Showing posts with label wlan. Show all posts
Showing posts with label wlan. Show all posts

Wednesday, February 5, 2014

Mind The Gap in Your WLAN Design

Over the past few years I've had the opportunity to travel for work, a lot. I'm always navigating airports large and small, and trekking out and about around urban areas finding my way from airport to hotel to meeting venue or just plain exploring the local scene in my free time. I've got a bit of an "adventure seeker" flair as well, so sometimes I just head out on my own without a map, guide, or itinerary just to soak up the local culture and find the backroads that really embody the travel destination that I find myself in.

In urban areas, this invariably involves navigating the local railway or subway system. In many places all the signs are posted in both the local language as well as English, but I always try to force myself to gather the meaning of the signs without resorting to reading the English version. One sign that is almost universal among these train systems is the warning to "Mind The Gap" between the railcar and the platform. With trains barreling down the tracks at significant speeds, railway architects need to leave a buffer of space to ensure the cars don't hit the platform.

It occurs to me that with greater velocity or momentum comes the need for more flexibility in design at the sacrifice of a small amount of precision. However, there is a fine balance to this design that must be maintained. Make the gap too large and passengers are at greater risk of injury. Make the gap too small and the rail design is too inflexible, causing damages and the system ends up breaking down quickly requiring replacement.



This serves as a fairly good analogy, in my estimation, for the wireless LAN industry. The WLAN market is like the railway car, picking up velocity and traveling at a fairly fast speed down the tracks. No one can deny the pace of change in the WLAN world, where users are adopting Wi-Fi mobile devices in record-breaking numbers, the Internet of Things (IoT) is on the horizon, and businesses are finding that Wi-Fi can actually enable new services and insights that help them differentiate. Users, meanwhile, are standing on the platforms trying to hop onto this fast-moving train, all-the-while expecting an effortless and satisfactory experience that they have been accustomed to for the past decade. WLAN administrators are caught in the middle, trying to design these systems to be flexible enough to accommodate the increased velocity and change in the industry while trying to minimize the "gap" between the railway car (WLAN services) and the platform (Users). A tough job indeed!

If WLAN administrators have any hope of succeeding in minimizing the gap, they need to place proper focus on understanding market direction and be armed with the proper tools and resources to effectively design a solution that not only meets the current needs but future needs as well. With every new advancement that comes along, the industry is challenged to identify and develop tools that enable administrators to effectively design the WLAN system based on these new capabilities and changes user demand. If the gap widens too far (product advancements or user demands outpace the ability for administrators to effectively design the WLAN) then users are at risk of falling through and suffering a poor user experience and dissatisfaction.

Therefore, a constant ebb and flow exists in the industry where the gap widens as advancements are made and user demands change, only to shrink as the technology matures, deployment experiences reveal what works and what doesn't, and administrators gain the resources to design and plan for the new requirements.

One of the major "gaps" that has arisen over the course of the last several years is the overwhelming increase in demand for Wi-Fi capacity but the lack of quality resources and tools for network administrators to design for capacity requirements. Instead, WLAN admins are forced to twist RF coverage design tools into what they need using crude rule-of-thumb estimates on the number of APs per square meter / feet based on an ambiguous (at best) concept of the network type they are planning for such as data, voice, or location-services.

I say enough is enough! We need:
  • Solid Understanding - Administrators need to understand what factors determine capacity in a WLAN, including AP and client capabilities, applications in use on the network, and the unique mix of devices on their network.
  • Holistic Planning - Administrators need to fill the gaps in the WLAN design process to adequately perform capacity forecasting. This includes proper research and requirements gathering as well as integration of capacity planning alongside RF coverage planning.
  • Design Approach - Administrators need an approach to WLAN capacity planning is purpose-built for the job. Relying on RF coverage tools, not designed to account for user density, device capabilities, and application demands is simply not good enough.
  • Quality Resources - Administrators need quality tools and resources that are built specifically to aid in the task of WLAN capacity planning. The lack of quality WLAN capacity planning tools in the industry is glaringly apparent. 
Do you have gaps in your WLAN design process?

I'll be speaking about WLAN capacity planning and presenting a methodology and approach that can be used for every WLAN, big or small, at the Wireless LAN Professionals Conference next week in Austin, TX. If you're attending, please join me on Wednesday, Feb. 12th at 9am CST in Ballroom B of the Hilton Austin Airport Hotel. If you are unable to attend, a recorded video of the presentation will be made available after the event.

Cheers,
Andrew

Monday, August 19, 2013

Wi-Fi Site-Surveying 101

What Is Wi-Fi Site Surveying
Wi-Fi site surveying is a critical component of deploying a successful modern WLAN that meets user expectations and the needs of the organization. The site survey process allows you to understand the unique RF propagation characteristics of the facility and environment into which you are deploying the WLAN. You can validate previously gathered design parameters obtained through predictive modeling using live network measurements to ensure that the deployed WLAN will meet the established coverage, capacity, and performance goals. This section introduces various types of Wi-Fi site surveys and provides guidelines on site surveying to meet the demanding needs placed on a modern WLAN.

This blog series only provides an introduction to site surveying, defining each of the various methods, outlining their objectives, and identifying best practices for success. For more detailed information on different types of site surveys and instructions for performing them, I recommend the CWDP training material provided by CWNP, Inc. For information on using specific software applications to conduct site surveys, refer to the documentation and training supplied by the software vendor.

