Sunday, July 12, 2009

Locating a Wireless LAN

When you install, configure, and finally start up a wireless LAN client device such as a USB client or PCMCIA card, the client will automatically “listen" to see if there is a wireless LAN within range. The client is also discovering if it can associate with that wireless LAN. This process of listening is called scanning. Scanning occurs before any other process, since scanning is how the client finds the network.

There are two kinds of scanning: passive scanning and active scanning. In finding an access point, client stations follow a trail of breadcrumbs left by the access point. These breadcrumbs are called service set identifiers (SSID) and beacons. These tools serve as a means for a client station to find any and all access points.


Service Set Identifier

The service set identifier (SSID) is a unique, case sensitive, alphanumeric value from 2- 32 characters long used by wireless LANs as a network name. This naming handle is used for segmenting networks, as a rudimentary security measure, and in the process of joining a network. The SSID value is sent in beacons, probe requests, probe responses, and other types of frames. A client station must be configured for the correct SSID in order to join a network. The administrator configures the SSID (sometimes called the ESSID) in each access point. Some stations have the ability to use any SSID value instead of only one manually specified by the administrator. If clients are to roam seamlessly among a group of access points, the clients and all access points must be configured with matching SSIDs. The most important point about an SSID is that it must match EXACTLY between access points and clients.


Beacons

Beacons (short for beacon management frame) are short frames that are sent from the access point to stations (infrastructure mode) or station-to-station (ad hoc mode) in order to organize and synchronize wireless communication on the wireless LAN.


Passive Scanning


Passive scanning is the process of listening for beacons on each channel for a specific period of time after the station is initialized. These beacons are sent by access points (infrastructure mode) or client stations (ad hoc mode), and the scanning station catalogs characteristics about the access points or stations based on these beacons. The station searching for a network listens for beacons until it hears a beacon listing the SSID of the network it wishes to join. The station then attempts to join the network through the access point that sent the beacon. Passive scanning is illustrated in Figure 7.1. In configurations where there are multiple access points, the SSID of the network the station wishes to join may be broadcast by more than one of these access points. In this situation, the station will attempt to join the network through the access point with the strongest signal strength and the lowest bit error rate.

Stations continue passive scanning even after associating to an access point. Passive scanning saves time reconnecting to the network if the client is disconnected (disassociated) from the access point to which the client is currently connected. By maintaining a list of available access points and their characteristics (channel, signal strength, SSID, etc), the station can quickly locate the best access point should its current connection be broken for any reason.

Stations will roam from one access point to another after the radio signal from the access point where the station is connected gets to a certain low level of signal strength. Roaming is implemented so that the station can stay connected to the network. Stations use the information obtained through passive scanning for locating the next best access point (or ad hoc network) to use for connectivity back into the network. For this reason, overlap between access point cells is usually specified at approximately 20-30%. This overlap allows stations to seamlessly roam between access points while disconnecting and reconnecting without the user’s knowledge.


Active Scanning


Stations send this probe frame when they are actively seeking a network to join. The probe frame will contain either the SSID of the network they wish to join or a broadcast SSID. If a probe request is sent specifying an SSID, then only access points that are servicing that SSID will respond with a probe response frame. If a probe request frame is sent with a broadcast SSID, then all access points within reach will respond with a probe response frame, as can be seen in Figure 7.2.

The point of probing in this manner is to locate access points through which the station can attach to the network. Once an access point with the proper SSID is found, the station initiates the authentication and association steps of joining the network through that access point.

The information passed from the access point to the station in probe response frames is almost identical to that of beacons. Probe response frames differ from beacons only in that they are not time-stamped and they do not include a Traffic Indication Map (TIM).

The signal strength of the probe response frames that the PC Card receives back helps determine the access point with which the PC card will attempt to associate. The station generally chooses the access point with the strongest signal strength and lowest bit error rate (BER). The BER is a ratio of corrupted packets to good packets typically determined by the Signal-to-Noise Ratio of the signal. If the peak of an RF signal is somewhere near the noise floor, the receiver may confuse the data signal with noise.

