RE: [WIRELESS-LAN] [EXTERNAL]Re: [WIRELESS-LAN] [External] Re: [WIRELESS-LAN] Wi-Fi expectations/service levels and validation

2021-09-25 Thread Jeffrey D. Sessler
When I read the uiowa wifi SLA link, I can't help but think it's boarding on an excuse, rather than a true SLA between the service operator and the customer. Don't misunderstand, there are technical limitations to WiFi, but we can also engineer around many of them assuming the organization

Re: [WIRELESS-LAN] Amazon prime video error (Your device is connected to the internet using a VPN or proxy service)

2021-09-17 Thread Jeffrey D. Sessler
If you aren’t blocking P2P anonymizer clients, where user devices are endpoints for folks in other regions, Amazon and others may blacklist your IP range. These clients may show up with students from other countries, or students who have returned from being abroad. If you have something like

RE: PoE Load Tester Recommendation

2021-09-09 Thread Jeffrey D. Sessler
I don't know about other brands, but if you have Cisco Catalyst switches, many have a built in TDR that can help with determining if you have a cable/distance issue. In a building we completed a couple of years ago I found some of the AP runs exceeded 100m (conduit plan not followed), which

Re: [WIRELESS-LAN] ISE-NPS-Azure MFA

2021-08-26 Thread Jeffrey D. Sessler
I 2nd Tim’s suggestion. If the VPN is Cisco-based, they support using SAML against AzureAD including MFA. https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215935-configure-asa-anyconnect-vpn-with-micros.html Jeff From: The EDUCAUSE Wireless Issues

RE: [WIRELESS-LAN] eduroam CAT Config/Cert Renewal with New Root

2021-08-09 Thread Jeffrey D. Sessler
thread as it has nothing to do with the original question. tim From: The EDUCAUSE Wireless Issues Community Group Listserv mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> on behalf of Jeffrey D. Sessler mailto:j...@scrippscollege.edu>> Sent: Monday, Au

Re: [WIRELESS-LAN] eduroam CAT Config/Cert Renewal with New Root

2021-08-09 Thread Jeffrey D. Sessler
Per the RFC, the certificate-using application _MAY_ require the EAP extended key usage extension to be present. It is not a must or shall, so I’m not exactly sure the problem here. Vendors have chosen against requirement. The certificate-using application appears to be satisfied by the server

Re: [WIRELESS-LAN] eduroam CAT Config/Cert Renewal with New Root

2021-08-09 Thread Jeffrey D. Sessler
I’m curious about this and would like to know more. Many operating systems require the Server Auth (1.3.6.1.5.5.7.3.1) EKU, and MS calls this out as a requirement for EAP. Last I looked, public CA’s include this when minting a so called web server cert. Jeff From: The EDUCAUSE Wireless

RE: [WIRELESS-LAN] can Active Directory backend for ISE be tested before adding all wireless auth?

2021-08-04 Thread Jeffrey D. Sessler
As a point of reference, if you are cloud-based and have deployed Microsoft’s AADDS (Azure Active Directory Domain Services), the architecture model for that service puts a LB in front of the DCs to assist with service scale out, including replica sets across geographic regions. One could

RE: [WIRELESS-LAN] Ekahau Licensing & Alternatives

2021-07-20 Thread Jeffrey D. Sessler
I think it is reasonable for Ekahau to enforce their license, especially when licensing it for multiple team members may be cheaper than using a third party. Then again, if pushing the envelope of the licensing is what made it less money than using a third party, perhaps shifting that work

RE: [WIRELESS-LAN] [EXTERNAL] [WIRELESS-LAN] Cisco 8540 Code Recommendation, Based on Stability?

2021-06-09 Thread Jeffrey D. Sessler
I would encourage those with these open cases to join the EFT. Once you join, you get to interface directly with the BU, with direct eyes-on from the developers. Jeff From: The EDUCAUSE Wireless Issues Community Group Listserv On Behalf Of Rios, Hector J Sent: Wednesday, June 09, 2021 2:32

Re: Cisco 8540 Code Recommendation, Based on Stability?

