Showing posts with label wi-fi. Show all posts
Showing posts with label wi-fi. Show all posts

Monday, August 4, 2014

802.11ac Adjacent Channel Interference (ACI)

I was reading this article on development of 5G cellular technologies when this bit on OFDM deficiencies and the need for new waveforms to support higher capacities and user densities caught my attention (emphasis added by me):
4G and 4G+ networks employ a type of waveform called orthogonal frequency division multiplexing (OFDM) as the fundamental element in the physical layer (PHY).  In fact, almost all modern communication networks are built on OFDM because OFDM improved data rates and network reliability significantly by taking advantage of multi-path a common artifact of wireless transmissions.  However as time and demands progress, OFDM technology suffers from out-of-band spectrum regrowth resulting in high side lobes that limit spectral efficiency.  In other words, network operators cannot efficiently use their available spectrum because two users on adjacent channels would interfere with one another.  OFDM also suffers from high peak-to-average ratio of the power amplifier, resulting in lower battery life of the mobile device.  To address OFDM deficiencies, researchers are investigating alternative methods including generalized frequency division multiplexing, filter bank multi-carrier, and universal filter multi-carrier.  Researchers speculate that using one of these approaches over OFDM may improve network capacity by 30 percent or more while improving the battery life for all mobile devices."


This aligns with most Wi-Fi professionals' recommendations to deploy 5 GHz radios on non-adjacent channels to avoid that dreaded adjacent channel interference (ACI). 

And if you look at an OFDM Wi-Fi transmit spectral mask, either the limits defined in the standard or using a spectrum analyzer, you will see rather significant side lobes that can impact adjacent channels (and channels even further away, depending on proximity and power levels). I have even considered including discussion of OFDM spectral masks within my 802.11ac presentations and writing due to the fact that as channel widths get wider, so to do their side lobes because the frequency distance from the main carrier signal at which the relative power level must be reduced to be in compliance increases as well. 

Here is an illustration that I put together over a year ago but never published and kept in the appendix of my 11ac presentation. It illustrates how ACI can increase due to the spectral mask differences as channel widths get larger. I have inlaid two 20 MHz spectral masks inside the 40 MHz mask, and two 40 MHz masks inside the 80 MHz mask. Essentially, the side lobe power level reduction requirements are based on the size of the main signal lobe; as the main signal lobe gets larger, so too does the allowed power in side band lobes.

Spectral Mask Comparison of 20, 40, and 80 MHz Wi-Fi Channels
And below is a capture from a spectrum analyzer approximately 10 feet away from an 802.11ac AP operating in 80 MHz mode with a large amount of traffic. Notice the high signal level in adjacent channels (52-64, and likely would impact the as-of-yet unapproved U-NII 2B band). 


Spectrum Analysis Capture of an 802.11ac 80 MHz Waveform

This is why you need a minimum of 10 feet of separation between radios operating in the same frequency band (unless other shielding mechanisms are used, which increase cost), as well as the recommendation to have adjacent 5 GHz radios operating on non-adjacent channels. This will start to become a bigger issue as we deploy more 5 GHz radios to handle capacity and user density demands. More manufacturers are considering developing software-defined radios (SDR) as well as multi-radio APs that have more than one radio operating in the 5 GHz band. You should carefully research and verify (through real-world testing) these solutions to ensure that interference within the AP is not an issue.

As always, the better you understand what's going on at the physical layer, the better wireless engineer and architect you will be. 

Happy signal hunting,
Andrew 

Wednesday, April 2, 2014

10 Wi-Fi Terms You've Probably Been Using Incorrectly

Sometimes we fall into bad habits. Unfortunately, the improper use of terminology is quite common in the Wi-Fi industry. This can cause a great deal of confusion when people discuss technical topics. Therefore, as a Wi-Fi industry, I think we should start referring to the following terms using more accurate terminology so we are all on the same page.

Here goes:

  1. Over-the-Air Rogue APs - if it's not on your wired network, it's NOT a "Rogue AP" so let's start calling them Neighboring APs so we all know what someone is talking about rather than having to inquire each and every time someone mentions a rogue for clarification. And let's reserve using the term Rogue APs for when unauthorized APs are on the internal wired network.
    Correct Term: Neighboring APs

  2. Co-Channel Interference (CCI) - APs and clients that are operating on the same channel don't cause interference with one another, they contend for the same airtime and backoff if another one is transmitting. This is distinctly different from interference where a transmission cannot be properly decoded because the receiver can't distinguish the valid signal from noise.
    Correct Term: Co-Channel Contention (CCC)

  3. Collision - okay, here is one that most of you may not have really thought deeply about. Collisions don't actually happen on wireless networks (not in the traditional wired network meaning of the term 'collision'). Instead, the receiver simply cannot properly decode a valid signal because it can't distinguish it from the surrounding noise with the precision required by the modulation used.
    Correct Term: Interference

  4. Coverage Area - most Wi-Fi professionals refer to an APs coverage area as the physical area in which they intend for clients to connect to the AP, usually with an associated signal strength (such as -67dBm). However, the RF signal actually keeps going and can cause co-channel contention (see what I did there!) over a much larger area (usually out to a signal strength of around -85dBm). So, to refer to the area in which we expect clients to connect to the AP based on an RF design let's start using a different term such as Association Area and leave the term Coverage Area to refer to the area where CCC occurs.
    Correct Term: Association Area

  5. AES versus TKIP - this one is easy to get wrong, even for Wi-Fi professionals! Many times we interchangeably use AES, TKIP, and WEP to refer to the encryption on the wireless network. However, in so doing we confuse encryption protocols with cipher suites. For accuracy we should always mention like for like. CCMP, TKIP and WEP are all encryption protocols that we configure for a wireless network. Each of those protocols use a cipher suite to accomplish the heavy lifting: CCMP uses AES, TKIP uses RC4, and WEP uses RC4. Thanks to George Stefanick for bringing this up.
    Correct Term(s): Reference protocols (CCMP, TKIP, WEP) or ciphers (AES, RC4) but don't use them interchangeably

  6. 802.1x - I see this all the time in written material to refer to the IEEE 802.1X Port Based Network Access Control. Unfortunately, it should be used with capital letter 'X' since it is a (standalone) standard, whereas lowercase letters refer to amendments to standards (see here). So, whenever you reference it use the correct capitalization (802.1X).
    Correct Term: 802.1X

  7. WAP - many people use this term to refer to an access point and it's just annoying. It's just AP people. Referring to it as wireless AP (WAP) is just redundant.
    Correct Term: AP

  8. Antenna Gain in Decibels (dB) - many people refer to antenna gain in dB, which is incorrect. Decibels (dB) alone is a relative measurement and requires a point of reference. Instead, you should refer to antenna gain referencing either an isotropic radiator (dBi) or less commonly referenced to a standard dipole antenna (dBd). This establishes the absolute reference point for the measurement which actually gives it meaning.
    Correct Term(s): dBi or dBd

