Monday, November 1, 2021

Building the whole network stack at the Office

Good evening, I have the task of setting up an office's entire network stack, and it's a doozy. I'm going to lay this out as best as I can in text. I was looking at Unifi and I've read enough horror stories about the slow decline, and I can't order anything from them anyways since it's all out of stock that I'm not keen on trying them at the moment. As for other brands, I'm not sure if I want to try Aruba's Instant On (literally just read about it tonight through here), Fortinet's offerings, TP-Link since we already have some, or just wing it. (Kidding, no one should ever wing it when it's public services.)

Gear we will likely keep for now: TP-Link EAP330, TP-Link RE580D as they are still usable, however I'm inclined to replace them now to add them in as part of the "sticker shock", as well as get WPA3 compatible gear, assuming they stop updating the firmware from this point forward.

Modem in bridge mode, serving a /29 range, so two IP addresses. One address will be for a government connection, the other will handle phones, BYOD, Guest access.
The government access side has a PA-220 appliance I have no control over. It is my understanding the PA-220 is also the router in this scenario, therefore no need to provide one. Internally it needs a switch to connect a WAP, another switch for the far side of the building, and printers. Nothing right now needs POE on that switch. Far side of the building will have another small switch for printers and the Wifi repeater/WAP, no POE.

The Public side needs a router, and a switch with at least 14 ports for POE (802.3af 15W phones) with a minimum 300w budget, 1 WAP, a connection to a switch on the far side of the building for 2 POE phones and another WAP/repeater for BYOD/Guest access.

The state requires physical separation of everything, hence the doubling up. My ideal solution would be to go with the same brand across the stack for management purposes, but it's not a requirement.

What I'm looking for:

  • Switches, 4 or 8-port POE, and 24-port POE+, managed not required but a nice-to-have.
  • Possibly a router, but I'm not against making a pFsense box.
  • WAP's/Repeaters that optionally could be powered via POE for flexibility
  • Ideally same brand for management, but if not, then some suggestions on how to best mix it together.

Thanks in advance for any suggestions :)



No comments:

Post a Comment