Sunday, July 5, 2009

IEEE standards

The Institute of Electrical and Electronics Engineers (IEEE) is the key standards maker for most things related to information technology in the United States. The IEEE creates its standards within the laws created by the FCC. The IEEE specifies many technology standards such as Public Key Cryptography (IEEE 1363), FireWire (IEEE 1394), Ethernet (IEEE 802.3), and Wireless LANs (IEEE 802.11).

It is part of the mission of the IEEE to develop standards for wireless LAN operation within the framework of the FCC rules and regulations. Following are the four main IEEE standards for wireless LANs that are either in use or in draft form:
  • 802.11
  • 802.11b
  • 802.11a
  • 802.11g

IEEE 802.11

The 802.11 standard was the first standard describing the operation of wireless LANs. This standard contained all of the available transmission technologies including Direct Sequence Spread Spectrum (DSSS), Frequency Hopping Spread Spectrum (FHSS), and infrared.

The IEEE 802.11 standard describes DSSS systems that operate at 1 Mbps and 2 Mbps only. If a DSSS system operates at other data rates as well, such as 1 Mbps, 2 Mbps, and 11 Mbps, then it can still be an 802.11-compliant system. If, however, the system is operating at any rate other than 1 or 2 Mbps, then, even though the system is 802.11- compliant because of its ability to work at 1 & 2 Mbps, it is not operating in an 802.11- compliant mode and cannot be expected to communicate with other 802.11-compliant devices.

IEEE 802.11 is one of two standards that describe the operation of frequency hopping wireless LAN systems. If a wireless LAN administrator encounters a frequency hopping system, then it is likely to be either an 802.11-compliant or OpenAir compliant system (discussed below). The 802.11 standard describes use of FHSS systems at 1 and 2 Mbps. There are many FHSS systems on the market that extend this functionality by offering proprietary modes that operate at 3-10 Mbps, but just as with DSSS, if the system is operating at speeds other than 1 & 2 Mbps, it cannot be expected to automatically communicate with other 802.11-compliant devices.

802.11 compliant products operate strictly in the 2.4 GHz ISM band between 2.4000 and 2.4835 GHz. Infrared, also covered by 802.11, is light-based technology and does not fall into the 2.4 GHz ISM band.


IEEE 802.11b

Though the 802.11 standard was successful in allowing DSSS as well as FHSS systems to interoperate, the technology has outgrown the standard. Soon after the approval and implementation of 802.11, DSSS wireless LANs were exchanging data at up to 11 Mbps. But, without a standard to guide the operation of such devices, there came to be problems with interoperability and implementation. The manufacturers ironed out most of the implementation problems, so the job of IEEE was relatively easy: create a standard that complied with the general operation of wireless LANs then on the market. It is not uncommon for the standards to follow the technology in this way, particularly when the technology evolves quickly.

IEEE 802.11b, referred to as "High-Rate" and Wi-Fi™, specifies direct sequencing (DSSS) systems that operate at 1, 2, 5.5 and 11 Mbps. The 802.11b standard does not describe any FHSS systems, and 802.11b-compliant devices are also 802.11-compliant by default, meaning they are backward compatible and support both 2 and 1 Mbps data rates. Backward compatibility is very important because it allows a wireless LAN to be upgraded without the cost of replacing the core hardware. This low-cost feature, together with the high data rate, has made the 802.11b-compliant hardware very popular.

The high data rate of 802.11b-compliant devices is the result of using a different coding technique. Though the system is still a direct sequencing system, the way the chips are coded (CCK rather than Barker Code) along with the way the information is modulated (QPSK at 2, 5.5, & 11 Mbps and BPSK at 1 Mbps) allows for a greater amount of data to be transferred in the same time frame. 802.11b compliant products operate only in the 2.4 GHz ISM band between 2.4000 and 2.4835 GHz.


IEEE 802.11a

The IEEE 802.11a standard describes wireless LAN device operation in the 5 GHz UNII bands. Operation in the UNII bands automatically makes 802.11a devices incompatible with all other devices complying with the other 802.11 series of standards. The reason for this incompatibility is simple: systems using 5 GHz frequencies will not communicate with systems using 2.4 GHz frequencies.