  9. 802.11b 1 Mbps and 2 Mbps Data Rates - do you reference all of the lower data rates of 1, 2, 5.5, and 11 Mbps as 802.11b? If you do, you've been using this amendment name incorrectly. The original 802.11 standard (802.11-1997) defined the 1 Mbps and 2 Mbps data rates as part of the DSSS PHY, as is generally referred to as 802.11 Prime. Then in 1999, along came the 802.11b amendment which added the 5.5 Mbps and 11 Mbps data rates as part of the HR-DSSS PHY. So, to be correct, when talking about 1 Mbps and 2 Mbps data rates you should reference 802.11-Prime (not 802.11b).
    Correct Term: 802.11 Prime (or 802.11-1997)

  10. 5 GHz Signals Attenuate Faster than 2.4 GHz Signals - it's common for many Wi-Fi professionals and writers to state that 5 GHz signals attenuates faster than 2.4 GHz signals in order to describe the common symptom that 5 GHz has less effective coverage area. However, this too is incorrect in most circumstances. 5 GHz signals attenuate through free space at the same rate as 2.4 GHz signals according to the FSPL (free space path loss) formula; it is not directly dependent on the frequency of the signal. Instead, the construction of the receiving antenna is a fractional multiple of the frequency to which it is tuned. This makes a standard 1/4 wavelength antenna for 2.4 GHz longer than a 1/4 wavelength antenna for 5 GHz, which causes a difference in antenna aperture. To put it simply, a 2.4 GHz antenna has a larger aperture than a similar 5 GHz antenna and can "capture" more of the signal as it passes by the antenna element.
    Correct Term: 5 GHz Antennas Have Smaller Apertures

Do you have any other terms that are misleading or misused and you think should be corrected? Drop a comment below!

Thanks,
Andrew

Thursday, March 13, 2014

WLAN Professionals Conference Videos Posted

Videos of presentations from the WLAN Professionals Conference that occurred Feb. 10-12th in Austin, TX have now been posted by Keith Parsons and the Prime Image Media team. The conference was chalk-full of great content, both technical and business focused, by some of the best experts in the industry!

I had the honor of presenting a session titled "Going Beyond RF Coverage: Designing for Capacity." The topic is about how to define, measure, and plan for capacity needs for ALL wireless networks (not just high-density environments - for which no commonly accepted definition even exits). I provided a bit of background on why I decided to give my presentation on this topic in my previous blog "Mind the Gap in Your WLAN Design" and you can download the full presentation and related material.

Check it out!


WLAN Pros Summit 2014 | Andrew Von Nagy Beyond RF Coverage 1 from Keith R. Parsons on Vimeo.

Be sure to check out all of the great presentations from the event on the WLAN Pros website and Keith's Vimeo channel!

Cheers,
Andrew

Tuesday, February 11, 2014

WLPC Conference Day 1 Highlights

I'm here at the WLAN Professionals Conference (#WLPC if you're following on Twitter). This is the first of what hopefully will turn into an annual conference dedicated to the Wi-Fi industry. But this conference is a bit different than what you might think a typical conference is. First and foremost, it's got a grassroots, peer-to-peer focus. It's engineers talking about Wi-Fi and gathering for discussion. It's not overly promoted by vendors or full of presentations with marketing drivel. Instead, it's just people who are passionate about this technology coming together to share their knowledge and experiences with each other to better everyone! What a great concept!

There are over 100+ attendees, many of whom are also presenters. I hear there was more demand than seats available, so next year Keith Parsons, organizer of the event, should have a solid baseline to grow the conference and allow more of you (the community) to attend and get involved. What's also great is that many of the presentations have been interactive, with great questions and quality discussion fostering the entire group to share information. The focus on the technology instead of the marketing that so often surrounds the technology and products in this industry. That's refreshing!

Day one of the conference was full of great content. Since there are two tracks of presentations, I can't cover all of the great presentations that occurred, but all sessions are being recorded so I plan on going back and watching the ones that I missed. Here are the highlights that stuck out from day one for me.

First up, Matthew Gast presented on 802.11ac. In typical Matthew Gast fashion, "minds were blown!" Matthew mixes the technical geeky details along with practical implications of the technology on real-world networks and the motivations that IEEE standard developers considered when drafting the protocol amendment. At one point Matthew also entered The Matrix (no not that virtual world in which machines rule mankind, rather the steering matrix for RF beamforming), but luckily spared the audience by dumbing down the mathematics for normal engineers :) Attendees also received a copy of his 802.11ac book.

Matthew Gast presents on 802.11ac

After a much needed coffee (and brain) break, Chuck Lukaszewski presented on high-density WLAN design. Chuck's presentation highlighted the method he uses to gather a Rough Order of Magnitude (ROM) to scope customer expectations and frame the design and budget early on in the process. This included understanding the associated user capacity, active user capacity, AP layout requirements, infrastructure dimensioning, and developing the ROM quote. This serves as a great starting point to ensure all parties are on the same page early on in the project and to focus more detailed activities that will follow with on-site visits such as site surveying and design.

High Density Rough Order of Magnitude (ROM) Process

Chuck then turned to RF coverage design in stadiums, detailing the mounting options available and the preferred methods his team uses in different situations to minimize co-channel interference. One point that he highlighted was music to my ears... the fact that CCA Busy is triggered by the physical preamble and PLCP header (and NOT by the ability for a receiver to decode the MAC header and read the Duration/NAV value). This impacts the distance at which an AP or client causes CCI because the preamble and PLCP header is encoded at the minimum PHY Basic rate (e.g. 1, 2, or 6 Mbps) and can be decoded at great distances! I've been explaining this to anyone who will listen for several years and it has a HUGE impact on RF network design.

Interference (CCI) goes MUCH farther than you think!

Brad Crump from CWNP discussed certifications and your career. This was one of the most engaging and useful discussions that I've had at the conference so far. Brad posed several questions to the audience about learning methods (live class, online, self study, boot camp) which prompted some passionate debate in the room. Several members of the audience were current or former instructors and had some very good information to share about how they've been able to effectively train students. Additional discussion on vendor-neutral and vendor-specific training was lively as well. Brad framed the discussion by explaining that there is a trade-off between acquiring knowledge and attaining a certification that HR managers are looking for in employee candidates. In short, HR managers are looking for "Expertise" and they often recognize vendor brand certifications like Cisco more than vendor-neutral. But Brad and team (including Julia Baldini, marketing whiz) are working to build the CWNP into a globally recognized brand! Woohoo, I wish them great success in this endeavor. I'm a big fan of CWNP content and certifications. Go get some CWNP people!

What is expertise?