Remember that a modern Wi-Fi network must not only provide adequate coverage throughout the environment, but must also provide sufficient capacity to meet aggregate demand while simultaneously achieving a high level of application performance and a satisfactory user experience. This is accomplished by maintaining high signal strength and a high SNR for client connections. These two factors allow clients to transmit at maximum data rates, achieve higher application throughput, and reduce individual client airtime utilization. Your Wi-Fi network design should also minimize medium contention by avoiding co-channel interference among both APs and clients and distributing clients and traffic load across the available spectrum. The goal of a site survey is to design and validate that these criteria are being met throughout the entire service area.
Wi-Fi Site Survey Software

Three types of site surveys exist:
  1. Predictive modeling
  2. Pre-deployment (sometimes called “AP-on-a-stick”) surveys 
  3. Post-deployment surveys
I recommend that you perform all three types of site surveys for modern WLANs. However, post-deployment site surveys should always be performed (never eliminate this step)! If peak client density and capacity significantly differ between coverage areas, you might need to gather service requirements for those areas and design individualized Wi-Fi plans for them accordingly. I covered predictive modeling in a previous blog post: Tips for Accurate Predictive Site Surveys. Now, let's discuss pre-deployment and post-deployment site surveys, which have different objectives. I will also discuss Active and Passive surveying techniques that can be used for both pre- and post-deployment surveys.

Site surveys should follow proper requirements gathering and capacity forecasting to meet all design goals for coverage and capacity. You can read more about those topics in my High-Density Wi-Fi Design Series (including three videos: Forecasting AP Capacity, RF Design, and WLAN Configuration Best Practices).

Pre-Deployment Site Surveys
A pre-deployment site survey, often-called an “AP-on-a-stick” survey, is performed before a WLAN network deployment. This type of survey determines the RF signal propagation characteristics of the environment. Measuring and recording the RF behavior in a facility results in a better WLAN design, one uniquely tailored to the physical properties of the environment. You can also use it to verify and adjust a preliminary Wi-Fi network design and to minimize changes to purchase orders once you have procured and installed your WLAN equipment. Spectrum analysis is an integral part of a pre-deployment site survey. Use it to identify and remediate sources of RF interference that could cause WLAN performance issues.

The following are the goals of a pre-deployment site survey:
  • Determine the optimal locations for access point placement
  • Verify coverage in all required areas at the desired minimum signal strength and SNR
  • Ensure that adequate coverage overlap exists for client roaming
  • Establish a baseline of the RF noise floor in each area (using spectrum analysis)
  • Identify sources of RF interference that will impact WLAN performance and require remediation or incorporation into the WLAN design
  • Validate actual client performance (when an active site survey is performed)
Notice that a pre-deployment site surveys includes design criteria prior to deployment of the WLAN infrastructure, such as AP placement. This is one of the major benefits of performing a pre-deployment site survey, because moves/adds/changes are more expensive and time-consuming when identified using a post-deployment site survey.


Post-Deployment Site Surveys
A post-deployment site survey is performed after the WLAN equipment has been installed and configured. This type of site survey reflects the RF signal propagation characteristics of the deployed WLAN. At this point, you have already installed the network equipment, and the focus of the survey is to validate that the installation matches the final network design.

The goals of a post-deployment site survey are
  • Verification of sufficient RF signal strength and SNR throughout the coverage area (this includes spectrum analysis, which is described in the tips section later in this post)
  • Verification of adequate coverage overlap between adjacent Wi-Fi access points for fast roaming
  • Measure and reduce co-channel interference (CCI) among access points operating on the same channels
  • Validate actual client performance (when an active site survey is performed)

The post-deployment site survey provides an opportunity for you to make adjustments before putting the network into production. Perform a passive site survey after deployment to measure RF signal levels from multiple installed WLAN access points as a cohesive system. By doing so, you can validate that the network installation matches the final network design.

Active and Passive Site Survey Techniques
An active site survey is performed when the survey device (a client device) associates to a wireless access point to measure signal strength, noise, bidirectional performance characteristics, and other connection parameters. Measurements are recorded for only a single access point at a time, but they reflect the actual performance characteristics that client devices will experience once the network goes into production. Active site surveys are required to reflect the coverage and performance characteristics for each client device type. For access points that include Transmit Beamforming or smart antenna systems, an active survey should always be performed. However, active surveys do not record information on neighboring Wi-Fi installations that might cause interference. Therefore, active site surveys are best performed prior to WLAN installation during a pre-deployment site survey (“AP-on-a-stick”) to design the internal Wi-Fi network for proper coverage, signal quality, and capacity.

For access points that include beamforming or smart antenna systems, an active survey should always be performed, and signal strength should be recorded from both the client and AP since signal gain due to beamforming only occurs in the downlink direction. A passive survey should also be performed to establish the effective cell size for AP discovery and association by clients since broadcast management traffic does not use beamforming.

A passive site survey is performed when the survey device (a client device) passively scans the RF environment. This type of survey detects all Wi-Fi access points operating within range and measures their received signal strength, noise, and other signal characteristics (depending on the survey application). The survey device typically performs channel scanning across multiple channels in succession to detect access points that are either part of the internal network or belong to neighboring Wi-Fi installations. This method provides detailed information about the interaction among multiple APs regarding channel assignment, coverage overlap, and ACI/CCI (adjacent-channel interference/co-channel interference). It also provides information about multiple virtual SSIDs and SSID availability in various locations. However, passive site surveys do not measure WLAN performance characteristics and can only provide signal strength assessment based on broadcast management traffic like beacons. This approach can also provide an accurate Wi-Fi coverage assessment and cell sizing for access points that use beamforming or smart antenna systems because those APs do not use beamforming to direct management traffic to a single client; they broadcast it. This allows you to perform passive surveys successfully by monitoring management traffic, regardless of whether the APs use beamforming for data traffic.