2021-06-03 Thread Jeffrey D. Sessler
Note on code. Cisco does run a very helpful EFT program for their code, and in most cases it is supported for production use. It is also supported directly by the Wireless BU, which is a plus. They will post announcements on the Cisco community site, and once you’ve signed up, you’ll get

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-22 Thread Jeffrey D. Sessler
that whatever our legal team concluded on this issue was defensible. From: The EDUCAUSE Wireless Issues Community Group Listserv mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> On Behalf Of Jeffrey D. Sessler Sent: Thursday, April 22, 2021 3:04 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-22 Thread Jeffrey D. Sessler
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> On Behalf Of Jeffrey D. Sessler Sent: Thursday, April 22, 2021 1:06 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU> Subject: Re: [WIRELESS-LAN] WPA3/OWE as campus solution? Tim, I would take a look

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-22 Thread Jeffrey D. Sessler
! From: The EDUCAUSE Wireless Issues Community Group Listserv mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> on behalf of Jeffrey D. Sessler mailto:j...@scrippscollege.edu>> Sent: Thursday, April 22, 2021 12:04 To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mail

RE: WPA3/OWE as campus solution?

2021-04-22 Thread Jeffrey D. Sessler
2726 Mobile/text [CAD LOGO EMAIL SIG] From: Jeffrey D. Sessler mailto:j...@scrippscollege.edu>> Sent: Wednesday, April 21, 2021 4:05 PM Subject: Re: WPA3/OWE as campus solution? Jennifer, I would hope that the service itself has authorization/admittance controls vs relyin

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-22 Thread Jeffrey D. Sessler
On 2021-04-21 21:30:53+, Tim Cappalli wrote: > I'd also like to address the comment about post-college experience. > > Most organizations these students are going to work at are going to > require MDM or MAM on their personal devices. So I fundamentally > disagree with the comment that

RE: WPA3/OWE as campus solution?

2021-04-21 Thread Jeffrey D. Sessler
Jennifer, I would hope that the service itself has authorization/admittance controls vs relying on the user’s device and/or the particular network the device is in for permission. I’d also argue that there is enough breadcrumbs about any given device to determine the user without the need for

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-19 Thread Jeffrey D. Sessler
On 2021-04-16 22:38:48+0000, Jeffrey D. Sessler wrote: > Educause did an extensive review of DMCA and concluded there is no > need to "know with reasonable certainty who is using the network." What about for CALEA? I found [this][1] page, but all the FAQs linked ar

RE: [External] Re: [WIRELESS-LAN] Rate Limits on Guest Wi-Fi

2021-04-19 Thread Jeffrey D. Sessler
We've never used rate limits. Doing the math, the price for larger internet pipes was significantly less that the rate/traffic shaping technology plus related FTE staffing costs. Jeff From: The EDUCAUSE Wireless Issues Community Group Listserv On Behalf Of Adam T. Ferrero Sent: Tuesday,

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-16 Thread Jeffrey D. Sessler
SE.EDU>> On Behalf Of Jeffrey D. Sessler Sent: Friday, April 16, 2021 11:47 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU> Subject: Re: [WIRELESS-LAN] WPA3/OWE as campus solution? I’m all for the connection experience being as simple as possible. We subject

RE: [WIRELESS-LAN] WPA3/OWE as campus solution?

2021-04-16 Thread Jeffrey D. Sessler
I’m all for the connection experience being as simple as possible. We subject our casual users to often extreme onboarding measures when they’ll never experience this outside of their 4-years, or even outside the college community. If we consider the forward march to SaaS and other aaS products

RE: [WIRELESS-LAN] Issues with Zoom in Res Halls

2021-01-25 Thread Jeffrey D. Sessler
There was mention of a bug in one of the code bases (maybe 8.5) that could cause this, but there was updated code for it. Also, go have a look at the events for the AP's in question. We had a few reports of call pauses/lags, and with the Zoom diagnostic data from the meeting details in-hand,

RE: [WIRELESS-LAN] [External Email] Re: [WIRELESS-LAN] Transitioning from older controller to new controller

2020-10-09 Thread Jeffrey D. Sessler
The 9800 does have a conversion tool for the aireOS controller configs and does most everything but the encrypted stuff. Even if building from scratch, running the existing config through the tool may help in understanding how all the pieces work, including the equivalent commands between the

RE: Client roaming

2020-10-09 Thread Jeffrey D. Sessler
My personal belief is that even today, technologies like band select just compete with the secret sauce on the client side, and are subject to problems. Every time I've experimented with it, I turn it back off (cisco and aruba), as your success is often short-lived until the next device OS or

RE: [WIRELESS-LAN] Mac wireless issue

2020-10-07 Thread Jeffrey D. Sessler
What channels are the impacted AP’s running on? A few weeks ago I had a similar issue (Cisco wireless), My Mac laptop would attach to our WPA2 network no problem – auth was successful (5 GHz), but would never get an IP. If I walked the Mac laptop (running Catalina) into rage of another AP

RE: Cisco 8.10.130.0 eduroam issues

2020-09-23 Thread Jeffrey D. Sessler
You probably want 8.10.139.43, which is fully BU supported and suggested for production. This is a link to the release notes, I'd check to see if any of these apply. Also, verify your timeouts aren't set too low for the radius responses coming from eduroam. I ran into this at Cal Poly in

RE: [WIRELESS-LAN] Antenna mounting suggestions

2020-08-29 Thread Jeffrey D. Sessler
I’m a fan of ground or near-ground mounting. We use the Cisco outdoor AP’s, and place them in planters and other areas where they disappear into landscape. Occasionally we’ll mount them below the cameras on a security pole. Jeff From: The EDUCAUSE Wireless Issues Community Group Listserv On

RE: [WIRELESS-LAN] New certificate expiration for certificates affecting 802.1X?