Using the UNII bands, most devices are able to achieve data rates of 6, 9, 12, 18, 24, 36, 48, and 54 Mbps. Some of the devices employing the UNII bands have achieved data rates of 108 Mbps by using proprietary technology, such as rate doubling. The highest rates of some of these devices are the result of newer technologies not specified by the 802.11a standard. IEEE 802.11a specifies data rates of only 6, 12, and 24 Mbps. A wireless LAN device must support at least these data rates in the UNII bands in order to be 802.11a-compliant. The maximum data rate specified by the 802.11a standard is 54 Mbps.


IEEE 802.11g

802.11g provides the same maximum speed of 802.11a, coupled with backwards compatibility for 802.11b devices. This backwards compatibility will make upgrading wireless LANs simple and inexpensive. Since 802.11g technology is new, 802.11g devices are not yet available as of this writing.

IEEE 802.11g specifies operation in the 2.4 GHz ISM band. To achieve the higher data rates found in 802.11a, 802.11g compliant devices utilize Orthogonal Frequency Division Multiplexing (OFDM) modulation technology. These devices can automatically switch to QPSK modulation in order to communicate with the slower 802.11b- and 802.11- compatable devices. With all of the apparent advantages, 802.11g’s use of the crowded 2.4 GHz band could prove to be a disadvantage.

Sunday, June 21, 2009

RF Splitters

An RF Splitter is a device that has a single input connector and multiple output connectors. An RF Splitter is used for the purpose of splitting a single signal into multiple independent RF signals. Use of splitters in everyday implementations of wireless LANs is not recommended. Sometimes two 120-degree panel antennas or two 90-degree panel antennas may be combined with a splitter and equal-length cables when the antennas are pointing in opposite directions. This configuration will produce a bidirectional coverage area, which may be ideal for covering the area along a river or major highway. Back-to-back 90 degree panels may be separated by as little as 10 inches or as much as 40 inches on either side of the mast or tower. Each panel in this configuration may have a mechanical down tilt. The resultant gain in each of the main radiation lobes is reduced by 3 - 4 dB in these configurations.

When installing an RF splitter, the input connector should always face the source of the RF signal. The output connectors (sometimes called "taps") are connected facing the destination of the RF signal (the antenna). Figure 5.26 shows two examples of RF splitters. Figure 5.27 illustrates how an RF splitter would be used in a wireless LAN installation.

Splitters may be used to keep track of power output on a wireless LAN link. By hooking a power meter to one output of the splitter and the RF antenna to the other, an administrator can actively monitor the output at any given time. In this scenario, the power meter, the antenna, and the splitter must all have equal impedance. Although not a common practice, removing the power meter from one output of the splitter and replacing it with a 50 ohm dummy load would allow the administrator to move the power meter from one connection point to another throughout the wireless LAN while making output power measurements.


RF Connectors

RF connectors are specific types of connection devices used to connect cables to devices or devices to devices. Traditionally, N, F, SMA, BNC, & TNC connectors (or derivatives) have been used for RF connectors on wireless LANs.

In 1994, the FCC & DOC (Canadian Department of Communications) ruled that connectors for use with wireless LAN devices should be proprietary between manufacturers. For this reason, many variations on each connector type exist such as:
  • N-type
  • Reverse polarity N-type
  • Reverse threaded N-type