Passive surveys measure broadcast management frame signal strength, whereas active surveys measure data frame signal strength.

Clients discover and assess access point signal strength for initial association and roaming using either passive scanning of broadcast beacon frames, for which beamforming cannot occur, or through active scanning (probing), which often does not provide a sufficient amount of data to allow beamforming to take effect. Passive site surveys still provide an accurate assessment of Wi-Fi cell sizing for client association and roaming, but not for client performance once connected. Passive site surveys are best performed after WLAN installation, during a post-deployment site survey, to validate Wi-Fi network coverage, channel planning, and ACI/CCI levels.

Active and passive site surveys may be performed either pre or post WLAN network installation. Performing both pre-deployment and post-deployment site surveys is critical to success for a high-density WLAN due to the complex RF design that is required to provide high performance for a large, dense client population.

Site Surveying Best Practices
Follow these guidelines for successful site surveying (in addition to the guidelines for predictive site surveys):

1. Define Coverage Requirements
Before performing the survey, establish the minimum signal strength, minimum SNR, and desired AP coverage overlap requirements the network design must meet in all locations. Recommended values are a minimum -67 dBm RSSI, minimum 25 dB SNR, and 10-20 feet of overlap at these signal levels between APs. These values can be carried over from a predictive site survey, if performed.

2. Survey Both Frequency Bands
Perform the survey primarily on the 5 GHz frequency band to determine optimal AP placement, cell overlap, and co-channel separation. Use the 5 GHz band because at shorter distances between APs, which is typical in high-density environments, the coverage is nearly identical to the 2.4 GHz band. However, 5 GHz signals typically suffer greater attenuation through most RF obstructions and require adequate measurements to ensure sufficient coverage and capacity (no coverage holes!).

The survey must also include signal measurements on the 2.4 GHz frequency band. You can accomplish this while measuring the 5 GHz band if your channel scanning includes both frequency bands for a passive site survey or if you use two Wi-Fi adapters at once during an active site survey. If you cannot survey both bands at the same time, then make a second pass through the environment.

3. Channel Scanning
When performing a passive site survey, configure the survey software to scan only the channels that the production WLAN will be using. The number of channels scanned can affect the accuracy of the sampled data. If you select too many channels, it can take a significant amount of time for the survey software to scan all of them. If you spend an insufficient amount of time at every physical location, then the sampled data will not accurately reflect the location where you recorded it. Monitor the survey software to ensure that you scan all the channels at every sampling location. If performing auto-sampling, also ensure that your walking pace allows sufficient time to scan all channels between each sampling location.

4. Signal Propagation Assessment
Configure the client survey software with the correct signal propagation assessment, which controls how far away from collected data points the software will estimate RF signal quality. The distance should mirror your walking pace if using automatic data sampling or should reflect the distance between manual data sampling locations. In general, shorter signal propagation assessments provide more accurate data but require more data collection points. Use a distance between 10-20 feet (3-6 meters); the smaller the better.

5. Collect Sufficient Data Points
Related to the signal propagation assessment value, be sure to collect enough data points throughout the coverage area during the site survey. Collect them at distances that match the signal propagation assessment value, typically every 10-20 feet (3-6 meters). If you do not collect sufficient data points, the survey will display areas where no measurements were taken within the signal propagation assessment distance. These areas might appear to be without RF coverage and will prevent an adequate assessment of signal strength and coverage for network design validation. To prevent this from occurring, make sure to collect sufficient survey data points; do not increase the signal propagation assessment value!

6. Survey Both Sides of RF Obstructions
For site survey measurements to reflect the signal attenuation characteristics of an RF obstruction accurately, it is necessary to survey on both sides of the object. If you do not, the survey software will attempt to predict the signal loss through an object based only on a pre-defined object type (drywall, for example), which is essentially a guess and might not be accurate. Sampling data on both sides of the obstruction provides accurate RF signal attenuation and signal strength measurements, which are critical to network design as it relates to providing adequate coverage and minimizing co-channel interference. For example, how much coverage and interference will an AP mounted outside an auditorium provide inside the auditorium?

7. Access Point Hardware
Use the exact access point models, antennas, and accessories that will be installed in the production WLAN to ensure accurate measurements of signal propagation and performance characteristics. Access points should be placed in the correct locations, and at the appropriate height and orientation at which they will be used in production.

8. Access Point Configuration
Disable dynamic radio management on the survey APs during the site survey to avoid channel and power changes that could result in incorrect measurements. Configure APs with the transmit power levels that will be used in production or the levels estimated in the preliminary design.

9. Active Site Survey Techniques
When performing an active site survey, use either a production client device operating in site survey mode or configure the survey client radio to mimic a production client device, including power output, power-save, and 802.11n spatial stream settings. Align survey client settings with the least-capable client device considered critical on the production WLAN. This ensures that network performance is adequate for all client devices. If possible, it is advantageous to use multiple client device types that will be used on the production network as part of the site survey process and to test clients in all orientations in which they will be used (for example, landscape versus portrait). Perform the active site survey with only one access point at a time to ensure your client is associated with the correct AP to gather measurements. Configure your survey client to associate exclusively with the BSSID of the survey AP to prevent roaming. (Using only one AP at a time is time consuming; some engineers may opt to use more APs at once to minimize the time required to complete the survey but also risk not gathering sufficient data for every AP location. The choice is yours!)

Ensure that the site survey client captures data at the edge of the contention range for each AP (for example, -85 dBm). This ensures that you collect sufficient data to estimate co-channel interference among multiple APs accurately.