2020-08-19 Thread Jeffrey D. Sessler
MFA is common place at the cohorts I interface with, and was driven by a mix of the financial aid security requirements (GLBA) finally being enforced (Dear Colleague Letter in 2014), and Internet2 Net+ collaborations starting with DUO in 2012. If you're an organization with everything behind

RE: [WIRELESS-LAN] New certificate expiration for certificates affecting 802.1X?

2020-08-19 Thread Jeffrey D. Sessler
For a student population that will only be with the institution for 4 years, and then spend the next 60 years using WiFi options with lower barriers and potentially a little more risk, are EDU’s getting it wrong? Are we too focused on something with low risk while ignoring other higher risk

RE: [WIRELESS-LAN] Openroaming - anyone connected?

2020-08-17 Thread Jeffrey D. Sessler
lack of understanding throughout the industry of what OR actually is. tim From: Jeffrey D. Sessler<mailto:j...@scrippscollege.edu> Sent: Monday, August 17, 2020 11:56 To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU> Subject: Re: [WIRELESS-LAN] Openroam

RE: [WIRELESS-LAN] Openroaming - anyone connected?

2020-08-17 Thread Jeffrey D. Sessler
Why not the other way around, and standardize on OpenRoaming, and have everything else become a member of it? Do we still need eduroam at that point? Do we care if the client device is using their ATT, Spectrum, or college credentials? I’m reminded that in EDU we often fix problems nobody

Re: MAC Randomization, a step further...

2020-07-20 Thread Jeffrey D. Sessler
As higer-ed transitions more and more to SaaS/IaaS services, and we are running fewer services on-premise, WiFi is nothing more than a commodity gateway to the Internet. Why not make it easier on everyone and move to less obtrusive ways to get folks connected? Passpoint, or rather,

RE: [WIRELESS-LAN] Icing ISE 2.1 but where to jump

2020-07-17 Thread Jeffrey D. Sessler
I don't know Lee, within our consortium of 5 undergrad and 2 grad universities, all running AireOS-based WLCs, the reliability has been exceptional. My last show-stopper (WLC crash) was way back in 5.x days. Sure, there have been AP radio code challenges, but most of those were wayward client

RE: Cisco pre-DNA Spaces Location Service, Contact Tracing

2020-05-28 Thread Jeffrey D. Sessler
Lee, Even without location services, one can get association data for a device and use that for rudimentary contact tracing. I used it over the summer for a possible COVID case, and it was helpful in determining where the person was not. That is, it's not accurate enough to exclude people

RE: Wireless location data for contact tracing

2020-05-15 Thread Jeffrey D. Sessler
It's pretty trivial today to look at a device/person's association data and reconstruct where they've been. I suspect we all use this data from time to time to diagnose a user reported problem, and someone could theoretically use it for something more intrusive. It's a policy and procedure

Re: [EXTERNAL] [WIRELESS-LAN] Pod-style Residence Halls

2020-02-25 Thread Jeffrey D. Sessler
All of our new residential halls are wireless only, and as we remodel our historic residential halls, we’re pulling the network copper from the room plates into the celling to support the addition of a celling mounted AP. Our density is every other room by default/minimum, so it’s very dense

Re: [WIRELESS-LAN] Who has transitioned away from Aruba, and why?

2020-01-10 Thread Jeffrey D. Sessler
I try to remind myself that EDU’s (Higher ed in particular) are outliers. We want to buy the cutting-edge WiFi technology, but at the same time, we have the most diverse of environments that will absolutely cause every lurking bug or compatibility issue to come out of the shadows. While it

Re: Who has transitioned away from Aruba, and why?

2020-01-09 Thread Jeffrey D. Sessler
Our consortium had both Cisco and Aruba, and about 12-18 months ago the Aruba folks tossed in the towel and went Cisco. Various unresolvable problems with Aruba AP’s, including one that required a weekly reboot of a particular model. As Lee mentions, the grass isn’t always greener, so expect

Re: [WIRELESS-LAN] Azure AD and RADIUS - anyone moved this direction?

