MacGyver phone redux
Sadly there have been some unreliability in the system. My WiFi meter shows the Aruba device she is equiped with constantly broadcasts on Channel 10 Wifi and Channel 36 WiFi (despite not using the WiFi, it just chatters away anyway). And this proved a problem for a couple of reasons:
- More RF noise makes less reliability all around
- It overlaps with the nearest Access Point to her, increasing the affect on her system
- You should not use Channel 10 in 2.4GHz (use 1/6/11 only, I talked about this in WiFi: going from good to great is very hard)
So, I decided to redo it. I purchased a Wavlink WL-WN575A3, a dual-band wifi repeater. They are a dime a dozen, quite a few out there in the $40-$80 range. I purchased this on a couple of assumptions:
- It would likely run OpenWRT (spoiler: it does, based on MediaTek MT7628AN)
- dual-band means I could use the 5G as an upstream and the 2.4G as a downstream if I had to (never use a wifi repeater where it has a single radio).
- It would have adequate antenna diversity to improve the overal signal strength and resilience
So, repeater acquired I set it up. Installing OpenWRT was a breeze. I then disabled the 2.4GHz wireless, set the 5G wireless to my house WAN, moved the 2 Ethernet ports to a LAN bridge, boom, we are done.
Was it a great success? Yes I think so. Signal rate is -77dBm, noise floor is -100dBm, so the SNR is ok.
I would really rather the Aruba would turn off its transmitters (both), but, workaround achieved.
Now, this brought up an interesting dilemma. You see, the Aruba widget she was sent home with is an IPSEC VPN. They wanted you to plug the laptop into it as well as the phone. Previously we had the phone there, but the laptop was on the (guest) WiFi, and she would VPN it in directly. So, the general Internet speed of the laptop is now *lower*. Why? Because all traffic trombones through the company, our downstream (1Gbps) is throttled by their upstream (seems 90Mbps).
But, she doesn’t have to start/stop her VPN.
Is this a good tradeoff?
From a security standpoint, no.There is an Ethernet jack in our house on their corporate network. Zero-Trust would be better, get rid of this VPN.
From a employee happiness standpoint? Maybe. She will have a worse experience doing video conferencing and youtube and browsing. But she will have a better experience with (what is that horror, is it a 3270 terminal emulator? its some text-based interface run in a shell, probably AS/400?) their built in tools.