Sometimes active survey data is skewed based on the walking path, typically the path away from the access point. If the data appears to be skewed, perform two active surveys in opposite walking directions and then merge them to obtain more accurate data.

10. Design Validation
Perform 20% of a pre-deployment site survey and then stop to validate the network design against the predictive site survey. If you find significant differences between the measured RF signal propagation characteristics and the predictive model, then adjust the network design to incorporate the newly collected data. This process allows you to identify design changes that could affect AP placements early in the pre-deployment site survey process and can prevent surveying incorrect locations.

11. Spectrum Analysis
Include spectrum analysis in both pre-deployment and post-deployment site surveys to provide a baseline of the RF noise floor in the environment and identify potential sources of RF interference that could negatively affect the WLAN. Use a dedicated spectrum analyzer hardware adapter to provide more accurate data than a Wi-Fi adapter, which typically only guesses RF noise levels based on received 802.11 data frames. Spectrum analysis solutions are available that integrate directly into the same software program used to perform the site survey, simplifying data collection and recording. If you use a separate software program to collect spectrum data, ensure the data is recorded and that it can be accurately mapped back to the original physical locations for future playback and analysis.

12. Documentation
Document the exact installation locations, mounting methods, and non-wireless requirements, such as available switch port capacity and cabling runs from switch closets to AP locations.


Do you have additional tips on site surveying? Please leave your comment below and let's discuss!

Cheers,
Andrew

Friday, May 31, 2013

Apple iOS Fast Roaming with Aerohive Wi-Fi APs

Well folks, after what seems like an eternity, true standards-based Wi-Fi fast roaming is really here! I blogged back in December that Apple iOS version 6.01 added support for fast roaming with 802.11r and 802.11k. And WLAN infrastructure vendors have added support as well, with Aerohive 6.0 and Cisco 7.2 code releases.

Recently, I had the opportunity to test this functionality out on an iPhone 5 and an iPad mini with an Aerohive WLAN. I'd like to share my results with you... and I can tell you that you won't be disappointed! How do 8.5ms roams sound?!


Apple iPad Fast Roaming (1) and Aerohive AP Neighbor Report (2)
As you can see, the iPad completes the roam in 8.5ms, the time it takes to complete the 802.11 authentication and reassociation; no full 802.1X authentication, RADIUS TLS session resumption, or even 4-way handshake are required! This is the result of support for the Wi-Fi Alliance Voice-Enterprise certification on both the WLAN and client. In the tests that were captured, the WLAN was configured for WPA2-Enterprise with 802.1X authentication and dynamic keying. The initial client association resulted in a full 802.1X authentication with the RADIUS server, followed by fast roams as shown above.

Roaming with 802.11r (Fast BSS Transition) is noticeably faster than other proprietary fast-roaming methods (OKC/PKC) and it's also faster than roaming on a Pre-Shared Key (PSK) WLAN. This is because the 4-Way Handshake exchange can be eliminated by embedding the key derivation material (ANonce, SNonce, MIC, and GTK) within the Fast Transition Information Element inside the 802.11 Authentication and Reassociation frames. There is also a Mobility Domain IE that comes into play to distinguish boundaries between different WLANs (since key material must be exchanged between APs on the backend, two separate WLANs cannot facilitate fast roaming).

Here's a look at the Fast Transition IE inside the Reassociation Response (frame 18) from the AP to the iPad:

802.11r Fast Transition Information Element

You may want to review my previous post on The Many Variations of Wi-Fi Roaming to compare the frame exchanges required with each roaming method, CWNP's whitepaper on Fast BSS Transition [PDF] and blogs (here and here) to understand the key hierarchy and exchange between the initial AP authenticator (PMK-R0) and subsequent APs (PMK-R1).

Immediately after the fast roam completes, the Apple iPad submits a Neighbor Report Request within a Management Action frame. In essence, the client is requesting a list of all the neighbors from the AP in order to build a list for future roaming events. This report can be requested on-demand by the client and can help improve roam times by reducing or eliminating the need for the client station to actively scan off-channel. This way, the client has a list of nearby APs that is always up-to-date and can quickly move to another channel where it knows another AP is waiting.

Here is a look inside the Neighbor Report sent back to the iPad from the Aerohive AP (frame 21):

802.11k Neighbor Report
Unfortunately, Wireshark does not yet have a protocol dissector for 802.11k neighbor reports, so manual decoding must be performed. You can see that the Category Code is 5 (Radio Measurement) is used. Inside the tagged parameters lies the neighbor report details, which contains an element for each neighboring AP in the same WLAN and details about the AP such as it's BSSID and channel number which I have highlighted above. In this case, there is one neighboring AP with BSSID "08:ea:44:78:14:28" and it is operating on channel 161 (0xA1 in hexadecimal). Other information in the report includes AP's reachability, security policy (similar or different), and capabilities for spectrum management, quality of service, power save, block acknowledgements, and PHY type (802.11a/b/g/n).

There are three IEEE 802.11 amendments that come into play which are all bundled up in the Wi-Fi Alliance Voice-Enterprise certification.

Standards and Certification Recap
The core of fast roaming was drafted in the IEEE 802.11r amendment, defining "Fast BSS Transition"  or just Fast Transition (FT) for short. The name is derived because every individual AP radio cell is defined as a "Basic Service Set (BSS)" in the standard, and the amendment defines a method for client stations to transition (also called roaming) very fast between AP radios. It accomplishes this by defining a Mobility Domain comprised of a set of BSSs (APs) within the same Extended Service Set (ESS, otherwise known as an SSID) which have been validated. Validated APs must coordinate with each other to exchange client station details, including pairwise master key (PMK) encryption material, and perform pre-authentication of the client prior to the roam. This speeds the client roam by eliminating the need to re-authenticate the client through 802.1X/RADIUS or having to perform the 4-Way Handshake to derive pairwise transient key (PTK) encryption key material even in the case of a simple PSK network. The 802.11r amendement was ratified in 2008.