2019-09-25 Thread Jeffrey D. Sessler
ion? I know that most times RTT between campus and cloud is low, but I just think its something to be fearful of when authentication times matter. You really are going to have no data center footprint to host local services? From: The EDUCAUSE Wireless Issues Community Group Listserv On Beha

Azure AD and RADIUS - anyone moved this direction?

2019-09-25 Thread Jeffrey D. Sessler
Curious if anyone has moved their RAIDUS to authenticating againstAzure AD, and if so, what path did you take? There doesn’t seem to be a clear MS solution other than standing up domain services for azure AD and running a NPS VM, and I’ve also found a couple of RaaS (radius as a service)

Re: [WIRELESS-LAN] Feasibility of an open SSID for student use

2019-09-13 Thread Jeffrey D. Sessler
uldn’t argue, but I would point out that an improperly configured 1x device puts the user’s credentials at risk. 802.1x isn’t all upside from a security perspective either. Chuck From: The EDUCAUSE Wireless Issues Community Group Listserv mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>&g

Re: [WIRELESS-LAN] Feasibility of an open SSID for student use

2019-09-12 Thread Jeffrey D. Sessler
I’ve never been a fan of the complicated onboarding. It’s intrusive, and unlike any other wireless experience an individual will encounter in their life i.e. any other wifi-enabled location/venue. With the growing trend of EDUs moving to SaaS and other Cloud solutions, wireless will be nothing

Re: [WIRELESS-LAN] Wireless Only in Student Housing?

2018-08-24 Thread Jeffrey D. Sessler
Dan, We were one of the first colleges nationally to provide wired “gigabit to the pillow” in all of our residential halls. Today, those residential halls are WiFi-only and we’ve abandoned the wired, going as far as to remove the copper doing renovations. Done well, with dense coverage

Re: [WIRELESS-LAN] Cisco - Field Notice - 70253 - Wireless Client Fails to Associate: AID

2018-08-24 Thread Jeffrey D. Sessler
e is strictly my personal opinion and not that of my employer Bruce Osborne Senior Network Engineer Network Operations - Wireless (434) 592-4229 LIBERTY UNIVERSITY Training Champions for Christ since 1971 From: Jeffrey D. Sessler [mailto:j...@scrippscollege.edu] Sent: Thursday, August 23, 20

Re: [WIRELESS-LAN] Cisco - Field Notice - 70253 - Wireless Client Fails to Associate: AID Error

2018-08-23 Thread Jeffrey D. Sessler
Ian, I could be misremembering, but I believe, at least on the 2800/3800, that the OS is based on Meraki's with the additional cisco pieces such as CAPWAP added-in. Also, the engineering team members I've worked with for the product are located in San Jose. I do agree that there were growing

Re: [WIRELESS-LAN] Cisco - Field Notice - 70253 - Wireless Client Fails to Associate: AID Error

2018-08-23 Thread Jeffrey D. Sessler
Here is my counter to your statement Lee: Until I joined my neighborhood Nextdoor app, I had no idea that people were getting their mail stolen, animals taken by coyotes and mountain lions, unlocked cars ransacked, and so on. As I studied this, I realized that I was now seeing a small number

Re: [WIRELESS-LAN] Cisco - Field Notice - 70253 - Wireless Client Fails to Associate: AID Error

2018-08-23 Thread Jeffrey D. Sessler
It’s great to hear Aruba is adding features such as “automated RF management” that Cisco has had for over a decade. In another ten years maybe they’ll catch up to Cisco’s CleanAir technology? :D In all seriousness,. if you’re talking specifically about AP updates, cisco has had AP code

Re: [WIRELESS-LAN] Cisco AP2800 failure rate

2018-08-17 Thread Jeffrey D. Sessler
ot check the console port of the AP, but the port on the switch was not lighting up either. -Sam -Original Message- From: The EDUCAUSE Wireless Issues Constituent Group Listserv On Behalf Of Jeffrey D. Sessler Sent: Thursday, August 16, 2018 7:59 PM

Re: [WIRELESS-LAN] Cisco AP2800 failure rate

2018-08-16 Thread Jeffrey D. Sessler
I’ve got a metric ton of 3800’s and 2800’s spanning FCS (first customer ship) to less than a month old and have had zero failures. I agree with one of the other posters that even with no lights displayed, there can be action on the console port. Was the initial failure when connected to a POE

Re: [WIRELESS-LAN] Meraki AP connectivity to eduroam

2018-07-27 Thread Jeffrey D. Sessler
Same as others said. Define the management IP to be allowed by your radius sever and it works great. If you have a lot of locations, and less control of the management IP network e.g. it’s hanging on say a comcast network where the IP changes, the alternative is to use Meraki’s proxy radius.