Choosing an RF Connector

There are five things that should be considered when purchasing and installing any RF
connector, and they are similar in nature to the criteria for choosing RF amplifiers and
attenuators.
  1. The RF connector should match the impedance of all other wireless LAN components (generally 50 ohms).
  2. Know how much insertion loss each connector inserted into the signal path causes. The amount of loss caused will factor into your calculations for signal strength required and distance allowed.
  3. Know the upper frequency limit (frequency response) specified for the particular connectors. This point will be very important as 5 Ghz wireless LANs become more and more common. Some connectors are rated only as high as 3 GHz, which is fine for use with 2.4 GHz wireless LANs, but will not work for 5 GHz wireless LANs. Some connectors are rated only up to 1 GHz and will not work with wireless LANs at all, other than legacy 900 MHz wireless LANs.
  4. Beware of bad quality connectors. First, always consider purchasing from a reputable company. Second, purchase only high-quality connectors made by name-brand manufacturers. This kind of purchasing particularity will help eliminate many problems with sporadic RF signals, VSWR, and bad connections.
  5. Make sure you know both the type of connector (N, F, SMA, etc.) that you need and the sex of the connector. Connectors come in male and female. Male connectors have a center pin, and female connectors have a center receptacle.

Sunday, June 14, 2009

Wireless LAN Accessories

When the time comes to connect all of your wireless LAN devices together, you will need to purchase the appropriate cables and accessories that will maximize your throughput, minimize your signal loss, and, most importantly, allow you to make the connections correctly. This section will discuss the different types of accessories and where they fit into a wireless LAN design. The following types of accessories are discussed in this section:
  • RF Amplifiers
  • RF Attenuators
  • Lightning Arrestors
  • RF Connectors
  • RF Cables
  • RF Splitters

Each of these devices is important to building a successful wireless LAN. Some items are used more than others, and some items are mandatory whereas others are optional. It is likely that an administrator will have to install and use all of these items multiple times while implementing and managing a wireless LAN.


RF Amplifiers

As its name suggests, an RF amplifier is used to amplify, or increase the amplitude of, an RF signal, which is measured in +dB. An amplifier will be used when compensating for the loss incurred by the RF signal, either due to the distance between antennas or the length of cable from a wireless infrastructure device to its antenna. Most RF amplifiers used with wireless LANs are powered using DC voltage fed onto the RF cable with a DC injector near the RF signal source (such as the access point or bridge).

Sometimes this DC voltage used to power RF amplifiers is called "phantom voltage" because the RF amplifier seems to magically power up. This DC injector is powered using AC voltage from a wall outlet, so it might be located in a wiring closet. In this scenario, the RF cable carries both the high frequency RF signal and the DC voltage necessary to power the in-line amplifier, which, in turn, boosts the RF signal amplitude. Figure 5.20 shows an example of an RF amplifier (left), and how an RF amplifier is mounted on a pole (right) between the access point and its antenna.

RF amplifiers come in two types: unidirectional and bi-directional. Unidirectional amplifiers compensate for the signal loss incurred over long RF cables by increasing the signal level before it is injected into the transmitting antenna. Bi-directional amplifiers boost the effective sensitivity of the receiving antenna by amplifying the received signal before it is fed into the access point, bridge, or client device.


RF Attenuators


An RF attenuator is a device that causes precisely measured loss (in –dB) in an RF signal. While an amplifier will increase the RF signal, an attenuator will decrease it. Why would you need or want to decrease your RF signal? Consider the case where an access point has a fixed output of 100mW, and the only antenna available is an omni-directional antenna with +20 dBi gain. Using this equipment together would violate FCC rules for power output, so an attenuator could be added to decrease the RF signal down to 30mW before it entered the antenna. This configuration would put the power output within FCC parameters. Figure 5.22 shows examples of fixed-loss RF attenuators with BNC connectors (left) and SMA connectors (right). Figure 5.23 shows an example of an RF step attenuator.

Sunday, June 7, 2009

Power over Ethernet (PoE) Devices

Power over Ethernet (PoE) is a method of delivering DC voltage to an access point, wireless bridge, or wireless workgroup bridge over the Cat5 Ethernet cable for the purpose of powering the unit. PoE is used when AC power receptacles are not available where wireless LAN infrastructure devices are to be installed. The Ethernet cable is used to carry both the power and the data to the units.

Consider a warehouse where the access points need to be installed in the ceiling of the building. The labor costs that would be incurred to install electrical outlets throughout the ceiling of the building to power the access points would be considerable. Hiring an electrician to do this type of work would be very expensive and time consuming. Remember that Ethernet cables can only carry data reliably for 100 meters and, for any distance more than 100 meters, PoE is not a viable solution. The following figure illustrates how a PoE device would provide power to an access point.