The IEEE 802.11k amendment on "Radio Resource Measurement" defines methods for information exchange about the RF environment between APs and client stations. The goal is to enable the client stations to understand the radio environment in which they exist so that they have more information to make correct decisions about roaming and performance. Stations can take radio measurements locally, request measurement by other stations, or have measurement requested of them and return the results. One interesting aspect for fast roaming is the Neighbor Report, where a client can request an AP to measure and report the neighboring APs which are available within the same Mobility Domain, including several pieces of operational information about each neighbor such as: BSSID, channel, security policy, and capabilities for QoS, APSD (power-save), BlockAck, spectrum management, and PHY type (802.11a/b/g/n). Some other reports available with 802.11k include: channel load, noise histogram, location configuration information, link measurement, and traffic stream measurements. The 802.11k amendment was ratified in 2008 as well.

The IEEE 802.11v amendment on "Wireless Network Management (WNM)" defines methods for stations to exchange information for the purpose of improving overall performance of the wireless network. Where 802.11k is concerned only with the radio environment, 802.11v expands it to include broader operational data surrounding existing network conditions allowing stations to be more cognizant of the topology and state of the network. There are a multitude of WNM services, the most interesting (for me, at least) is the BSS Transition Management capability, whereby an AP can request a client to roam to another AP for better performance or capacity. Some other services include: co-located interference, diagnostic reporting, directed multicast services, location services, multiple BSSID capability, proxy ARP, QoS traffic capability, and traffic filtering service, to name only a few. The 802.11v amendment was ratified in 2011.

Each of these amendments define numerous capabilities, of which I will only scratch the surface in this post to highlight a few. If you are interested in learning more about the services defined in each of the amendments, visit the IEEE Get Program website to download the 802.11-2012 standard, or search the web for PDF versions of each amendment.

Aerohive WLAN Configuration
Prior to being able to test and execute a fast transition (FT) roam, you need to configure the WLAN infrastructure to support the 11r/k/v features. In Aerohive HiveManager, navigate into the Configuration section and edit the SSID on which FT roaming should be supported. In the Advanced section of the SSID configuration you will see two sections, one for WMM and one for Voice Enterprise.

Aerohive Voice-Enterprise Configuration (IEEE 802.11r, k, v)

Upon checking the first check box for Voice Enterprise, you will be presented with the following notice, informing you that Voice-Enterprise requires 802.11rkv and WMM AC-Voice which will all be enabled automatically.


You may have also noticed the note which states 802.11r requires WPA2 key management. This is because 802.11r advertises FT support in-part through the Authentication and Key Management (AKM) suites in the Robust Security Network (RSN) Information Element, which was included in the 802.11i amendment and WPA2 certification program. Pre-standard WPA did not include the RSN IE and therefore cannot support fast transition. So make sure you're using WPA2 (with either 802.1X or PSK) on the SSID as well.

Save and upload this configuration to at-least two APs, which will then begin including the Mobility Domain IE, Fast Transition IE, and Radio Management capabilities in beacons and probe responses to advertise these capabilities to clients.

Note - no explicit configuration is required to enable Voice-Enterprise on Apple iOS devices. Simply run iOS 6.01 or later and join a Voice-Enterprise enabled WLAN.

Client Limitations
In addition, the RSN IE which advertises encryption ciphers and authentication and key management (AKM) methods in-use on the WLAN to clients now includes a new AKM type to advertise Fast Transition key management. Some existing client drivers have issues parsing the RSN IE with additional AKM and will fail to association to the WLAN - in fact, they won't even try. Until client drivers are updated by manufacturers to support this addition AKM type, they will be unable to join any SSID that has Voice-Enterprise (specifically 802.11r) enabled.

Therefore, it is recommended to create a separate SSID specifically for Fast Transition capable clients and migrate them over to the new SSID.

Final Thoughts
Wi-Fi roaming performance has been a painful sore spot on the industry for many years. Problems were initially obscured through the use of open or WEP encrypted networks where roaming was relatively fast due to the simple security models implemented. However, as security improved with 802.11i and WPA2-Enterprise, roaming performance became a glaring issue, often taking >500ms or worse! This impacted the usability of real-time applications on an enterprise WLAN, forcing many network administrators to rely on less-secure PSK security methods.

Some vendors responded with proprietary fast roaming methods such as CCKM, OKC, and PKC. However, this served to fragment the industry and support for these methods were spotty at best. The IEEE thankfully stepped in and ratified the 802.11r amendment in 2008, yet it has taken nearly 5 years since then for enough momentum to build to finally implement standards-based testing and certification of fast roaming through the Wi-Fi Alliance Voice-Enterprise certification program.

However, now that standards-based fast roaming is here, IT IS GLORIOUS! I applaud Apple for being an advocate for fast roaming and implementing it into their iOS platform, likely because their devices get blamed for poor performance all the time. I encourage other mobile device manufacturers to follow suit, especially if their devices are used with real-time voice or video applications.

