TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How we solved our office Wi-Fi problems

384 pointsby Harjover 6 years ago

29 comments

baschover 6 years ago
&gt;Assign static IPs for infrastructure like access points. This makes them easy to reach when reconfiguration is needed<p>Am I missing something, or did they buy consumer routers to use as access points?<p>Triplebyte, I can save you a ton of management, troubleshooting, and learning time: switch to Ubiquiti Unifi or an equivelant now, youll have one pane of glass to reconfigure every device. The devices will talk to each other, to help hand off clients between them. All channel management will be by the devices working together, they can throttle down power if they are causing each other interference. I cant even begin to list all the different benefits with a single set of settings vs devices that dont work together. Even an asus aimesh network would likely be better. Youre asking for a troubleshooting nightmare.<p>You can either pay a couple hundred a year for the management interface, or $80 for an on prem tiny little stick that hosts it. (paying for the cloud hosted one, has its benefits, and is my recommendation.)<p>Access Point - <a href="https:&#x2F;&#x2F;unifi-hd.ubnt.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;unifi-hd.ubnt.com&#x2F;</a><p>POE Switch - <a href="https:&#x2F;&#x2F;www.ubnt.com&#x2F;unifi-switching&#x2F;unifi-switch-poe&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.ubnt.com&#x2F;unifi-switching&#x2F;unifi-switch-poe&#x2F;</a><p>Management Interface - <a href="https:&#x2F;&#x2F;www.ubnt.com&#x2F;unifi&#x2F;unifi-cloud-key&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.ubnt.com&#x2F;unifi&#x2F;unifi-cloud-key&#x2F;</a> OR Cloud Management <a href="https:&#x2F;&#x2F;unifi.ubnt.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;unifi.ubnt.com&#x2F;</a><p>Router - <a href="https:&#x2F;&#x2F;www.ubnt.com&#x2F;unifi-routing&#x2F;usg&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.ubnt.com&#x2F;unifi-routing&#x2F;usg&#x2F;</a><p>You should never need to track down or log into individual devices to configure them.<p>I dont mean to be a complete ballsack, but isnt it weird for a company thats mission is matching talent to problems, to fail to find the talent to adequately address their problem, and to be giving authoritative (mis)advice on something they are not remotely domain experts in. It doesnt seem like the best advertisement.<p>That said, this is the KIND of post companies should be making when their seo expert says to use keywords. Good job writing about improving the internals of your company, and not just what your company does. Write a V2 of this post once you upgrade, and rename the old one, &quot;How we Created (and then mitigated a Device Management and Troubleshooting Nightmare)
评论 #18081003 未加载
评论 #18079364 未加载
评论 #18079903 未加载
评论 #18079198 未加载
评论 #18079300 未加载
评论 #18079881 未加载
评论 #18080235 未加载
评论 #18081293 未加载
评论 #18079520 未加载
评论 #18079317 未加载
评论 #18079515 未加载
评论 #18079734 未加载
评论 #18080135 未加载
评论 #18081245 未加载
评论 #18080326 未加载
评论 #18079331 未加载
评论 #18081900 未加载
评论 #18080022 未加载
评论 #18081009 未加载
评论 #18080450 未加载
linsomniacover 6 years ago
Generally pretty solid advice. I say that as someone who is known for solving tough wireless problems. :-)<p>On the cable termination part: I&#x27;ve (mostly) stopped crimping cables because I&#x27;ve had too many go flaky and don&#x27;t have 4-5 figure testing equipment. One thing I&#x27;ll add is that there are ends for solid conductor and stranded, make <i>SURE</i> you have the right ones for the cable you are using.<p>These days I always just put on keystone ends and then use commercial patch cables from there. I&#x27;ve had very good luck. I&#x27;d recommend against the advice to use a screw driver to punch them down, the Leviton ones I prefer you just put the cap on and they punch down themselves. The random ones I get from Ace Hardware have a little punch tool included.<p>One additional recommendation I have is to put 5GHz radios in each space. 5GHz has more spectrum, and less interference, but it penetrates drywall significantly worse. But that&#x27;s a good thing, because it cuts down on interference from your neighbors.<p>Beware of microwave ovens, baby monitors, cordless phones (last 2 more in residential areas). They can be intermittent interference, and won&#x27;t show up on the non-commercial spectrum analyzers. Our 2.4GHz used to go out when we&#x27;d run our brand new microwave. But it would also go out at other times, possibly when a neighbor ran theirs? 2.4GHz penetrates buildings quite well, which kind of sucks.<p>My credentials: <a href="https:&#x2F;&#x2F;www.tummy.com&#x2F;articles&#x2F;pycon2012-network&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.tummy.com&#x2F;articles&#x2F;pycon2012-network&#x2F;</a>
评论 #18080397 未加载
评论 #18080533 未加载
MBCookover 6 years ago
It’s only sort of passively mentioned in the article but I am AMAZED at the number of people who don’t hardwire everything they can.<p>Obviously phones are out, but why not hardwire every laptop when it’s at the desk? If someone’s using a actual desktop computer like an iMac then what’s the point of Wi-Fi? Clear up the signal space and get a 100% reliable and ultra fast connection.
