Textbook attached below. Answer questions for each case study
from the channel center, so that they actually consume five overlapping channels (for example, transmitting on channel 6 may cause interference on channels 5 and 7 as well as limited on channels 4 and 8). This leaves only three nonoverlapping (simultaneously usable) 20-MHz channels: 1, 6, and 11. IEEE 802.11a networks have 555 MHz spread across 23 nonover- lapping channels.
Channel allocation is covered in Chapter 5.
Managing the radio frequency spectrum of 802.11b/g—and to a lesser degree 802.11a—wireless networks can be challenging. Setting all of the APs to the same channel number would result in reduced throughput because each station must wait a longer period of time for its turn to transmit (called cochannel interference). To eliminate this interference it is necessary to arrange the coverage areas of the APs so that one channel does not interfere with an adjacent channel. In Figure 7-6, only channels 1, 6 and 11 are used as nonoverlap- ping channel numbers. Each cell is separated from other cells so that no two adjacent cells have the same channel number in order to reduce interference (known as adjacent channel interference). This type of WLAN is called a multiple-channel architecture or MCA because more than one channel is in the wireless network.
One of the keys to an MCA is to have the correct cell size in order to minimize adjacent channel interference. This is especially true when “scaling” or adding additional capacity to the WLAN. The most common approach, called the micro-cell architecture, creates small areas of coverage. Typically, in order to add wireless network capacity, more APs are added while the transmission power of all APs is reduced to minimize potential interference. This can usually provide acceptable network throughput if the site has been properly surveyed to identify the best locations for the APs. In addition, the configuration of BSSIDs and ESSIDs can be made easier in a micro-cell architecture.
Single-Channel Architecture (SCA) The fundamental reason why multiple APs in a MCA are necessary is because the interference range of wireless devices exceeds their useful communication range. That is, devices that are too far apart to communicate can still be close enough to interfere with each other. An alter- native to MCA that addresses this weakness is the single-channel architecture (SCA). Instead of having each cell use a different channel as in WCA, WLANs using SCA have all of the APs use the same channel. Each AP has overlapping coverage that forms a continuous region on a single channel, thereby reducing interference. The SCA architecture is accomplished through
6 1 11 116 1
11 6 1 11 6 1
6 1 11 116 1
11 6 1 11 6 1
Figure 7-6 Nonoverlapping cells
© Cengage Learning 2013
256 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
the use of lightweight APs and WLCs. Each lightweight AP broadcasts the same virtual BSSID (instead of multiple BSSIDs) and each has the same configured MAC address. This also serves to eliminate the cochannel interference problem.
There are several advantages to SCA. The first advantage is smoother handoffs. A mobile sta- tion must receive an uninterrupted flow of frames when moving from the coverage area of one AP to another AP, especially when using VoIP. With MCA, the station responsible for this pro- cedure monitors the signal strength from multiple APs or data frame error rates. With SCA, the handoff is instead accomplished through coordination between the lightweight APs and the WLC. The stations cannot distinguish which AP is providing the coverage; instead, the net- work decides which AP should transmit and receive data for a particular station. This means that the stations are not involved in any handoff decision from one AP to another. As stations move, the network directs traffic to them via the nearest AP with available capacity.
With SCA, the roaming clients are “fooled” into thinking that they are always interacting with the same AP when in reality they may be communicating with several different APs.
A second advantage to SCA is that the often tedious planning process required for MCA WLANs is no longer needed. All APs are set to the same common RF channel and transmit power, eliminating the need for lengthy and often complex planning regarding the location and unique configuration of each AP.
Another advantage to SCA is that because each AP is operating on the same channel, cochan- nel interference is no longer an issue. This can also improve the signal-to-noise ratio (SNR) that in turn increases throughput and reliability.
A final advantage is that the SCA architecture provides more network information in order to make informed decisions. With MCA, a station and AP are essentially “in the dark” regarding the overall status of the network. Yet with SCA a more complete knowledge of the conditions at neighboring APs, and even historical information about how stations reacted previously when in similar situations, can be used when deciding which AP a roam- ing client should be associated with.
MCA is similar to the centralized handover control of first-generation cellular telephone networks, while today’s 3G and 4G is based on a shared network-client responsibility like SCA.
SCA can also support channel stacking. Channel stacking allows for increased capacity by hav- ing more than one SCA operating in an area. Instead of having only one SCA on channel 1, another set of APs operating on channel 6 can also be added using a different BSSID. Stations can then associate with either SCA, thus dramatically increasing the available capacity. This additional capacity can be used for redundancy or to support higher data rates or user density.
Instead of installing additional APs, channel stacking can also be accomplished by using APs that support multiple radios.
Multiple-Channel Architecture vs. Single-Channel Architecture Models 257
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Wireless Network Management Systems (WNMS)
C W N A
4.4.4. Define, describe, and implement a WNMS that manages autonomous APs, WLAN controllers, and mesh nodes.
A wireless network management system (WNMS) is a set of hardware and/or software that can be used to provide unified management of a wireless network. This includes configuration man- agement, deployment, and especially troubleshooting. A WNMS can be used to isolate and solve wireless problems, which can have many different root causes (station wireless configuration errors, authentication problems, connectivity issues, problems with wired ports or switches, etc.).
The typical features of a WNMS include:
● Configuration management. A new or updated configuration can be “pushed” out to all wireless devices, a single device, or a group of specific devices. These configurations can be designed so that general updates do not override specific configuration settings unique to each device.
● Firmware/Software distribution. As new firmware and software is made available, these can be distributed to all devices from a central management facility, with no need to “touch” each device.
● Intelligent scheduling. To minimize the impact of a new configuration or firmware update, many WNMS can be scheduled to automatically occur late at night or on the weekends when the wireless network usage is low. In addition, recurring tasks can be scheduled to automatically occur on a regular daily, weekly, or monthly basis.
● User and device monitoring. A WNMS can locate a specific user or device on a wire- less network often by WLAN administrator clicking a single button on a Web-based software interface. This allows a wireless technician to monitor historical information and use special diagnostic information to address problems.
One of the disadvantages of a WNMS is that it cannot be used to monitor wireless network traffic as it occurs.
Power Management
C W N A
3.1.3. Explain and apply the power management features of WLANs.
Most stations in a WLAN are portable laptop or tablet computers, giving the users the freedom to roam without being tethered to the network by wires. These devices depend upon batteries as their primary power source when they are mobile. To conserve battery power,
258 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
laptops are usually configured to go into a “sleep” mode after a specific period of time, when functions such as the hard drive or display screen are temporarily powered down by the computer.
However, a laptop that is part of a WLAN must remain “awake” in order to receive wireless network transmissions. If a laptop is in sleep mode, it could miss important transmitted infor- mation or even lose the network connection altogether. The dilemma is how to allow the lap- top to power down into sleep mode during idle periods to preserve battery life yet continue to be active to receive network transmissions.
The reason a wireless laptop must continue to remain awake to receive network transmissions is because the original IEEE 802 standard assumes that stations are always ready to receive a network message.
The answer to the problem is known as power management. Power management allows a station to be in either active mode when it is continuously awake or in power save mode, which turns off the wireless network interface card adapter to conserve battery life but still not miss wireless transmissions. Power management is transparent to all protocols and appli- cations so that it will not interfere with normal network functions.
Power save mode is also called continuous aware mode or constantly awake mode.
IEEE 802.11 power management can be divided into two categories: basic power manage- ment and enhanced power management techniques.
Basic Power Management In a BSS infrastructure WLAN, the steps of power save mode are as follows:
1. A station sends a frame to the AP with the Power Management field set to 1 to indicate that it will go into power save mode after this frame transmission.
2. The AP records that the station is in power save mode to prevent any frames from being sent to that station from the AP.
3. As the AP receives frames specifically for that station (unicast frames) it temporarily stores those frames at the AP (buffering).
