Monday, August 24, 2009

Roaming

Roaming is the process or ability of a wireless client to move seamlessly from one cell (or BSS) to another without losing network connectivity. Access points hand the client off from one to another in a way that is invisible to the client, ensuring unbroken connectivity. Figure 7.12 illustrates a client roaming from one BSS to another BSS. When any area in the building is within reception range of more than one access point, the cells’ coverage overlaps. Overlapping coverage areas are an important attribute of the wireless LAN setup, because it enables seamless roaming between overlapping cells. Roaming allows mobile users with portable stations to move freely between overlapping cells, constantly maintaining their network connection.


When roaming is seamless, a work session can be maintained while moving from one cell to another. Multiple access points can provide wireless roaming coverage for an entire building or campus.

When the coverage area of two or more access points overlap, the stations in the overlapping area can establish the best possible connection with one of the access points while continuously searching for the best access point. In order to minimize packet loss during switchover, the “old” and “new” access points communicate to coordinate the roaming process. This function is similar to a cellular phones’ handover, with two main differences:
  • On a packet-based LAN system, the transition from cell to cell may be performed between packet transmissions, as opposed to telephony where the transition may occur during a phone conversation.
  • On a voice system, a temporary disconnection may not affect the conversation, while in a packet-based environment it significantly reduces performance because the upper layer protocols then retransmit the data.

Standards

The 802.11 standard does not define how roaming should be performed, but does define the basic building blocks. These building blocks include active & passive scanning and a reassociation process. The reassociation process occurs when a wireless station roams from one access point to another, becoming associated with the new access point.

The 802.11 standard allows a client to roam among multiple access points operating on the same or separate channels. For example, every 100 ms, an access point might transmit a beacon signal that includes a time stamp for client synchronization, a traffic indication map, an indication of supported data rates, and other parameters. Roaming clients use the beacon to gauge the strength of their existing connection to the access point. If the connection is weak, the roaming station can attempt to associate itself with a new access point.

To meet the needs of mobile radio communications, the 802.11b standard must be tolerant of connections being dropped and re-established. The standard attempts to ensure minimum disruption to data delivery, and provides some features for caching and forwarding messages between BSSs.

Particular implementations of some higher layer protocols such as TCP/IP may be less tolerant. For example, in a network where DHCP is used to assign IP addresses, a roaming node may lose its connection when it moves across cell boundaries. The node will then have to re-establish the connection when it enters the next BSS or cell. Software solutions are available to address this particular problem.

The 802.11b standard leaves much of the detailed functioning of what it calls the distribution system to manufacturers. This decision was a deliberate decision on the part of the standard designers, because they were most concerned with making the standard entirely independent of any other existing network standards. As a practical matter, an overwhelming majority of 802.11b wireless LANs using ESS topologies are connected to Ethernet LANs and make heavy use of TCP/IP. Wireless LAN vendors have stepped into the gap to offer proprietary methods of facilitating roaming between nodes in an ESS.


Connectivity

The 802.11 MAC layer is responsible for how a client associates with an access point. When an 802.11 client enters the range of one or more access points, the client chooses an access point to associate with (also called joining a BSS) based on signal strength and observed packet error rates.

Once associated with the access point, the station periodically surveys all 802.11 channels in order to assess whether a different access point would provide better performance characteristics. If the client determines that there is a stronger signal from a different access point, the client re-associates with the new access point, tuning to the radio channel to which that access point is set. The station will not attempt to roam until it drops below a manufacturer-defined signal strength threshold.


Reassociation

Reassociation usually occurs because the wireless station has physically moved away from the original access point, causing the signal to weaken. In other cases, reassociation occurs due to a change in radio characteristics in the building, or due simply to high network traffic on the original access point. In the latter case, this function is known as load balancing, since its primary function is to distribute the total wireless LAN load most efficiently across the available wireless infrastructure.

Association and reassociation differ only slightly in their use. Association request frames are used when joining a network for the first time. Reassociation request frames are used when roaming between access points so that the new access point knows to negotiate transfer of buffered frames from the old access point and to let the distribution system know that the client has moved. Reassociation is illustrated in Figure 7.13.


This process of dynamically associating and re-associating with access points allows network managers to set up wireless LANs with very broad coverage by creating a series of overlapping 802.11 cells throughout a building or across a campus. To be successful, the IT manager ideally will employ channel reuse, taking care to configure each access point on an 802.11 DSSS channel that does not overlap with a channel used by a neighboring access point. While there are 14 partially overlapping channels specified in 802.11 DSSS (11 channels can be used within the U.S.), there are only 3 channels that do not overlap at all, and these are the best to use for multi-cell coverage. If two access points are in range of one another and are set to the same or partially overlapping channels, they may cause some interference for one another, thus lowering the total available bandwidth in the area of overlap.


VPN Use

Wireless VPN solutions are typically implemented in two fashions. First, a centralized VPN server is implemented upstream from the access points. This VPN server could be a proprietary hardware solution or a server with a VPN application running on it. Both serve the same purpose and provide the same type of security and connectivity. Having this VPN server (also acting as a gateway and firewall) between the wireless user and the core network provides a level of security similar to wired VPNs.

The second approach is a distributed set of VPN servers. Some manufacturers implement a VPN server into their access points. This type of solution would provide security for small office and medium-sized organizations without use of an external authentication mechanism like RADIUS. For scalability, these same access point/VPN servers typically support RADIUS.

Tunnels are built from the client station to the VPN server, as illustrated in Figure 7.14. When a user roams, the client is roaming between access points across layer 2 boundaries. This process is seamless to the layer 3 connectivity. However, if a tunnel is built to the access point or centralized VPN server and a layer 3 boundary is crossed, a mechanism of some kind must be provided for keeping the tunnel alive when the boundary is crossed.