Charlie Clemmer talked in the afternoon about RF in warehouse environments. Since I used to be directly responsible for managing over 3 dozen large warehouses with varying sizes and product inventory, this is a topic near and dear to my heart. Charlie shared is insights on why warehouses are not as easy as most people think. Sure, the clients typically require low bandwidth for telnet/SSH and warehouse management applications. But the environment can be extremely challenging due to legacy client compatibility issues, very high ceilings, unique freezer environments, high availability requirements, and some interesting IDF and wired network restrictions. Once again, great discussion ensued with the audience. Several seasoned wireless engineers who deal with warehouses shared their experiences and how to solve for some of the unique challenges that can be encountered. One topic of large discussion was how to cost-effectively design WLANs by performing a hybrid site survey with predictive modeling that is grounded with real-world data from on-site surveying in select sample areas of the warehouse. Otherwise, performing a full site-survey for warehouses that can be thousands or millions of square feet in size is too time consuming and expensive.

Charlie Clemmer presents on RF in warehouse environments

Finally, I'd like to give a quick shout out to all of the old friends that I've seen this week and new friends that I've met in person for the first time. These types of events are absolutely great to meet fellow peers in the industry! Also, a shout out to Prime Image Video who are recording all of the sessions and working their magic to make this content available for everyone online who couldn't attend in person. Ben and Andrea are awesome people and they are outstanding media professionals! If I haven't met you in person at the conference yet, don't be shy, come up and say 'Hi'!

Cheers,
Andrew von Nagy


P.S. If you're at the conference, I'll be speaking about capacity planning for every WLAN on Wednesday morning. I hope you'll swing on in!

Wednesday, February 5, 2014

Mind The Gap in Your WLAN Design

Over the past few years I've had the opportunity to travel for work, a lot. I'm always navigating airports large and small, and trekking out and about around urban areas finding my way from airport to hotel to meeting venue or just plain exploring the local scene in my free time. I've got a bit of an "adventure seeker" flair as well, so sometimes I just head out on my own without a map, guide, or itinerary just to soak up the local culture and find the backroads that really embody the travel destination that I find myself in.

In urban areas, this invariably involves navigating the local railway or subway system. In many places all the signs are posted in both the local language as well as English, but I always try to force myself to gather the meaning of the signs without resorting to reading the English version. One sign that is almost universal among these train systems is the warning to "Mind The Gap" between the railcar and the platform. With trains barreling down the tracks at significant speeds, railway architects need to leave a buffer of space to ensure the cars don't hit the platform.

It occurs to me that with greater velocity or momentum comes the need for more flexibility in design at the sacrifice of a small amount of precision. However, there is a fine balance to this design that must be maintained. Make the gap too large and passengers are at greater risk of injury. Make the gap too small and the rail design is too inflexible, causing damages and the system ends up breaking down quickly requiring replacement.



This serves as a fairly good analogy, in my estimation, for the wireless LAN industry. The WLAN market is like the railway car, picking up velocity and traveling at a fairly fast speed down the tracks. No one can deny the pace of change in the WLAN world, where users are adopting Wi-Fi mobile devices in record-breaking numbers, the Internet of Things (IoT) is on the horizon, and businesses are finding that Wi-Fi can actually enable new services and insights that help them differentiate. Users, meanwhile, are standing on the platforms trying to hop onto this fast-moving train, all-the-while expecting an effortless and satisfactory experience that they have been accustomed to for the past decade. WLAN administrators are caught in the middle, trying to design these systems to be flexible enough to accommodate the increased velocity and change in the industry while trying to minimize the "gap" between the railway car (WLAN services) and the platform (Users). A tough job indeed!

If WLAN administrators have any hope of succeeding in minimizing the gap, they need to place proper focus on understanding market direction and be armed with the proper tools and resources to effectively design a solution that not only meets the current needs but future needs as well. With every new advancement that comes along, the industry is challenged to identify and develop tools that enable administrators to effectively design the WLAN system based on these new capabilities and changes user demand. If the gap widens too far (product advancements or user demands outpace the ability for administrators to effectively design the WLAN) then users are at risk of falling through and suffering a poor user experience and dissatisfaction.

Therefore, a constant ebb and flow exists in the industry where the gap widens as advancements are made and user demands change, only to shrink as the technology matures, deployment experiences reveal what works and what doesn't, and administrators gain the resources to design and plan for the new requirements.

One of the major "gaps" that has arisen over the course of the last several years is the overwhelming increase in demand for Wi-Fi capacity but the lack of quality resources and tools for network administrators to design for capacity requirements. Instead, WLAN admins are forced to twist RF coverage design tools into what they need using crude rule-of-thumb estimates on the number of APs per square meter / feet based on an ambiguous (at best) concept of the network type they are planning for such as data, voice, or location-services.

I say enough is enough! We need:
  • Solid Understanding - Administrators need to understand what factors determine capacity in a WLAN, including AP and client capabilities, applications in use on the network, and the unique mix of devices on their network.
  • Holistic Planning - Administrators need to fill the gaps in the WLAN design process to adequately perform capacity forecasting. This includes proper research and requirements gathering as well as integration of capacity planning alongside RF coverage planning.
  • Design Approach - Administrators need an approach to WLAN capacity planning is purpose-built for the job. Relying on RF coverage tools, not designed to account for user density, device capabilities, and application demands is simply not good enough.
  • Quality Resources - Administrators need quality tools and resources that are built specifically to aid in the task of WLAN capacity planning. The lack of quality WLAN capacity planning tools in the industry is glaringly apparent. 
Do you have gaps in your WLAN design process?

I'll be speaking about WLAN capacity planning and presenting a methodology and approach that can be used for every WLAN, big or small, at the Wireless LAN Professionals Conference next week in Austin, TX. If you're attending, please join me on Wednesday, Feb. 12th at 9am CST in Ballroom B of the Hilton Austin Airport Hotel. If you are unable to attend, a recorded video of the presentation will be made available after the event.

Cheers,
Andrew

Friday, November 8, 2013

Referencing Wi-Fi Channel Numbers Correctly

It occurred to me today that many people still use the old Wi-Fi terminology for referencing wide channel numbers in the 5 GHz band. Since channel numbering changed with 802.11ac, I thought it might be helpful to get everyone on the same page when we're talking about channel number.

So here is a quick reference guide to referencing the 5 GHz Wi-Fi channels.