4. At prescribed set times, the AP will send out a beacon frame to all stations. At the same time, all stations switch to active mode to receive the frame. This frame contains a list of the stations that have buffered unicast frames waiting at the AP. This list is known as the traffic indication map (TIM).
5. If a station learns from the TIM that buffered frames are waiting for it, that station will request the AP to have those frames forwarded (if it has no buffered frames then it can return to power save mode). Once the buffered frames are received the station can again return to power save mode. This is illustrated in Figure 7-7.
Power Management 259
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The amount of power that a wireless network interface card adapter consumes is significant. One typical card requires 450 millionths of an amp (mA) to transmit and 270 mA to receive. While in power save mode it only consumes 15 mA.
When a station in power save mode must receive a frame intended for all stations (multicast or broadcast frame) the AP will send a special TIM called a delivery traffic indication message (DTIM). All stations will then change to active mode to receive the frame.
Power management for an IBSS is different because there is no AP. Every station in an IBSS must buffer the frames that it attempts to send to another device in case the receiving device is asleep. At a specific period of time, known as the ad hoc traffic indication message (ATIM) window, each station must be awake. At this time a station sends a beacon frame to all other stations. Those stations that previously attempted to send a frame to a sleeping station will now send an ATIM frame, which indicates that the receiving station has pending data to be received and must remain awake (any device that does not receive an ATIM frame can go back to sleep). Finally, the data frames are retrieved from the buffer and sent to the station that is now awake.
There are a variety of configuration settings that can be used with power management. For example, different power save levels can be specified for a station in power save mode. One level may require that a station turn off the radio for as long as possible without losing network connectivity for the greatest power savings at the sake of network per-
formance, while another setting can require that the station turn off the radio for small periods in order to provide optimal network performance.
Enhanced Power Management Although the basic power management features can provide power savings, there are enhanced power management technologies that can provide additional functionality and
Station A
Power save mode
Power save mode
Active mode
Station B
Station C TIM
Station
A Yes
Station
C No Access point
Send frames request
Figure 7-7 Request for frames
© Cengage Learning 2013
260 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
power savings. These include Unscheduled Automatic Power Save Delivery, Power Save Multi-Poll, and Spatial Multiplexing Power Save.
Unscheduled Automatic Power Save Delivery (U-APSD) The Unscheduled Automatic Power Save Delivery (U-APSD), which is similar to the Wi-Fi Alliance’s WMM Power-Save (WMM-PS), is often used when a wireless station is using VoIP. With the basic power management settings a device using VoIP for a voice conversation may receive frames every 10–20 milliseconds (ms), while an AP usually sends out a beacon frame every 100 ms. Because the delay is too long, normally a station using VoIP simply could not afford to go into power save mode.
With U-APSD, the station would inform the AP that it is operating according to this proto- col, and the AP will then save any frames destined for this station. However, instead of waiting for the AP to send a beacon frame to all stations as with basic power management, whenever the AP sees a frame coming from the station it will immediately release any frames it has been holding for the station. This allows the station to sleep until it needs to send a VoIP frame to the AP, and that frame also serves as an indicator to release any packets des- tined for it. Once the station has received its frames it then goes back into power save mode.
There is a slight delay for the station in listen mode when using VoIP with U-APSD while the AP gathers up and sends the frames, at which time the station goes into receive mode.
U-APSD improves the efficiency of the basic power management in two ways: it increases the amount of time that a station can be in power save mode and it decreases the number of frames that a station must send and receive in order to download stored frames on the AP. An interesting benefit of U-APSD is that, when higher data rates are used, overall power savings increase. This is because a station will spend less time actively transmitting and receiving and will spend more time in power save mode.
A device using U-APSD for VoIP consumes approximately one-sixth of the power compared with not using U-APSD.
Power Save Multi-Poll (PSMP) Another enhanced power management mechanism is the Power Save Multi-Poll (PSMP), which can have either a scheduled or an unscheduled component. Scheduled PSMP (S-PSMP) allows an AP to send a transmission schedule to one or more stations in a WLAN. This schedule informs the stations when they should be in active mode to receive frames as well as when they are allowed to begin transmitting. And since a station can only send or receive frames based on the schedule, other stations cannot interfere with the transmissions by attempting to send simultaneously. By using a schedule, stations can be in power save mode for the maximum amount of time without missing any frames.
Unscheduled PSMP (U-PSMP) functionality does not replace U-APSD (WMM), but rather extends it to add further functionality.
Power Management 261
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Although an improvement over basic power management, S-PSMP still requires a significant amount of overhead. In addition, stations may not be able to be in power save mode for extended periods of time. For example, with VoIP transmissions the time gap for station may be so short that the station must still remain in active mode while other stations are receiving their VoIP packets. Generally speaking, P-SPMP is used only if the number of sta- tions using VoIP associated with a single AP exceeds 15. If fewer than 15 stations are using VoIP, then U-APSD should be used instead.
Spatial Multiplexing Power Save (SMPS) Spatial Multiplexing Power Save (SMPS) can be used with IEEE 802.11n devices using Multiple-Input Multiple-Output (MIMO). A device using MIMO may have a 2x3:2 configuration of two transmit antennas and three receive antennas (along with two data spatial streams), each having its own radio chain. Yet it is not necessary for all three of the receive radio chains to be simultaneously awake. This is because the station is only waiting to receive a low data rate beacon that may not be sent with MIMO encoding.
SMPS allows the station to change from a 2x3:2 configuration to a 1x1:1 to save power. If the station is plugged into an electrical outlet running on alternating current (AC), it can be configured to run using all radio chains (since conserving power is not a concern). However, if the station begins running on a direct current (DC) battery, it will automatically “down- shift” to 1x1:1 while waiting to receive beacons. The station would then “upshift” back to 2x3:2 when necessary.
SMPS is also called Dynamic MIMO Power Save.
A device using SMPS can downshift and then tell the AP to prevent it from sending any MIMO-encoded frames to the device with only one receive radio chain. The AP can then send a request to send (RTS) packet that indicates the AP is about to send a MIMO packet so that the device can upshift to receive it.
The power savings provided by SMPS can be significant. The ability to dynamically change the MIMO configuration can reduce power consumption by 30 percent when the traffic is low.
Chapter Summary ■ The most common type of wireless architecture is an autonomous access point archi-
tecture. Each AP is independent or autonomous from all other APs. There are several enhanced features in this type of architecture. Two of the most advanced features are Quality of Service (QoS) and wireless virtual LANs (VLANs). QoS provides the ability to prioritize different types of frames so that those frames that are more time-dependent, such as voice and video, can be given a higher priority (and arrive earlier) than standard data frames. A wireless VLAN is often used to segment traffic. Wireless
262 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
VLANs can be configured in one of two ways. The difference depends upon which device separates the packets and directs them to different networks.
■ A controller-based architecture uses a wireless LAN controller (WLC) to manage and provide configuration services to the WLAN. Access points in a controller-based architecture are significantly different. A lightweight access point does not contain the management and configuration functions that are found in autonomous access points; instead, these features are contained in the centralized WLC. Lightweight access points only have simplified radios for wireless communication between devices and a media converter for accessing the wired network. A lightweight mesh AP can be used instead of a standard mesh AP. Lightweight mesh APs can also be centrally configured and managed through a WLC. A captive portal AP uses a standard Web browser to pro- vide information, give the wireless user the opportunity to agree to a policy, or present valid login credentials. The WLC is a device that can be centrally configured; these settings are then automatically distributed to all lightweight access points.
■ Besides autonomous access point architectures and control-based architectures, there are other types of WLANs. A WLAN array is a proprietary product that resembles a round consumer-grade smoke detector and replaces a standard WLC installed in a rack in a server closet. The WLAN array contains a WLC that can be directly con- nected to as many as 16 integrated access points. Cooperative control is another proprietary technology marketed architecture that enables APs to communicate and coordinate with each other without the need for a WLC, so that each AP contains the capabilities of a WLC. Wireless mesh access points communicate wirelessly with the next closest mesh access point.