Layer 2 & 3 Boundaries

A constraint of existing technology is that wired networks are often segmented for manageability. Enterprises with multiple buildings, such as hospitals or large businesses, often implement a LAN in each building and then connect these LANs with routers or switch-routers. This is layer 3 segmentation has two major advantages. First, it contains broadcasts effectively, and second it allows access control between segments on the network. This type of segmentation can also be done at layer 2 using VLANs on switches. VLANs are often seen implemented floor-by-floor in multi-floor office buildings or for each remote building in a campus for the same reasons. Segmenting at layer 2 in this fashion segments the networks completely as if multiple networks were being implemented. When using routers such as seen in figure 7.15, users must have a method of roaming across router boundaries without losing their layer 3 connection. The layer 2 connection is still maintained by the access points, but since the IP subnet has changed while roaming, the connection to servers, for example, will be broken. Without subnet-roaming capability (such as with using a Mobile IP solution or using DHCP), wireless LAN access points must all be connected to a single subnet (a.k.a. "a flat network"). This work-around can be done at a loss of network management flexibility, but customers may be willing to incur this cost if they perceive that the value of the end system is high enough.



Many network environments (e.g., multi-building campuses, multi-floored high rises, or older or historical buildings) cannot embrace a single subnet solution as a practical option. This wired architecture is at odds with current wireless LAN technology. Access points can't hand off a session when a remote device moves across router boundaries because crossing routers changes the client device's IP address. The wired system no longer knows where to send the message. When a mobile device reattaches to the network, all application end points are lost and users are forced to log in again, reauthenticate, relocate themselves in their applications, and recreate lost data. The same type of problem is incurred when using VLANs. Switches see users as roaming across VLAN boundaries.


A hardware solution to this problem is to deploy all access points on a single VLAN using a flat IP subnet for all access points so that there is no change of IP address for roaming users and a Mobile IP solution isn't required. Users are then routed as a group back into the corporate network using a firewall, a router, a gateway device, etc. This solution can be difficult to implement in many instances, but is generally accepted as the "standard" methodology. There are many more instances where an enterprise must forego use of a wireless LAN altogether because such a solution just isn't practical.

Even with all access points on a single subnet, mobile users can still encounter coverage problems. If a user moves out of range, into a coverage hole, or simply suspends the device to prolong battery life, all application end points are lost and users in these situations again are also forced to log in again and find their way back to where they left off.


Load Balancing

Congested areas with many users and heavy traffic load per unit may require a multi-cell structure. In a multi-cell structure, several co-located access points “illuminate” the same area creating a common coverage area, which increases aggregate throughput. Stations inside the common coverage area automatically associate with the access point that is less loaded and provides the best signal quality.

As illustrated in Figure 7.17, the stations are equally divided between the access points in order to equally share the load between all access points. Efficiency is maximized because all access points are working at the same low-level load. Load balancing is also known as load sharing and is configured on both the stations and the access point in most cases.

Sunday, August 16, 2009

Service Sets

A service set is a term used to describe the basic components of a fully operational wireless LAN. In other words, there are three ways to configure a wireless LAN, and each way requires a different set of hardware. The three ways to configure a wireless LAN are:
  • Basic service set
  • Extended service set
  • Independent basic service set

Basic Service Set (BSS)

When one access point is connected to a wired network and a set of wireless stations, the network configuration is referred to as a basic service set (BSS). A basic service set consists of only one access point and one or more wireless clients, as shown in Figure 7.9. A basic service set uses infrastructure mode - a mode that requires use of an access point and in which all of the wireless traffic traverses the access point. No direct clientto-client transmissions are allowed.

Each wireless client must use the access point to communicate with any other wireless client or any wired host on the network. The BSS covers a single cell, or RF area, around the access point with varying data rate zones (concentric circles) of differing data speeds, measured in Mbps. The data speeds in these concentric circles will depend on the technology being utilized. If the BSS were made up of 802.11b equipment, then the concentric circles would have data speeds of 11, 5.5, 2, and 1 Mbps. The data rates get smaller as the circles get farther away from the access point. A BSS has one unique SSID.


Extended Service Set (ESS)

An extended service set is defined as two or more basic service sets connected by a common distribution system, as shown in Figure 7.10. The distribution system can be either wired, wireless, LAN, WAN, or any other method of network connectivity. An ESS must have at least 2 access points operating in infrastructure mode. Similar to a BSS, all packets in an ESS must go through one of the access points.


Other characteristics of extended service sets, according to the 802.11 standard, are that an ESS covers multiple cells, allows – but does not require – roaming capabilities, and does not require the same SSID in both basic service sets.


Independent Basic Service Set (IBSS)

An independent basic service set is also known as an ad hoc network. An IBSS has no access point or any other access to a distribution system, but covers one single cell and has one SSID, as shown in Figure 7.11. The clients in an IBSS alternate the responsibility of sending beacons since there is no access point to perform this task.


In order to transmit data outside an IBSS, one of the clients in the IBSS must be acting as a gateway, or router, using a software solution for this purpose. In an IBSS, clients make direct connections to each other when transmitting data, and for this reason, an IBSS is often referred to as a peer-to-peer network.

Sunday, August 9, 2009

Authentication Security

Shared Key authentication is not considered secure because the access point transmits the challenge text in the clear and receives the same challenge text encrypted with the WEP key. This scenario allows a hacker using a sniffer to see both the plaintext challenge and the encrypted challenge. Having both of these values, a hacker could use a simple cracking program to derive the WEP key. Once the WEP key is obtained, the hacker could decrypt encrypted traffic. It is for this reason that Open System authentication is considered more secure than Shared Key authentication.