Cheers,
Andrew

Tuesday, April 2, 2013

High-Density Wi-Fi Design Part 3 - WLAN Configuration Best Practices

In this video, I explain the best practices for configuring a Wi-Fi network for high-density environments. These include:
  • Proper encryption required to use 802.11n high throughput data rates
  • Proper use of Quality of Service (QoS) through Wi-Fi Multimedia (WMM)
  • Disabling lower data rates to maintain high performance
  • Prioritizing key business applications over recreational applications
  • Client rate-limiting to prevent "greedy" clients from hogging bandwidth
  • The important role that bi-directional band steering plays in optimizing spectral use
  • Load balancing clients based on airtime utilization on different channels to serve users where the most capacity exists
  • Using airtime fairness to adequately handle a mixed-client environment
  • Proper consideration of wired network resources, including switch port bandwidth, power over Ethernet, and Internet/WAN bandwidth
  • Appropriately sizing IP subnets to account for device density and user mobility


These principles are covered in more depth in the Aerohive High-Density Wi-Fi Design and Configuration Guide.

Read the Entire High-Density Wi-Fi Design Series:
Design Your WLAN for High Capacity
Video Blog: High-Density Wi-Fi Design Part 1 - Forecasting AP Capacity
Video Blog: High-Density Wi-Fi Design Part 2 - RF Planning
Video Blog: High-Density Wi-Fi Design Part 3 - WLAN Configuration Best Practices

Cheers,
Andrew

Monday, March 18, 2013

Video Blog: High-Density Wi-Fi Design Part 1 - Forecasting AP Capacity

In my previous post, Design your WLAN for High Capacity, I outlined the increasing demands being placed on modern enterprise WLANs caused by the growth in the number of Wi-Fi connected devices, the proliferation of mobile devices and BYOD, and the increasing reliance on the WLAN as the primary network for users in the enterprise. As described in the Aerohive High-Density Wi-Fi Design and Configuration Guide, the key to supporting this increased demand is to design the WLAN for capacity rather than simply coverage.

The first step in designing a WLAN to meet capacity demands is to perform adequate requirements gathering. This starts with a proper understanding of client device capabilities. Because RF is a shared environment, the capacity is determined by the capabilities of the AP infrastructure and the client devices, application bandwidth requirements, and the resulting airtime utilization that results from their unique combination.

In this first of three videos on high-density Wi-Fi design, I describe how these variables interact and can be used to derive a preliminary forecast of the required AP capacity to support the intended network load. I also walk through a few examples to highlight how to apply this method to both homogenous and heterogeneous client environments.

The resulting AP capacity forecast is a starting point to aid the RF design and site survey process. The value in deriving the AP capacity forecast is to ensure that capacity needs are properly accounted for in the site survey process. For example, even though one AP may provide adequate coverage in a university lecture hall, several more APs may be required for capacity. Historically, RF site surveys have only focused on providing adequate RF coverage for the physical area, which may provide sufficient signal in all desired locations but lack AP and channel capacity to successfully support the client and application load.




Once you’ve watched the examples in the video, walk through a few of your own scenarios using the requirements gathering worksheets in the appendix of the Aerohive High-Density Wi-Fi Design and Configuration Guide.

Stay tuned for the remaining two videos in this series, where I’ll cover key RF design and network configuration principles for high-density networks.


Read the Entire High-Density Wi-Fi Design Series:


Cheers,
Andrew



Full Disclosure - This video was created in cooperation with Aerohive Networks, my current employer. 

Monday, December 10, 2012

Design your WLAN for High Capacity

High-Density Wi-Fi Design Series:

The demand for high-capacity Wi-Fi networks continues to grow at an astonishing rate. The migration to 802.11n has taken Wi-Fi networking within the enterprise from an overlay to existing wired networks and made it the primary network connectivity method. And the upcoming 802.11ac standard promises to boost demand for Wi-Fi even higher. Users are increasingly adopting mobile devices that solely rely on Wi-Fi for connectivity to the network (when was the last time you left your desk without your laptop, tablet, or smartphone?). They are also carrying an average of 2-3 devices each, to work in the manner that suits them best depending on the situation.

This has spawned initiatives for consumerization of IT (corporate issued mobile devices) and BYOD (personally owned laptop and mobile devices) in many organizations. While the focus has shifted largely to supporting these devices on enterprise networks and securing the network and corporate data, organizations must also be aware of the need to re-assess Wi-Fi network performance.

But there’s a problem. Many Wi-Fi networks were never designed to handle the amount of clients or the traffic load that we see on our networks today. Instead, they were designed in an era not so long ago where simply providing adequate signal strength and coverage was sufficient.  Many organizations are quickly realizing that their existing WLAN deployments designed for basic coverage are no longer adequate to meet these growing demands and that simply adding more access points is usually ineffective, often necessitating new network planning and design. These increasing demands have brought with them new requirements to effectively design and deploy high-capacity wireless networks. But where do you start?

Aerohive’s new High-Density Wi-Fi Design and Configuration Guide provides resources for engineers working with any vendor’s equipment to understand the factors that influence WLAN deployment success, and to begin designing WLAN networks that meet the demands placed upon them.

