DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

AP900 and Roaming

  • eskdale
  • Topic Author
  • User
  • User
More
19 Feb 2015 11:36 #13 by eskdale
Replied by eskdale on topic Re: AP900 and Roaming
Hi - Yes, I'm not currently using it as managed - I've edited all three AP's individually manually.
You don't have to use the managed to have the fast roaming although managed does save you entering the same details into all the AP's
I've also tried different Radius servers. If you turn on the logging and look at the logs you can see the devices failing to authenticate and then later authenticate without me changing anything. In my opinion there is something seriously wrong with the fast roaming and the Radius server mode. Spent a lot of time on it but not for the last few weeks as have had other priorities.

Jon

Please Log in or Create an account to join the conversation.

  • sicon
  • User
  • User
More
26 Feb 2015 10:10 #14 by sicon
Replied by sicon on topic Re: AP900 and Roaming
We have not experienced any issue with the roaming yet and have it set up on multiple sites. None use the built in radius though its all AD and NPS.
Some site are also running multiple VLANs and they all roam fine.

Please Log in or Create an account to join the conversation.

  • eskdale
  • Topic Author
  • User
  • User
More
26 Feb 2015 11:41 #15 by eskdale
Replied by eskdale on topic Re: AP900 and Roaming

sicon wrote: We have not experienced any issue with the roaming yet and have it set up on multiple sites. None use the built in radius though its all AD and NPS.
Some site are also running multiple VLANs and they all roam fine.



So what mode are you using?
Do you have it configured as 802.1x in the mode if you do then you would need a radius server to authenticate with and that is where the problem seems to be. My problems occur whether it is a built in Radius server or an external one it does seem to make any difference

Jon

Please Log in or Create an account to join the conversation.

  • sicon
  • User
  • User
More
02 Mar 2015 12:28 #16 by sicon
Replied by sicon on topic Re: AP900 and Roaming
The RADUIS is part of the NPS policy on the 2012 R2 server,
There is then a policy/restriction to only allow users who are part of a certain security group to log on to the Wifi.
Yes it is 802.1X - the server then authenticates the access points with a Shared Secret.
The mode is mixed G & N only

The guest Wifi is just normal WPA2/PSK

Please Log in or Create an account to join the conversation.

  • eskdale
  • Topic Author
  • User
  • User
More
02 Mar 2015 12:48 #17 by eskdale
Replied by eskdale on topic Re: AP900 and Roaming
Hi Sicon - The problems all seem to occur when Mode within the security section is set to have 802.1x e.g wpa2/802.1x

I agree the guest Wifi should be WPA2/PSK in the mode, but what do you have the mode within the security section set to for the main users?
Perhaps the use of "Mode" in different contexts is confusing things here.

It would need to be wpa2/802.1x in my opinion and then you need to configure the AP900 to use the Radius server on the Server 2012. I don't have AD setup here but have tried it against different Radius servers and the problem still exists. Its not that it never authenticates it is just that it doesn't always and you can see it in the AP900 syslogs which causes it to lose wifi connection normally on hand over.

Jon

Please Log in or Create an account to join the conversation.

  • hansfords
  • User
  • User
More
02 Mar 2015 23:14 #18 by hansfords
Replied by hansfords on topic Re: AP900 and Roaming
So is quality roaming doable using just Draytek routers and APs and, if so, is it better with or without radius? Or is it better just to have a different SSID on each AP?

Please Log in or Create an account to join the conversation.