评论 #18080998 未加载
评论 #18081139 未加载
评论 #18080449 未加载
评论 #18080296 未加载
akurilinover 6 years ago
If you&#x27;re based in SF and want to have a high quality boutique IT shop work with you, without hiring IT staff yourself, then I can&#x27;t recommend <a href="https:&#x2F;&#x2F;www.boxit.net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.boxit.net&#x2F;</a> enough.<p>I was managing consumer grade routers for the company since its inception until we switched to Aruba APs (which are awesome &lt;3) and then eventually to an office with a real firewall, several APs, and a switch for 100+ cabled desks. The folks at BoxIT were a real life-saver at that stage, both for the initial setup and proactive monitoring of your network&#x27;s health over time. Having your staff spend brain cycles on this stuff isn&#x27;t the best ROI IMO.<p>The one thing to watch out for is VoIP in SF office buildings. Our APs conflict with about 300 other APs in the area, so getting reliable VoIP for your sales people over WiFi is not even worth trying. We got lucky and inherited an office where the previous company learned that the hard way and wired every nook and cranny with ethernet.
评论 #18081664 未加载
vandotover 6 years ago
My startup purchased Meraki, and we don&#x27;t have to deal with many of these issues. We also paid an electrician to do wiring and crimping. SDE time is expensive and we want the team focused on building our product, so we made the tradeoff to pay more for the network gear and installation. As a result our entire team, engineering and everyone else, has network access that &quot;just works&quot;. This was true when the 35 person team showed up at our last office for the first time, and continues to be true.<p>The configuration is done through a hosted dashboard that also provides monitoring. We&#x27;re in a heavily regulated field, and the Meraki dashboard provides a lot of evidence for compliance audits. It also enables us to remotely control devices (e.g. lock, wipe, locate) and ivestigate issues when integrated the Meraki MDM solution.<p>We did have to tune the bitrate for wireless.<p>We also cannot setup redundant VPN tunnels to AWS (Meraki only supports one tunnel for non Meraki VPNs), so we have to do manual faiilover. This is my biggest gripe with Meraki. We are investigating adding a Cisco ASA to handle site-to-site VPN to AWS with redundant tunnel support.
teerayover 6 years ago
&gt; Use fast DNS servers<p>I use GRC&#x27;s DNS Benchmark tool[1] for this whenever I set up DHCP somewhere, and the results are sometimes surprising. If you&#x27;re on a *nix or macOS, it runs well under Wine.<p>[1] <a href="https:&#x2F;&#x2F;www.grc.com&#x2F;dns&#x2F;benchmark.htm" rel="nofollow">https:&#x2F;&#x2F;www.grc.com&#x2F;dns&#x2F;benchmark.htm</a>
评论 #18079051 未加载
评论 #18078936 未加载
exabrialover 6 years ago
Pro tip: Keep your router&#x2F;managed switch configurations in source control as text files.
tradertefover 6 years ago
Biggest issue I have with the solution proposed is the recommendation to avoid DFS channels. These channels are much more &quot;cleaner&quot; as adoption is less due to added cost caused by extra design and certification.<p>Radars are pretty static and does not come and go (especially weather radars), so the router does not need to move from channel pretty much. False alarm can be an issue but if one has a decent quality router, it should not be very often. Furthermore, after a radar detection (false alarm or actual), routers can switch to non-DFS channels and and start operating immediately.