Shared Secrets & Certificates

Shared secrets are strings of numbers or text that are commonly referred to as the WEP key. Certificates are another method of user identification used with wireless networks. Just as with WEP keys, certificates (which are authentication documents) are placed on the client machine ahead of time. This placement is done so that when the user wishes to authenticate to the wireless network, the authentication mechanism is already in place on the client station. Both of these methods have historically been implemented in a manual fashion, but there are applications available today that allow automation of this process.


Emerging Authentication Protocols

There are many new authentication security solutions and protocols on the market today, including VPN and 802.1x using Extensible Authentication Protocol (EAP). Many of these security solutions involve passing authentication through to authentication servers upstream from the access point while keeping the client waiting during the authentication phase. Windows XP has native support for 802.11, 802.1x, and EAP. Cisco and other wireless LAN manufacturers also support these standards. For this reason, it is easy to see that the 802.1x and EAP authentication solution could be a common solution in the wireless LAN security market.


802.1x and EAP
The 802.1x (port-based network access control) standard is relatively new, and devices that support it have the ability to allow a connection into the network at layer 2 only if user authentication is successful. This protocol works well for access points that need the ability to keep users disconnected if they are not supposed to be on the network. EAP is a layer 2 protocol that is a flexible replacement for PAP or CHAP under PPP that works over local area networks. EAP allows plug-ins at either end of a link through which many methods of authentication can be used. In the past, PAP and/or CHAP have been used for user authentication, and both support using passwords. The need for a stronger, more flexible alternative is clear with wireless networks since more varied implementations abound with wireless than with wired networks.

Typically, user authentication is accomplished using a Remote Authentication Dial-In User Service (RADIUS) server and some type of user database (Native RADIUS, NDS, Active Directory, LDAP, etc.). The process of authenticating using EAP is shown in Figure 7.6. The new 802.11i standard includes support for 802.1x, EAP, AAA, mutual authentication, and key generation, none of which were included in the original 802.11 standard. “AAA” is an acronym for authentication (identifying who you are), authorization (attributes to allow you to perform certain tasks on the network), and accounting (shows what you’ve done and where you’ve been on the network).

In the 802.1x standard model, network authentication consists of three pieces: the supplicant, the authenticator, and the authentication server.


Because wireless LAN security is essential – and EAP authentication types provide the means of securing the wireless LAN connection – vendors are rapidly developing and adding EAP authentication types to their wireless LAN access points. Knowing the type of EAP being used is important in understanding the characteristics of the authentication method such as passwords, key generation, mutual authentication, and protocol. Some of the commonly deployed EAP authentication types include:

EAP-MD-5 Challenge. The earliest EAP authentication type, this essentially duplicates CHAP password protection on a wireless LAN. EAP-MD5 represents a kind of baselevel EAP support among 802.1x devices.

EAP-Cisco Wireless. Also called LEAP (Lightweight Extensible Authentication Protocol), this EAP authentication type is used primarily in Cisco wireless LAN access points. LEAP provides security during credential exchange, encrypts data transmission using dynamically generated WEP keys, and supports mutual authentication.

EAP-TLS (Transport Layer Security). EAP-TLS provides for certificate-based, mutual authentication of the client and the network. EAP-TLS relies on client-side and serverside certificates to perform authentication, using dynamically generated user- and session-based WEP keys distributed to secure the connection. Windows XP includes an EAP-TLS client, and EAP-TLS is also supported by Windows 2000.

EAP-TTLS. Funk Software and Certicom have jointly developed EAP-TTLS (Tunneled Transport Layer Security). EAP-TTLS is an extension of EAP-TLS, which provides for certificate-based, mutual authentication of the client and network. Unlike EAP-TLS, however, EAP-TTLS requires only server-side certificates, eliminating the need to configure certificates for each wireless LAN client.

In addition, EAP-TTLS supports legacy password protocols, so you can deploy it against your existing authentication system (such as Active Directory or NDS). EAP-TTLS securely tunnels client authentication within TLS records, ensuring that the user remains anonymous to eavesdroppers on the wireless link. Dynamically generated user- and session-based WEP keys are distributed to secure the connection.


EAP-SRP (Secure Remote Password). SRP is a secure, password-based authentication and key-exchange protocol. It solves the problem of authenticating clients to servers securely in cases where the user of the client software must memorize a small secret (like a password) and carries no other secret information. The server carries a verifier for each user, which allows the server to authenticate the client. However, if the verifier were compromised, the attacker would not be allowed to impersonate the client. In addition, SRP exchanges a cryptographically strong secret as a byproduct of successful authentication, which enables the two parties to communicate securely.

EAP-SIM (GSM). EAP-SIM is a mechanism for Mobile IP network access authentication and registration key generation using the GSM Subscriber Identity Module (SIM). The rationale for using the GSM SIM with Mobile IP is to leverage the existing GSM authorization infrastructure with the existing user base and the existing SIM card distribution channels. By using the SIM key exchange, no other preconfigured security association besides the SIM card is required on the mobile node. The idea is not to use the GSM radio access technology, but to use GSM SIM authorization with Mobile IP over any link layer, for example on Wireless LAN access networks.

It is likely that this list of EAP authentication types will grow as more and more vendors enter the wireless LAN security market, and until the market chooses a standard.

VPN Solutions
VPN technology provides the means to securely transmit data between two network devices over an unsecure data transport medium. It is commonly used to link remote computers or networks to a corporate server via the Internet. However, VPN is also a solution for protecting data on a wireless network. VPN works by creating a tunnel on top of a protocol such as IP. Traffic inside the tunnel is encrypted, and totally isolated as can be seen in Figures 7.7 and 7.8. VPN technology provides three levels of security: user authentication, encryption, and data authentication.
  • User authentication ensures that only authorized users (over a specific device) are able to connect, send, and receive data over the wireless network.
  • Encryption offers additional protection as it ensures that even if transmissions are intercepted, they cannot be decoded without significant time and effort.
  • Data authentication ensures the integrity of data on the wireless network, guaranteeing that all traffic is from authenticated devices only.