Wide channel numbering changed with 802.11ac:

  • 802.11n Channels (the "old" way)
    • One 20 MHz primary channel, with a channel extension above or below
    • 40 MHz Example: Channel 36, +1
    • 40 MHz Example: Channel 40, -1
    • 40 MHz Example: Channel 36+40
    • This terminology should no longer be used

  • 802.11ac Channels (the "new" way)
    • Reference the center channel frequency for the entire 40/80/160 MHz wide channel
    • Designate one 20 MHz portion of the wide channel as the Primary 20 MHz
    • 40 MHz Example: Channel 38 with Primary 20 MHz channel 36
    • 80 MHz Example: Channel 155 with Primary 20 MHz channel 149
    • 160 MHz Example: Channel 50 with Primary 20 MHz channel 44

Cheers,
Andrew von Nagy

Friday, October 25, 2013

Wi-Fi Alliance Voice-Enterprise Certification: Standardized Fast Secure Roaming


Two of the most important aspects of building a successful modern enterprise wireless LAN are enabling transparent user mobility across the network and strong security to protect sensitive corporate data. 

However, these two objectives have historically been difficult to achieve in tandem. A balancing act between mobility and security has caused an unpleasant trade-off for organizations due to the time-consuming processes that strong security methods require. On one hand, high performance mobility can be provided when relatively weak security is implemented with an Open or WPA2-Personal WLAN, but this leaves sensitive corporate data at higher risk of exposure. On the other hand, much stronger security can be implemented with WPA2-Enterprise, lowering the exposure risk of sensitive corporate data, but resulting in poor mobility performance due to the time-consuming 802.1X authentication process. Thus, the introduction of more secure Wi-Fi networks solved one problem (security) but created another (roaming performance).

The industry needed a high performance, yet secure, solution to this mobility problem. The answer lies with fast secure roaming. Pre-standard solutions, such as CCKM and OKC have been around for some time but have failed to realize widespread adoption, especially by client manufacturers. The Wi-Fi Alliance™ Voice-Enterprise certification program, introduced May 2012 and already appearing in major WLAN products, brings a standards-based fast roaming method to market, which serves to align infrastructure and client manufacturers on a common implementation method and provides the benefits of low-latency roaming performance while maintaining strong security with WPA2-Enterprise.

I dive deeper into the Voice-Enterprise certification program and implementation details of fast secure roaming in the new whitepaper, "Wi-Fi Alliance Voice-Enterprise Certification: Standardized Fast Secure Roaming" [PDF].

Whitepaper: Wi-Fi Alliance Voice-Enterprise Certification
(Click to Download)

Download this whitepaper to learn:
  • Challenges in providing both transparent user mobility and strong security
  • Requirements that products must pass to achieve Voice-Enterprise certification
  • Performance criteria that Voice-Enterprise products must achieve
  • Technical details of the Fast BSS Transition specification, based on IEEE 802.11r, for both controller-based and controllerless WLANs
  • Performance optimizations available with Radio Resource Measurement (802.11k) and Wireless Network Management (802.11v), both part of the Voice-Enterprise program
Cheers,

Friday, October 4, 2013

SSID Overhead - How Many Wi-Fi SSIDs Are Too Many?

One of the most commonly cited best practices among Wi-Fi professionals is to the limit the number of SSIDs you have configured on your WLAN in order to reduce the amount of overhead on the network and to maintain high performance. But there is not a lot of public data out there to really drive home this point when explaining it to another engineer, management, or a customer. Simply telling someone that they shouldn't create more than 'X' number of SSIDs isn't very convincing.

Therefore, I've created a visual tool to help you explain WHY too many SSIDs is a bad thing:

The Wi-Fi SSID Overhead Calculator
(Click Image to Download)
Wi-Fi SSID Overhead Calculator

This tool calculates the percentage of airtime used by 802.11 beacon frames based on the following variables:
  1. Beacon Data Rate - beacon frames are sent at the lowest Basic / Mandatory data rate configured on the WLAN. Beacons must be sent at a "legacy" data rate, meaning only 802.11a/b/g rates. Select the beacon data rate from the drop-down menu within the tool.
  2. Beacon Frame Size - beacon frames can vary in size based on the version of the 802.11 standard implemented (802.11a/b/g/n/ac) and features enabled on the WLAN (such as 802.1X authentication, CCX, 802.11r fast roaming, and 802.11u Hostpost 2.0). I recommend using a wireless sniffer to capture a beacon frame from your WLAN for use within the tool. Enter a beacon frame size that represents the total size of the MAC header and data payload.
  3. Beacon Interval - beacon frames are sent at a default interval of 102.4ms, but this may be modified in most enterprise WLAN products. Note that beacons are always sent at a multiple of the Time Units (TUs), where one TU equals 2^10 Kilomicroseconds (or 1.024 milliseconds). Therefore, 100 TUs equals 102.4ms. Enter the time interval between beacons, in milliseconds.
The calculation includes the inter-frame spacing (using WMM), physical layer preamble and header, MAC layer header, and data payload. It calculates the amount of time required for modulation of the bits over the air, but does not account for collisions or retransmissions. Technically, you wouldn't reach 100% airtime utilization on a Wi-Fi network because medium contention due to collisions and retransmission backoff result in a maximum airtime utilization of around 80-90%. But for SSID overhead planning purposes this level of detail is not required because the network will be equally degraded if we represent it with or without the collisions.

The tool also takes into consideration the number of co-channel APs within the physical area. All access points, either from your WLAN or a neighboring WLAN, contribute to the overhead on the channel. Remember, Wi-Fi operates in unlicensed spectrum and everyone shares the airtime!

I have also included a subjective rating of the amount of overhead into the following categories:
  • 0-10% = Low Overhead
  • 10-20% = Medium Overhead
  • 20-50% = High Overhead
  • >50% = Very High Overhead

You should ALWAYS attempt to keep your WLAN at low overhead (0-10%). 

If you have an existing deployment that falls within the medium overhead range (10-20%) you might consider methods to consolidate SSIDs and reduce the amount of overhead as your WLAN needs evolve over time. 

If you have an existing deployment that falls within the high overhead range (20-50%) you are likely experiencing significant performance problems on your WLAN already and should investigate immediate methods to consolidate and eliminate SSIDs at the earliest possible time.

If you have an existing deployment that falls within the very high overhead range (>50%) it is likely that you are in a highly congested area and will need to coordinate the WLAN configuration with your neighbors in order to reduce the amount of overhead to a reasonable level. This is common in dense urban / downtown areas and in multi-tenant buildings. 

I hope this tool proves useful. Enjoy!

Cheers,
Andrew 

Tuesday, April 2, 2013

High-Density Wi-Fi Design Part 3 - WLAN Configuration Best Practices

In this video, I explain the best practices for configuring a Wi-Fi network for high-density environments. These include:
  • Proper encryption required to use 802.11n high throughput data rates
  • Proper use of Quality of Service (QoS) through Wi-Fi Multimedia (WMM)
  • Disabling lower data rates to maintain high performance
  • Prioritizing key business applications over recreational applications
  • Client rate-limiting to prevent "greedy" clients from hogging bandwidth
  • The important role that bi-directional band steering plays in optimizing spectral use
  • Load balancing clients based on airtime utilization on different channels to serve users where the most capacity exists
  • Using airtime fairness to adequately handle a mixed-client environment
  • Proper consideration of wired network resources, including switch port bandwidth, power over Ethernet, and Internet/WAN bandwidth
  • Appropriately sizing IP subnets to account for device density and user mobility


These principles are covered in more depth in the Aerohive High-Density Wi-Fi Design and Configuration Guide.

