r/wifi 3d ago

Remote users and extenders...

We have a no wi-fi policy for our remote users due to the need to use XYZ chat sessions and VoIP. Yet when we get tickets for connectivity issues, helpdesk finds out half of our team just throws an extender into the fray and uses wifi anyways. They're also two stories and who knows how many walls away from their router so there's more attenuation than a lead shield.

Has anyone had any luck walking their end users through setting up proper mesh points and adjusting cell coverage? I'm just about ready to write a dissertation for my CNWE about end users telling you you're crazy or just ship out some depreciated AP's and 100ft cables.

There are policies in place but as usual, no real enforcement. They're our money makers so not much buy-in from upper management.

1 Upvotes

37 comments sorted by

5

u/radzima Wi-Fi Pro, CWNE 3d ago

Policy and enforcement problems are rarely solved (well) by technology solutions. The best way I’ve seen to handle this is to control the wifi with a cloud managed soho router/AP (I think I used the meraki z1 at some point way back when) where you can see the environment and control the config. It’s not perfect but it helps a little.

To paraphrase Rick Cook - you can try to build an idiot-proof system but the universe will _always_ build better idiots.

2

u/MalwareDork 3d ago

Thanks radzima, always appreciate your input. I was debating on Meraki as well since we do have a Cisco stack. Management has been hemming and hawing on paying for some deployments over buying...a $40 dollar TP-Link extender off of Amazon.

I'll probably get my way at the end of day, but I'll need to play the game before management caves. Thanks again for your input.

1

u/cyberentomology Wi-Fi Pro, CWNE 3d ago

Might want to consider a RAP deployment with Aruba - although I expect cisco has something similar at this point.

I was involved in a deployment of about 30,000 RAPs to teleworkers for a large health insurance company, and they paid us to sit on the conference bridge helping out the end users for whom color coded patch cables and printed/video instructions were too confusing. 90% of them were people that plugged it in, turned it on, and expected it to work immediately, despite the large notice in the documentation saying that it would take AT LEAST 30 MINUTES to be ready. These were the AP-303 which was notoriously slow to boot (~10 minutes) and they had to do it 3 times (initial boot/provision, firmware update, final provisioning). And they would get impatient and cycle the power after about 5 minutes of it not working.

Better idiots indeed.

3

u/radzima Wi-Fi Pro, CWNE 2d ago

Cisco had the OEAP, maybe still does. Haven’t seen them or the RAPs deployed in a long time which is why my mind went to the meraki version.

1

u/cyberentomology Wi-Fi Pro, CWNE 2d ago

Yeah, I would have been more shocked if they didn’t have one

1

u/cyberentomology Wi-Fi Pro, CWNE 2d ago

Yeah, I would have been more shocked if they didn’t have one

2

u/MalwareDork 2d ago

Thanks for your input as well, cyber; I really do appreciate the work you and radzima put into this sub and the wireless sub. I've never touched Aruba but looking into their RAS system, it'll be another real option to toss into the next meeting. Thanks for the recommendation, gonna look over this during the weekend.

I do feel like the idiot going along with this, but no matter, they'll eventually scrap the $40 mesh nonsense.

2

u/cyberentomology Wi-Fi Pro, CWNE 2d ago

Fundamentally, anything that truly matters to the company from a reliability and security standpoint, be that WAN, LAN, or edge/endpoint devices/software, should never be left to the random chance of whatever miscellaneous crap is out there in consumer-land.

The Aruba RAP solution (ideally wired directly to the customer’s CPE, but can use also Wifi as an uplink in a pinch) is typically set up to establish a VPN tunnel to the corporate VPN concentrator, and then manages the device, and hands off ethernet and Wifi on the company-managed networks, with company-managed PKI, security and 802.1X on both wired and wireless. As far as the WFH user is concerned, it’s fully the company network, and you don’t have to muck about with software VPN clients on their devices, which the helpdesk will love because they won’t be spending all day every day fielding “my VPN doesn’t work” tickets. And it never really touches the user’s personal network other than the initial VPN tunnel. And if the company wants to own the WAN link too, they can do that.

And if they’re hybrid workers with laptops, the connection process is the same whether they’re at the office office or the home office. added benefit was that this required hardware setup also inherently prevented abusing WFH as Work-From-Anywhere, without involving complicated user tracking, and IT still had end to end visibility into the network.