Aerohive High-Density Wi-Fi Design and Configuration Guide
(Click to download the PDF)

The design guide covers the following topics:

  • Requirements Gathering – These steps are critical to understanding the load and demand that will be placed on the network. We must know what our goal is before we can design to meet and exceed it! This includes requirements for the infrastructure, clients, applications, and forecasting the number of APs required to service the client population.
  • Network Planning and Design – This section details the factors that influence Wi-Fi network capacity, including spectrum capacity, channel planning, minimizing co-channel interference, working with unique facility characteristics, collocating APs to achieve higher capacity, and site surveying. A discussion of critical wired network design variables such as switch port bandwidth, PoE, subnet allocation, DHCP, and Internet bandwidth are also included.
  • Aerohive Network Configuration – Provides detailed recommendations for configuring an Aerohive Wi-Fi network for high capacity, including SSIDs, RADIUS integration, QoS, security, and radio settings.
  • Network Monitoring and Optimization – Managing a high performing wireless network does not stop once it is deployed. Ongoing maintenance and network optimization will ensure that the network continues to exceed performance expectations. This section details monitoring an Aerohive Wi-Fi network through the tools provided within HiveManager to tune network performance as needs change.
  • Appendix – The appendix contains useful worksheets to aid in the process of requirements gathering and forecasting capacity demands, as well as a configuration checklist for deploying the network.
One of the heavily stressed points in the document is the need for proper planning. Wi-Fi can be deceiving, because signal strength no longer guarantees a successful network. Proper Wi-Fi network design must take into account both the client and the infrastructure because airtime is a shared resource. The capabilities of your client population will directly impact the capacity and performance of your wireless network. Only by understanding your client population (or at minimum, making some educated assumptions) can your network be successful.

I put in some long hours and gave my blood, sweat, and tears to this document. I hope it proves valuable for anyone reading it, and translates into successful WLAN deployments.


Cheers,
Andrew

This post originally appeared on the Aerohive Blogs website.

Sunday, June 24, 2012

My IPv6 Mission

I've decided that I've procrastinated long enough. Therefore, over the next few months I'm on a mission, an IPv6 mission. I'll be reading as much material as I can get my hands on, deploying native IPv6 on my home network (including WLAN), and connecting to Hurricane Electric's tunnel broker service for native IPv6 Internet access.

To help me get started, I've acquired the following resources:

Cisco 871W Router
This router is a bit older, but it was easy to acquire, can run dual-stack IPv4 and IPv6 which gives me support for both protocols in my home (because not all of my clients support IPv6, like my Roku and Wii), and it is still receiving software upgrades from Cisco. I won't be using the integrated radio in this unit since it's ancient by fast-moving Wi-Fi standards (802.11g only; when this unit first came out it didn't even support AES-CCMP... so yeah, the radio hardware is a bit old).
Aerohive AP 330 (x2, and one AP 170)
Let's not overlook IPv6 for our Wi-Fi clients! I already have an Aerohive WLAN at home, and it supports IPv6 client access. The AP 330s have two 3x3:3 MIMO radios, full enterprise-class features, and mesh networking which I've extended out to my garage (hey, the man garage cave needs streaming Internet radio while I'm working on my motorcycle)!
IPv6 Essentials, 2nd Edition
Deploying IPv6 Networks
IPv6 for Enterprise Networks

I'll be posting what I learn as I go on this blog. I'll also be tweeting what I learn and my progress using the #IPv6Mission hashtag on Twitter. 

Follow along if you're new to IPv6, and I hope you enjoy! Even if you are familiar with IPv6, I'll be covering specific implementation details for Wi-Fi networks, which can be a bit different animal than wired IPv6 (there are a few gotchas that you'll need to be aware of - but let's save those for another post). And for those IPv6 experts out there, I may just need some help from time to time :)

Cheers,
Andrew

Wednesday, May 4, 2011

Wireshark WLAN Traffic Statistics and IO Graphs

Protocol analysis skills continue to be increasingly important for network engineers in all fields, especially for wireless engineers. As the 802.11 protocol continues to increase in complexity, maintaining interoperability while implementing support for numerous optional features becomes critical. Even more critical is having the skill set to investigate, diagnose, and resolve issues.

Engineers attempting to learn protocol analysis techniques often start with free tools that allow them to get comfortable looking at packets and expected versus abnormal behavior. However, this often comes at the expense of sophisticated analysis features which can greatly simplify the process and reduce analysis time. This can be both a blessing and a curse at the same time. It's a blessing for engineers because it forces them to learn the fundamentals of protocol analysis without the aid of automated tools that abstract the underlying protocol operation. This is a good thing (despite initial grumblings by those learning). It can also be a curse, because engineers often need to resolve issues quickly and efficiently, where sophisticated analysis tools can help identify and determine the root cause much faster.

Smart IT organizations will implement a mix of both scenarios, purchasing the (expensive) analysis tools for experienced engineers and the support organization, while training junior engineers or those new-in-role using the fundamentals approach.

The first step is for an engineer to learn and understand the fundamental Wi-Fi protocol exchanges such as active scanning, association, 802.1X/EAP authentication, the 4-way handshake, as well as various packets of interest including 802.11 power management techniques, retransmissions, fragmentation, medium reservation (RTS/CTS), and protection mechanisms. Easy identification of these exchanges can be achieved using Wireshark coloring rules and display filters as previously discussed.

In this post, we will continue our look at free methods to enhance Wi-Fi protocol analysis using incrementally more sophisticated analysis techniques. In subsequent posts, we will explore professional analysis tools that can automate many of these techniques.

Wireshark WLAN Traffic Statistics
The WLAN Traffic Statistics tool provides engineers with a high-level overview of the networks (BSSIDs) that are observed within the capture.

Navigate to the Statistics menu, then select WLAN Traffic.

Wireshark WLAN Traffic Statistics View
The top frame displays network traffic volumes by BSSID as a percentage of packets observed, as well as breakdowns for common wireless frame types such as beacons, probe req/resp, authentications, and de-auths. This information can be useful to identify which base stations and SSIDs are most active in the area and time the packet capture was taken.

By selecting a network from the top frame, a list of traffic within the BSSID is shown in the bottom frame. This can give engineers valuable information about top talkers within the network and can be useful for identifying bandwidth hogs, problematic clients, or clients having issues indicated by excessive probing or de-auth behavior. This can also be a rough measure of quality of service based on packet transmissions on the network. However, be sure NOT to use this as a measure of airtime fairness, as most vendor algorithms are based on byte-level fairness to override packet-level fairness inherent in the 802.11 protocol.

