08-26-2020 09:54 PM
08-27-2020 02:31 PM
08-27-2020 06:41 AM
08-27-2020 03:00 PM
05-15-2021 11:39 AM
I want to add:
1) If you have just 30-50 devices, all of them probably 1-2x MIMO, and 100-200Mbps/s Internet connection, you will be not using R750 capabilities enough. R550 will be adequate, and in most cases, in a building you are better served by 2-3 middle-class APs, than 1 premium.
2) I agree that gateway mode is not a preferred way to use Ruckus AP. It was added because a lot of home users asked for it, as when tried to install Ruckus they were surprised to find that AP is really AP, not a router, even so it was written in specification. So it can be used if really needed, but if you can avoid it -- use a separate router. In my practice, the best functionality for money you can get from Mikrotik, its configuration interface is not intuitive at all, but it has high performance and is cheap, as well as has the functionality of enterprise router (Cisco-level, up to BGP, MPLS and other high-end feature support).
In my opinion, the main limitation is disabled NAT-traversal support in gateway mode -- IPSEC VPNs fail over it. Probably, can be fixed by some CLI configuration, but I haven't looked into it as I never use it. Should be turned on by default, as now VPNs are a common part of home network.
I see in the CLI manual such commands as
conn-cap ipsec-vpn open
conn-cap ikev2 open
Probably they can do a trick (what else they could do?), but I don't have Unleashed network to test (we use almost exclusively vSZ managed APs). I am curious, and probably I'll convert some AP to Unleashed and test this later, but for sure somebody have done this already?
If somebody has a positive experience configuring NAT-traversal over UNLEASHED AP in Gateway mode, please share it.
3} About free URL filtering -- I can't imagine why you would need it ever?
If you mean static URL filters in routers, they are some remnants from the past, easy to realize, no real use. Yes, you can list some 20 URLs, so what use it is? Disable access to google, Microsoft, etc ? May be, but not much than that. And there is always way around using some public proxy or VPN.
Ruckus URL option isn't this static table, but a constantly updated URL classification list in the cloud, so you can disable such categories as adult content, violence, games, etc. It isn't bulletproof too, but as good as they get, so it may make sense in schools or for children access. Anyway, I think it is much better when you can rely on users to make proper choices...
There are always ways how users can get around URL filtering to access disabled content, as well as false positives - when business web-site for some reason is disabled.
If you really want to filter what users can access, you can use DNS filtering servers, such as Open DNS, to disable mentioned categories of sites, or 9.9.9.9 ( to avoid infected and fraudulent sites). To use these sponsored services you even don't need to have any service in the router, you just need to set it as DNS server for clients.
They are not ideal too, as they blindly aggregate lists from different sources, and some sites may be blacklisted without real reason, or some really bad sites -- not listed.
4} About support and any other costs to run Unleashed -- RMAs for AP are very rare, and I never have seen issues with that, and you don't need any other licenses to run Unleashed.
Ruckus is an enterprise system, and corporate support is great, and yes, you need paid support contract for enterprise support. It is mainly applicable to systems with controllers. You can buy support for unleashed, it is cheap, one license per network up to 25 APs, but why you'll need it for 1 home AP?
You don't get enterprise support for free when you take home AP without a support contract - but it's the same situation with HP/Aruba, Cisco, and any other enterprise vendor.
Ruckus Unleashed uses enterprise-grade hardware without any additional management licenses or hardware. It allows you to do a lot of things, but you have to know what you do. So if you are new to wireless systems, better ask some colleague with experience to help you, it will make things much easier.