Key Design Considerations of Campus Networks
Campus networks usually include several buildings with a high density of client devices brought by students and faculty that usually below requirements need to be considered:
Role-based Networks need to be considered that certain services or servers can be accessed with different privileges by student role or faculty roles, so
Student can bring their own device (BYOD) and access the registration and learning management platforms
Faculty can then manage classroom AV systems, content creation tools, and research networks
Broadcast and multicast traffic control to limit the impact of broadcast storms.
WiFi Consideration
EduRoam Support
Role-based Networks
Since different roles, like faculty, student, will access different services and servers, one simple design is to create different SSIDs for different VLANs to separate the traffic such as "Student SSID", "Faculty SSID", however, this design might not be flexible and cause more tedious management issues.
Another good practice is to leverage "Security Group" of the AD server so that everyone accesses the single "Campus SSID" and let pre-defined "Security groups" of "Faculty" and "Student" of the same AD server control the "role-based" privilege of the user to access authorized services or servers.
EnGenius supports multiple "Groups" of AD server authentication both through 802.1x WPA-Enterprise or Captive Portal
Create a single "Campus" SSID
Choose WPA-Enterprise or Captive portal by using external AD authentication, and then create "groups" to map to the "security groups" created in AD servers
Broadcast and Multicast Traffic Control
Since HD AV streaming is commonly used in training courses in the classroom for students to watch the same video at the same time, multicast is needed for one-to-many streaming distribution and forward broadcast packets from one multicast server to many clients. Unicast streaming, on the contrary, creates a session between the streaming server with every single client, which has less packet loss and higher bit rate.
EnGenius AP has Multicast-to-Unicast enabled by default to convert multicast packets to unicast packets to have higher video streaming quality
EnGenius AP also has "BCMC Suppression" enabled by default to reduce broadcast and multicast traffic from wired to WiFi by reducing small frames sent in wireless at a basic rate.
Broadcast and multicast traffic will always impact the clients in the same subnet, especially when broadcast storm happens. More VLANs will be highly recommended to limit the broadcast traffic within small group of clients in a VLAN. However, if administrator pre-groups the clients to different VLANs, it's hard to manage the group, and cannot expect how many VLAN clients will actually use the Networks to limit the traffic.
EnGenius dynamic “VLAN pooling” is a function to randomly assign VLAN, within a range of VLAN defined by Administrator, to each client device accessing the SSID to minimize the broadcast/multicasting traffic within smaller groups of devices.
High-Density WiFi
In the auditorium, there might be lots of students and faculty using WiFi for certain events like graduation ceremony that hundreds of clients will need to access the AP's while each AP has limited client connection.
When more AP's are deployed in a high-density area, the channel interfering can become a key issue of performance. More channels will definitely lower the channel interference.
Recommend to use DFS channel to have more channels in 5G
User EnGenius “S” series, like ECW220S or ECW230S, has a dedicated scanning radio to provide Zero-wait DFS, so clients can switch to other available DFS channels without waiting time.
Recommend using WiFi 7 and opening up 6G radio band to provide more channels than 5G band
EduRoam
EduRoam allows any user from an EduRoam participating site to get network access at any institution connected to EduRoam, depending on local policies at the visited institutions, which stays securely at the local institution for remote institutions to query when EduRoam users visit the remote campus.
For the authentication server to be able to be queried from other campus servers, the query traffic needs to be protected that "RadSec" is required between the authentication servers. It's also highly recommended to have "RadSec" between AP and Authentication Radius servers.
EnGenius AP supports RadSec to secure the radius traffic transferred between AP and the local Radius server.
EduRoam is a member of the Wireless Broadband Alliance (WBA) and a pioneer member of the OpenRoaming federation service. enabling automatic and secure Wi-Fi.
EnGenius AP supports OpenRoaming and is certified by WBA OpenRoaming.
Demands and Features Quick Links
Vertical Application Wizard (Campus) | Leads to Key Features (PRO) |
Create “Campus Network” with separated group (staff/student) authentication of AD server | Group function of AD authentication server |
EduRoam | |
Minimize multicast traffic impact | VLAN Pooling |
High Density |