■ A multiple-channel architecture, or MCA, has more than one channel in the wireless network. Each cell is separated from other cells so that no two adjacent cells have the same channel number in order to reduce interference. An alternative to MCA is the single-channel architecture (SCA). Instead of having each cell use a different channel as in WCA, WLANs using SCA have all of the APs use the same channel. Each AP has overlapping coverage that forms a continuous region on a single channel, thereby reducing interference. The SCA architecture is accomplished through the use of lightweight APs and WLCs.
■ A wireless network management system (WNMS) is a set of hardware and/or software that can be used to provide unified management of a wireless network. This includes configuration management, deployment, and especially troubleshooting. A WNMS can be used to isolate and solve wireless problems, which can have many different root causes (station wireless configuration errors, authentication problems, connectivity issues, problems with wired ports or switches, etc.).
■ Power management allows a station to be in either active mode (continuously awake) or in power save mode (turns off the wireless network interface card adapter to con- serve battery life but still not miss wireless transmissions). Power management is transparent to all protocols and applications so that it will not interfere with normal network functions. Basic power management involves the AP temporarily storing frames and then releasing them to the stations. Although the basic power management features can provide power savings, there are enhanced power management technolo- gies that can provide additional functionality and power savings. With Unscheduled Automatic Power Save Delivery (U-APSD) a station informs the AP that it is operating
Chapter Summary 263
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
according to this protocol, and the AP will then save any frames destined for this station. Whenever the AP sees a frame coming from the station, it will immediately release any frames it has been holding for the station. Power Save Multi-Poll (PSMP) allows an AP to send a transmission schedule to one or more stations in a WLAN. This schedule informs the stations when they should be in active mode to receive frames as well as when they are allowed to begin transmitting. Spatial Multiplexing Power Save (SMPS) allows a station to change from a MIMO configuration to a single radio in order to conserve power.
Key Terms active mode A power management state in which the station is continuously awake. ad hoc traffic indication message (ATIM) window A specific period of time that each station must be awake. adjacent channel interference Each cell is separated from other cells so that no two adjacent cells have the same channel number in order to reduce interference. captive portal AP An AP that uses a standard Web browser to provide information, give the wireless user the opportunity to agree to a policy, or present valid login credentials. channel stacking A technology that allows for increased capacity by having more than one SCA operating in an area. cloud management Connecting wireless devices together using the Internet in order to remotely manage them. cochannel interference Reduced throughput caused as a result of all of APs set to the same channel number. cooperative control A proprietary product in which each AP contains the capabilities of a WLC. delivery traffic indication message (DTIM) A special TIM sent by an AP that is used when a station in power save mode must receive a frame intended for all stations. distributed WLAN architecture A wireless architecture configuration in which multiple APs form a non-centralized network through a wireless connection. IEEE 802.11e-2005 The IEEE QoS standards. IEEE 802.1q An IEEE standard for marking VLAN packets. lightweight mesh AP A mesh AP that is centrally configured and managed through a WLC. micro-cell architecture A wireless architecture that creates small areas of coverage. multiple-channel architecture (MCA) A wireless architecture in which more than one channel is used in the wireless network. power management A technology that allows a WLAN to conserve power. power save mode A power management state in which the station turns off the wireless network interface card adapter to conserve battery life. Power Save Multi-Poll (PSMP) An enhanced power management technology that can have either a scheduled or an unscheduled component. Quality of Service (QoS) Prioritizing different types of frames over a network.
264 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
Scheduled PSMP (S-PSMP) An enhanced power management technology in which the AP sends a transmission schedule to one or more stations in a WLAN. single-channel architecture (SCA) An architecture in which all of the APs use the same channel. SNMP (Simple Network Management Protocol) A management protocol that provides information such as the number of bytes transmitted and received, the number of frames transmitted and received, the number of errors, and port status. Spatial Multiplexing Power Save (SMPS) An enhanced power management technology that turns off MIMO radios. split MAC A division in which lightweight APs only handle the real-time layer functions while MAC functionality is processed by the WLC. total cost of ownership (TCO) The total cost of owning a product, including acquisition, setup, support, ongoing maintenance, service, and all operating expenses. traffic indication map (TIM) A list of stations that have buffered unicast frames waiting at the AP. trunking A single cable is used to support multiple virtual LANs. Unscheduled Automatic Power Save Delivery (U-APSD) A technology in which whenever the AP sees a frame coming from the station it will immediately releases any frames it has been holding for the station. virtual local area network (VLAN) A logical grouping of network devices within a larger physical network. Voice over IP (VoIP) A telephony system that uses Internet Protocol (IP-based) data packet switching networks to transmit voice communications. Wi-Fi Multimedia (WMM) A QoS specification created in 2004 by the Wi-Fi Alliance modeled after a wired network QoS prioritization scheme. wireless network management system (WNMS) A set of hardware and/or software that can be used to provide unified management of a wireless network. wireless switch Another name for a WLAN controller. wireless VLANs A wireless virtual LAN typically used to segment traffic. WLAN array A proprietary product marketed that contains a WLC that can be directly connected to as many as 16 integrated APs. WLAN profile A set of specific configurations that can be applied to different wireless stations. WMM Power-Save (WMM-PS) A technology that is similar to Unscheduled Automatic Power Save Delivery (U-APSD).
Review Questions 1. In an autonomous access point the “intelligence” for wireless management, authentica-
tion, and encryption is contained in which device?
a. wireless network interface card adapter
b. WLC
c. station
d. access point
Review Questions 265
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2. Each of the following is a feature found in an autonomous access point except:
a. support for Wireless Distribution Systems (WDS).
b. quality of service.
c. adjustable transmit power.
d. WLC.
3. The capability to prioritize different types of frames is known as .
a. VoIP
b. Quality of Service (QoS)
c. Wi-Fi Prioritization (WFP)
d. IEEE 802.15f
4. The most flexible approach for separating packets and directing them to different networks in a wireless VLAN is to use the network .
a. access point (AP)
b. switch
c. hub
d. router
5. What is a split MAC architecture?
a. A lightweight AP that handles only the real-time MAC layer functions in itself while all other functions are processed by the WLC
b. A WLC that has two MAC addresses
c. A VoIP WLAN that uses a different MAC for each station
d. A wireless network interface card adapter that can change its MAC address
6. Each of the following can be used by a captive portal AP except:
a. advertisement.
b. encryption.
c. general authentication.
d. agree to an Acceptable Use Policy.
7. Which of the following is not a recognized functional area of a network?
a. core layer
b. distribution layer
c. station layer
d. access layer
8. A is a set of specific configurations that can be applied to different wireless stations.
a. WLAN profile
b. management configuration
266 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
c. WLC frame
d. data resource package (DRP)
9. A WLAN array .
a. is only a prototype and has not yet been developed for actual use
b. can only be used on a mesh network
c. uses multiple HiveAPs to share load balancing
d. contains a WLC that can be directly connected to as many as 16 integrated access points
10. Which is not true regarding a multiple-channel architecture configuration?
a. Cochannel interference can be a significant problem.
b. With IEEE 802.11b/g there are only three nonoverlapping channels.
c. Each cell must be separated from other cells so that no two adjacent cells have the same channel number.
d. WLCs cannot be used in a multiple-channel architecture.