评论 #18081437 未加载
matthew-wegnerover 6 years ago
UniFi is already mentioned elsewhere in the comments already, so this whole post is likely redundant. If you&#x27;re at the level of cobbling together consumer routers, even flashed to DD-WRT&#x2F;Tomato&#x2F;whatever, change. If someone your team is Cisco certified from a previous life as a network engineer, and insists you use Meraki kit and pay the fees, well, you&#x27;re in SF and paying SF salaries anyway, so probably just go for it.<p>If you run a full UniFi stack, you can view your entire topology in the dashboard--it&#x27;ll tell you which switch port or access point&#x2F;SSID a client is connected to. Here&#x27;s my home topology:<p><a href="https:&#x2F;&#x2F;imgur.com&#x2F;MnJwHiB" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;MnJwHiB</a><p>Note that most switches are double-uplinked for 2000Mbps throughput, and there&#x27;s a 10-gigabit core router. 10gbe isn&#x27;t nearly as expensive as you might think, especially for very small teams. It is possible to get access points to deliver 500-700Mbps speeds, too--that&#x27;s going to depend a lot more on your device&#x27;s radios than anything. See speed benches for UniFi kit at: <a href="https:&#x2F;&#x2F;goo.gl&#x2F;RL4kkW" rel="nofollow">https:&#x2F;&#x2F;goo.gl&#x2F;RL4kkW</a><p>This guide doesn&#x27;t cover VLANs, but it probably should mention they exist. Any IOT or networked camera type devices that don&#x27;t need Internet access shouldn&#x27;t be allowed egress, and VLANs are an easy way to implement network segregation. You almost certainly want a guest network too, both wired and wireless.
jpm_sdover 6 years ago
&gt; There’s no IT team at startups<p>Uh, what? Are you nuts? Hire somebody.
评论 #18079864 未加载
评论 #18081265 未加载
dhessover 6 years ago
I&#x27;ve tried all kinds of WiFi gear over the past 5 years -- Apple, UniFi, Aruba Instant -- and all of them have been unsatisfactory in one way or another:<p>* Most of my client devices are from Apple, and I easily got the best WiFi performance overall with 802.11ac-capable Airport Extremes, which is impressive given how relatively cheap they are. However, I&#x27;d like multiple SSIDs, and Apple gear can&#x27;t do that (the guest network support doesn&#x27;t count). Regardless, Apple is out of the game, so this isn&#x27;t a long-term solution.<p>* The UniFi gear had <i>terrible</i> 802.11ac performance, even when my devices were in the same room as the WAP. At the time, I was using first-gen 802.11ac hardware from UniFi, so it&#x27;s somewhat understandable, but the poor performance combined with 2 of the units failing within the first 6 months didn&#x27;t leave a good impression.<p>* The Aruba Instant WAPs were reliable and got good performance (though not as good as the Apple WAPs), but I&#x27;m not a fan of their licensing. Without a support contract, it was possible to hunt down the latest firmware updates, but they didn&#x27;t make it easy.<p>I recently bought a PC Engines APU3C4 with a mini-PCIe WiFi card and a couple of Chaohang antennas [1], and I&#x27;m contemplating build my own WAP. This would give me all of the configurability and tweaking that I want, and I could deploy it as just another piece of my personal little devops pipeline.<p>However, I don&#x27;t know much about the RF side of things. I&#x27;m aware there&#x27;s a lot of black magic involved, but it&#x27;s not clear to me how much performance and&#x2F;or range I&#x27;m going to lose by piecing together COTS stuff versus a professionally-engineered solution from Ubiquiti et al. If anyone who&#x27;s reading has built their own WAPs, I&#x27;d love to hear from you.<p>[1] <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B01E29566W" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B01E29566W</a>
评论 #18082532 未加载
slantyyzover 6 years ago
While it doesn&#x27;t really matter whether you use EIA-586-B or EIA-586-A so long as you&#x27;re consistent, I&#x27;ve been told that EIA-586-A is the standard in Canada.<p>addendum:<p>Re crimping RJ45 - the better way to do terminations is to use the EZ-RJ45 pass-through plugs like the ones made by Platinum Tools. You need a special crimper, but it&#x27;s night and day easier. If you&#x27;re using AWG23 Cat 6, you also need to make sure your plugs can handle those wires (not an issue with the Platinum Tools plugs).
评论 #18100678 未加载
评论 #18080836 未加载
评论 #18080517 未加载
评论 #18080396 未加载
keeperofdakeysover 6 years ago
When you&#x27;re deploying multiple APs you also want to turn down the broadcast power on them. If the signal of multiple APs overlap too much, clients won&#x27;t roam onto the next AP in time.<p>Also don&#x27;t be afraid to hire someone to do a wireless survey - or do it yourself. Someone will walk around with a laptop, and try to find wifi blackspots&#x2F;hotspots, and can recommend adjustments to AP power and&#x2F;or placement.
评论 #18081431 未加载
Tharkunover 6 years ago
Shame that security wasn&#x27;t really addressed, other than the brief mention of WPA2-PSK. I feel like PSK in general is a horrible idea in an office environment. Lots of people + lots of devices ≈ shitty password which never gets changed.<p>But then I still haven&#x27;t had any luck setting up a WPA2 Enterprise config that works on all devices.
