HW086: High Density Wi-Fi Part 2
This episode discusses advanced wireless networking strategies for high-density deployments, covering DHCP management across multiple gateways, bandwidth shaping myths, QoS implementation, interference mitigation, and infrastructure considerations like cabling and power management. The hosts share practical lessons from a large-scale event deployment using primarily Apple devices across 5GHz and 6GHz bands.
Summary
The episode revisits a large high-density Wi-Fi deployment with listeners' follow-up questions. For DHCP management, the team implemented nine VLAN/gateway pools using RADIUS MAC authentication to randomly assign devices on first connection, with each MAC address remembering its VLAN assignment for a week. They discuss client isolation, explaining it prevents direct device-to-device communication but doesn't eliminate inter-client communication entirely—it just forces traffic through the router.
A significant discussion centers on bandwidth shaping and QoS. The speakers argue against bandwidth limiting on Wi-Fi, contending that capping individual user speed forces clients to consume more airtime by transmitting slower, which impacts all users in the area. They emphasize that in Wi-Fi environments, airtime is the constrained resource, not bandwidth. The team deployed three 10-gigabit WAN connections across nine gateways without implementing bandwidth shaping at either the Wi-Fi or WAN layer. They explain QoS requires end-to-end understanding from client through application to all network hops, and some applications don't respect QoS markings anyway. In this deployment, QoS was left at default settings, with audio-visual traffic isolated on a separate physical network entirely.
Regarding interference from non-owned access points, the team discovered numerous unauthorized APs (160MHz channels in 5GHz and misconfigured 2.4GHz radios) from vendors, contractors, and event staff. They used Wi-Fi Explorer Pro, CEDOS Wave, Wi-Fi Explorer Pi with Hamina Clip (which provides audio proximity feedback) to locate rogue devices. The approach emphasized cooperation over enforcement, noting that contractors legally have equal right to use unlicensed spectrum. They worked with device owners to either power down unnecessary APs or reconfigure problematic channels.
For band balancing and steering, the team deprecated forcible deauthentication-based band balancing in favor of BSS Transition Request signaling, which asks clients to move bands without forcing disconnection. With six-band capable clients comprising 60% of devices and 40% limited to 5GHz, they observed 6GHz clients spent approximately 90% of time on 6GHz APs (despite smaller cell sizes causing more frequent roaming than 5GHz clients).
The deployment used a single SSID covering both 5GHz and 6GHz, with band steering disabled and Reduced Neighbor Reporting (RNR) enabled. RNR allows 5GHz beacons to announce 6GHz AP availability with specific channel and SSID details, enabling direct client roaming without passive scanning. This simplified design contrasted with the previous year's separate 5/6GHz SSIDs, which caused confusion and roaming problems.
The speakers address device-type considerations, noting that while most devices were Apple (MacBooks, iPhones), Windows and Android devices present behaved similarly for RF principles, though they may roam differently based on chipset (Windows devices often less sticky, jumping between APs with smaller RSSI changes). The team tested roaming primarily with Apple devices.
On SSID quantity, the consensus recommends limiting to two SSIDs maximum (corporate and guest), with three as absolute maximum. They argue against separate 2.4/5/6 SSIDs, recommending instead one SSID for 2.4 only and one for 5/6 combined. Avoid duplicating the same SSID across multiple bands—let clients decide their band preference through steering mechanisms rather than manual selection.
Infrastructure considerations receive substantial attention. The deployment featured 10-gigabit connections to most access points (with few exceptions), UPS-backed switches in each data closet, and single-strand bidirectional single-mode fiber for backbone connectivity to the main distribution frame. Critical lesson: copper cabling runs near high-powered tri-phase cables caused interference and Wi-Fi service degradation. The team recommends Ethercon highly-shielded cabling for similar high-interference environments. Beyond cabling and power, network engineers must understand the entire ecosystem: what other systems share the switching fabric, whether audio-visual infrastructure uses the same network, and how all dependencies affect Wi-Fi reliability.
