell you which switch port or access point/SSID a client is connected to. Here's my home topology: https://imgur.com/MnJwHiB https://imgur.com/MnJwHiB Note that most switches are double-uplinked for 2000Mbps throughput, and there's a 10-gigabit core router. 10gbe isn't nearly as expensive as you might think, especially for very small teams. It is possible to get access points to deliver 500-700Mbps speeds, too--that's going to depend a lot more on your device's radios than anything. See speed benches for UniFi kit at: https://goo.gl/RL4kkW https://goo.gl/RL4kkW This guide doesn't cover VLANs, but it probably should mention they exist. Any IOT or networked camera type devices that don't need Internet access shouldn't be allowed egress, and VLANs are an easy way to implement network segregation. You almost certainly want a guest network too, both wired and wireless.
- ufo 8y ago> Multiple access points should share the same SSID. [...]. If you use separate SSIDs [...] it will often lead to laptop users remaining marginally connected to an AP they’re barely within range of. I constantly run into this issue in my home network. Is solving it really just a matter of reconfiguring the routers to share she same SSID or is there more to it?
- eli 8y agoIt’ll probably help. In practice it’s always still a little wonky. I think it’s on the OS to determine if to when there’s a closer AP to switch to
- sulam 8y agoIt really is that easy in my experience. I had five APs at the last house and Android, iOS, MacOS and Windows all were able to hunt automatically as long as I had the same SSID. When I tried to get cute stuff got a lot less usable.
- azernik 8y agoOne more thing is required - the different APs must all be on the same layer 2 network. 802.11 (WiFi) clients, by design, assume that all APs broadcasting the same SSID provide access to the same 802 (Ethernet & friends) network, and so assume their DHCP leases and TCP connections etc. will carry over. If you break that assumption then roaming will cause issues.
- knorker 8y agoI disagree on the channel width. Yes, a packet uses double the bandwidth, thus double the chance of collision. But also half the time so half the chance of collision. And you can get more channels than 3, if you use 20Mhz channels, not the 22MHz channels by simply not using 802.11b. only use g&n and you get four channels. And do use the DFS channels, exactly because people like this author are not there to congest the channel. Just make sure you have non-DFS too while the DFS AP is in listen mode. So this article is very much not written by an expert.
- vandot 8y agoMy startup purchased Meraki, and we don't have to deal with many of these issues. We also paid an electrician to do wiring and crimping. SDE time is expensive and we want the team focused on building our product, so we made the tradeoff to pay more for the network gear and installation. As a result our entire team, engineering and everyone else, has network access that "just works". This was true when the 35 person team showed up at our last office for the first time, and continues to be true. The configuration is done through a hosted dashboard that also provides monitoring. We're in a heavily regulated field, and the Meraki dashboard provides a lot of evidence for compliance audits. It also enables us to remotely control devices (e.g. lock, wipe, locate) and ivestigate issues when integrated the Meraki MDM solution. We did have to tune the bitrate for wireless. We also cannot setup redundant VPN tunnels to AWS (Meraki only supports one tunnel for non Meraki VPNs), so we have to do manual faiilover. This is my biggest gripe with Meraki. We are investigating adding a Cisco ASA to handle site-to-site VPN to AWS with redundant tunnel support.
- nodesocket 8y agoNever seen parallel s3 chunked downloading using `aria2c -x 16 -s 16 -k 4M -o ${OUTPUT_FILENAME} ${DOWNLOAD_S3_URL}`. Any drawbacks of this? Corruption?
- nodesocket 8y agoI have gigabit internet at my house and a single WiFi access point. I am running dual SSID's one for 2.4GHz (don't use it), and one for 5Ghz (use it). The 2.4Ghz is set to auto-channel, but the 5Ghz I statically set to channel 161 (5Ghz, 80Mhz). It shows a Tx rate of 866Mbps, and on SpeedTest.net I get around 400ish Mbps up and down. Sometimes going further back into my apartment I have to connect and disconnect from WiFi in macOS. Should I try using a lower 5Ghz channel such as 36 or 40? Won't that decrease overall throughput? My understanding was the higher the channel number on 5Ghz, the theoretically higher the throughput.
- djmips 8y agoThis is so boring it feels like a placed ad on hacker news.
- system2 8y agoAgreed. Can't understand the votes for this. This is literally IT 101.
- Tharkun 8y agoShame that security wasn't really addressed, other than the brief mention of WPA2-PSK. I feel like PSK in general is a horrible idea in an office environment. Lots of people + lots of devices ≈ shitty password which never gets changed. But then I still haven't had any luck setting up a WPA2 Enterprise config that works on all devices.
- geek_at 8y agowondered too how they didn't even mention WPA2 Enterprise I thought that was the defacto-standard in office environments. It certainly is for EDU
- deleted 8y ago[deleted]
- majidazimi 8y agoDon't you need a central controller for seamless roaming?
- Jaruzel 8y ago> Multiple access points should share the same SSID. They must have exactly the same security settings (same password, exact same mode, i.e. WPA2-PSK Personal) for clients to be able to automatically roam between APs. I will also add to this, consider having all the APs on the same channel. My experience is that some OSs (I'm looking at you, Windows) don't roam properly if the following three things are not the same: 1. SSID 2. Authentication/Encryption 3. Channel It does sound like the author has deployed consumer access points. For a proper office scenario centrally managed is the way to go. Finally, never use WPA2-PSK Personal in a work environment. Use proper back-end authentication such as Radius or MAC filtering, or a 'Register me via a captive portal' system with a central LDAP type user directory.
- Blaiz0r 8y agoI had to change my SSID's on my 5Ghz and 2.8Ghz WiFi because Macs used to confuse themselves and constantly disconnect. Using the same name for both didn't work
- Jaruzel 8y agoYour problem is using the same SSID for both frequencies. Have a single SSID for all your 5Ghz APs and another for the 2.4Ghz ones.
- justusthane 8y agoThat's the opposite of what this article says to do, which I think is why the above commenter mentioned it.