Common PoE Options
PoE devices are available in several types.
  • Single-port DC voltage injectors
  • Multi-port DC voltage injectors
  • Ethernet switches designed to inject DC voltage on each port on a given pair of pins

Single-port DC Voltage Injectors

Access points and bridges that specify mandatory use of PoE include single-port DC voltage injectors for the purpose of powering the unit. See Figure 5.17 below for an example of a single-port DC voltage injector. These single-port injectors are acceptable when used with a small number of wireless infrastructure devices, but quickly become a burden, cluttering wiring closets, when building medium or large wireless networks.


Multi-port DC Voltage Injectors

Several manufacturers offer multi-port injectors including 4, 6, or 12-port models. These models may be more economical or convenient for installations where many devices are to be powered through the Cat5 cable originating in a single wiring closet or from a single switch. Multi-port DC voltage injectors typically operate in exactly the same manner as their single-port counterparts. See Figure 5.18 for an example of a multi-port PoE injector. A multi-port DC voltage injector looks like an Ethernet switch with twice as many ports. A multi-port DC voltage injector is a pass-through device to which you connect the Ethernet switch (or hub) to the input port, and then connect the PoE client device to the output device, both via Cat5 cable. The PoE injector connects to an AC power source in the wiring closet. These multi-port injectors are appropriate for mediumsized wireless network installations where up to 50 access points are required, but in large enterprise rollouts, even the most dense multi-port DC voltage injectors combined with Ethernet hubs or switches can become cluttered when installed in a wiring closet.


Active Ethernet Switches

The next step up for large enterprise installations of access points is the implementation of active Ethernet switches. These devices incorporate DC voltage injection into the Ethernet switch itself allowing for large numbers of PoE devices without any additional hardware in the network. See Figure 5.19 for an example of an Active Ethernet switch. Wiring closets will not have any additional hardware other than the Ethernet switches that would already be there for a non-PoE network. Several manufacturers make these switches in many different configurations (number of ports). In many Active Ethernet switches, the switch can auto-sense PoE client devices on the network. If the switch does not detect a PoE device on the line, the DC voltage is switched off for that port. As you can see from the picture, an Active Ethernet switch looks no different from an ordinary Ethernet switch. The only difference is the added internal functionality of supplying DC voltage to each port.

Monday, June 1, 2009

RF Antenna Concepts

There are several concepts that are essential knowledge when implementing solutions that require RF antennas. Among those that will be described are:
  • Polarization
  • Gain
  • Beamwidth
  • Free Space Path Loss
The above list is by no means a comprehensive list of all RF antenna concepts, but rather a set of must-have fundamentals that allow an administrator to understand how wireless LAN equipment functions over the wireless medium. A solid understanding of basic antenna functionality is the key to moving forward in learning more advanced RF concepts.

Knowing where to place antennas, how to position them, how much power they are radiating, the distance that radiated power is likely to travel, and how much of that power can be picked up by receivers is, many times, the most complex part of an administrator's job.


Polarization
A radio wave is actually made of up two fields, one electric and one magnetic. These two fields are on planes perpendicular to each other, as shown in the following figure.


The sum of the two fields is called the electro-magnetic field. Energy is transferred back and forth from one field to the other, in the process known as "oscillation." The plane that is parallel with the antenna element is referred to as the "E-plane" whereas the plane that is perpendicular to the antenna element is referred to as the "H-plane." We are interested primarily in the electric field since its position and direction with reference to the Earth's surface (the ground) determines wave polarization.

Polarization is the physical orientation of the antenna in a horizontal or vertical position. The electric field is parallel to the radiating elements (the antenna element is the metal part of the antenna that is doing the radiating) so, if the antenna is vertical, then the polarization is vertical.
  • Horizontal polarization - the electric field is parallel to the ground
  • Vertical polarization - the electric field is perpendicular to the ground
Vertical polarization, which is typically used in wireless LANs, is perpendicular to the Earth’s plane. Notice the dual antennas sticking up vertically from most any access point - these antennas are vertically polarized in that position. Horizontal polarization is parallel to the Earth. In the foolowing figure illustrates the effects polarization can have when antennas are not aligned correctly. Antennas that are not polarized in the same way are not able to communicate with each other effectively.


