-
-
Save troyhunt/86ce1de40e58b1eed0961ce6a7a906d5 to your computer and use it in GitHub Desktop.
That's it - I've finally lost it with Linksys and both my WRT 1900ACs that are only a year old are getting chucked. Don't get me started on all the reasons why, but it's primarily down to continued degradation of wifi signal and the constant need for reboots. Going by the responses to this tweet, that's just what they do: https://twitter.com/troyhunt/status/778867707655487488 | |
I’m going all out with Ubiquiti instead. No, I'm not interested in [insert the other thing you think rocks here], there's a really vocal majority in favour of Ubiquiti so that's that. Now I need help speccing out what I need for my house as it’s not quite as straight forward as just chucking in a couple of (dodgy) routers. | |
Here’s what I’m working with: | |
- Large multi-level house about 500m2 (needs at least 2 APs, probably more) | |
- Wired ethernet to every room (I believe Cat 5e, was here when I got here) | |
- Patch board in the garage and a 100Mbps hub (running patch cables out to a Linksys 8 port gigabit switch instead) | |
- 4 wired connections used in the lounge (presently has 1 Linksys WRT 1900AC + ISP cable modem which needs to be the because that’s where the cable enters) | |
- 6 wired connections used in office (presently had 1 Linksys WRT 1900AC + a Linksys 8 port gigabit switch) | |
- Internet connectivity: Cable modem -> Linksys WRT 1900AC (lounge) -> patch board -> Linksys WRT 1900AC (office) | |
Here’s the Ubiquiti bits I think I need: | |
- UniFi Security Gateway (sits between switch and cable modem): https://www.ubnt.com/unifi-routing/usg/ | |
- 3 x UniFi US‑8‑150W 8 port UniFi switches, 1 for the lounge, 1 for patch board and 1 for office, both with PoE: https://www.ubnt.com/unifi-switching/unifi-switch-8-150w/ | |
- 2 x UAP-AC-PRO access points for lounge and office (or go all out and get a 5 pack of them): https://www.ubnt.com/unifi/unifi-ap-ac-pro/ | |
- UniFy Cloud Key to manage it all: https://www.ubnt.com/unifi/unifi-cloud-key/ | |
Network topology wise, it then does this: | |
Cable modem in bridge mode (lounge) | |
| | |
| | |
UniFi Security Gateway (lounge) | |
| | |
| Wired lounge devices | |
| / | |
US‑8‑150W switch (lounge) | |
| \ | |
UAP-AC-PRO | UAP-AC-PRO for lounge wifi | |
(somewhere else) | | |
\ | | |
US‑8‑150W switch | |
/ (garage) | |
UAP-AC-PRO | | |
(somewhere else) | Wired office devices | |
| / | |
US‑8‑150W switch | |
(office) \ | |
UAP-AC-PRO for office wifi | |
Questions: | |
- What would you do differently / better? | |
Thank you! |
Is there a reason for both the USG and the edge router? Other then also allowing you to manage your AP's (which you could do with a cloud key or even if you wanted to setup a cloud controller on AWS) they both fill a similar role in the network. If you need extra ports the edge router will probably be a better option. I would suggest a cloud key and edge router instead of the USG and Edge router. you can place the the key at any point in the network where there is a free POE port.
https://www.reddit.com/r/Ubiquiti/comments/4dyarr/usg_vs_edgerouter/
The rest of your layout is pretty spot on. with only the 5 ports in the lounge, you may end up wanting another switch for expansion in the lounge but you can add that when needed. Having just setup a edge router lite recently, the included wizards in their latest firmware make sure for initial configuration very simple. just remember any config you do before running the wizard will be wiped out once you run it! Unbox -> update firmware -> run wizard -> modify as needed.
Do you really need 24 ports of POE? You're spending $600 for 24 gigabit ports otherwise, which is really costly. You can get 8 port VLAN capable switches for ~$35 and then a couple of POE injectors for your APs.
If you think you may need additional ports in any location, I'd get a bigger switch now, vs adding another later.