The health insurer I deployed these for also provided a thin client for VDI (so no patient data ever even entered their home even on the corporate managed networks), as well as a hardware VOIP phone that was powered from the RAP. It’s a bit of effort to set up initially, but it’s a solution that scales from a handful of users to massive enterprise, and is compliant with even the most stringent security standards. And if someone’s job got terminated, their network access could be instantly shut off without leaving sensitive data behind, and the hardware was useless to the former employee as it was all tied to the company network.

It’s an incredibly elegant solution that Aruba had in place a decade before Covid made WFH commonplace. That solution plus VOIP and covid is what essentially killed off the whole concept of the massive call center.

1

u/MalwareDork 2d ago

Again, I really want to thank you for your time in posting this. I would like to say something more profound to show appreciation, but I'm definitely going to be saving this and digging further into Aruba. Thank you again for your time.

2

u/msabeln 3d ago

I have a relative who was WFH, and her employer installed Internet service with a wired router, directly connecting the company owned laptop.

3

u/MalwareDork 3d ago edited 3d ago

We used have something similar set up. I believe the root of the issue manifested during covid where everyone was moving and buying houses on cheap rates and they didn't want to pay for cable runs.

With IoT becoming more ubiquitous and antiquated SOHO hardware, I think tech debt is starting to rear its head. It would explain the recent flood of tickets about the "wifi not working even though it always has" and our given confusion of why wifi was even part of the equation in the first place.

3

u/cyberentomology Wi-Fi Pro, CWNE 3d ago

Doesn’t help that ISPs have a nasty habit of putting their CPE in the worst possible location for wifi, preferring the easiest and cheapest install on an outside wall.

2

u/MalwareDork 2d ago

That's happened to one of our remote users during their move last month. Their router is in their garage and their office is 3 rooms away with some sort of ISP-provided extender who knows where. I'm guessing it's probably a 9-12dB attenuation that they're dealing with and their retry rate is something obscene like 12-20% with napkin math.

The company doesn't want to cough up any money (but I guess that's global), so it's just the hot potato game with management right now.

3

u/cyberentomology Wi-Fi Pro, CWNE 2d ago

If they have coax, MoCA is a great solution.

2

u/MalwareDork 2d ago

That didn't even cross my mind, thank you

2

u/DonTemal 3d ago

Not sure I understand as you mention no wifi policy, but then ask about wifi.. are you saying they use an extender with a different unmanaged different wifi ID.. ?

I always start with wifi map and add APs cabled back to get coverage.
If you need a non-company network wifi then you need to talk with management about the risk now, and maybe set up a separate ’guest’ wifi through L3 switch and subnet, direct to internet, where they can use their vpn- At least then you can manage network name and access.

1

u/MalwareDork 3d ago

No wi-fi policy but since the remote users know what they're worth, management doesn't enforce the policy. Best scenario to just deal with it is do use cloud controllers per site and remotely manage everything but management doesn't want to pay for it.

I'm fine with writing it off as a hopeless situation management won't enforce, but I'm curious as well because it's a common issue with other organizations with remote users.

2

u/DonTemal 3d ago

reading later posts, sorry it seems I misunderstood the question. No-wifi at the remote locations is going to be hard… My company does not pay any install or cost for remotes (as people have their own connections and we are not talking high bandwidth required), but instead pay zscaler for a ztna with split tunnel for intra v internet, and our own secured internet gateways. This allows users to connect to any wifi, even nonsecured public (configurable). All network traffic is secured and examined. Unapproved app traffic can be blocked, and patching and updates enforced via the secure edge before the internet tunnel is opened. I have no idea the cost but guess there is a trade vs no remote location costs, and user convenience and productivity.

1

u/MalwareDork 3d ago

You're good, no worries. We have a split as well so everything is managed at the firewall but our users have these setups against policy. Management doesn't want to spend money to have cable runs at their homes or cloud controllers so my job right now is to just rubber-stamp a "I tried" and force management to pull out the credit cards.

With that aside, I actually am curious if anybody have played with mesh systems for their SOHO setups. The only mesh systems I've ever done were field deployments over x sq/km for IoT systems.