11. A WLAN that uses a single-channel architecture has each AP .
a. using the same channel number
b. in a mesh network
c. in a closed array configuration
d. using higher power levels to send the signal farther
12. Channel stacking .
a. can only be used with MCA
b. is restricted to WLAN array configurations
c. uses more than one SCA in an area
d. is illegal in the United States
13. A set of hardware and/or software that can be used to provide unified management of a wireless network is called a .
a. configuration manager
b. Unified Software System
c. Wireless LAN Controller (WLC)
d. wireless network management system (WNMS)
14. Which of the following is not a step of the power save mode in basic power manage- ment in a BSS?
a. A station sends a frame to the AP with the Power Management field set to 1 to indicate that it will go into power save mode after this frame transmission.
b. The user must manually put the wireless network card interface adapter into power save mode.
Review Questions 267
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
c. As the AP receives frames specifically for that station it temporarily stores those frames at the AP.
d. At prescribed set times the AP will send out a beacon frame to all stations.
15. What is a traffic indication map (TIM)?
a. a list of the stations that have buffered unicast frames waiting at the AP
b. the route that frames take when transmitted from the AP to a station
c. the congestion that results from too many stations in a micro cell
d. a grid on a mesh network that lists all of the WLCs
16. Which of the following is not a characteristic of the Unscheduled Automatic Power Save Delivery (U-APSD)?
a. It is similar to Wi-Fi Alliance’s WMM Power-Save (WMM-PS).
b. It cannot be used with VoIP.
c. Stations inform the AP that it is operating according to this protocol.
d. Whenever the AP sees a frame coming from the station it will immediately release any frames it has been holding for the station.
17. Power Save Multi-Poll (PSMP) sends a(n) from the AP to the stations.
a. schedule
b. arbitration frame
c. automated alert
d. Point Coordination Function IFS
18. Spatial Multiplexing Power Save (SMPS) can only be used with which devices?
a. VoIP
b. WLC
c. IEEE 802.11a
d. IEEE 802.11n
19. With Distributed Coordination Function (DCF) .
a. each wireless station has the same opportunity as all other stations for accessing the medium
b. all stations register with the AP their unique TDIM
c. data transmissions have a higher priority than voice frames
d. QoS is unnecessary
20. The IEEE QoS standard for WLANs is known as .
a. Background Scheduling
b. QoS Scheduling Configuration (QSC)
c. WMM Background Priority
d. IEEE 802.11e-2005
268 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
Hands-On Projects
Project 7-1: Configuring Access Points—Advanced Settings The ability to properly configure an access point is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In
this project you will use an online emulator from D-Link to configure an autonomous access point’s advanced settings.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you.
3. Click Support.
4. Click Go next to Emulators.
5. Scroll down and click DAP-1522.
6. Click DAP-1522 AP Mode.
7. The emulated login screen appears. Click Login.
8. An emulated Setup screen displaying what a user would see when configuring an actual DAP-1522 is displayed, as shown in Figure 7-8.
9. Click Advanced on the horizontal menu bar.
10. Click Advanced Wireless in the left pane to display the Advanced Wireless screen.
11. Click the down arrow next to Transmit Power. Click the down arrow again to close the drop-down list without making any changes. Why would you want to reduce the power of the AP? Click the down arrow again to close the drop-down list without making any changes.
12. Notice that, by default, the Beacon Period is set to 100 msec. What would happen if you decreased that value? What would happen if you increased it?
13. WMM Enable is selected by default. Wi-Fi Multimedia (WMM) is modeled after a wired network QoS prioritization scheme and outlines four levels of prioritization for WLAN QoS. Should this be on by default? What impact would it have on the WLAN?
14. The Short GI is also on by default. In the right pane, under Help, click More and read about the settings for this model under Advanced Wireless. If you were using this device, would you use Short GI? Why or why not?
15. Keep the emulator open in your browser for the next project.
Hands-On Projects 269
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Project 7-2: Configuring Access Points—QoS In this project you will use the online emulator from D-Link to configure an autonomous access point’s QoS settings.
1. If necessary navigate to the DAP-1522 Advanced Wireless screen.
2. Click QOS in the left pane to display the QOS menu as shown in Figure 7-9.
3. In the right pane, under Help, click More and read about the settings for this model under QOS.
4. Click your browser’s Back button to return to the QOS screen.
5. Under QOS click the Enable Qos box to insert a check.
6. Now create a QoS rule. Under ADD QOS RULE, click the Enable Qos box to insert a check.
7. In the Name box type WebTraffic. This will set a rule for HTTP Web traffic to be at the lowest priority.
8. Verify that the Priority is set to Background(BK). Background has the lowest level of priority.
Figure 7-8 DAP-1522 Emulated Setup screen
© Cengage Learning 2013
270 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
9. In the Protocol box select TCP.
10. For the Host 1 IP Range, type the range 192.168.1.1 in the first box and 192.168.1.101 in the second box. This part of the rule will apply to traffic that is received by any device in the local network that has an IP address within this range.
11. For the Host 1 Port Range, enter 80 in the first box and 80 in the second box. This part of the rule will apply to traffic in which Host 1’s port number is within this range (HTTP traffic).
12. For the Host 2 IP Range, enter the range 0.0.0.0 in the first box and 255.255.255.255 in the second box. This sets the rule to apply to traffic that is sent by any device that has an IP address within this range (any computer).
13. For the Host 2 Port Range, enter 0 in the first box and 65535 in the second box. This rule applies to traffic in which Host 2’s port number is within this range (all protocols).
14. Click Clear.
15. Now create the settings that give the highest priority to FTP traffic for computers on the local network.
16. Close all windows.
Figure 7-9 DAP-1522 QoS screen
© Cengage Learning 2013
Hands-On Projects 271
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Project 7-3: Configuring Access Points—Performance In this project you will use the online emulator from D-Link to configure an autonomous access point’s performance settings.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you.
3. Click Support.
4. Click Go next to Emulators.
5. Scroll down and click DAP-3520
6. The emulated login screen appears. Click Login.
7. An emulated Home screen displaying what a user would see when configuring an actual DAP-3520.
8. In the left pane, expand all of the options so that they are displayed as shown in Figure 7-10.
9. In the left pane, under Basic Settings, click Wireless.
10. Click the down arrow next to Wireless Band. What are the two types of IEEE 802.11 networks that are available for the first band? What are available for the second band? Click the down arrow again to close the drop-down menu without making any changes.
11. Click the down arrow next to Mode. When would the device be configured as a Wire- less Distribution System (WDS)? When would it be used as a WDS with AP? Click the down arrow again to close the drop-down menu without making any changes.
12. Change the Wireless Band from 2.4GHz to 5GHz. Notice how the Channel also changes. Why does it change?
13. Change the Wireless Band back to 2.4GHz.
14. In the left pane under Advanced Settings click Performance.
15. Change the Wireless Mode setting to Mixed 802.11g and 802.11b.
16. Click the down arrow next to Data Rate. What options are available? Click the down arrow again to close the drop-down menu without making any changes.
17. Change the Wireless Mode setting to Mixed 802.11n, 802.11g and 802.11b.
18. What is the only Data Rate option that appears for this mode?
19. Click the arrow next to Transmit Power. Why is the default set to the lowest value? Click the down arrow again to close the drop-down menu without making any changes.
20. Change the Wireless Mode setting to Mixed 802.11g and 802.11b. Why does the Short GI become disabled with this option?
21. Keep the emulator open for the next project.
272 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
Project 7-4: Configuring Access Points—VLAN In this project you will use an online emulator from D-Link to configure an autonomous access point’s VLAN settings.
1. If necessary, navigate to the DAP-3520 Home screen.
2. In the left pane, click Multi-SSID under Advanced Settings to display the Multi-SSID settings as shown in Figure 7-11.
3. Check the Enable Multi-SSID box to insert a check. When would this option be used?
4. Click the Enable Priority box to insert a check.
5. In the left screen, click VLAN under Advanced Settings to display the used VLAN Settings screen.
6. Next to VLAN Status click Enable.
7. Click the Add/Edit VLAN tab.
8. Next to VLAN ID (VID) enter VLAN1.
Figure 7-10 DAP-3520 Emulated Home screen
© Cengage Learning 2013
Hands-On Projects 273
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9. Next to VLAN Name enter Accounting.