Unifi works great for simple networks, and my experience with USG is a little dated, but there were two things that made my life difficult at one point:
-
IPSec L2L VPN to another entity was only achievable via hacking a JSON POST manually, and it would be overwritten if you saved the config in the GUI that called that same place again.
-
Switches were unable to configure only specific VLANs on VLAN Trunks. All Trunks got all VLANs.
Either/Both of these may be fixed by now, or may not be an issue for you at all.
I'm also not much of a fan of the CloudKey. It doesn't take many resources for the controller. I normally use Debian stable as a base install, and host one publicly for F&F sites that I manage. Add the Unifi repository, and away you go. 2GB of RAM though, Java is a pig!
Hi Troy,
I would recommend getting a 24 port edge switch as that would provide POE and have enough ports to bring all the cables back to one point. I would also encourage you to run cat 6 for more headroom. check our the belden Reconnect for the AP. I found out some of my crimp jobs were only getting 10Mbit dispute looking perfect. these connectors would solve that problem. I would also ditch the gateway for the $500 PFsense box and it has 3 ports allowing for IOT isolation. I have some of the PFsense hardware at work and it has fantastic throughput and is easy to configure. with plugins you can also block ads, filter sites and protect the kids.
one last thing. don't skimp on the wall jacks and the patch cords. I did some home testing and found a noticeable improvement my using high qualify cables ($7) over the generic $1 cable.
my config is a follows:
PF sense home built PC
8 cat 6 runs and cat 6 jacks
12pt patch panel
meraki 10 port switch (POE) .. it was free
same AP as you have listed
raspberry pi 2 running ubnt controller
DSL modem
Hi Troy
For the last 6 months or so, I've running a USG, 8 port POE Switch with 2 UAC AP Lite's - 1 in bridge mode and a Cloudkey.
It's been super reliable and even the bridged AP has been almost flawless (I think I had to reboot it once). I love being able to manage everything from a single interface and that the Cloudkey is just another appliance, not a another "computer" to manage.
In a few weeks, we'll be moving to a house similar to yours - 2 stories and +- 550m2. The USG, switches (I'll add another 8 port) and cloudkey will all be in the garage with cat6 cables to each room/tv (multiple to some locations like office) etc. I'll also be adding a 3rd AP but this time they'll all be wired. I'll report back on coverage once I'm up and running in the new house.
Good USG vs EdgeRouter vid
https://www.youtube.com/watch?v=XvWOx3PvYFM&spfreload=1
What are peoples thoughts on fewer UAP-AC-PRO vs more UAP-AC-LITE? My thoughts behind this are to provide more 5Ghz APs so you get better performance in more rooms.
More APs running at lower power is generally better than one or two high power APs. Less power required on both ends, leading to longer battery life in mobile devices and decreased RF pollution. The main issue with that kind of setup is that a lot of devices have very poor roaming and will hold onto a low quality signal for way too long before switching to another AP. There are workarounds such as forced deauth if a client signal gets too low, but when you "kick" a client as opposed to letting the radio roam by itself you will interrupt active connections.
Just wanted to add some thoughts:
I'm running the controller on a Pi2 with no issues, While I admit the PoE is nice I don't really think it's needed unless you have LOTs of network devices using the power and/or they're in places where getting power is hard. For just two (or even five) APs I don't think it's worth it. Just use the power injectors that come with them.
I suggest you to analyse the UBNT firmware before deciding to go all UBNT. You can get their firmware online from the support / firmware updates page and just take a look at how they do stuff. At least years back when I had to deal with support for bunch of ubnt hardware, the general rule of thumb was that their hardware is great, but products get released before software is even 50% ready for release - especially regarding locking down the system and doing basic attack surface reduction. Might be better now.
Suggestion: get one device, have some fun breaking it, and then decide for or against it 😄
regarding the wifi side: rule of thumb is to favor 5GHz over 2.4 GHz if all devices support it. Much more stable data transfer. Also, make sure to lower down the transmission power setting to only cover te area that you need. More transmission power on just one side will only raise noise level, but not improve connectivity because your laptop/smartphone/tablet will only send with the usual low dBm values and are optimized for low power consumption.