Applying VPN technology to secure a wireless network requires a different approach than when it is used on wired networks for the following reasons.
  • The inherent repeater function of wireless access points automatically forwards traffic between wireless LAN stations that communicate together and that appear on the same wireless network.
  • The range of the wireless network will likely extend beyond the physical boundaries of an office or home, giving intruders the means to compromise the network.
The ease and scalability with which wireless LAN solutions can be deployed makes them ideal solutions for many different environments. As a result, implementation of VPN security will vary based on the needs of each type of environment. For example, a hacker with a wireless sniffer, if he obtained the WEP key, could decode packets in real time. With a VPN solution, the packets would not only be encrypted, but also tunneled. This extra layer of security provides many benefits at the access level.

Monday, July 27, 2009

Authentication & Association

The process of connecting to a wireless LAN consists of two separate sub-processes. These sub-processes always occur in the same order, and are called authentication and association. For example, when we speak of a wireless PC card connecting to a wireless LAN, we say that the PC card has been authenticated by and has associated with a certain access point. Keep in mind that when we speak of association, we are speaking of Layer 2 connectivity, and authentication pertains directly to the radio PC card, not to the user. Understanding the steps involved in getting a client connected to an access point is crucial to security, troubleshooting, and management of the wireless LAN.


Authentication

The first step in connecting to a wireless LAN is authentication. Authentication is the process through which a wireless node (PC Card, USB Client, etc.) has its identity verified by the network (usually the access point) to which the node is attempting to connect. This verification occurs when the access point to which the client is connecting verifies that the client is who it says it is. To put it another way, the access point responds to a client requesting to connect by verifying the client’s identity before any connection happens. Sometimes the authentication process is null, meaning that, although both the client and access point have to proceed through this step in order to associate, there's really no special identity required for association. This is the case when most brand new access points and PC cards are installed in their default configuration.

The client begins the authentication process by sending an authentication request frame to the access point (in infrastructure mode). The access point will either accept or deny this request, thereafter notifying the station of its decision with an authentication response frame. The authentication process can be accomplished at the access point, or the access point might pass along this responsibility to an upstream authentication server such as RADIUS. The RADIUS server would perform the authentication based on a list of criteria, and then return its results to the access point so that the access point could return the results to the client station.


Association


Once a wireless client has been authenticated, the client then associates with the access point. Associated is the state at which a client is allowed to pass data through an access point. If your PC card is associated to an access point, you are connected to that access point, and hence, the network.

The process of becoming associated is as follows. When a client wishes to connect, the client sends an authentication request to the access point and receives back an authentication response. After authentication is completed, the station sends an association request frame to the access point who replies to the client with an association response frame either allowing or disallowing association.


States of Authentication & Association

The complete process of authentication and association has three distinct states:
  1. Unauthenticated and unassociated
  2. Authenticated and unassociated
  3. Authenticated and associated

Authentication Methods


FIGURE 7.4 Open System Authentication Process The IEEE 802.11 standard specifies two methods of authentication: Open System authentication and Shared Key authentication. The simpler and also the more secure of the two methods is Open System authentication. For a client to become authenticated, the client must walk through a series of steps with the access point. This series of steps varies depending on the authentication process used. Below, we will discuss each authentication process specified by the 802.11 standard, how they work, and why they are used.

Open System Authentication
Open System authentication is a method of null authentication and is specified by the IEEE 802.11 as the default setting in wireless LAN equipment. Using this method of authentication, a station can associate with any access point that uses Open System authentication based only on having the right service set identifier (SSID). The SSIDs must match on both the access point and client before a client is allowed to complete the authentication process. The Open System authentication process is used effectively in both secure and non-secure environments.

Open System Authentication Process

The Open System authentication process occurs as follows:
  1. The wireless client makes a request to associate to the access point
  2. The access point authenticates the client and sends a positive response and the client becomes associated (connected)
These steps can be seen in Figure 7.4.


Open System authentication is a very simple process. As the wireless LAN administrator, you have the option of using WEP (wired equivalent privacy) encryption with Open System authentication. If WEP is used with the Open System authentication process, there is still no verification of the WEP key on each side of the connection during authentication. Rather, the WEP key is used only for encrypting data once the client is authenticated and associated.

Open System authentication is used in several scenarios, but there are two main reasons to use it. First, Open System authentication is considered the more secure of the two available authentication methods for reasons explained below. Second, Open System authentication is simple to configure because it requires no configuration at all. All 802.11-compliant wireless LAN hardware is configured to use Open System authentication by default, making it easy to get started building and connecting your wireless LAN right out of the box.


Shared Key Authentication

Shared Key authentication is a method of authentication that requires use of WEP. WEP encryption uses keys that are entered (usually by the administrator) into both the client and the access point. These keys must match on both sides for WEP to work properly. Shared Key authentication uses WEP keys in two fashions, as we will describe here.


Shared Key Authentication Process

The authentication process using Shared Key authentication occurs as follows.

1. A client requests association to an access point – this step is the same as that of Open System authentication.

2. The access point issues a challenge to the client – this challenge is randomly generated plain text, which is sent from the access point to the client in the clear.

3. The client responds to the challenge – the client responds by encrypting the challenge text using the client’s WEP key and sending it back to the access point.

4. The access point responds to the client’s response – The access point decrypts the client's encrypted response to verify that the challenge text is encrypted using a matching WEP key. Through this process, the access point determines whether or not the client has the correct WEP key. If the client’s WEP key is correct, the access point will respond positively and authenticate the client. If the client’s WEP key is not correct, the access point will respond negatively, and not authenticate the client, leaving the client unauthenticated and unassociated.