Gain
Antenna gain is specified in dBi, which means decibels referenced to an isotropic radiator. An isotropic radiator is a sphere that radiates power equally in all directions simultaneously. We haven't the ability to make an isotropic radiator, but instead we can make omni-directional antennas such as a dipole that radiates power in a 360-degree horizontal fashion, but not 360 degrees vertically. RF signal radiation in this fashion gives us a doughnut pattern. The more we horizontally squeeze this doughnut, the flatter it becomes, forming more of a pancake shape when the gain is very high. Antennas have passive gain, which means they do not increase the power that is input into them, but rather shape the radiation field to lengthen or shorten the distance the propagated wave will travel. The higher the antenna gain, the farther the wave will travel, concentrating its output wave more tightly so that more of the power is delivered to the destination (the receiving antenna) at long distances. As was shown in the figure, the coverage has been squeezed vertically so that the coverage pattern is elongated, reaching further.


Beamwidth
As we've discussed previously, narrowing, or focusing antenna beams increases the antenna’s gain (measured in dBi). An antenna’s beamwidth means just what it sounds like: the “width” of the RF signal beam that the antenna transmits. The following figure illustrates the term
beamwidth.

There are two vectors to consider when discussing an antenna’s beamwidths: the vertical and the horizontal. The vertical beamwidth is measure in degrees and is perpendicular to the Earth's surface. The horizontal beamwidth is measured in degrees and is parallel to the Earth's surface. Beamwidth is important for you to know because each type of antenna has different beamwidth specifications. The chart below can be used as a quick reference guide for beamwidths.


Free Space Path Loss
Free Space Path Loss (or just Path Loss) refers to the loss incurred by an RF signal due largely to "signal dispersion" which is a natural broadening of the wave front. The wider the wave front, the less power can be induced into the receiving antenna. As the transmitted signal traverses the atmosphere, its power level decreases at a rate inversely proportional to the distance traveled and proportional to the wavelength of the signal. The power level becomes a very important factor when considering link viability.
The Path Loss equation is one of the foundations of link budget calculations. Path Loss represents the single greatest source of loss in a wireless system. Below is the formula
for Path Loss.

Sunday, May 24, 2009

Highly-directional Antennas

As their name would suggest, highly-directional antennas emit the most narrow signal beam of any antenna type and have the greatest gain of these three groups of antennas. Highly-directional antennas are typically concave, dish-shaped devices, as can be seen in Figures 5.10 and 5.11. These antennas are ideal for long distance, point-to-point wireless links. Some models are referred to as parabolic dishes because they resemble small satellite dishes. Others are called grid antennas due to their perforated design for resistance to wind loading.




Usage
High-gain antennas do not have a coverage area that client devices can use. These antennas are used for point-to-point communication links, and can transmit at distances up to 25 miles. Potential uses of highly directional antennas might be to connect two buildings that are miles away from each other but have no obstructions in their path. Additionally, these antennas can be aimed directly at each other within a building in order to "blast" through an obstruction. This setup would be used in order to get network connectivity to places that cannot be wired and where normal wireless networks will not work.

Monday, May 18, 2009

Semi-Directional Antennas

Semi-directional antennas come in many different styles and shapes. Some semidirectional antennas types frequently used with wireless LANs are Patch, Panel, and Yagi (pronounced “YAH-gee”) antennas. All of these antennas are generally flat and designed for wall mounting. Each type has different coverage characteristics. Figure 5.7 shows some examples of semi-directional antennas.


These antennas direct the energy from the transmitter significantly more in one particular direction rather than the uniform, circular pattern that is common with the omnidirectional antenna. Semi-directional antennas often radiate in a hemispherical or cylindrical coverage pattern as can be seen in Figure 5.8.