Do not use more then 3 SSIDs on one 40MHz wide channel and do not place nearby wifi APs on same or overlapping channels.
Also yes, always use proper CAT 6 or CAT 7 cable or you will have to redo some cabling in a few years. Don't be too greedy on the network cable. Replacing anything else is done quick and easily, but redoing network cable which might even be hidden inside some walls is lots of work.
I have 2 x UAP-AC-PRO covering my house using POE from an edge switch, works really well love that I can use schedules to turn off the kids ssid to make sure they are not staying online all night! Only issue I have had is the 24 port edge switch runs pretty hot. Mine is in a wall mounted mini rack cabinet (in my attached garage) along with my adsl router, qnap nas , 2x hd homerun tv tuners and a cloudkey and I had to put a fan in the cabinet to stop the switch overheating (everything else runs cool enough, even in a 42 deg C Canberra summer).
The cloudkey lost it settings last time I did a firmware upgrade but has been rock solid since then, I have not touched it in 6 months. Roaming didn't work too well so I ended up turning it off, the ap's are on different channels and do overlap slightly, in practice the range is good on both aps over most of the house.
The ap's are fussy about the cabling, one ap (furtherest from switch) will only connect at 10Mb even with Cat6, have recrimped the connectors on both ends twice, and it checks out just fine with cable testers or even my macbook... so not sure what's up there, if I take the ap and plug into short cable into the switch it connects at 100Mb.. haven't had time to look into it further and with my 5Mbit adsl1 connection it's not really an issue!
I've been looking at Ubiquiti too for a similar reason but I keep encountering posts about quality like this
https://lukas.im/2016/01/25/replace-broken-usb-stick-in-ubiquiti-edgemax-routers/index.html
So they use USB sticks for storage, power it off by pulling power and youre likely to corrupt things.
one ap (furtherest from switch) will only connect at 10Mb even with Cat6, have recrimped the connectors on both ends twice, and it checks out just fine with cable testers or even my macbook...
@vincentparrett not unusual for Ubiquiti to have some deaf units. Check if you get 100Mb/s on a very short cable and reset he device. If you don't get it to connect at 100Mb/s, send it back to your seller and request a replacement.
@basisbit - I decided to update the firmware tonight (1st time in 6 months) and now both AP's are now connecting at 1Gbps. Go figure!
I concur with tweaking the setup a little bit, mostly eliminating the EdgeRouter for a few reasons:
I think you're better off with a third 8-port here if management via a single interface is a big draw. It'll make VLAN isolation management and such easier to deal with. There are no fans in the ES‑8‑150W, they're silent. Non-rack form factor and silence were a bonus for me.
Cloud Key: I'm using one. I've had it lose configuration once when re-plugging switch power several times in a short period. Otherwise it's been solid, always keep a backup of the controller after changes no matter what you decide to run it on. I also know several people running it on a Pi 3 with no issues, it's just not as clean on the wiring (if that matters).
APs: while you can bridge through the APs (for example in the office), just keep in mind that settings changes (triggering a re-provision) will interrupt that connection. So they're good for chaining 1 thing (e.g. a bedroom TV or something) but not chunks of the network. There's also the shared bandwidth issue in doing that.
Switches: Just to node, if cost is an issue at all, keep in mind that the US‑8‑150W is mostly about management and a clean wiring setup. They're not essential since each AP has a PoE injector in the box, but they are damn nice :)
I'm very happy with the Ubiquiti setup here with 2 UAP-AC-PROs, 1x US‑8‑150W, 1x USG, and 1x CloudKey and I'll add another 1-2 APs when we finish the basement and likely stack another ES‑8‑150W over the 2x SFP over the next few months. Let me know if you have more questions or want a dashboard tour to poke at - happy to do a hangout or something. Good luck!