10. In the Port section next to Untag note that the Mgmt option is selected. What would this option do?
11. In the Port section next to Tag, check the LAN option. What would this do?
12. Close all windows.
Case Projects
Case Project 7-1: WMM Devices Wi-Fi Multimedia (WMM) technology can now be found in televisions, cam- eras, and other devices to create a wireless infrastructure for home entertain- ment networks. Use the Internet to research WMM technology in these devices. Write a one-page paper on your findings.
Figure 7-11 DAP-3520 Emulated Multi-SSID Settings screen
© Cengage Learning 2013
274 Chapter 7 WLAN Management and Architectures
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7
Case Project 7-2: HCCA HCF Controlled Channel Access (HCCA) uses polling along with centralized scheduling controlled by the AP. Use the Internet to research HCCA. How does it function? What are its strengths and limitations? Why is it preferable over other forms of QoS? Write a one-page paper about your research.
Case Project 7-3: Captive Portal APs Captive Portal APs are very commonly found in a variety of settings. Use the Internet to research Captive Portal APs. How are they typically used? What are their security vulnerabil- ities? What open source products are available? Write a one-page paper on your research.
Case Project 7-4: Proprietary Products Both WLAN arrays and cooperative control are proprietary products from Xirrus and Aero- hive. Access the Web sites of these companies and research these two products. In what applications are they found? How are they being used? What advantages are advertised for them? Write a paper on the information that you find.
Case Project 7-5: Nautilus IT Consulting Nautilus IT Consulting (NITC), a computer technology business, needs your assistance with one of their new clients.
Dawn’s Art and Interiors (DAI) operates several galleries across the state and wants to upgrade their WLAN. They have recently migrated to VoIP and they want to extend this functionality to their wireless network. DAI needs help determining which QoS option is best for them.
1. Create a PowerPoint presentation of eight or more slides that compares the different types of QoS, discussing their respective strengths and weaknesses. This presentation should contain technical information for the IT staff.
2. After your presentation DAI wants your opinion. Write a one-page memo that presents your choice and explains why they should explore this option.
Case Projects 275
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
chapter8
Conducting a Site Survey
After completing this chapter you should be able to:
• Explain what a site survey is and how it can be used • List and describe the tools used for conducting a site survey • Describe the procedures for performing a site survey
277 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
A key link in the chain of putting products into the hands of consumers is a distribu- tion center (DC). DCs receive tens of thousands of different products from suppliers all across the world each hour. The job of the DC is to store these items and then as needed select the correct items and quantities to ship to retail stores or directly to consumers. Most DCs have miles of conveyor belts that snake their way through the building past racks holding the products. Workers who are stationed in specific areas walk over and pick the required items off these racks and place them on the con- veyor (called “pick and pass”). The items make their way to “sortation” areas, where all of the items for a shipment are consolidated together and loaded onto a truck. DCs are very labor-intensive operations, with many workers making multiple touches of each and every product.
Yet instead of having workers wait by a moving conveyor belt to pick and pass products, what if the products came directly to the workers? That’s the idea behind a new type of DC system developed by Kiva Systems (which was purchased by Amazon in 2012). Mobile robotic drive units bring inventory pods directly to the workers who then select the items needed for the order. A single worker can complete an entire order—even consisting of hundreds of products—without having to move.
When a pallet of items from a supplier enters the DC, instead of being moved by a forklift to be stored on a rack, it is instead placed onto a pod base. The pod base (along with the pallet) is then moved by the robots, which have been called “fast- moving orange tortoises.” When an order comes in for that product, the robots bring the entire pallet to a stationary worker at a packing station, where the items are selected, packed into boxes, and loaded onto trucks. The use of these intelligent robots makes it possible to build more flexibility into the process. For example, the sequence of the robots can be controlled so that heavier items arrive first (to be placed at the bottom of the shipping box) before lighter items arrive. In addition, items that are more popular (such as Christmas ornaments in December) can be located closer to packing stations to reduce the time needed to reach the station.
The robotic drive units navigate by reading removable optical markers that form a grid pattern on the DC’s floor, so it is not necessary to bury wires in the floor’s con- crete. The drive units are battery powered and can operate for up to eight hours on a single charge. (When the batteries begin to run low, the drive unit automatically goes to a charging station on the floor and plugs itself in.) Controlling software deci- des which order goes to which operator, which drive unit retrieves which pod, and which path a drive unit should take to reach the packing station. Because the drive units are portable, the software communicates with them using wireless local area network technology, which can also interface with any existing WLAN in the DC.
Real World Wireless
278 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
One of the unique challenges of setting up a wireless LAN (WLAN) is determining the opti- mum location for the access points (APs) and other wireless devices. Because obstacles such as walls, floors, elevator shafts, and even people can impact the radio frequency (RF) signal, it is important to take these factors into consideration prior to installing equipment. In addi- tion, as conditions continue to change—new office walls are installed or old walls removed, more wireless users are added to the network, competing wireless networks are installed in neighboring offices—it is important to monitor and adjust the WLAN to keep it operating at peak efficiency. This involves using a variety of specific tools and established procedures.
In this chapter you explore the necessary steps for locating wireless equipment by performing a site survey. First you learn what a site survey is and about the different types of surveys. Next, you explore the tools that are used to conduct the survey. Finally, you look at how to gather the necessary data and conduct a survey.
What Is a Site Survey?
C W N A
6.2.1 Identify the equipment, applications, and system features involved in performing predictive site surveys.
6.2.3 Identify the equipment, applications, and methodologies involved in self-managing RF technologies.
Most users, when installing a WLAN in a home or apartment, generally do not give much time to determining the optimum location for the wireless router so that its RF signal coverage is uniform throughout the house but extends outside it as little as possible. Instead, these devices are typically placed wherever it is convenient, such as next to the Internet connection, near a desktop computer, or even tucked away on a bookcase that happens to have enough space to accommodate it. If the wireless signal happens not to reach into the far corners of the house or outside onto an outdoors deck, then those areas are simply recognized as being “dead space” and are just avoided when using the network.
However, when installing a WLAN for an organization, areas of dead space may not be so easily tolerated. Whereas at home a user may simply move to another room, that may not always be possible in a building with multiple offices, locked doors, and private cubicles. This means important considerations must be taken into account when installing a new WLAN for an organization: all areas of a building should have adequate wireless coverage, all employees must have a reasonable amount of bandwidth, and, for security reasons,
The technology provided by Kiva Systems is not cheap. The least expensive system costs $1 million for 30 robots and two packing stations, while systems for large DCs usually cost between $4 million to $6 million. (Soon it will be possible to lease Kiva Systems technology for high-peak seasonal times.) Yet with worker efficiency increased by up to 400 percent, Kiva’s wireless devices may become the wave of the future.
What Is a Site Survey? 279
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
a minimum amount of wireless signal should “bleed” outside the walls of the building. A vari- ety of factors can impact these goals, such as:
● Are there machines and electronic devices—such as cordless phones, lighting, satellite dishes, or microwave ovens—emitting radio waves that could interfere with or even block the WLAN signals?
● Will the wireless network be in an open environment with few walls or structures to block the signal, or will the network be installed in a warehouse or office that is filled with steel beams, concrete pillars, large filing cabinets, and heavy machinery that could reduce the range of the signal?
● Are office and conference room doors frequently closed or do they remain open? ● Will machinery be periodically moved to different locations? ● Are partitions moved frequently? ● Is the company expanding its physical plant or adding more employees that might
impact wireless transmissions? ● Is there any potential interference from existing internal WLANs? ● Could there be interference from wireless signals from outside the organization, such
as from a nearby building?