Re: [WIRELESS-LAN] TimeClocks Plus

2018-07-02 Thread Jeffrey D. Sessler
Have you taken a packet capture to see what’s up? We have similar android-based timeclocks from our timekeeping vendor Kronos. At one of the campuses they have a similar issue with their clocks, only they are wired. Jeff From: "wireless-lan@listserv.educause.edu" on behalf of

Re: [WIRELESS-LAN] Wireless Options

2018-05-21 Thread Jeffrey D. Sessler
better version of the controller product. From: The EDUCAUSE Wireless Issues Constituent Group Listserv <WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> On Behalf Of Jeffrey D. Sessler Sent: Friday, May 18, 2018 1:30 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.E

Re: [WIRELESS-LAN] Wireless Options

2018-05-18 Thread Jeffrey D. Sessler
dor-managed market. Thomas Carter Network & Operations Manager / IT Austin College 900 North Grand Avenue Sherman, TX 75090 Phone: 903-813-2564 www.austincollege.edu<http://www.austincollege.edu/> From: The EDUCAUSE Wireless Issues Constituent Group Listserv <WIRELESS-LAN@LISTSERV.EDUCA

Re: [WIRELESS-LAN] Wireless Options

2018-05-18 Thread Jeffrey D. Sessler
Chuck has the right idea here. Our respective college strategic missions don’t mention running servers or wireless controllers as strategic to the mission of the college. Cloud/SaaS solutions free up folks from the mundane tasks, allowing them to focus on those higher-up technology layers that

Re: [WIRELESS-LAN] Wireless Options

2018-05-17 Thread Jeffrey D. Sessler
We are using Meraki (cloud) as well as Cisco (controller). For the cloud requirement, the Meraki is really easy to setup and manage and they have both small as well as very large enterprise deployments. The interface it great, and like other cloud offering, you get out of the management of

Re: [WIRELESS-LAN] Need help

2018-04-23 Thread Jeffrey D. Sessler
Is there a reason you are on that code? I’d start with running the recommended 8.2MR7 interim. Jeff From: "wireless-lan@listserv.educause.edu" on behalf of Hector J Rios Reply-To: "wireless-lan@listserv.educause.edu"

Re: [WIRELESS-LAN] Wireless RFP - Preparing to Start the Process

2018-03-01 Thread Jeffrey D. Sessler
If you are a member of Gartner or other similar service, they have fantastic frameworks/templates for this sort of thing. Jeff From: "wireless-lan@listserv.educause.edu" on behalf of Manuel Amaral Reply-To:

Re: [WIRELESS-LAN] Offline/Spare Gear Inventory Size

2018-02-27 Thread Jeffrey D. Sessler
* Look at the turn-around time for warranty replacement. The free limited-lifetime may take longer than if the AP is under an extended contract. * Evaluate your deployment plan. If your deployment is coverage-based, where the loss of a single AP could be devastating to clients, then keep

Maybe OT - Cell repeater - SureCAll Force 5

2018-02-13 Thread Jeffrey D. Sessler
My facilities department resides at the other side of my building, and about six weeks ago they installed a SureCall Force 5 cell booster. Had no idea this occurred (no surprise), but at the exact same time everyone in my office with ATT stopped being able to make outgoing calls. For the

Re: [WIRELESS-LAN] iPhone - Incorrect Wi-Fi Password Error

2018-01-30 Thread Jeffrey D. Sessler
Sean, Are you running a multi-controller setup? If so, I’d look to make sure inter-controller roaming and mobility groups are operating correctly. Have you removed the lower data rates from your AP’s so that clients don’t stick as long to distant APs? Jeff From:

Re: [WIRELESS-LAN] Cisco Channel Width

2018-01-19 Thread Jeffrey D. Sessler
RV.EDUCAUSE.EDU<mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> on behalf of "Jeffrey D. Sessler" <j...@scrippscollege.edu<mailto:j...@scrippscollege.edu>> Reply-To: The EDUCAUSE Wireless Issues Constituent Group Listserv <WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto

Re: [WIRELESS-LAN] Cisco Channel Width

2018-01-19 Thread Jeffrey D. Sessler
A lot of these magic sauce features e.g. FRA, have expectations/dependencies on other services like DCA operating at current best-practices. If you’ve been running a Cisco solution for years, a well-meaning admin may have tweaked them for any number of reasons. If those settings aren’t reviewed