Read the Entire High-Density Wi-Fi Design Series:
Design Your WLAN for High Capacity
Video Blog: High-Density Wi-Fi Design Part 1 - Forecasting AP Capacity
Video Blog: High-Density Wi-Fi Design Part 2 - RF Planning
Video Blog: High-Density Wi-Fi Design Part 3 - WLAN Configuration Best Practices

Cheers,
Andrew

Monday, April 1, 2013

¡Viva la Revolución! Three Years of Revolution Wi-Fi

Three years ago today I started the Revolution Wi-Fi blog as a way to aid my Cisco CCIE Wireless studies. What started out as a location to store and share my notes as I strived to achieve those prestigious "digits" quickly turned into a platform that allowed me to voice my opinions on the state of the industry and to help educate others seeking to know the mysterious ways of WiFi. Now here I am, 212 posts later!

Finding My Style
My writing over time has changed quite a bit. Early on my posts were strictly technical, in a "just-the-facts" type of way. I wasn't accustomed to putting my own analysis and opinions down on paper. Being an engineer meant sticking to the technology allowed me to stay in my comfort zone while trying out this whole blogging thing. This was also quite easy to do since my wireless studies back in 2010 has progressed beyond learning the basic RF foundations (thank you CWNP) and I became entrenched in Cisco-world. Therefore, the early posts focused on the ever-present "Cisco Way" of implementing wireless networks: learning their features, how to configure Cisco networks, and how controllers and APs operated in tandem.

However, as I became more comfortable with blogging, I definitely learned to dive a bit deeper beyond the 0's and 1's to provide a well-reasoned opinion and analysis. I also became more comfortable in my knowledge by interacting with other professionals on social media (especially Twitter) and realizing that the world was woefully short of great Wi-Fi engineers (relative to demand) and needed those with experience and expertise to share their knowledge with others and help grow our ranks. Some of my posts have been controversial, some have touched a nerve (especially with vendors), but mainly I've received overwhelmingly positive feedback on my analysis. Many of my posts have also spurred great conversations that allow me to see alternate perspectives on topics and re-examine my own analysis. That is perhaps the biggest personal benefit I have found through blogging, the ability to deepen my own understanding by interacting with others.

Finally, I've found that I like writing about many complex topics through a series of posts. In the article archives section you'll find series on wireless QoS, fast roaming, high-density networks, 802.11ac Gigabit Wi-Fi, industry analysis, and vendor-specific products. Let's face it, Wi-Fi is a complex subject and requires integration with other equally complex technologies (*ahem* EAP). Designing and deploying wireless networks aren't for the timid; it requires good organization, a focus on planning, thoroughness of execution, and significant attention to detail. I find such complex topics to be best examined with a matching level of detail, broken down into digestible chunks, which lends nicely to writing multi-part articles.

What I've Learned
First, I found early on it was extremely important to establish guiding principles with which I would blog. Those include: 1) to be as objective as possible, 2) to provide relevant and timely content to readers researching often sparsely documented topics, and 3) to help educate others engineers that aspire to be Wi-Fi experts. Without these principles as a blogger, I might as well get paid for my writing as an analyst or vendor-shill. This does not mean that I am unbiased, I'm not. No one is in my estimation. But I strive to take an objective eye, ensure that I'm well-informed, consider alternate perspectives, and provide an honest opinion that I believe is accurate. It's important to understand that the blog post does not end when I hit the publish button. Rather, it only begins. I've placed my knowledge and opinion out there for the world to read and react to. The dialogue after a post has been published is where the topic grows legs, spurs conversations, and allows those participating to grow better at our craft through dialogue with others.

Second, despite working in a digital world, not everything is black and white, 0 or 1. Analysis matters! Where vendor materials pronounce great capabilities but gloss over the important details, independent bloggers pick up the slack and dive-in to separate the oil from the water, the marketing FUD from the real-world benefits.

Third, your employer will have hesitation about you blogging! This can take a variety of shapes, but in general I've found that your employer will be cautious about one of their employees taking such an active role in social media. This can include fear about divulgence of sensitive information, potential impact to brand image (if a public company) or to vendor and partner relationships, and HR related concerns about the opinions you express reflecting the company. Be sure to set clear expectations and guidelines with your employer when you begin blogging, and be prepared to re-visit these topics periodically with management.

Blog Statistics
Over the course of the past 3 years, I've received a total of 904,000+ page views! Wow! Just wow! I'm astonished at how many people visit my little corner of the web. I'm even more amazed at this considering two things: the Wi-Fi engineering world is incredibly small (but is growing daily), and my writing is extremely niche - focusing typically on deep technical subject-matter that not many engineers would even need to read.

My readership has grown over time and my blog receives approximately 2,500 views/day (weekdays) 1,500 views/day (weekends), and 55,000 views/month.

Monthly Readership

It also helps when influential industry websites and experts pick up your content and link to it. That big noticeable spike in August 2012 directly correlates to my post on the Defcon cracking of MS-CHAPv2 being picked up in the comments on one of Bruce Schneier's posts (yes, just mentioned in the comments)!

Most Popular Posts:

Article Title Date Published Total Page Views Avg. Page Views / Month
Wake on Wireless LAN Nov. 8, 2010 65,446 2,256/mo
Apple iPad 3 Wi-Fi Specifications Mar. 8, 2012 34,690 2,668/mo
Is WPA2 Security Broken Due to Defcon MS-CHAPv2 Cracking? July 31, 2012 32,973 4,121/mo
Mac OS X Lion Creating Wi-Fi 802.1X Profiles Feb. 7, 2012 26,257 1,875/mo
Wi-Fi Roaming Analysis Part 2 - Roaming Variations Feb. 2, 2012 7,233 517/mo

Several of my most popular posts are from the past year. Hopefully this means that my content is increasingly touching on the most relevant subjects in the industry and resonating with readers!

Opening Doors
The great thing about blogging is the opportunity it has afforded me in my professional career. I've found that people value independent analysis and that translates into establishing a solid reputation in the industry. I can't count how many times I've been fortunate enough to run into one of my readers who has thanked me for the information that I share through this blog.

Before starting this blog, I thought like many others, that Wi-Fi professionals are too few and far between and that I was alone in my quest for knowledge. Although the group is still comparatively small to route/switch/data center professionals, I've found that other great Wi-Fi engineers do exist. And I've been able to meet many of them through the opportunities presented by blogging and interacting on social media. I've been invited to participate in multiple industry events such as Wireless Field Day and Interop, which are always a pleasure.