Assuring that a WLAN can provide its intended functionality and meet its required design goals can best be achieved through a site survey. A site survey is an in-depth examination and analysis of a WLAN site. There are several reasons for conducting a site survey, just as there are different types of surveys.
Purpose of a Site Survey A site survey is more than determining the location for a new AP. Instead, site surveys have several different design goals:
● Achieve the best possible performance from the WLAN ● Certify that the installation will operate as promised ● Determine the best location for APs ● Develop networks optimized for a variety of applications ● Ensure that the coverage will fulfill the organization’s requirements ● Locate any unauthorized APs on the network ● Map any nearby wireless networks to determine existing radio interference ● Reduce radio interference as much as possible ● Make the wireless network secure
Often the success or failure of a wireless network can be directly linked to the thoroughness of the site survey.
280 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
A site survey provides a realistic understanding of the infrastructure required for the installation of a new wireless network. It also assists in predicting network capability and throughput, as well as indicating the exact location of APs and power levels required. Where applicable, interference from existing devices or neighboring sites is also addressed during the site survey.
Conducting a site survey is both an art and a science. Some of the steps in a site survey involve taking detailed measurements, but other steps can require a combination of experience and trial and error to achieve optimal results.
When to Perform a Site Survey Although a site survey should be performed prior to installing a WLAN, a site survey is important other times, too. This is because a variety of factors can change the performance of the wireless network, and these factors may not have been in existence or may have signif- icantly changed since the original survey. These factors include:
● Physical changes to a building. Remodeling can introduce new sources of interference within the coverage area of the AP, such as motors or metal structures.
● Changes to an existing wireless network. When modifying or extending an existing network structure, it is important to reevaluate the placement of the APs and antennas.
● Changes in network needs. If employees are performing significantly different duties, such as downloading large files on a regular basis, then a new site survey should be performed.
● Significant changes in personnel. Adding several new employees to an office or moving employees from one area to another area may necessitate a new site survey.
Site surveys fall into four different categories, based on when they are conducted. These are summarized in Table 8-1.
Site Survey Category Description
Predeployment Site Surveys Prior to installing one or more APs, a predeployment survey should be conducted. The purpose of this survey is to understand the RF signal behavior in the specific environment.
Postdeployment Site Surveys After the WLAN is installed, it is important to thoroughly test the setup to ensure that all of the APs are providing the necessary coverage.
Periodic Site Surveys This “health check” site survey is generally not as thorough as a postdeployment survey. Instead, the purpose is simply to check that the WLAN is functioning as expected from the perspective of a client device.
Troubleshooting Site Surveys When the WLAN is not functioning as anticipated a troubleshooting site survey can help to identify the reason for the inadequate performance.
Table 8-1 Categories of Site Surveys
© Cengage Learning 2013
What Is a Site Survey? 281
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Many organizations perform a periodic site survey regularly once each quarter.
One of the primary factors dictating the need for site surveys is the ever-changing environ- ment in which the RF signal must be transmitted. Closed doors, newly installed walls, addi- tional employees, and other factors all can impact the RF signal. Would it be possible for the wireless devices to monitor the environment and then automatically adjust power levels or channels to compensate for changes? This type of dynamic “self-managing” WLAN uses what is known as automated RF resource management. There are currently available wire- less network management systems (WNMS) using lightweight APs and wireless LAN control- lers (WLCs) that can monitor the environment and make changes “on the fly.” These WNMS take advantage of such technologies as transmit power control (TPC) found in IEEE 802.11a WLANs. TPC sends this information to the wireless devices and also indicates the maximum transmit power allowed in the WLAN and the transmit power the AP is currently using. The device then responds with its own transmit power capability. The AP uses this data to determine the maximum power for this WLAN network segment so that the radio power can be adjusted dynamically. Despite the fact that automated RF resource manage- ment can make some dynamic adjustments, it is not considered a substitute for a site survey.
TPC, WNMS, lightweight APs, and WLCs are covered in Chapter 5.
Types of Site Surveys There are two types of site surveys. A manual site survey typically involves walking through the WLAN area while carrying a wireless client like a laptop or tablet computer. A site sur- vey software application installed on the computer allows for different network measure- ments to be taken and recorded as the surveyor moves through the area.
Manual site surveys can be divided into two subcategories. A passive manual site survey is used to gather information regarding the RF characteristics on the premises by collecting RF measurements, such as signal strengths, noise levels, and the signal-to-noise ratio (SNR). The survey is “passive” because the wireless client device is only listening to packets as they are sent and received. An active manual site survey can provide more insight into the network connectivity and its performance. This type of manual survey involves both receiving as well as sending packets to determine the status of the WLAN. Packet loss, packet delay, associated APs, and other information can then be gathered. In addition, an active manual site survey can reveal the locations and other details about all the APs such as the MAC addresses, channels, and service set identifiers (SSIDs) in the network.
The second type of site survey is a predictive site survey. Instead of requiring a human sur- veyor to walk through an area with a portable wireless device, a predictive site survey is a virtual survey of the area that uses modeling techniques to design the wireless network. In a predictive site survey, the building floor plans are loaded into the predictive analysis simula- tion application survey software (also called RF planning and management tools) used to
282 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
develop a wireless network design. Predictive site survey application and verification tools can account for building materials, square footage, the number of wireless users, types of applications, antenna models and other variables in a simulated environment to provide a wireless plan for the facility. This also allows for changes to the proposed design to be quickly tested in a “what-if” scenario, something that would be much more difficult with a manual site survey. An example of a predictive analysis simulation application is illustrated in Figure 8-1.
Some WLAN controllers have integrated predictive site survey features.
Performing an outdoor site survey is considered much more difficult than an indoor survey, because of the difficulty in obtaining accurate data. The type of data needed for an outdoor site survey includes:
● Height and material of the buildings, light poles, or other structures that are to host an AP.
● Location, size, and density of areas where trees, foliage, hills, or other obstacles may interfere with the signal.
● Types of applications or the desired bandwidth to be carried.
Figure 8-1 Predictive analysis simulation application
Courtesy of Motorola Solutions, Inc.
What Is a Site Survey? 283
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Availability of power at each building, light pole, or outbuilding to power the APs. ● Availability of data connectivity at each location.
In addition, this information must often be multiplied several times over different areas. That is because remote wireless bridges are commonly used in outdoor settings to connect two or more networks that are separated by a longer distance, and information of the area around each bridge must be obtained. Because of the complexity of an outdoor site survey, many wireless professionals recommend that a predictive site survey first be conducted followed by a manual survey.
Due to the low cost of wireless infrastructure devices, such as APs and wireless routers, some individuals advocate a different approach. In areas in which it is difficult or costly to obtain accurate informa- tion for the site survey, instead of spending large amounts of time and money in a site survey, they suggest that it is more cost-
effective to simply install multiple lower-cost APs in a “best-guess” of a good location, knowing that multiple devices will provide sufficient signal strength to users. However, signal strength is only one factor to be considered; without proper coordination, different devices may actually interfere with each other. The best approach is to perform a site survey when at all possible.
Site Survey Tools
C W N A
6.1.1 Explain the importance of and the processes involved in infor- mation collection for manual and predictive RF site surveys.
6.2.2 Identify the equipment, applications, and methodologies involved in performing manual site surveys.
Different tools are useful when conducting a site survey. For a predictive site survey, all that is needed are the area’s floor plans and the survey software. Most predictive site sur- vey software uses AutoCAD drawing (.dwg) files with embedded detail about building materials. If AutoCAD files are not available, it is possible to import simple floor plan images created in formats such Portable Network Graphics (.png), Joint Photographic Experts Group (.jpg), Graphics Interchange Format (.gif), or Bitmap Image File (.bmp). If a simple floor plan image is used in predictive site survey software, the user must also input data to establish the scale, describe walls and windows, itemize RF barriers on each floor, and so on.