Re: [WIRELESS-LAN] Cisco Channel Width

2018-01-19 Thread Jeffrey D. Sessler
Been running that option (Best) for a long time. No downside that I’ve found and after a few passes it’s very stable with channel width. Even in our dense AP deployment residential areas, most all of our WAPs are running at 80Mhz - our students having mostly 11ac devices. The bandwidth use in

Re: [WIRELESS-LAN] Eduroam and Govroam

2018-01-04 Thread Jeffrey D. Sessler
I’m not speaking to my security model. I’m speaking of all these public-sector entities that can’t seem to support their mobile workforce, and are asking that someone else “solve” the problem for them e.g. govroam. Maybe the solution is to abandon both eduroam and govroam and create a global

Re: [WIRELESS-LAN] Eduroam and Govroam

2018-01-04 Thread Jeffrey D. Sessler
witter.com/LondonBSchool> [facebook.jpg] <http://www.facebook.com/pages/London-United-Kingdom/London-Business-School/14027365105> Become a fan on Facebook<http://www.facebook.com/pages/London-United-Kingdom/London-Business-School/14027365105> From: The EDUCAUSE Wireless Issues Consti

Re: [WIRELESS-LAN] Eduroam and Govroam

2018-01-04 Thread Jeffrey D. Sessler
Seems ripe for PII to leak via independently run WiFi networks that broadcast govroam, yet are under no obligation to “do the right thing” with the public sector data flowing over their private networks. And by providing this at the university, does the university suddenly become a party to

Re: [WIRELESS-LAN] Another Cisco WLC Code Thread

2017-12-20 Thread Jeffrey D. Sessler
.edu<mailto:lhbad...@syr.edu> w its.syr.edu SYRACUSE UNIVERSITY syr.edu From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Wednesday, December 20, 2017 11:41 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.ED

Re: [WIRELESS-LAN] Another Cisco WLC Code Thread

2017-12-20 Thread Jeffrey D. Sessler
Well, 8.2 MR7 interim with that fix has been available since early September, but there are several newer builds including the Dec 18th 8.2.167.2 that include it and other fixes and new features. Those first early builds were likely restricted i.e. if you aren’t hitting the bug then why risk

Re: [WIRELESS-LAN] Another Cisco WLC Code Thread

2017-12-19 Thread Jeffrey D. Sessler
. (I used the 3800 cause I know that model, I have no idea what the 1815w is targeted to replace) Mike On Tue, Dec 19, 2017 at 9:27 PM, Jeffrey D. Sessler <j...@scrippscollege.edu<mailto:j...@scrippscollege.edu>> wrote: Discussions like this just reinforce the notion that no one-customer

Re: [WIRELESS-LAN] Another Cisco WLC Code Thread

2017-12-19 Thread Jeffrey D. Sessler
Discussions like this just reinforce the notion that no one-customer is the same as another. Folks like myself have been rock solid where others seem to excite every little bug. There are also customers who want to push the cutting edge with code version and feature-set, but are not

Re: [WIRELESS-LAN] upgrade from 802.11n to 802.11ac

2017-12-06 Thread Jeffrey D. Sessler
If it’s a coverage-based design, all of your gains in 11ac are in 5GHz, so your performance gains have a lot to do with density i.e. if the WAPs are still installed in hallways you may not see the gains you are expecting. If you’re making the jump to 11ac it’s best to redesign around

Re: [WIRELESS-LAN] Wi-Fi Temperature Sensor Inquiry

2017-12-04 Thread Jeffrey D. Sessler
There are a whole host of Zigbee mesh sensors in the facilities management space. Way easier to deploy and less expensive than a device that connects to 802.11a/b/g/n, and most of the sensors are battery powered with a life of up to five years. Jeff From: "wireless-lan@listserv.educause.edu"

Re: [WIRELESS-LAN] Managing static power/channel assignments?

2017-12-01 Thread Jeffrey D. Sessler
I'm curious about what's driving the need for two AP's in each elevator, or to have them there in the first place? Even in medical/hospital settings, I typically see an AP placed on each floor in the elevator lobby. Given how sticky clients are today, it seems to work very well even for latency

Re: [WIRELESS-LAN] Feedback for Cisco WLC software release 8.2.166.0

2017-11-23 Thread Jeffrey D. Sessler
What version of 8.2 are you currently on? In general for the x800 series, the latest code is recommended. If you are already on .164.0 then 166.0 probably won't make a difference. If you're not on 164.0 then do get to the latest code. Jeff On 11/22/17, 10:52 AM, "The EDUCAUSE Wireless Issues

Re: [WIRELESS-LAN] WLC Mobility Groups

2017-11-15 Thread Jeffrey D. Sessler
As far as I know, mobility scales with the controllers, and the limit is 24 controllers in the same mobility group. With a mobility list (bundle of different mobility groups) you can have up to 72 members. 24 8540's would get you 144,000 WAPs in a single mobility group. Jeff On 11/15/17,

Re: [WIRELESS-LAN] Wireless Door Locks?