Blogging has also opened doors to new jobs, mainly by establishing a reputation as a solid networking professional. A great blog is a digital portfolio you can use to highlight your work, often replacing your resume/CV completely. The best opportunities come through those individuals you meet on the path of enlightenment, which is really what a great blog does - informs your readers and yourself!

What's Next
I've recently started experimenting with vlogging through the high-density Wi-Fi design series. It's my first real attempt at using video to explain concepts and share information. But I'm still not sure if it's right for me; it feels awkward being in front of a camera.

I'll continue to write, for sure, and hope to post articles more frequently. However, that is a struggle with my the amount of travel I'm currently engaged in, and my approach to learning is still very much focused on knowing the subject-matter in-depth. That tends to lead to a very similar approach to writing in depth, which takes significant time and effort to research, lab, and organize my thoughts on a subject.

Final Thoughts
What a ride it's been these last 3 years writing this blog. What started out as a personal journey to acquire my CCIE digits (which I did by the way) turned into a place that I could share my experience and knowledge with world and interact with others equally passionate about Wi-Fi as I am. I've learned a great deal and become a better engineer through the conversations my articles have prompted. I've met many of my readers and received great feedback, giving me the motivation to continue writing. I've met other Wi-Fi professionals and been able to network in the community in ways I never imagined when I started.

I'd like to thank all of my readers, new and old, for having the desire to learn, being passionate about wireless and networking technologies, questioning and challenging my opinions at times, and helping me become a better engineer through the process.

¡Viva la Revolución!

Andrew

Sunday, December 23, 2012

Cellular MVNO's Increasingly Rely on Wi-Fi Offload to Net Subscribers

Are MVNOs pioneering the next "innovation" wave in cellular? The answer may be 'Yes' based on unique business models that appear to be working.

Cellular MVNOs (Mobile Virtual Network Operators) are gaining attention and subscribers in the U.S. due in-part to cheaper pricing models built around BYOD and Wi-Fi offload:

many new MVNOs are adopting Bring Your Own Device (BYOD) strategies, with SIM-only MVNOs like Simple Mobile, Red Pocket and Ultra on the GSM side, and a new BYO Sprint Device solution for MVNOs like Kajeet, Ting and others on the CDMA network. Sprint’s BYOSD program has the added benefit that no SIM kit or installation is required; the handset is activated simply via its serial number.

With BYOSD, for example, Kajeet offers network-based parental controls, web filtering and location services on recycled handsets. BYOD solves two problems for the MVNO – eliminating handset subsidies and reducing logistics cost (kitting, shipping, warranty repairs and returns). Even where customized handsets are used, MVNOs sell them above cost, eliminating costly subsidies.
[...]

Service – airtime and data – costs can also be reduced. With increasing data usage, many MVNOs utilize dual-mode phones (cellular and Wi-Fi) to offload voice and data traffic to Wi-Fi networks, which is increasingly available in homes, offices and businesses. And an added benefit for providers: offloading to Wi-Fi turns off the carrier’s meter.
[...]

When Republic Wireless introduced its $19/month unlimited plan as a beta trial, everyone asked how they planned to do it. Republic relies heavily on Wi-Fi networks at home and work, using “hybrid calling” or cellular offload where traffic only rolls to Sprint’s cellular network when Wi-Fi is unavailable. Republic is now shipping a Motorola Android smartphone, running proprietary Republic software (for $259), which completes the no-contract package. And apparently the beta trial worked just fine: the same $19 plan is now available to all.

FreedomPop guarantees 500MB of free 4G mobile broadband data every month, with no data caps or throttling, and attractive plans ($17.99/month for 2GB of data, a cent per MB additional). Customers can earn additional data for each friend referred or unlimited data by engaging in partner promotions. The Freedom Hub Burst, a 4G Wi-Fi router that offloads cellular to wireline and supports up to 10 devices, is free with security deposit. They also offer the Freedom Sleeve Rocket, an iPod Touch case that turns it into an iPhone. Plans include trading bandwidth with other FreedomPop users, and creating bandwidth-sharing communities. Launched on Clearwire, FreedomPop will add Sprint’s LTE network next year.
For those unacquainted with MVNOs, they purchase wholesale access to the larger carrier networks and repackage services with different pricing plans to subscribers.

What I find interesting is the unique business approaches being offered by MVNOs through a combination of cellular data coupled with prioritized Wi-Fi offload when Wi-Fi is available. BYOD is also a new approach in the cellular world, where historically strict control over subscriber client device options helped ensure network performance.

MVNOs are also leading solutions to ease international cellular data roaming.
If you travel overseas and want to maintain your mobile data connection, you’re either going to pay criminal roaming rates or endure tremendous hassles avoiding them. But a new breed of virtual operators like Voiamo are looking to create the first truly international plans.
[...]

To put it simply, international data roaming is broken, and no U.S. carrier seems to be lifting a finger to fix it. They seem to prefer the miserable status quo to the headaches required to repair the system. But where the network operators are falling down, mobile virtual network operators (MVNOs) are picking up the slack.
[...]

While most MVNOs tend to work in a single country with a single carrier, there’s nothing preventing them from buying capacity on multiple networks in multiple countries and then selling international access to a customer in a single pricing plan.

London-based Voiamo, however, is thinking bigger with a new service called GlobalGig. Instead of just renting you a hotspot and selling you a temporary plan when you travel, it proposes to replace your current country-limited 3G or 4G modem plan with a service that will work in multiple countries with a single pricing plan. Its rates are a comparable to the prices most of the major carriers charge for hotspot plans — starting at $25 for 1 GB a month and up to $50 for 5 GB — but those rates are good for the U.S., the U.K. and Australia.

In the U.S., GlobalGig uses Sprint’s network, while in the U.K. and Australia it uses the 3 and Optus networks, but it is negotiating deals with carriers in other countries and plans to expand its global footprint soon, Voiamo CEO and founder Nigel Bramwell said. Its $120 hotspot — which can connect up to five devices through Wi-Fi — can support networks in 100 different countries, Bramwell said. As GlobalGig adds more carriers to its roster it will periodically send out new SIM cards to its customers, expanding their coverage to new countries.

MVNOs are typically thought of as services that cater to the more price-conscious consumers; those that can't afford more expensive contracts by the larger carriers that lock subscribers into 2-year commitments.

But perhaps it's time to re-assess their offerings and take a serious look at MVNOs for better service offerings than their larger competitors.

Cheers,
Andrew

Tuesday, July 31, 2012

Is WPA2 Security Broken Due to Defcon MS-CHAPv2 Cracking?

Quick answer - No. Read on to hear why.