This process is shown in Figure 7.5.


It would seem that the Shared Key authentication process is more secure than that of Open System authentication, but as you will soon see, it is not. Rather, Shared Key authentication opens the door for would-be hackers. It is important to understand both ways that WEP is used. The WEP key can be used during the Shared Key authentication process to verify a client's identity, but it can also be used for encryption of the data payload send by the client through the access point.

Sunday, July 12, 2009

Locating a Wireless LAN

When you install, configure, and finally start up a wireless LAN client device such as a USB client or PCMCIA card, the client will automatically “listen" to see if there is a wireless LAN within range. The client is also discovering if it can associate with that wireless LAN. This process of listening is called scanning. Scanning occurs before any other process, since scanning is how the client finds the network.

There are two kinds of scanning: passive scanning and active scanning. In finding an access point, client stations follow a trail of breadcrumbs left by the access point. These breadcrumbs are called service set identifiers (SSID) and beacons. These tools serve as a means for a client station to find any and all access points.


Service Set Identifier

The service set identifier (SSID) is a unique, case sensitive, alphanumeric value from 2- 32 characters long used by wireless LANs as a network name. This naming handle is used for segmenting networks, as a rudimentary security measure, and in the process of joining a network. The SSID value is sent in beacons, probe requests, probe responses, and other types of frames. A client station must be configured for the correct SSID in order to join a network. The administrator configures the SSID (sometimes called the ESSID) in each access point. Some stations have the ability to use any SSID value instead of only one manually specified by the administrator. If clients are to roam seamlessly among a group of access points, the clients and all access points must be configured with matching SSIDs. The most important point about an SSID is that it must match EXACTLY between access points and clients.


Beacons

Beacons (short for beacon management frame) are short frames that are sent from the access point to stations (infrastructure mode) or station-to-station (ad hoc mode) in order to organize and synchronize wireless communication on the wireless LAN.


Passive Scanning


Passive scanning is the process of listening for beacons on each channel for a specific period of time after the station is initialized. These beacons are sent by access points (infrastructure mode) or client stations (ad hoc mode), and the scanning station catalogs characteristics about the access points or stations based on these beacons. The station searching for a network listens for beacons until it hears a beacon listing the SSID of the network it wishes to join. The station then attempts to join the network through the access point that sent the beacon. Passive scanning is illustrated in Figure 7.1. In configurations where there are multiple access points, the SSID of the network the station wishes to join may be broadcast by more than one of these access points. In this situation, the station will attempt to join the network through the access point with the strongest signal strength and the lowest bit error rate.

Stations continue passive scanning even after associating to an access point. Passive scanning saves time reconnecting to the network if the client is disconnected (disassociated) from the access point to which the client is currently connected. By maintaining a list of available access points and their characteristics (channel, signal strength, SSID, etc), the station can quickly locate the best access point should its current connection be broken for any reason.

Stations will roam from one access point to another after the radio signal from the access point where the station is connected gets to a certain low level of signal strength. Roaming is implemented so that the station can stay connected to the network. Stations use the information obtained through passive scanning for locating the next best access point (or ad hoc network) to use for connectivity back into the network. For this reason, overlap between access point cells is usually specified at approximately 20-30%. This overlap allows stations to seamlessly roam between access points while disconnecting and reconnecting without the user’s knowledge.


Active Scanning


Stations send this probe frame when they are actively seeking a network to join. The probe frame will contain either the SSID of the network they wish to join or a broadcast SSID. If a probe request is sent specifying an SSID, then only access points that are servicing that SSID will respond with a probe response frame. If a probe request frame is sent with a broadcast SSID, then all access points within reach will respond with a probe response frame, as can be seen in Figure 7.2.

The point of probing in this manner is to locate access points through which the station can attach to the network. Once an access point with the proper SSID is found, the station initiates the authentication and association steps of joining the network through that access point.

The information passed from the access point to the station in probe response frames is almost identical to that of beacons. Probe response frames differ from beacons only in that they are not time-stamped and they do not include a Traffic Indication Map (TIM).

The signal strength of the probe response frames that the PC Card receives back helps determine the access point with which the PC card will attempt to associate. The station generally chooses the access point with the strongest signal strength and lowest bit error rate (BER). The BER is a ratio of corrupted packets to good packets typically determined by the Signal-to-Noise Ratio of the signal. If the peak of an RF signal is somewhere near the noise floor, the receiver may confuse the data signal with noise.

Sunday, July 5, 2009

IEEE standards

The Institute of Electrical and Electronics Engineers (IEEE) is the key standards maker for most things related to information technology in the United States. The IEEE creates its standards within the laws created by the FCC. The IEEE specifies many technology standards such as Public Key Cryptography (IEEE 1363), FireWire (IEEE 1394), Ethernet (IEEE 802.3), and Wireless LANs (IEEE 802.11).

It is part of the mission of the IEEE to develop standards for wireless LAN operation within the framework of the FCC rules and regulations. Following are the four main IEEE standards for wireless LANs that are either in use or in draft form:
  • 802.11
  • 802.11b
  • 802.11a
  • 802.11g

IEEE 802.11

The 802.11 standard was the first standard describing the operation of wireless LANs. This standard contained all of the available transmission technologies including Direct Sequence Spread Spectrum (DSSS), Frequency Hopping Spread Spectrum (FHSS), and infrared.

The IEEE 802.11 standard describes DSSS systems that operate at 1 Mbps and 2 Mbps only. If a DSSS system operates at other data rates as well, such as 1 Mbps, 2 Mbps, and 11 Mbps, then it can still be an 802.11-compliant system. If, however, the system is operating at any rate other than 1 or 2 Mbps, then, even though the system is 802.11- compliant because of its ability to work at 1 & 2 Mbps, it is not operating in an 802.11- compliant mode and cannot be expected to communicate with other 802.11-compliant devices.