Usage
Semi-directional antennas are ideally suited for short and medium range bridging. For
example, two office buildings that are across the street from one another and need to
share a network connection would be a good scenario in which to implement semidirectional antennas. In a large indoor space, if the transmitter must be located in the corner or at the end of a building, a corridor, or a large room, a semi-directional antenna would be a good choice to provide the proper coverage. Figure 5.9 illustrates a link between two buildings using semi-directional antennas.


Many times, during an indoor site survey, engineers will constantly be thinking of how to best locate omni-directional antennas. In some cases, semi-directional antennas provide such long-range coverage that they may eliminate the need for multiple access points in a building. For example, in a long hallway, several access points with omni antennas may be used or perhaps only one or two access points with properly placed semi-directional antennas - saving the customer a significant amount of money. In some cases, semidirectional antennas have back and side lobes that, if used effectively, may further reduce the need for additional access points.

Monday, May 11, 2009

RF Antennas

An RF antenna is a device used to convert high frequency (RF) signals on a transmission line (a cable or waveguide) into propagated waves in the air. The electrical fields emitted from antennas are called beams or lobes. There are three generic categories of RF antennas:
  • Omni-directional
  • Semi-directional
  • Highly-directional
Each category has multiple types of antennas, each having different RF characteristics and appropriate uses. As the gain of an antenna goes up, the coverage area narrows so that high-gain antennas offer longer coverage areas than low-gain antennas at the same input power level. There are many types of antenna mounts, each suited to fit a particular need. After studying this section, you will understand which antenna and mount best meets your needs and why.

Omni-directional (Dipole) Antennas

The most common wireless LAN antenna is the Dipole antenna. Simple to design, the dipole antenna is standard equipment on most access points. The dipole is an omnidirectional antenna, because it radiates its energy equally in all directions around its axis. Directional antennas concentrate their energy into a cone, known as a "beam." The dipole has a radiating element just one inch long that performs an equivalent function to the "rabbit ears" antennas on television sets. The dipole antennas used with wireless LANs are much smaller because wireless LAN frequencies are in the 2.4 GHz microwave spectrum instead of the 100 MHz TV spectrum. As the frequency gets higher, the wavelength and the antennas become smaller.

Figure 5.1 shows that the dipole's radiant energy is concentrated into a region that looks like a doughnut, with the dipole vertically through the "hole" of the "doughnut." The signal from an omni-directional antenna radiates in a 360-degree horizontal beam. If an antenna radiates in all directions equally (forming a sphere), it is called an isotropic radiator. The sun is a good example of an isotropic radiator. We cannot make an isotropic radiator, which is the theoretical reference for antennas, but rather, practical antennas all have some type of gain over that of an isotropic radiator. The higher the gain, the more we horizontally squeeze our doughnut until it starts looking like a pancake, as is the case with very high gain antennas.

The dipole radiates equally in all directions around its axis, but does not radiate along the length of the wire itself - hence the doughnut pattern. Notice the side view of a dipole radiator as it radiates waves in Figure 5.2. This figure also illustrates that dipole antennas form a "figure 8" in their radiation pattern if viewed standing beside a perpendicular antenna.

If a dipole antenna is placed in the center of a single floor of a multistory building, most of its energy will be radiated along the length of that floor, with some significant fraction sent to the floors above and below the access point. Figure 5.3 shows examples of some different types of omni-directional antennas. Figure 5.4 shows a two-dimensional example of the top view and side view of a dipole antenna.


High-gain omni-directional antennas offer more horizontal coverage area, but the vertical coverage area is reduced, as can be seen in Figure 5.5. This characteristic can be an important consideration when mounting a high-gain omni antenna indoors on the ceiling. If the ceiling is too high, the coverage area may not reach the floor, where the users are located.

