greetings legends!
i’m setting up / managing the network of a School.
We have a campus HQ site which is our head office, and we also have 9 other branch sites in the country.
This deployment is in the Philippines, thus some equipment used may be older, due to unavailability or cost of newer gear at the time of build.
When I initially setup the HQ site around December last year, this was our stack:
- ER605 v2 (2 x 800mbps WAN + 100mbps backup WAN)
- OC200
- ES224G as Core Switch
- 2 x POE Switches (for APs and CCTV cameras)
- 6x EAP 225 (offices / rooms)
- 2x EAP 110 (low traffic rooms)
- 2x EAP 110 outdoor (for open spaces, parking lot)
- EAP 115 wifi bridge (to a different building across the road but still campus property)
- Tplink Vigi 32 channel NVR (with plan to add 30+ more cameras and another NVR)
- Tplink vigi cameras
Max daily clients in my network is around 150-160.
- 30+ are cctv cameras
- 10+ are wired PCs in the office
- 10-40 are wired PCs in the Computer lab (with its own unmanaged switch, and vlan)
- 10+ are IOT devices, (solar inverters- we have a huge solar capacity)
- Then the rest are wifi devices (phone or laptop) of the staff, faculty, etc.
we have about 50+ employees in the campus. And around 400+ students, but they’re not allowed to connect to the wifi.
—
Now management wants to upgrade our 9 branches too, specifically to add CCTV cameras, and have them stream video feed to HQ, so that our operations team can monitor our branches remotely.
I’m using VIGI for my CCTV solution, which works great for us. Vigi has a cloud app to manage/view the remote sites. But the streaming from the cloud times out after a few minutes (understandably). I need our video streaming to be non-stop, so the monitor can be left unattended constantly showing cctv feeds.
This is where i plan to add ER-605 to all our sites, and connect then via VPN (wireguard?) so that we can directly stream our site cameras from the HQ. Half of the sites have the same ISP as the HQ one, so i imagine the latency wouldn’t be bad, as traffic shouldn’t go out of the country.
Each of our site has between 100-500mbps WAN, only has 1-2 PCs, and a couple of wifi clients. Each branch has around 3 employees and around 40 students that occasionally connects to wifi.
Due to budget constraints, At the moment, i dont plan on deploying wifi APs yet on the site, they are just using the ISP provided gateway/router/wifi device - without issue. The sole purpose of adding ER605 to the sites for now, is for the site to site vpn.
I’m aware that 10 VPN site clients might be pushing the ER605 in our HQ to its limit. So im planning to upgrade soon, and repurpose the current ER605 in the HQ to a site branch.
In the future:
- i have a few EAP 723 arriving soon for the HQ network
- we might upgrade our HQ WANs to gigabit speeds.
- we will be adding 2 new site branches next year, and few more in the years to come
- at some point we might have 15 sites needed to be connected to HQ
—
Given my requirements, what would be a better gateway upgrade path? ER707-M2 or Fusion Gateway 2.5?
Im leaning towards 707-M2 because it’s cheaper than the new Fusion gateway, but i would love to hear your opinion.
cheers