IEEE 802.11 is one of two standards that describe the operation of frequency hopping wireless LAN systems. If a wireless LAN administrator encounters a frequency hopping system, then it is likely to be either an 802.11-compliant or OpenAir compliant system (discussed below). The 802.11 standard describes use of FHSS systems at 1 and 2 Mbps. There are many FHSS systems on the market that extend this functionality by offering proprietary modes that operate at 3-10 Mbps, but just as with DSSS, if the system is operating at speeds other than 1 & 2 Mbps, it cannot be expected to automatically communicate with other 802.11-compliant devices.

802.11 compliant products operate strictly in the 2.4 GHz ISM band between 2.4000 and 2.4835 GHz. Infrared, also covered by 802.11, is light-based technology and does not fall into the 2.4 GHz ISM band.


IEEE 802.11b

Though the 802.11 standard was successful in allowing DSSS as well as FHSS systems to interoperate, the technology has outgrown the standard. Soon after the approval and implementation of 802.11, DSSS wireless LANs were exchanging data at up to 11 Mbps. But, without a standard to guide the operation of such devices, there came to be problems with interoperability and implementation. The manufacturers ironed out most of the implementation problems, so the job of IEEE was relatively easy: create a standard that complied with the general operation of wireless LANs then on the market. It is not uncommon for the standards to follow the technology in this way, particularly when the technology evolves quickly.

IEEE 802.11b, referred to as "High-Rate" and Wi-Fi™, specifies direct sequencing (DSSS) systems that operate at 1, 2, 5.5 and 11 Mbps. The 802.11b standard does not describe any FHSS systems, and 802.11b-compliant devices are also 802.11-compliant by default, meaning they are backward compatible and support both 2 and 1 Mbps data rates. Backward compatibility is very important because it allows a wireless LAN to be upgraded without the cost of replacing the core hardware. This low-cost feature, together with the high data rate, has made the 802.11b-compliant hardware very popular.

The high data rate of 802.11b-compliant devices is the result of using a different coding technique. Though the system is still a direct sequencing system, the way the chips are coded (CCK rather than Barker Code) along with the way the information is modulated (QPSK at 2, 5.5, & 11 Mbps and BPSK at 1 Mbps) allows for a greater amount of data to be transferred in the same time frame. 802.11b compliant products operate only in the 2.4 GHz ISM band between 2.4000 and 2.4835 GHz.


IEEE 802.11a

The IEEE 802.11a standard describes wireless LAN device operation in the 5 GHz UNII bands. Operation in the UNII bands automatically makes 802.11a devices incompatible with all other devices complying with the other 802.11 series of standards. The reason for this incompatibility is simple: systems using 5 GHz frequencies will not communicate with systems using 2.4 GHz frequencies.

Using the UNII bands, most devices are able to achieve data rates of 6, 9, 12, 18, 24, 36, 48, and 54 Mbps. Some of the devices employing the UNII bands have achieved data rates of 108 Mbps by using proprietary technology, such as rate doubling. The highest rates of some of these devices are the result of newer technologies not specified by the 802.11a standard. IEEE 802.11a specifies data rates of only 6, 12, and 24 Mbps. A wireless LAN device must support at least these data rates in the UNII bands in order to be 802.11a-compliant. The maximum data rate specified by the 802.11a standard is 54 Mbps.


IEEE 802.11g

802.11g provides the same maximum speed of 802.11a, coupled with backwards compatibility for 802.11b devices. This backwards compatibility will make upgrading wireless LANs simple and inexpensive. Since 802.11g technology is new, 802.11g devices are not yet available as of this writing.

IEEE 802.11g specifies operation in the 2.4 GHz ISM band. To achieve the higher data rates found in 802.11a, 802.11g compliant devices utilize Orthogonal Frequency Division Multiplexing (OFDM) modulation technology. These devices can automatically switch to QPSK modulation in order to communicate with the slower 802.11b- and 802.11- compatable devices. With all of the apparent advantages, 802.11g’s use of the crowded 2.4 GHz band could prove to be a disadvantage.

Sunday, June 21, 2009

RF Splitters

An RF Splitter is a device that has a single input connector and multiple output connectors. An RF Splitter is used for the purpose of splitting a single signal into multiple independent RF signals. Use of splitters in everyday implementations of wireless LANs is not recommended. Sometimes two 120-degree panel antennas or two 90-degree panel antennas may be combined with a splitter and equal-length cables when the antennas are pointing in opposite directions. This configuration will produce a bidirectional coverage area, which may be ideal for covering the area along a river or major highway. Back-to-back 90 degree panels may be separated by as little as 10 inches or as much as 40 inches on either side of the mast or tower. Each panel in this configuration may have a mechanical down tilt. The resultant gain in each of the main radiation lobes is reduced by 3 - 4 dB in these configurations.

When installing an RF splitter, the input connector should always face the source of the RF signal. The output connectors (sometimes called "taps") are connected facing the destination of the RF signal (the antenna). Figure 5.26 shows two examples of RF splitters. Figure 5.27 illustrates how an RF splitter would be used in a wireless LAN installation.

Splitters may be used to keep track of power output on a wireless LAN link. By hooking a power meter to one output of the splitter and the RF antenna to the other, an administrator can actively monitor the output at any given time. In this scenario, the power meter, the antenna, and the splitter must all have equal impedance. Although not a common practice, removing the power meter from one output of the splitter and replacing it with a 50 ohm dummy load would allow the administrator to move the power meter from one connection point to another throughout the wireless LAN while making output power measurements.