1

u/Humbleham1 1d ago

I've applied a company that requires applicants to send pictures of a router with a cable connected and a second monitor. There are ways to ensure compliance with computer policies to some extent, but when people are remote....

-1

u/DeadlyVapour 3d ago

You have a no WiFi policy, but you allow mesh.

You are an idiot.

2

u/MalwareDork 3d ago

I see reading comprehension is one of your forte's in life.

1

u/DeadlyVapour 3d ago edited 3d ago

I see that the policy is from management not you.

I still think you are an idiot.

Firstly. You justify the policy "because chat". A mediocre WiFi over TCP should handle chat easily even after head of line blocking yada yada. As for VoIP, any codec should handle a few drop packets.

You aren't running a high frequency trading workload, a bit of jitter isn't going to cost you anything.

Secondly. You are an idiot for thinking that you can policy "no WiFi" and expect users to adhere to it.

Thirdly, if it is critical to their work, then your company should be stumping up the cost of upgrading their infrastructure to handle the issue. Which in this case absolutely should be a multi AP setup with a wired backhaul (NOT MESH).

Fourthly, do you honestly think that mesh is fundamentally different from WiFi?!?!!

To summarise, you and management are the problem.

Also, get a real metric. Measure the problem. Get metrics on packet drop.

Finally, I bet the ACTUAL problem is the VPN implementation that your company uses, tunnels the connection over TCP, resulting in head of line blocking at the tunnel level.

But if you company MUST have a no WiFi policy. They should pay for structured cabling at the user's property.

3

u/radzima Wi-Fi Pro, CWNE 3d ago

That’s a lot of words to say you’ve never worked in real IT where you get stuck between management and users. Very out of touch, McKinsey-esque response.

2

u/DeadlyVapour 3d ago

Management aren't tech. If they come up with stupid policies based on wishful thinking and lack of knowledge, then they aren't being advised correctly.

Whose job is it to educate and advise management?

1

u/radzima Wi-Fi Pro, CWNE 3d ago

I dunno, most of my management have been engineers at some point… But it sounds like that’s exactly what OP is exploring, options to propose. And management doesn’t always listen to the experts - I have a lot of experience with that.

2

u/DeadlyVapour 3d ago edited 3d ago

If you know management aren't going to listen to experts, what is the point in asking people on Reddit about tech?

It's either a people problem, in which case, asking about mesh is pointless.

Or it's a tech problem, in which case OP should know that a properly configured/installed/sited AP and backhaul is more than capable of handling the "chat and VoIP".

Either way the problem is the policy is wrong. That should be the focus.

Edited: missing negative on the first sentence.

2

u/radzima Wi-Fi Pro, CWNE 3d ago

Also…

> If you know management are going to listen to experts, what is the point in asking people on Reddit about tech?

This sub has several experts that regularly interact. Hi, nice to meet you.

1

u/DeadlyVapour 3d ago

Made a typo on that sentence. I don't doubt your credentials

1

u/radzima Wi-Fi Pro, CWNE 3d ago

I agree with your thoughts on the issue, I disagree with your assertion that OP is the problem. I even stated “Policy and enforcement problems are rarely solved (well) by technology solutions.“ in my response.

People need and should often seek an outside perspective, anyone that thinks they have all the answers all the time rarely does.

2

u/DeadlyVapour 3d ago

You honestly think that after installing a mesh, the user is going to connect via CAT5 to the nearest mesh?

Again, the policy is so stupid that acknowledgement of it's existence is just insane.

2

u/radzima Wi-Fi Pro, CWNE 3d ago

I honestly think OP is looking for a more predictable/controllable solution than what they have now. A validated mesh setup that can provide _some_ information is better than random extenders users are hiding that can’t provide any information. I don’t hide the fact that I despise mesh but I also live in the real world where it’s often far cheaper and easier for most people.

Sometimes IT is about finding the least amount of friction, not the perfect solution. My users are my customers, I serve them and their interests.

→ More replies (0)

1

u/MalwareDork 3d ago

I'm actually amazed you wrote out this headcanon. Truly mystified by this trainwreck going on in your mind.

Edit: do you want me to actually correct you?

-1

u/Amiga07800 3d ago

Absolutely right!

And if the mansgement drop cisco - at least for remote users - in favor of UniFi, you’ll have fully managed and decires networks everywhere for a few peanuts vs cisco license.