If you want to limit WLAN traffic statistics to a subset of packets in the capture, apply a display filter for the desired traffic, then open the statistics tool and check the box that states "Limit to display filter". This allows more focused analysis on subsets of data within the packet capture.

If you find a network or station of interest, Wireshark does provide some basic drill-down filtering capabilities by right-clicking on the entry, as show below.

Wireshark's Basic Drill-Down Filtering
Wireshark IO Graphs
The Wireshark IO Graphs tool allows engineers to graphically represent data within the packet capture for more intuitive analysis of information. This can be useful to graph the occurrence of events or packet exchanges over time, or to graph the relationship between multiple types of packets over time. This automates many analysis scenarios, eliminating manual compilation of such data.

Navigate to the Statistics menu, then select IO Graphs.

Wireshark IO Graphs
For example, the graph above shows the relationship between wireless data frames (line graph) and wireless retransmissions of data frames (bar graph). This allows the engineer to graphically observe network health over time and identify periods of degraded performance due to retransmissions. Here we see a spike of retransmissions around time mark 13:51:28 in the packet capture.

IO Graphs use the same syntax as display filters and coloring rules, so virtually any field or information within a packet capture can be graphed. Also note, that if the filter is modified you must un-select and re-select the Graph1 through Graph5 buttons to the left for the new filter to be applied and shown.

Additional Wireshark Features
In addition to WLAN traffic statistics and IO graphs, take time to explore the use of other built-in analysis tools. These include:
  • Enabled Protocols - used to decode various protocols for interpretation and analysis. Be sure to enable wireless protocols such as IEEE 802.11, LWAPP, CAPWAP, EtherIP (EoIP), RADIUS, EAPoL, EAP, and WLCCP. This will aid analysis of encapsulated protocols used in lightweight architectures as well as common wireless protocols either over the air or on the wire.

  • Endpoints - to identify top talkers and data volume per station, based on either frames or bytes.

  • Set Time References - used to mark packets and adjust time displayed in subsequent packets based on the marked packet. Useful for marking the beginning of a client roam and calculating the time required for an individual roam event. It's also useful for quickly setting time references on all first packets of roaming events to at once (tip - set a display filter for EAPoL Start or EAP Request Identity frames), or to see how long a client was associated to each AP before roaming.
Sample Roam Time Calculation Using the Wireshark Set Time Reference Feature
Also, combine output from multiple tools to provide focused analysis. For example:
  • Identify the BSSID and/or station transferring the most frames in the WLAN traffic statistics tool, apply an appropriate display filter to limit the scope of analysis, then review the frame and byte level data using the Endpoints tools.

  • Identify a period of time where there are a large percentage of 802.11 retransmissions in the IO Graphs, apply a display filter to narrow the packet range to just that time interval and only retransmitted frames, then view the WLAN Traffic Statistics limited to displayed packets to see what BSSIDs or stations were having the most problems. This will help identify if there is an issue with one station (hidden node, localized interference by STA, bad hardware, multipath, etc.), all stations on one access point (failing AP, localized interference by AP, installation error, etc.), or if there are problems with multiple APs and stations in the area (larger source of interference, environmental issue, etc.).

Revolution or Evolution? - Andrew's Take
Using free tools such as Wireshark are great for engineers that need to learn how protocols operate by experiencing them first hand. Also, by knowing some of the advanced features of such tools, both beginning as well as seasoned engineers can perform more in-depth and sophisticated protocol analysis.

However, there are limitations to free protocol analysis tools. They often have problems opening and analyzing large packet captures, difficulty or complexity in identifying and narrowing the focus of analysis, and limited ability to perform trending analysis. They also take time to learn and master.

In subsequent posts, I will explore more professional (paid) tools that eliminate some of these limitations, and automate sophisticated analysis techniques to reduce the learning curve required to accomplish similar tasks.

Cheers,
Andrew

Other Posts You Might Like:

Friday, February 4, 2011

Cisco Unified Wireless Network Ports

Here is a reference for the well-known Cisco Unified Wireless Network ports. This list is handy as a reference when creating firewall and security rule-sets, as well as for protocol analysis, decoding session and stream conversations, troubleshooting, and studying for various certification exams.


Cisco Unified Wireless Network Ports


LWAPP Data Packets: UDP 12222
LWAPP Control Messages: UDP 12223


CAPWAP Control: UDP 5246
CAPWAP Data: UDP 5247


WCP for WiSM: UDP 10000


Mobility Control Messages: UDP 16666 and/or UDP 16667 (secure-mode)
Mobility EoIP Tunnel: IP Protocol 97


RRM Messages 802.11b/g Client: UDP 12124
RRM Messages 802.11b/g Server: UDP 12134
RRM Messages 802.11a Client: UDP 12125
RRM Messages 802.11a Server: UDP 12135


Radius Authentication: UDP 1812
Radius Accounting: UDP 1813
Radius Authentication (legacy): UDP 1645
Radius Accounting (legacy): UDP 1646


TACACS+: TCP 49


DHCPv4 Clients: UDP 68
DHCPv4 Server: UDP 67
DHCPv6 Clients: TCP/UDP 546
DHCPv6 Server: TCP/UDP 547


HTTPS: TCP 443
HTTP: TCP 80
Telnet: TCP 23
SSH: TCP 22
TFTP: UDP 69
SNMP: UDP 161 and UDP 162
Syslog: UDP 514
NTP: UDP 123


Cheers,
Andrew