I recently took over a student housing complex because the previous guy wasn’t answering the phone and they were completely down. They had 2.4 ghz original unifi APs (yes, that’s what Tom uses at home) and over the past year we’ve been swapping them with ac-lr to handle the traffic demand. We’re almost done swapping out all the APs but there now we’re getting complaints from people in apartments that already have the new equipment. We changed out the unifi gateway router with a pfsense appliance built on an intel i5 protectli. Last year they had on average about 300 devices connected but now we’re seeing up to 480. Students are now bringing watches, speakers, and other iot on top of their phone, laptop, and tablet. The previous guy had it setup as a flat /23 network so we replicated that for the sake of getting them up and running. I’ve been thinking about setting up each AP with it’s own VLAN knowing that as students roam they’ll hop to different IP addresses.
The big issue I have now is traffic prioritization. I know that Untangle can do a much better job at application layer throttling so I’m wondering if I made a mistake doing PFSense. I need to completely block torrents to make sure that doesn’t hog the traffic. I need to have netflix and gaming down on priority. Web and voip/video (biggest complaint right now is online classes with zoom are freezing) need to be priority. I’ve been trying to contemplate an easy way to make sure they aren’t just allowing all their friends that don’t live there to connect and ruin the network for people that pay to be there. We doubled their fiber to 200 Mbps but I’m starting to see that their sustained traffic is increased over last year and if this continues we might have to go to 300. I don’t think that is currently a problem though. 1/3 of the apartments don’t have an AP in them and they feed off the neighbor but if I start to see too many devices I can start adding APs to each that doesn’t have one. Preferably we control the traffic though because college kids nowadays will saturate anything instead of doing homework so I’m worried if I install that many new APs and it doesn’t fix the problem that I’ll look like a fool.
Anybody have some advice? Do I need to ditch PFSense and go to Untangle? Will there be a big enough benefit to VLAN each AP? Do I do radius credentials or mac auth? Problem with radius is the iot devices can’t join. But if it’s off mac then the manager has to gather every mac from every device people bring and every 4 months they rotate 150 people. Do I rate limit per device at just enough speed to handle video stream and then their web browsing will suffer? Thanks for any input to improve this I really appreciate it.