评论 #18082831 未加载
Jaruzelover 6 years ago
&gt; <i>Multiple access points should share the same SSID. They must have exactly the same security settings (same password, exact same mode, i.e. WPA2-PSK Personal) for clients to be able to automatically roam between APs.</i><p>I will also add to this, consider having all the APs on the same channel. My experience is that some OSs (I&#x27;m looking at you, Windows) don&#x27;t roam properly if the following three things are not the same:<p>1. SSID<p>2. Authentication&#x2F;Encryption<p>3. Channel<p>It does sound like the author has deployed consumer access points. For a proper office scenario centrally managed is the way to go. Finally, never use WPA2-PSK Personal in a work environment. Use proper back-end authentication such as Radius or MAC filtering, or a &#x27;Register me via a captive portal&#x27; system with a central LDAP type user directory.
评论 #18082906 未加载
compumikeover 6 years ago
We had internal debates about different SSIDs for 2.4 vs 5 GHz, but in the end, this is the optimal configuration we landed on.<p>I was also surprised by how slow S3 was with a single download connection, but really fast when using aria2 to parallelize the download.
评论 #18079149 未加载
评论 #18078897 未加载
nodesocketover 6 years ago
I have gigabit internet at my house and a single WiFi access point. I am running dual SSID&#x27;s one for 2.4GHz (don&#x27;t use it), and one for 5Ghz (use it). The 2.4Ghz is set to auto-channel, but the 5Ghz I statically set to channel 161 (5Ghz, 80Mhz). It shows a Tx rate of 866Mbps, and on SpeedTest.net I get around 400ish Mbps up and down. Sometimes going further back into my apartment I have to connect and disconnect from WiFi in macOS.<p>Should I try using a lower 5Ghz channel such as 36 or 40? Won&#x27;t that decrease overall throughput? My understanding was the higher the channel number on 5Ghz, the theoretically higher the throughput.
intsunnyover 6 years ago
I really wish MacOS would allow you to choose which band or BSSID to connect to.<p>Every so often I have to physically drag my laptop to the superior AP and restart wifi to get my laptop to stop connecting to the bad AP.
评论 #18079087 未加载
评论 #18081159 未加载
knorkerover 6 years ago
I disagree on the channel width. Yes, a packet uses double the bandwidth, thus double the chance of collision. But also half the time so half the chance of collision.<p>And you can get more channels than 3, if you use 20Mhz channels, not the 22MHz channels by simply not using 802.11b. only use g&amp;n and you get four channels.<p>And <i>do</i> use the DFS channels, exactly because people like this author are not there to congest the channel. Just make sure you have non-DFS too while the DFS AP is in listen mode.<p>So this article is very much not written by an expert.
maerF0x0over 6 years ago
Anyone have a recommendation of a company in the Bay area that solves this issue for startups? Someone I can just call, have onsite and get my people back to work in &lt;5 business days?
评论 #18080491 未加载
评论 #18081423 未加载
评论 #18080168 未加载
ufoover 6 years ago
&gt; Multiple access points should share the same SSID. [...]. If you use separate SSIDs [...] it will often lead to laptop users remaining marginally connected to an AP they’re barely within range of.<p>I constantly run into this issue in my home network. Is solving it really just a matter of reconfiguring the routers to share she same SSID or is there more to it?
评论 #18082009 未加载
评论 #18081794 未加载
评论 #18081666 未加载
mcianciaover 6 years ago
&gt; connection requires only 8 of the 16 physical connections to be made successfully. A working 1000BASE-T (gigabit) connection requires all 16 of 16!<p>Small error here, should be 4 of 8 and 8 of 8, respectively ;)
评论 #18080393 未加载
nodesocketover 6 years ago
Never seen parallel s3 chunked downloading using `aria2c -x 16 -s 16 -k 4M -o ${OUTPUT_FILENAME} ${DOWNLOAD_S3_URL}`. Any drawbacks of this? Corruption?
qwerty456127over 6 years ago
Cool! Building big-office&#x2F;building-size WiFi networks had always been such a huge pain... Thank you for sharing your experience!
TabTwoover 6 years ago
On moving day ..? They rented office space and did not check the infrastructure? Glad you guys got power and running water.
jonny_ehover 6 years ago
&gt; Don’t put 5 GHz on its own band.<p>Uhh, do they mean &quot;don&#x27;t put 5 GHz on its own SSID&quot;?
评论 #18080017 未加载
评论 #18079819 未加载
GuyPostingtonover 6 years ago
I run a pfsense + unifi network for the home and it&#x27;s fantastic.
majidazimiover 6 years ago
Don&#x27;t you need a central controller for seamless roaming?
djmipsover 6 years ago
This is so boring it feels like a placed ad on hacker news.
评论 #18082463 未加载