Wireless Statistics Recommendations presented by The Library Network Wednesday, May 21 2014 Merit Conference Eagle Crest Conference Center 1275 S Huron Street Ypsilanti, Michigan
Your presenters today are: Angie Michelini, The Library Network Mike Vela, The Library Network Michael McEvoy, Northville District Library Carl Swanberg, Canton Public Library
OVERVIEW TLN = Public Library Cooperative Technology Committee comprised of IT staff that work at Public Libraries Wireless Committee subcommittee of Technology Committee
he TLN Wireless Committee identified specific objectives and trategies related to the use of technology that are critical to the bility of TLN and our members to meet their service goals. ub- Commi*ee Purpose: Iden4fy Vendors and Technologies for Wireless Service that provide adequate sta4s4cal repor4ng Iden4fy the recommended level of sta4s4cs repor4ng for the Library of Michigan State Aid report Form Best Prac4ces for Wireless Sta4s4cs collec4on and repor4ng
To accomplish these goals, the sub-committee Spoke with the Library of Michigan to clarify their expectation of what should be reported Arranged demonstrations with multiple local vendors Compared competing vendor solutions Researched solution for pre-existing wireless solutions, both vendor and open source Determined the best price/best service solution for vendor, b choosing two vendors for new purchases
STATE AID REPORT WIRELESS USAGE STATISTICS; Sec&on X: Library Services, Ques&on 19 19. Uses of Wireless Logins per Year Report the total number of wireless logins in the library during the last year. If the data element is collected as a weekly figure, mul&ple that figure by 50 to annualize it. Iden&fied Issue: No true methodology or minimum requirements are provided to guide libraries as to how to gather these sta&s&cs.
Best Practices for Wireless Statistics 1. Present a splash screen with your wireless and/or Internet usage guideline(s). a. The splash screen exists both to inform and to count. Patrons will be required to accept the page before accessing the wireless network. b. Systems without a splash screen may have issues with accurate counting. i. Can cause system to count passerbys who never use the system. 2. Ensure that your wireless solution allows creation of at least 1 public SSID, and 1 secured staff SSID. a. SSID is defined as Service Set Identifier, or the name provided to a wireless network. b. The Library of Michigan does not differentiate between Staff or Publ usage. They want to know how often your wireless connection is used.
Best Practices for Wireless Statistics (cont). Set any system to count by unique user. a. Unique Users are defined by MAC address. b. Counting by (Internet Protocol) IP addresses issued will result in ske results (higher or lower, depending on use/abuse).. Set counting mechanisms for your chosen system to store login informati or 12 hrs minimum and 24 hrs maximum. a. Decreasing this to shorter time intervals (example: 2 hrs) will result in inflated usage count. b. Many products default to 24 hours.. Ensure that the main Internet connection has a static IP address or use a ynamic DNS service. Otherwise, it can be very difficult or impossible to ge ccurate usage statistics.
RECOMMENDED WIRELESS PRODUCTS Site Requirements for both vendors include POE (Power Over Ethernet) Switch OR Power Injector
ABOUT Courtney McGowan, Cloud Networking Inside Sales - Michigan Cloud based Wireless All services are managed from a single web- based portal (htp://dashboard.meraki.com) Sta&s&cs are set to 24 hour lease by default High level of security, traffic control and filtering High level of sta&s&cal reports Includes System Manager to help manage your network Currently used at mul&ple TLN libraries
About Glen Leonardis, Inside Sales Representa&ve Great Lakes See Glen at the Aerohive booth for more detail Cloud based Wireless Sta&s&cs are set to 12 hour lease by default High level of security, traffic control and filtering High level of sta&s&cal reports 100% cloud based using HiveManager Currently used at Livonia Public Libraries, Grosse Pointe Libraries, uburban Library Coopera&ve
Dashboard - Network Summary
Dashboard Applica&on Visibility
Context- Based Visibility and Control Application Wireless Statistics Recommendations Firewall Prioritization Monitoring BYOD Policy Restricted VLAN Limit non-work apps 5Mbps per CORP user Policy M-F 8am-9pm Corp VLAN Prioritize Work Apps Diff Serv or 802.1p 10Mbps per GUEST user Policy 24HR Access Guest VLAN only No Netflix or BitTorrent 1Mbps max per user Restricted to 9-5 M-F
RECOMMENDED FOR PRE-EXISTING WIRELESS SYSTEM Google Analytics with m0n0wall http://www.mono.ch http://www.google.com/analytics pfsense http://www.pfsense.org
ANALYTICS WITH This is a cheap, or poten&ally free, solu&on for those who have exis&ng wireless that does not provide sta&s&cs gathering. Examples are: Cisco Aironet Linksys or home style wireless routers. m0n0wall socware directs all wireless users, atemp&ng to browse, to a cap&ve portal. The cap&ve portal holds the user un&l they are redirected from the splash or usage policy page. Upon clicking Accept, the user gets sent to a web page that has a zero second redirect which sends them to a website, i.e. a library s homepage. Google Analy&cs code tracks user connec&ons made to the zero second redirect page and a report can be created to gather this connec&on informa&on
ANALYTICS Four parts are necessary: Wireless Access Point(s) WITH A cap&ve portal, which is a hardware appliance or PC capable of running m0n0wall or other socware with a cap&ve portal feature Google Analy&cs account The ability to secure access to the zero second redirect page on the webserver that hosts the website
ANALYTICS WITH Any wireless access point can be used, but DHCP needs to be turned off on it in rder to allow the m0n0wall appliance to handle DHCP. Socware that includes the cap&ve portal feature is required. m0n0wall and Pfse ave this capability. A hardware appliance, like Soekris or older computer, that meet the minimum ystem requirements of the socware. Two network interfaces, on this hardware, a equired. The Google Analy&cs account requires a Google account. Highly customizable eports can be made, but for this purpose the report tracks access to one page. The webmaster will have to limit access, to the subfolder containing the zero econd redirect page, to the origina&ng IP address of the site being tracked.
Simple Single Access Point Network Multiple Access Point Network
Example C: m0n0wall on the same firewall interface with the staff LAN
pfsense is a free and powerful solu&on for those with an exis&ng wireless system that does not provide adequate sta&s&c or security sehngs. Any PC built within the last 5 years should be more than adequate. Most any access point can be used with pfsense. Provides Cap&ve Portal, Firewall services, traffic graphs, a web interface, and extensive monitoring features.
Staff Network Internet Staff Network switch or VLAN Wireless netowrk LAN Interface WAN Interface Access Point(s) Wireless Network switch or VLAN PfSense PC Firewal
Stat collec&on data sources Cap&ve portal status Cap&ve portal Log (/var/log/portalauth.log) DHCP leases. (/var/log/dhcpd.log) RRD Graph
/var/log/portalauth.log
Access portalauth.log for automated recording. Look for log entries with the word ACCEPT: Count Unique MAC addresses cat /var/log/portalauth.log grep -a ACCEPT awk '{print substr($8,0,17)}' sort uniq wc -l) To clear log; Delete and reboot pfsense
RRD Concurrent Users graph Shows sessions that have not &med out Balance idle &meout, between accuracy and user hassle.
Email reports can show: Shell command output Log file tail (buggy use command cat <path>) RRD graph screenshot Reports can be scheduled, to transmit daily, weekly, monthly, quarterly, or yearly.
PRICE INFORMATION Discount pricing is available for all public libraries in the State of Michigan for Meraki and Aerohive Products Contact Angie Michelini for further information.
Any Questions?
Thank you for your :me today!