A lot of press has been released this week surrounding the cracking of MS-CHAPv2 authentication protocol at Defcon. For example, see these articles from Ars Technica and CloudCracker. All of these articles contain ambiguous and vague references to this hack affecting Wi-Fi networks running WPA2 security. Some articles even call for an end to the use of WPA2 authentication protocols such as PEAP that leverage MS-CHAPv2.

But they fail to paint a true and accurate picture of the situation and the impact to Wi-Fi networks. I think this is misleading, and that any recommendations to stop using PEAP are flat-out wrong!

So let's clarify things.

Is MS-CHAPv2 authentication broken? 
Answer - Based on what I've read, let's assume it is TOTALLY broken. You can read about the details in those other articles. But for the topic of this post, applicability to Wi-Fi networks, it really doesn't matter if it is broken or not.

What is the Impact to Wi-Fi Network Security?
Specifically, does this make much of an impact for Wi-Fi networks where 802.1X authentication is employed where MS-CHAPv2 is used (namely EAP-PEAPv0 and EAP-TTLS)?
Answer - No, it really does NOT. The impact is essentially zero.

* Update - Microsoft has released a security advisory which recommends the use of PEAP encapsulation to mitigate this attack against un-encapsulated MS-CHAPv2 authentication. 

Let me explain why.

EAP Tunneled Authentication Protocols
MS-CHAPv2 is only used in what we call "tunneled authentication protocols," which includes EAP-PEAPv0 and EAP-TTLS. These EAP protocol specifications acknowledge that many insecure and legacy authentication methods need protection and should not be used on their own. They deal with that by wrapping the insecure protocol inside of another, much more secure, TLS tunnel. Hence, these protocols are called "tunneled authentication protocols."

This tunneling occurs by relying on asymmetric cryptography through the use of X.509 certificates installed on the RADIUS server, which are sent to the client device to begin connection setup. The client verifies the certificate is valid (more on that in a second), and proceeds to establish a TLS tunnel with the server and begin using symmetric key cryptography for data encryption. Once the TLS tunnel is fully formed, the client and server use the less secure protocol such as MS-CHAPv2 to authenticate the client. This exchange is fully encrypted using the symmetric keys established during tunnel setup. The encryption switches from asymmetric key cryptography to symmetric key cryptography to ease processing and performance, which are much faster this way. This is fundamentally the same method used for HTTPS sessions in a web browser.

Here is a reference ladder diagram of PEAP authentication which highlights the different phases of the connection process (outer TLS tunnel setup and inner MS-CHAPv2 authentication).

PEAP Ladder Diagram
(Click for full size image)
So, MS-CHAPv2 is not used natively for Wi-Fi authentication. We're safe right? Only if implemented properly.

Importance of Mutual Authentication
The key link in this chain then is the mutual authentication between the RADIUS server and the wireless client. The client must properly validate the RADIUS server certificate first, prior to sending it's credentials to the server. If the client fails to properly validate the server, then it may establish an MS-CHAPv2 session with a fake RADIUS server and send it's credentials along, which could then be cracked using the exploit that was shown at Defcon. This is commonly referred to as a Man-in-the-Middle attack, because the attacker is inserting their RADIUS server in the middle of a conversation between the client and the user database store (typically a directory server).

RADIUS Server Validation and Exposure to Attack
(Click for full size image)
The RADIUS server is validated as long as the certificate that it sends is trusted. For most client platforms, trusted certificates are provided by the manufacturer for public Certificate Authorities and PKI systems (such as Verisign, Thawte, Entrust, etc.) and are held in the certificate store or keychain on the device. In addition, for corporate environments, administrators can deploy certificates to managed devices in a number of different ways to enable trust for private Certificate Authorities and PKI systems, most common among these methods are Group Policy Objects (GPO) for Microsoft clients and Lion Server Profile Manager or the iPhone Configuration Utility (iPCU) for Apple clients (including OS X and iOS devices).

Enabling Server Certificate Validation on Clients
In Windows the RADIUS server validation is defined within each SSID profile. If you are looking directly on a Windows 7 workstation, you will want to view the SSID properties, select the Security tab, and go into the PEAP settings. Enable server validation, specify valid server names (which are checked against the Common Name - CN within the server certificate presented to the client), restrict which Root CAs the server certificate can be issued from, and prevent the system from prompting users to accept untrusted certificates (which is important, otherwise they could unknowingly accept a bad certificate and connect to an attacker's RADIUS server).

Windows RADIUS Server Validation

In Apple devices, including OS X Lion, Mountain Lion, and iOS, use the Lion Server Profile Manger or iPCU to define a configuration profile which includes credentials and a Wi-Fi policy. I'll show the iPCU in this example. First, add the Root CA certificate into the "Credentials" section. Next, define a Wi-Fi policy which specifies the trusted certificates and certificate names allowed.

Apple RADIUS Server Validation

Client Behavior for Server Validation
In both vendor implementations, the behavior of the client device is dictated by what policy has been defined on the system.

If no policy for the SSID has been defined or pushed to the client device by an administrator, the default behavior is to prompt the user to validate the certificate. This is likely not ideal, since users typically have a hard time distinguishing what a certificate means and whether or not they should proceed. For example, when an Apple iPhone attempts to join a network when no profile has been deployed for that SSID, the user receives a prompt to accept the connection and proceed:

iPhone Certificate Prompt

Therefore, for all corporate 802.1X environments, it is recommended to push profiles for all 802.1X SSIDs that end-users need on their systems. This goes for both production access and BYOD scenarios. The behavior on Windows 7, OS X Lion / Mountain Lion, and iOS devices when a profile has been installed for a specific SSID, is to check the local certificate store or keychain to validate the RADIUS server certificate. It must also match the Root CAs and server names specified in the deployed profile. In the event that an untrusted certificate is presented, all of these systems will NOT prompt the user and the connection is rejected. For example, here is rejected connection by an Apple iPhone for an SSID that has had a profile deployed by an administrator:

iPhone Certificate Rejection

Outstanding Vulnerabilities
You should still be aware of a few indirectly related vulnerabilities that have not yet been resolved relating to Wi-Fi authentication with 802.1X.

First, the default behavior of all systems (especially personal devices) is to prompt users to validate the RADIUS server certificate. This is often confusing and can lead to bad actions being taken by users and attempted authentication through an attacker's RADIUS server. This can be mitigated by having corporate environments deploy configuration profiles for all SSIDs in their network, both production and BYOD. Don't fall into the trap for BYOD of letting users connect on their own and try to decipher the certificate prompt. Establish a sound personal device on-boarding process which deploys a configuration profile to the device upon successful enrollment and policy acceptance. There are numerous ways to do this, ranging from simple solutions such as sending them a profile in an email or providing a web URL where users can download the profile, to more complex solutions such as MDM integration that allow self-registration and zero IT involvement.