2017-11-10 Thread Jeffrey D. Sessler
5 From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Friday, November 10, 2017 1:15 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] Wireless Door Locks? This is likely a DMARC failure ba

Re: [WIRELESS-LAN] Wireless Door Locks?

2017-11-10 Thread Jeffrey D. Sessler
This is likely a DMARC failure based on that sender’s record for their domain. They’ve basically told other receiving systems to reject messages that fail DKIM/SPF. In the case of listservers like this one, which may spoof the sender’s address, it will result in rejections or warnings on

Re: [WIRELESS-LAN] Wireless printers and other devices in residence halls

2017-10-19 Thread Jeffrey D. Sessler
herman, TX 75090 Phone: 903-813-2564 www.austincollege.edu<http://www.austincollege.edu/> From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Thursday, October 19, 2017 11:13 AM To: WIRELESS-LAN@LIS

Re: [WIRELESS-LAN] Wireless printers and other devices in residence halls

2017-10-19 Thread Jeffrey D. Sessler
If you move your design planning toward dense 5GHz and designate 2.4 as a legacy wasteland, these devices have little impact. Even if these devices more toward 5GHz, the abundance of channels coupled with low signal propagation and vendor channel management e.g. DCA in Cisco speak, greatly

Re: [WIRELESS-LAN] Best Wireless Solution for Residence Hall Rooms

2017-10-11 Thread Jeffrey D. Sessler
Move to in-room design even if the cost seems problematic. Vendors have never recommended in-hallway as a solution (well, maybe with the exception of xirrus because of their technology), and all the magic sauce works best when WAPs are deployed properly. While a WAP in every-room isn’t a

Re: [WIRELESS-LAN] FTE's for Wireless

2017-09-27 Thread Jeffrey D. Sessler
Hector, I’d recommend starting with your Institutional Research group and ask them who they consider cohorts for Louisiana State. From there, I’d query those universities directly as they’ll likely provide useful/actionable data vs a general request here. That is, my numbers won’t do you a lot

Re: [WIRELESS-LAN] Two RF Questions

2017-09-26 Thread Jeffrey D. Sessler
DU<mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> on behalf of "Jeffrey D. Sessler" <j...@scrippscollege.edu<mailto:j...@scrippscollege.edu>> Reply-To: The EDUCAUSE Wireless Issues Constituent Group Listserv <WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU<mailto:WIRELE

Re: [WIRELESS-LAN] Two RF Questions

2017-09-26 Thread Jeffrey D. Sessler
bject: Re: [WIRELESS-LAN] Two RF Questions Jeff, Take in context that GT works for a company that builds a tool to quantify wireless problems based in depth packet analysis. So when he says he sees 35% improvement, there’s a lot of data that goes into it. Sent from my iPhone On Sep 26, 2017, at 12:41 PM,

Re: [WIRELESS-LAN] Two RF Questions

2017-09-26 Thread Jeffrey D. Sessler
important), adding 20MHz APs is more costly and less effective effective than enabling 40 MHz. From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Tuesday, September 26, 2017 11:43 AM To: WIRELESS-LAN@LIST

Re: [WIRELESS-LAN] Two RF Questions

2017-09-26 Thread Jeffrey D. Sessler
the best use of spectrum and sure to give you the most smiles/hour on your lambo. I really like what cisco did with FRA. Give me the ability to see what it thinks the overlap is. I would LOVE to see the same with DBS, and give me what width it thinks all the APs in the building can pull off. S

Re: [WIRELESS-LAN] Two RF Questions

2017-09-26 Thread Jeffrey D. Sessler
Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Tuesday, September 26, 2017 10:20 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] Two RF Questions It’s surprising to me that anyone would purchase

Re: [WIRELESS-LAN] Two RF Questions

2017-09-26 Thread Jeffrey D. Sessler
It’s surprising to me that anyone would purchase a Lamborghini, then disconnect ten of the twelve cylinders and drive it at 25 mph on the autobahn. When I see static 20 MHz channels, or using 40 MHz in only limited areas, I wonder what’s behind the purposeful neutering of the system. If you are

RE: [WIRELESS-LAN] AAA Override Bug?