There are several of predictive site survey Web sites that allow users to upload floor plan images. Some of these sites will be used in the hands-on projects at the end of this chapter.
For manual site surveys, a wide variety of tools are available. Whereas some tools can be combined into a single hardware “bundle” that includes the necessary software installed on a
284 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
dedicated hardware device, other software tools can be installed and used individually on dif- ferent devices. These manual site survey tools include wireless device tools and specialized tools. In addition, special consideration may be given to performing a site survey in an area in which voice communications over the WLAN are used.
Wireless Device Tools Access points and wireless network interface card adapters generally include software tools that can be used to perform a basic site survey. However, these tools are rudimentary at best and should not be substituted for more sophisticated tools; rather, they can sometimes be used as the starting point for a survey.
Because a site survey focuses on the proper location of APs, the most basic tool in a site survey is the AP itself. With some APs, it is possible to adjust the output power; this can be important when conducting a survey. Figure 8-2 shows the setting on an AP for adjust- ing the power levels with a slider bar. Other APs use specific increments (Maximum, 100, 50, 30, 20, 5 and 1) while some use predefined settings (High, Ultra High, Super, and Extreme).
Most consumer-grade wireless routers do not have the capability to adjust power levels.
Access points operate on alternating current (AC) from an electrical outlet, but when testing the optimal location of an AP there may not always be an electrical outlet nearby. In that case, a DC-to-AC converter, which converts direct current (DC) from a battery to AC, can be used to power the AP.
Figure 8-2 Adjust power levels with slider bar
© Cengage Learning 2013
Site Survey Tools 285
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
When performing a basic site survey another desirable feature for an AP is to have connections for attaching an external antenna. This can be helpful when determining if an amplifier can be used to increase the amplitude of an RF signal instead of relocating the AP.
In addition to APs, another essential wireless tool is a wireless device such as a notebook or tablet computer with a wireless NIC. These are used to determine the signal strength received from the AP. All operating systems display signal strength, and many manufacturers bundle client utilities with their wireless NICs that show signal strength. Some of these client utilities display the Receive Signal Strength Indicator (RSSI); however, the RSSI should not be relied upon as a valid indicator. Other client utilities represent signal strength as a percentage (the percentage represents the RSSI for a particular packet divided by the maximum RSSI value, and then multiplied by 100). Often these utilities only display bars to indicate signal strength quality without any indication of what the bars represent, much like that of a cell phone. This is illustrated in Figure 8-3. However, because these utilities are not precise, they can only give a rough approximation of the necessary information needed for a site survey.
RSSI is covered in Chapter 3.
Figure 8-3 Signal strength quality in bars
© Cengage Learning 2013
286 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Specialized Tools Specialized site survey tools can provide an accurate picture of the environment and better assist in the precise placement of an AP and in troubleshooting. These specialized tools include dedicated site survey applications, spectrum analyzers, protocol analyzers, and docu- mentation tools.
Dedicated Applications Instead of simply looking at packets received, as when using wireless device tools, dedicated site survey application software can also send packets and then analyze both transmitting and receiving data. Dedicated applications either have limited features or can be more full-featured. A full-featured site survey analyzer software setup screen is seen in Figure 8-4. Some of the settings include:
● Destination MAC Address. This specifies the AP that will be involved in the test. The default is the MAC address of the AP with which the client adapter is currently associated.
● Continuous Link Test. Checking this box will cause the Active Mode test to run repeatedly until the Stop button on the Site Survey page is clicked.
● Number of Packets. This sets the quantity of packets that will be sent during the test. ● Packet Size. This parameter sets the size of the packets that will be sent during the test.
The Packet Size setting should match the packet size typically found during normal WLAN use.
● Data Retries. The Data Retries sets the number of times a transmission will be repeated if an acknowledgement (ACK) frame is not returned by the destination device.
Figure 8-4 Full-featured dedicated application setup
© Cengage Learning 2013
Site Survey Tools 287
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Data Rate. This parameter sets the bit rate at which packets will be transmitted. ● Delay Between Packets. The delay in milliseconds between successive transmissions is
set here. ● Packet Tx Type. This parameter sets the packet type that will be used during the test.
A unicast transmission means that a frame is sent from one sender to a single receiver. A multicast transmission means that a frame is sent from one sender to multiple recei- vers with a single “transmit” operation. Selecting the Unicast option means that the station will expect an ACK back from the destination and will continue to retry if it does not receive one. The Multicast option does not perform packet retries.
● Percent Success Threshold. This parameter allows the user to establish a baseline for what is considered satisfactory performance. Percentages that are greater than or equal to the Percent Success Threshold will be displayed as green bars while percentages below this value will show as yellow bars on the Percent Successful diagram.
The statistics that are generated by the site survey analyzer can be seen in Figure 8-5. Because these statistics are generated in real time, users can freely roam through the cover- age area while gathering statistics and viewing the relative signal strength on a bar graph.
Basic survey analyzer software contains far fewer features. A basic site survey analyzer soft- ware setup screen is seen in Figure 8-6 and the results displayed in Figure 8-7. These analy- zers may make it more difficult to conduct the site survey because they provide limited data.
Spectrum Analyzer A spectrum analyzer is a device that scans the RF spectrum (2.4 GHz or 5 GHz for WLANs) and can locate potential sources of interference. Spectrum
Figure 8-5 Full-featured dedicated application results
© Cengage Learning 2013
288 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
analyzers are passive receivers: they do not make any changes to the signal but instead dis- play it in a way that makes it easy to analyze. Spectrum analyzers usually display the raw and unprocessed signal information such as frequency, voltage, power, period, and the shape of the RF “wave.” The most common spectrum analyzer measurements are modula- tion, distortion, and noise.
Spectrum analyzers can make site surveys a “hit-or-miss” proposi- tion by indicating there is an area of interference so that the AP should be moved to avoid the interference. However, if it is necessary to move the AP then the spectrum analyzer should be run again to determine if the interference has been minimized or eliminated.
Until recently, the drawback to using spectrum analyzer devices has been their high cost, ranging from $10,000 to $40,000. However, new low-cost spectrum analyzers in the form of a USB device that is inserted into a computer have made spectrum analysis much more affordable. Figure 8-8 illustrates the output from a USB spectrum analyzer. The views (charts) are described in Table 8-2.
Figure 8-6 Limited-featured dedicated application setup
© Cengage Learning 2013
Figure 8-7 Limited-featured dedicated application results
© Cengage Learning 2013
Site Survey Tools 289
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Figure 8-8 USB spectrum analyzer output
© Cengage Learning 2013
Chart Name Description
Waterfall View The Waterfall View (the top panel in Figure 8-8) is a time-based graph that shows the aggregate energy collected since the start of the session over time for each frequency. The power of the energy in dBm is shown across the frequency range and one row is inserted in this graph every few seconds. Different colors are used to denote different levels of energy (blues and darker shades are low energy levels and increasingly brighter colors such as green, yellow, orange, and finally red designate higher energy levels).
Waveform View This view (the middle pane in Figure 8-8) shows the aggregate energy collected since the start of a session, with the power of the energy in dBm shown across the frequency range. This spectral view over time displays the current RF energy “signature” in an area.
Realtime View The Realtime View (the bottom pane in Figure 8-8) displays a traditional spectrum analyzer function in which energy (in dBm) is shown real-time as a function of frequency. It can indicate the current, average, and maximum power levels per channel.
Table 8-2 Description of USB Spectrum Analyzer Views
© Cengage Learning 2013
290 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Some USB spectrum analyzers sell for under $50.
Protocol Analyzer Wireless network traffic can be viewed by a stand-alone protocol analyzer device or a computer that runs protocol analyzer software. A protocol analyzer (also called a sniffer) is hardware or software that captures packets to decode and analyze its contents, as shown in Figure 8-9. Protocol analyzers can fully decode application-layer network protocols, such as HTTP or FTP.