RF Connectors

RF connectors are specific types of connection devices used to connect cables to devices or devices to devices. Traditionally, N, F, SMA, BNC, & TNC connectors (or derivatives) have been used for RF connectors on wireless LANs.

In 1994, the FCC & DOC (Canadian Department of Communications) ruled that connectors for use with wireless LAN devices should be proprietary between manufacturers. For this reason, many variations on each connector type exist such as:
  • N-type
  • Reverse polarity N-type
  • Reverse threaded N-type

Choosing an RF Connector

There are five things that should be considered when purchasing and installing any RF
connector, and they are similar in nature to the criteria for choosing RF amplifiers and
attenuators.
  1. The RF connector should match the impedance of all other wireless LAN components (generally 50 ohms).
  2. Know how much insertion loss each connector inserted into the signal path causes. The amount of loss caused will factor into your calculations for signal strength required and distance allowed.
  3. Know the upper frequency limit (frequency response) specified for the particular connectors. This point will be very important as 5 Ghz wireless LANs become more and more common. Some connectors are rated only as high as 3 GHz, which is fine for use with 2.4 GHz wireless LANs, but will not work for 5 GHz wireless LANs. Some connectors are rated only up to 1 GHz and will not work with wireless LANs at all, other than legacy 900 MHz wireless LANs.
  4. Beware of bad quality connectors. First, always consider purchasing from a reputable company. Second, purchase only high-quality connectors made by name-brand manufacturers. This kind of purchasing particularity will help eliminate many problems with sporadic RF signals, VSWR, and bad connections.
  5. Make sure you know both the type of connector (N, F, SMA, etc.) that you need and the sex of the connector. Connectors come in male and female. Male connectors have a center pin, and female connectors have a center receptacle.

Sunday, June 14, 2009

Wireless LAN Accessories

When the time comes to connect all of your wireless LAN devices together, you will need to purchase the appropriate cables and accessories that will maximize your throughput, minimize your signal loss, and, most importantly, allow you to make the connections correctly. This section will discuss the different types of accessories and where they fit into a wireless LAN design. The following types of accessories are discussed in this section:
  • RF Amplifiers
  • RF Attenuators
  • Lightning Arrestors
  • RF Connectors
  • RF Cables
  • RF Splitters

Each of these devices is important to building a successful wireless LAN. Some items are used more than others, and some items are mandatory whereas others are optional. It is likely that an administrator will have to install and use all of these items multiple times while implementing and managing a wireless LAN.


RF Amplifiers

As its name suggests, an RF amplifier is used to amplify, or increase the amplitude of, an RF signal, which is measured in +dB. An amplifier will be used when compensating for the loss incurred by the RF signal, either due to the distance between antennas or the length of cable from a wireless infrastructure device to its antenna. Most RF amplifiers used with wireless LANs are powered using DC voltage fed onto the RF cable with a DC injector near the RF signal source (such as the access point or bridge).

Sometimes this DC voltage used to power RF amplifiers is called "phantom voltage" because the RF amplifier seems to magically power up. This DC injector is powered using AC voltage from a wall outlet, so it might be located in a wiring closet. In this scenario, the RF cable carries both the high frequency RF signal and the DC voltage necessary to power the in-line amplifier, which, in turn, boosts the RF signal amplitude. Figure 5.20 shows an example of an RF amplifier (left), and how an RF amplifier is mounted on a pole (right) between the access point and its antenna.

RF amplifiers come in two types: unidirectional and bi-directional. Unidirectional amplifiers compensate for the signal loss incurred over long RF cables by increasing the signal level before it is injected into the transmitting antenna. Bi-directional amplifiers boost the effective sensitivity of the receiving antenna by amplifying the received signal before it is fed into the access point, bridge, or client device.


RF Attenuators


An RF attenuator is a device that causes precisely measured loss (in –dB) in an RF signal. While an amplifier will increase the RF signal, an attenuator will decrease it. Why would you need or want to decrease your RF signal? Consider the case where an access point has a fixed output of 100mW, and the only antenna available is an omni-directional antenna with +20 dBi gain. Using this equipment together would violate FCC rules for power output, so an attenuator could be added to decrease the RF signal down to 30mW before it entered the antenna. This configuration would put the power output within FCC parameters. Figure 5.22 shows examples of fixed-loss RF attenuators with BNC connectors (left) and SMA connectors (right). Figure 5.23 shows an example of an RF step attenuator.

Sunday, June 7, 2009

Power over Ethernet (PoE) Devices

Power over Ethernet (PoE) is a method of delivering DC voltage to an access point, wireless bridge, or wireless workgroup bridge over the Cat5 Ethernet cable for the purpose of powering the unit. PoE is used when AC power receptacles are not available where wireless LAN infrastructure devices are to be installed. The Ethernet cable is used to carry both the power and the data to the units.

Consider a warehouse where the access points need to be installed in the ceiling of the building. The labor costs that would be incurred to install electrical outlets throughout the ceiling of the building to power the access points would be considerable. Hiring an electrician to do this type of work would be very expensive and time consuming. Remember that Ethernet cables can only carry data reliably for 100 meters and, for any distance more than 100 meters, PoE is not a viable solution. The following figure illustrates how a PoE device would provide power to an access point.


Common PoE Options
PoE devices are available in several types.
  • Single-port DC voltage injectors
  • Multi-port DC voltage injectors
  • Ethernet switches designed to inject DC voltage on each port on a given pair of pins

Single-port DC Voltage Injectors

Access points and bridges that specify mandatory use of PoE include single-port DC voltage injectors for the purpose of powering the unit. See Figure 5.17 below for an example of a single-port DC voltage injector. These single-port injectors are acceptable when used with a small number of wireless infrastructure devices, but quickly become a burden, cluttering wiring closets, when building medium or large wireless networks.