Second, certificate binding to the SSID is still a manual process on wireless networks. It must be defined within the configuration profile. This is in contrast to SSL and TLS protocols that are used for secure web access where the end-user system can automatically verify if the FQDN within the URL matches the Common Name presented in the certificate. The manual binding process in Wi-Fi networks is born out of a lack of extensibility within the PKI system to handle network access scenarios such as this. A better solution is needed.

Finally, certificate revocation checking cannot occur by Wi-Fi clients since they do not yet have a network connection with which they can query a CRL distribution point or use OCSP. This means that client devices cannot check the status of the presented server certificate to see if it has been revoked, which could be caused by valid certificates that have subsequently been compromised or certificates that were invalidly issued by a CA. However, there is hope that the forthcoming 802.11u extensions to Wi-Fi can provide the means for this to occur through message exchanges prior to full network connection (thanks to Christopher Byrd for pointing this out to me during a Twitter conversation).


Revolution or Evolution? - Andrew's Take
We've known that MS-CHAPv2 is an insecure protocol for a long time. The recent Defcon exploit has just taken that one step further. Development of modern Wi-Fi security recognized the possible value in using legacy protocols such as these. Therefore, EAP protocols that employed such protocols were designed to tunnel the insecure protocol within a much more robust protocol such as TLS. These "tunneled authentication protocols" such as PEAP ensure protection for these insecure protocols through the use of certificates.

The onus for proper security then falls on RADIUS server validation to ensure the other end of the connection is trusted before allowing the client authentication to proceed. In a properly implemented wireless network, this MS-CHAPv2 exploit is a non-issue.

There is no need for Wi-Fi network administrators to abandon PEAP. Period.

Security is a complex field. It may be hard to distinguish the FUD from fact. If you're interested in learning more about Wi-Fi security, then I highly recommend engineers take training provided in the CWSP (Certified Wireless Security Professional) course offered by CWNP, Inc. or the SEC-617 (Wireless Ethical Hacking, Penetration Testing, and Defenses) course offered by the SANS Institute.

Cheers,
Andrew vonNagy

"Hotspot Zones" Born from Muni-Fi Failures and Hotspot Successes

Remember all those failed Muni-Fi (or Metro Wi-Fi) deployments in the mid-2000's? Well, most of them failed due to a combination of poor business planning where no anchor tenancy was established, advertising wasn't sufficient to foot the bill, over-zealous Wi-Fi design that called for far too few wireless APs (and subsequently poor performance), and difficulty in obtaining access rights to utility poles to get power and backhaul for AP locations which stalled deployments. (Read about all that over here; Minneapolis seems to be one bright spot in all that).

Now, Muni-Fi appears to be making a bit of a comeback. Although everyone has ditched that terminology, likely to avoid bringing the negative connotation that now comes with it :) This is not completely without just cause, as the focus has shifted from providing pervasive coverage over entire cities, to focused coverage in specific public areas where it makes sense. In some respects, I consider these new deployments a hybrid between Muni-Fi (pervasive public area coverage) and Hotspots (coverage in a specific location, typically tied to an establishment such as a coffee shop). I'd call them "Hotspot Zones".

AT&T and other carriers have installed hotspot zones in a few major urban areas, such as Manhattan and San Francisco. And Wi-Fi is even being installed in old phone booths in NYC to ease rights-of-way issues.


LightReading describes this initiative:

New York City's plan to house hot spots in pay phones to provide free Wi-Fi service in the Big Apple illustrates just how much wireless LAN has become part of everyday life even as the public telephone system has become a thing of the past. 
The city is working with pay-phone companies Titan and Van Wagner to install the hot spots, according to NY1 TV.

And the folks at Smart Wi-Fi provide insight on the economics of deployment in old phone booths:
Obviously phone booths are connected via the two wires needed for a POTS line which could easily be augmented with a DSL session.  Along with power, the locations can easily be re-born to a ‘smartphone’ world.  Maybe we can dub these “smartphone booths”. 
Putting Wi-Fi access points into un-used phone banks makes some sense, particularly with the new Next Generation Hotspot (NGH) and HotSpot2.0 initiatives.  Acompany can use their right-of-way to install and maintain the access points while changing back-end service providers (BoingoiPass, AT&T, …) to enable their subscriber’s access.
What's the difference this time around?

First, and most importantly, the deployment model has shifted from "large-scale" Wi-Fi installations trying to light up entire cities and communities, to much more focused "hotspot-zones" where Wi-Fi is deployed in areas that make sense from a public and consumer point-of-view.

Second, Wi-Fi is much more accessible and mobile than it was 7-10 years ago. Users increasingly no longer need to carry around laptops to access Wi-Fi hotspots, they have much more convenient access from smartphones and tablets. That should help increase adoption, improve the free Wi-Fi through advertising business model, and help these hotspot zones succeed.

Finally, Wi-Fi technology has dramatically improved with 802.11n, offering better speeds and rate-over-range for customer devices, translating into better service quality and perception.

It's all about the business model folks :) Okay - and some technology too.

Cheers,
Andrew

Tuesday, May 29, 2012

The Wi-Fi Creed


Vendors have a tendency to bash one another. But despite their differences, they share many beliefs in common. I would like to invite all Wi-Fi vendors to set aside their differences and gather together in professing a common love for this wonderful technology that changes our lives.

I’ll take the first step, and throw out some competitor love. After all, many of us in this industry recognize the innovation of others. I’ll do this by attempting to define a common set of goals that every Wi-Fi vendor should strive to meet. But I will do so by using product marketing catchphrases that various Wi-Fi vendors use. I think it gives it a little twist and creates an inclusive attitude. I call this “The Wi-Fi Creed”.


The Wi-Fi Creed

We BELIEVE in the power of RF, because layer 1 is where we flex our beams, showing the true power of wireless;

We commit to MOVE the industry forward, through the power of standards development and the industry might of our market leaders;

We provide SEAMLESS mobility through the world around us, which enables new applications and improves service delivery for our customers;

We enforce strong security, providing a CLEAR PASS to users and devices only when they meet the defined policy;

We must be ADAPTIVE and flexible, embracing change and moving in new directions when the market demands;

We pledge to translate customer business needs into a MULTI-SERVICE technology solution, capable of delivering robust features;

We aim to SIMPLI-FI enterprise networks, so customers and partners can effectively design, deploy and support mission-critical networks;

We keep PULSE on technologies that change our lives, society, and culture and identify ways to enhance their usefulness;

We strive to meet the demand brought by a dizzying ARRAY of new mobile devices and their explosive growth;

We resolve to shout out from every ROOFNET, evangelizing the power of Wi-Fi!


Won’t you join me?

Cheers,
Andrew vonNagy


P.S. – For brownie points, can you match each statement to the Wi-Fi vendor J