2017-09-15 Thread Jeffrey D. Sessler
That bug is fixed in 8.0.150.0 released about two weeks ago. Jeff From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Mccormick, Kevin Sent: Friday, September 15, 2017 8:32 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re:

Re: [WIRELESS-LAN] spurious cpi report of mass AP disassociation

2017-09-11 Thread Jeffrey D. Sessler
Did you go back and correlate the event? For example, SSH into a few of the WAP’s and look at their logs to see what they thought happened. Did the CAPWAP uptime actually change on their WAPs qne/or the hours they report being connected. The WAP logs tend to be very informative. If you use

Re: [WIRELESS-LAN] Defeating Android 8.X Captive Portal detection

2017-09-06 Thread Jeffrey D. Sessler
On 9/6/17, 8:46 AM, "The EDUCAUSE Wireless Issues Constituent Group Listserv on behalf of Curtis K. Larsen" wrote: It would be really nice if Google would join the club and allow their captive browser to switch

Re: [WIRELESS-LAN] Move In/Opening Week- Any Problems?

2017-08-31 Thread Jeffrey D. Sessler
CAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Thursday, August 31, 2017 1:10 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: Re: [WIRELESS-LAN] Move In/Opening Week- Any Problems? Longer client exclusion time

RE: [WIRELESS-LAN] Move In/Opening Week- Any Problems?

2017-08-31 Thread Jeffrey D. Sessler
Longer client exclusion times coupled with longer session timeouts mean the clients most impacted are the troublesome clients i.e. it only feels broken for the already broken clients. I use a 60 second exclusion timeout with very long user session timeouts. The longer exclusion timeouts are

Re: [WIRELESS-LAN] Plastered buildings

2017-08-29 Thread Jeffrey D. Sessler
You have to mount them in-room, and likely every or every-other room depending on the wall makeup between them. My campus is made of nothing but plastered walls with metal mesh, compounded by the internal construction which is mainly reinforced block/concrete. This was a curse in the early

Re: [WIRELESS-LAN] DFS Scans Seem to Have Run Amok

2017-08-28 Thread Jeffrey D. Sessler
5487 Phone 205-348-3992 john.watt...@ua.edu<mailto:john.watt...@ua.edu> [he University of Alabama]<https://www.ua.edu/> From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Jeffrey D. Sessler Sent: Monday, August 28, 20

Re: [WIRELESS-LAN] DFS Scans Seem to Have Run Amok

2017-08-28 Thread Jeffrey D. Sessler
TAC will likely suggest you install 8.0MR5 interim (8.0.141.46) given you have 2700’s (couple of radio bugs are fixed). DFS is as much art as science and older code isn’t always perfect i.e. I’ve seen newer devices that much older code sees as radar. You can request the code here and see the

Re: [WIRELESS-LAN] Move In/Opening Week- Any Problems?

2017-08-25 Thread Jeffrey D. Sessler
nt, Western Australia Ph. (08) 9442 1757 Mob. 0424 160 877 From: The EDUCAUSE Wireless Issues Constituent Group Listserv <WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU> on behalf of "Jeffrey D. Sessler" <j...@scrippscollege.edu> Reply-To: The EDUCAUSE Wireless Issues Constituent Group List

Re: [WIRELESS-LAN] Move In/Opening Week- Any Problems?

2017-08-25 Thread Jeffrey D. Sessler
Pair of 8540’s running 8.2.160 About half of all WAPs are now 2800/3800. 3800’s on multi-gig 20Gb Internet connection 3800-series equipped 110-bed residence hall, partially filled with a few early arrivals, already seeing peaks at over 600Mbps. No observed problems yet, but our first-years just

Re: [WIRELESS-LAN] Cisco 2802i and 3rd party injectors or switches

2017-08-22 Thread Jeffrey D. Sessler
At the appropriate discount for EDU, the AIR-PWRINJ6= is only slightly more than the third-parties and fully supported by TAC. Personally, if you have to power more than six in one location, invest the money in a new switch with UPoE so you’re covered for the next 7-10+ years. Jeff From:

Re: [WIRELESS-LAN] EAP-TLS

2017-08-15 Thread Jeffrey D. Sessler
“Our campus isn't comfortable with an open ESSID without verifying the identity of the user, so that's the value of eduroam - identity.” How exactly have you verified the identity of the user? Is it blind trust that other EDUs verify and manage identity in the same fashion that your campus

Re: [WIRELESS-LAN] EAP-TLS

2017-08-15 Thread Jeffrey D. Sessler
Couple of comments: * eduroam – using your point of “…most users can access what they want off-campus…”, what long-term value is there to eduroam? IMHO – not at lot. Back in the day, this would facilitate quick access for a visiting educator who may be collaborating with someone locally

  1   2   3   >