Multi-port DC Voltage Injectors

Several manufacturers offer multi-port injectors including 4, 6, or 12-port models. These models may be more economical or convenient for installations where many devices are to be powered through the Cat5 cable originating in a single wiring closet or from a single switch. Multi-port DC voltage injectors typically operate in exactly the same manner as their single-port counterparts. See Figure 5.18 for an example of a multi-port PoE injector. A multi-port DC voltage injector looks like an Ethernet switch with twice as many ports. A multi-port DC voltage injector is a pass-through device to which you connect the Ethernet switch (or hub) to the input port, and then connect the PoE client device to the output device, both via Cat5 cable. The PoE injector connects to an AC power source in the wiring closet. These multi-port injectors are appropriate for mediumsized wireless network installations where up to 50 access points are required, but in large enterprise rollouts, even the most dense multi-port DC voltage injectors combined with Ethernet hubs or switches can become cluttered when installed in a wiring closet.


Active Ethernet Switches

The next step up for large enterprise installations of access points is the implementation of active Ethernet switches. These devices incorporate DC voltage injection into the Ethernet switch itself allowing for large numbers of PoE devices without any additional hardware in the network. See Figure 5.19 for an example of an Active Ethernet switch. Wiring closets will not have any additional hardware other than the Ethernet switches that would already be there for a non-PoE network. Several manufacturers make these switches in many different configurations (number of ports). In many Active Ethernet switches, the switch can auto-sense PoE client devices on the network. If the switch does not detect a PoE device on the line, the DC voltage is switched off for that port. As you can see from the picture, an Active Ethernet switch looks no different from an ordinary Ethernet switch. The only difference is the added internal functionality of supplying DC voltage to each port.

Monday, June 1, 2009

RF Antenna Concepts

There are several concepts that are essential knowledge when implementing solutions that require RF antennas. Among those that will be described are:
  • Polarization
  • Gain
  • Beamwidth
  • Free Space Path Loss
The above list is by no means a comprehensive list of all RF antenna concepts, but rather a set of must-have fundamentals that allow an administrator to understand how wireless LAN equipment functions over the wireless medium. A solid understanding of basic antenna functionality is the key to moving forward in learning more advanced RF concepts.

Knowing where to place antennas, how to position them, how much power they are radiating, the distance that radiated power is likely to travel, and how much of that power can be picked up by receivers is, many times, the most complex part of an administrator's job.


Polarization
A radio wave is actually made of up two fields, one electric and one magnetic. These two fields are on planes perpendicular to each other, as shown in the following figure.


The sum of the two fields is called the electro-magnetic field. Energy is transferred back and forth from one field to the other, in the process known as "oscillation." The plane that is parallel with the antenna element is referred to as the "E-plane" whereas the plane that is perpendicular to the antenna element is referred to as the "H-plane." We are interested primarily in the electric field since its position and direction with reference to the Earth's surface (the ground) determines wave polarization.

Polarization is the physical orientation of the antenna in a horizontal or vertical position. The electric field is parallel to the radiating elements (the antenna element is the metal part of the antenna that is doing the radiating) so, if the antenna is vertical, then the polarization is vertical.
  • Horizontal polarization - the electric field is parallel to the ground
  • Vertical polarization - the electric field is perpendicular to the ground
Vertical polarization, which is typically used in wireless LANs, is perpendicular to the Earth’s plane. Notice the dual antennas sticking up vertically from most any access point - these antennas are vertically polarized in that position. Horizontal polarization is parallel to the Earth. In the foolowing figure illustrates the effects polarization can have when antennas are not aligned correctly. Antennas that are not polarized in the same way are not able to communicate with each other effectively.


Gain
Antenna gain is specified in dBi, which means decibels referenced to an isotropic radiator. An isotropic radiator is a sphere that radiates power equally in all directions simultaneously. We haven't the ability to make an isotropic radiator, but instead we can make omni-directional antennas such as a dipole that radiates power in a 360-degree horizontal fashion, but not 360 degrees vertically. RF signal radiation in this fashion gives us a doughnut pattern. The more we horizontally squeeze this doughnut, the flatter it becomes, forming more of a pancake shape when the gain is very high. Antennas have passive gain, which means they do not increase the power that is input into them, but rather shape the radiation field to lengthen or shorten the distance the propagated wave will travel. The higher the antenna gain, the farther the wave will travel, concentrating its output wave more tightly so that more of the power is delivered to the destination (the receiving antenna) at long distances. As was shown in the figure, the coverage has been squeezed vertically so that the coverage pattern is elongated, reaching further.


Beamwidth
As we've discussed previously, narrowing, or focusing antenna beams increases the antenna’s gain (measured in dBi). An antenna’s beamwidth means just what it sounds like: the “width” of the RF signal beam that the antenna transmits. The following figure illustrates the term
beamwidth.

There are two vectors to consider when discussing an antenna’s beamwidths: the vertical and the horizontal. The vertical beamwidth is measure in degrees and is perpendicular to the Earth's surface. The horizontal beamwidth is measured in degrees and is parallel to the Earth's surface. Beamwidth is important for you to know because each type of antenna has different beamwidth specifications. The chart below can be used as a quick reference guide for beamwidths.


Free Space Path Loss
Free Space Path Loss (or just Path Loss) refers to the loss incurred by an RF signal due largely to "signal dispersion" which is a natural broadening of the wave front. The wider the wave front, the less power can be induced into the receiving antenna. As the transmitted signal traverses the atmosphere, its power level decreases at a rate inversely proportional to the distance traveled and proportional to the wavelength of the signal. The power level becomes a very important factor when considering link viability.
The Path Loss equation is one of the foundations of link budget calculations. Path Loss represents the single greatest source of loss in a wireless system. Below is the formula
for Path Loss.