Usage
Omni-directional antennas are used when coverage in all directions around the horizontal axis of the antenna is required. Omni-directional antennas are most effective where large coverage areas are needed around a central point. For example, placing an omnidirectional antenna in the middle of a large, open room would provide good coverage. Omni-directional antennas are commonly used for point-to-multipoint designs with a hub-n-spoke topology (See Figure 5.6). Used outdoors, an omni-directional antenna should be placed on top of a structure (such as a building) in the middle of the coverage area. For example, on a college campus the antenna might be placed in the center of the campus for the greatest coverage area. When used indoors, the antenna should be placed in the middle of the building or desired coverage area, near the ceiling, for optimum coverage. Omni-directional antennas emit a large coverage area in a circular pattern and are suitable for warehouses or tradeshows where coverage is usually from one corner of the building to the other.

Sunday, May 3, 2009

Enterprise Wireless Gateways

An enterprise wireless gateway is a device that can provide specialized authentication and connectivity for wireless clients. Enterprise wireless gateways are appropriate for large-scale wireless LAN environments providing a multitude of manageable wireless LAN services such as rate limiting, Quality of Service (QoS), and profile management.

It is important that an enterprise wireless gateway device needs to have a powerful CPU and fast Ethernet interfaces because it may be supporting many access points, all of which send traffic to and through the enterprise wireless gateway. Enterprise wireless gateway units usually support a variety of WLAN and WPAN technologies such as 802.11 standard devices, Bluetooth, HomeRF, and more. Enterprise wireless gateways support SNMP and allow enterprise-wide simultaneous upgrades of user profiles. These devices can be configured for hot fail-over (when installed in pairs), support of RADIUS, LDAP, Windows NT authentication databases, and data encryption using Industry standard VPN tunnel types. Figure 4.18 shows an example of an enterprise wireless gateway, while Figure 4.19 illustrates where it is used on a wireless LAN.


Authentication technologies incorporated into enterprise wireless gateways are often built into the more advanced levels of access points. For example, VPN and 802.1x/EAP connectivity are supported in many brands of enterprise level access points.

Enterprise wireless gateways do have features, such as Role-Based Access Control
(RBAC), that are not found in any access points. RBAC allows an administrator to assign a certain level of wireless network access to a particular job position in the company. If the person doing that job is replaced, the new person automatically gains the same network rights as the replaced person. Having the ability to limit a wireless user's access to corporate resources, as part of the "role", can be a useful security feature.

Class of service is typically supported, and an administrator can assign levels of service to a particular user or role. For example, a guest account might be able to use only 500 kbps on the wireless network whereas an administrator might be allowed 2 Mbps connectivity.

In some cases, Mobile IP is supported by the enterprise wireless gateway, allowing a user to roam across a layer 3 boundary. User roaming may even be defined as part of an enterprise wireless gateway policy, allowing the user to roam only where the administrator allows. Some enterprise wireless gateways support packet queuing and prioritization, user tracking, and even time/date controls to specify when users may access the wireless network.


MAC spoofing prevention and complete session logging are also supported and aid greatly in securing the wireless LAN. There are many more features that vary significantly between manufacturers. Enterprise wireless gateways are so comprehensive that we highly recommend that the administrator take the manufacturer's training class before making a purchase so that the deployment of the enterprise wireless gateway will go more smoothly.

Consultants finding themselves in a situation of having to provide a security solution for a wireless LAN deployment with many access points that do not support advanced security features might find enterprise wireless gateways to be a good solution. Enterprise wireless gateways are expensive, but considering the number of management and security solutions they provide, usually worth the expense.


Configuration and Management
Enterprise wireless gateways are installed in the main the data path on the wired LAN segment just past the access point(s) as seen in Figure 4.19. Enterprise wireless gateways are configured through console ports (using CLI), telnet, internal HTTP or HTTPS servers, etc. Centralized management of only a few devices is one big advantage of using enterprise wireless gateways. An administrator, from a single console, can easily manage a large wireless deployment using only a few central devices instead of a very large number of access points.

Enterprise wireless gateways are normally upgraded through use of TFTP in the same fashion as many switches and routers on the market today. Configuration backups can often be automated so that the administrator won't have to spend additional management time backing up or recovering from lost configuration files. Enterprise wireless gateways are mostly manufactured as rack-mountable 1U or 2U devices that can fit into your existing data center design.