About this episode
By popular demand, Keith is joined once again by Ferney Muñoz and Tom Hildebrand to answer listener questions and to dive deeper into designing high-density Wi-Fi for large-scale events. Together they share practical insights on managing DHCP scopes, the realities of client isolation, and more.
Key Insights
- The team implemented RADIUS MAC authentication to assign devices to one of eight VLAN pools based on MAC address, with the VLAN assignment remembered for a week to avoid re-authentication overhead and MAC address rotation issues
- The speakers argue that bandwidth limiting on Wi-Fi forces slower transmission speeds that consume more airtime, degrading performance for all nearby users rather than just the targeted user—contradicting the assumption that rate limiting protects other users
- Rogue access points using 160MHz-wide channels in 5GHz and misconfigured 2.4GHz radios were discovered from event vendors and contractors, and the team used audio-feedback proximity tools (Hamina Clip) combined with Wi-Fi scanning software to physically locate devices
- The deployment achieved approximately 90% on-time 6GHz connectivity for 6GHz-capable clients using a single SSID with Reduced Neighbor Reporting, which allows 5GHz beacons to advertise 6GHz AP availability and channel details, eliminating need for passive scanning
- Infrastructure failures occurred when high-powered tri-phase power cables ran adjacent to copper Ethernet runs, causing electromagnetic interference that degraded Wi-Fi service despite the Wi-Fi layer itself functioning correctly, demonstrating dependency on proper cabling infrastructure and shielding
Topics
Transcript
Welcome back to another episode of Heavy Wireless, part of the Packet Pushers Podcast Network. This episode is a special episode based on a listener request. After having a discussion with Tom Hildebrand and Frenet Munoz about our work together on a large, high-density design, they had some additional questions and asked if we'd come back and readdress these. So, welcome, Tom. Welcome, Frenet. Welcome. Glad to be back. Well, let's just continue on where we were talking, and let's first touch on DHCP. Some of the things the listeners have asked for was more details about how we had addressed lots and lots of devices all needing DHCP requests. So, Tom, you want to tell us, how do we…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.
HN840: How to Make a Technology Buying Decision
Sean Morgan, a research director at Deloro Group, discusses how technology buying decisions should extend beyond engineering specifications to include business alignment, ROI calculations, and understanding total cost of ownership. Engineers must shift from viewing IT as a cost center to positioning it as a business enabler by connecting technical decisions to revenue impact and organizational objectives.
IPB207: Flying Blind: Monitoring Might Not See IPv6
The IPv6 Buzz hosts discuss critical gaps in IPv6 monitoring across enterprise networks, highlighting that many monitoring platforms lack IPv6 awareness, vendor parity, and advanced analytical capabilities. They emphasize that while basic IPv6 data ingestion has improved, sophisticated features like cross-protocol event correlation, extension header analysis, and device identity tracking remain significant industry challenges.
N4N063: Link Layer Discovery Protocol
Link Layer Discovery Protocol (LLDP) is a standardized Layer 2 protocol that enables network devices to announce information about themselves to directly connected neighbors, facilitating network topology discovery and device identification in multi-vendor environments. The protocol uses Ethernet frames with special multicast destination MAC addresses to ensure frames don't propagate beyond immediate neighbors, and includes mandatory TLVs (Type-Length-Values) like chassis ID, port ID, and TTL alongside optional ones for extended information.
TCG083: Superintelligence for Everyone: Who Actually Holds the Power?
Three technology experts discuss Mark Zuckerberg's manifesto on distributed superintelligence, examining whether his promises of universal access and individual empowerment align with infrastructure realities. They conclude that while decentralized AI is theoretically safer than centralized control, the manifesto fails to account for human complexity, existing inequalities, and the enormous capital requirements that will likely concentrate power rather than distribute it.