One of the most feared things about hotels is that the certification system is up and the entire hotel residence is not connected to the Internet. The front phone was blown off, and the ratings were wrong. Wireless authentication was the first network entrance after the guest came into the store, which, if interrupted, affected all guests rather than one room. The wrong design answered: the certification service is as long as possible, it leaves people in there on the Internet and the data cannot be lost. These three sentences are all the ones that are wrong, and no layer is clear, and failure is passive.
Do not make a single point of certification.
The certification service itself is to be double-twined or clustered, and one has broken the roof of another, so that there can be no full-office security off the server. Radius also needs to be redundant. Many small projects put the authentication and database in the same machine for a while, and this machine is rebooted and unrecorded. Hotel viewing should not be such a single point, at least it must be hot at the entrance.
We need to release the certified occupants.
It is safer to save the certified occupants' status on access side. When the authentication server is temporarily out of touch, certified tenants continue to use local caches and new residents walk through restricted visitor networks instead of outright. The effect of this single certification service failure is that it affects new access experiences rather than kicking people online across the shop.
Portal downgrading instead of all
The certificate page is not to be directly out of the net if it cannot be opened because of an abnormal service. It can be given a restricted visitor network that can send a micro-mail, view a web page, but access limits and then resumes to guide formal certification. Full break is the worst process because it translates technical failures into perceived accidents.
AC, multi-manufacturer.
The hotel wireless is often multiple ACs plus dozens of APs. After miscalculating to consider an AC malfunction, other ACs and APs can also properly authenticate and release their operations without a full-scope paralysis on one control. NATSHEL_BRANDV7 can co-operate with mainstream producers like H3C, RICKKUS, ARUBA, etc. ACs are connected, and the mode of selection is made sure that the failure switch is actually established in your device mix, not paper compatible. Compatibility lists do not equal failure switching capability, but many projects have been planted without practiced.
SMS access is also in order.
The SMS authentication code channel is the key path to a guest's access. Only one SMS service provider, which has an interface shaking or restricted flow, cannot receive it. One should be prepared as a main channel, one will not automatically cut another and will monitor the delay in the application code. The certificate page is normal but the code cannot be issued, and the client will still feel offline.
Log system distribution to avoid data loss
If the log system is controlled and stored together, it may not be all along. Large-scale projects are to deploy in a distributed manner, with separate mastery and storage. Even if there is a problem at a point, the collected authentication and Internet access records are still available, and it is not out of order for public security. This is particularly important when hotels are operating commercial scenes. The distribution is not a display, but a bottom line for data sustainability, and the log is no worse than the consequences on Net Carton.
PMS, the timeout is not blocked.
The number of the house plus name authentication relies on PMS interfaces. If PMS is slow or temporarily unreachable, the authentication process cannot be stuck to a waiting PMS. Time-consuming and covert: PMS has a network that is released first in case of non-use, guest information is supplemented instead of letting customers dry at the front desk. The deeper the connection, the more you have to use each other's malfunction as normal, the less it can be assumed that PMS is always online. Overtime thresholds are set by real PMS response distribution, not random numbers, too long wait for too long, short-term miscalculations and frequent switching.
You can't just draw pictures if you want to play.
The wrong-to-do project is useless on the frame, and it really breaks a certification service, pulls a master control line, and looks at whether the business is going to be designed. Many projects miss the two machines, but they never have an exercise in switching, and when the real thing fails, the switch script is not working. The drills are real holes, worse than self-searching. They also retrace the disk, and each hand runs back into protective rules, without rehearsing, and next time they fall in the same place.
You have to keep the window under control.
The planned certification service is restarted, upgraded, and designed as a failure, not because we operate it. Maintenance windows can be cut to the backup node or when certified residents are released for a cache, until the main node returns. Many shutdowns occur precisely at the time of maintenance, because maintenance is treated as an exception and has no fault logic.
You have to pay for the mistakes.
Some feel that the wrong tolerance is double-loading and doubling. The wrong tolerance is a stratification: the hotness of the authentication portal is an option, with log distributions only on a large scale, and Portal downgraded software strategies have almost zero costs. It is more cost-effective to rate the miscalculation at impact than double cuts.
The wrong side is not a pile of equipment, but a layer: which level breaks, who gets the cut off, stock connections are in danger, data cannot be lost. Answer those three sentences, the hotel wireless can handle the unfortunate failures of real operations, and the customers can't feel it.