Sniffer is technically a trademark name of the Sniffer Network Analyzer product. The more generic term protocol analyzer is preferred.
Figure 8-9 Protocol analyzer output
© Cengage Learning 2013
Site Survey Tools 291
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Protocol analyzers, which can be either integrated into other products or standalone, are widely used by network administrators for monitoring a network. The common uses include:
● Network troubleshooting. Protocol analyzers can detect and diagnose network problems such as addressing errors and protocol configuration mistakes.
● Network traffic characterization. Protocol analyzers can be used to paint a picture of the types and makeup of network. This helps to fine-tune the network and manage bandwidth in order to provide the highest level of service to users.
Documentation Tools Another category of tools for conducting a site survey is docu- mentation tools. The purpose of these tools is to create documentation of the site survey results so they will be available for future reference. A sample documentation form is illus- trated in Figure 8-10. Although there is no industry-standard form for site survey documen- tation, these forms should include the following information:
● Purpose of the report ● Survey methods ● RF coverage details (frequency and channel plan) ● Throughput findings ● Sources of interference
Figure 8-10 Sample site survey documentation form
© Cengage Learning 2013
292 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
● Problem zones ● Marked-up facility drawings with AP placement ● Access point configuration
Because of the amount of data created in a site survey and because a survey needs to be readily accessible for updates, it may be advisable to create a database to store the site survey informa- tion and generate reports. Storing the information in a database instead of using a word pro- cessor makes it much easier to consolidate and then search for and retrieve information.
Voice over WiFi (VoWiFi) Tools and Surveys Voice over WiFi (VoWiFi), which is the implementation of Voice over IP (VoIP) telephony on a WLAN, requires special considerations when performing a site survey. This type of trans- mission depends heavily upon each frame arriving in sequence, whereas data transmissions are not as sensitive to time. Delays in voice transmission can result in a voice conversation that has gaps of dead space.
Three major considerations must be taken into account when planning for VoWiFi:
● Packet loss. Lost packets can be accommodated in data transmission by requesting that a packet be resent. However, in VoWiFi a high number of lost packets can cause a noticeable impact on voice communications. Ideally packet loss in a VoWiFi network should be less than one percent of the total number of packets sent.
● Delay. Unlike packet loss, in which a packet never reaches its destination, delay is the amount of acceptable time that a late packet can arrive and still be used. If the delay of a packet is too long, an echo can be detected that will impact the voice quality. For VoWiFi, delay should be less than 50 milliseconds.
● Jitter. Jitter is the measure of delay between packets. Less than 5 milliseconds is con- sidered the acceptable jitter in a VoWiFi.
When performing a site survey for a WLAN environment that will support VoWiFi, it is recommended that the primary tools used are the built-in tools in the VoWiFi handset itself. These tools provide a true measurement of the RF environment based upon the radio of the VoWiFi handset. Other wireless tools can be used to provide additional assistance during the site survey if necessary.
The basic approach to planning for VoWiFi is to have overlap between adjacent cells of cov- erage area to ensure that there is sufficient RF signal strength present during a handoff between the cells. In an indoor office environment, it is recommended that the radio signal strength at the cell coverage boundary does not drop below –70 decibel milliwatts (dBm). This means that APs should be positioned so as to overlap their boundaries by approximately 6–10 dB. This is illustrated in Figure 8-11.
Technically, when the VoWiFi handset reaches a point where the RSSI is –70 dBm, that handset is also inside the adjacent cell. The RSSI from this AP is between –60 to –64 dBm.
Another consideration is that of antenna use in a VoWiFi handset. The IEEE 802.11n stan- dard takes advantage of advanced Multiple-Input Multiple-Output (MIMO) technology that
Site Survey Tools 293
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
uses multiple antennas and multiple radios resulting in higher speeds. However, MIMO’s benefits may not have a significant advantage to a VoWiFi handset. This is because MIMO requires more than one radio channel and antenna, which in turn means more power and hardware space is needed in the VoWiFi handset. For this reason many VoFiFi handsets do not support 802.11n and do not have multiple antennas. However, some VoWiFi handsets support load balancing of moving a new call to an alternate channel that is less congested.
When conducting a site survey to design a WLAN for VoWiFi sup- port, it is recommended that the network be designed to support a maximum of 10 simultaneous active calls per AP at any given time. This is significantly less than the number of simultaneous data users typically supported by an AP.
Procedures for Performing a Site Survey
C W N A
6.1.1 Explain the importance of and the processes involved in infor- mation collection for manual and predictive RF site surveys.
6.1.2 Explain the technical aspects involved in performing manual and predictive RF site surveys.
6.1.3 Describe site survey reporting and follow-up procedures for manual and predictive RF site surveys.
There are three basic steps in conducting a site survey: gathering the background data, performing the actual survey, and generating the site survey report.
Gathering Data Much of the work in a site survey is actually performed prior to setting up an AP and testing its RF pattern. This preliminary work of gathering the necessary “non-RF” data is critical to performing an effective site survey. Gathering data for a site survey involves examining
– 70 dBm
– 60 dBm
AP AP
– 70 dBm
Handoff should
occur here
– 60 dBm
Figure 8-11 Cell overlap for VoWiFi
© Cengage Learning 2013
294 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
business requirements, defining physical and security requirements, gathering site-specific docu- mentation, documenting existing network characteristics, and analyzing technical requirements.
Examining Business Requirements The first step is to determine the business rea- sons why a WLAN is being proposed for the organization or why an existing wireless net- work is being expanded. Without understanding the reasons why the network is needed it will be almost impossible to properly design and implement the network. This involves examining the business’ requirements needed in order to properly function.
The most common business requirement is that a wireless network provides mobility to its users. Yet it is important to understand what type of mobility is required. Are the users con- tinually in motion, such as in a warehouse or hospital? Or do the users work from different fixed locations throughout the site? Can the desired mobility be accomplished by installing a single AP in a conference room, or is it necessary to have APs throughout the entire floor of the building? Also, what types of applications will be used on the WLAN? And what types of devices will be connecting to the network?
Another requirement is to determine the amount of bandwidth that the users require. This is a function of the type of activity that users will be performing on the WLAN. Users need higher data rates for time-bound transmissions, such as audio and video. However, users who need basic data access may not need the higher bandwidth. And, there are different types of data users. A user who needs to frequently download large data files will need more bandwidth than a user who occasionally uses the wireless network to check e-mail or visit a Web site.
If wireless devices require higher data rates the number of users per AP may need to be limited, which requires more APs to be installed.
Examining business requirements usually involves performing interviews with key organiza- tion personnel. There are a variety of different types of interviews. These include:
● One-on-one interviews. This is the most common interview technique. It involves ask- ing questions of a key stakeholder for the purpose of gathering information. Usually this type of interview should be planned well ahead of the actual interview so that the interviewee can be prepared with the necessary information. The interview can be tailored to discuss current processes, uncover future needs, or determine the problems that need to be resolved.
Unlike a television courtroom drama, the purpose of a one-on-one interview is not to “trip up” the interviewee so that they reveal a secret. Instead, one-on-one interviews should help the interviewee put into words any thoughts and ideas that may not have been clearly articulated before.
● Group interviews. A group interview has the same goal as a one-on-one interview yet has the added benefit of several of the participants discussing and exchanging ideas between each other, as well as being able to provide multiple dimensions of the same answer. However, group interviews often are more difficult to conduct because of the
Procedures for Performing a Site Survey 295
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
larger number of participants and because they may not see “eye-to-eye.” This can make it difficult for the interviewer to filter out the actual answers.
● Facilitated sessions. In a facilitated session, a much larger group consisting of all primary and secondary stakeholders are gathered together with the goal of remaining together until all the requirements are gathered. Usually a trained facilitator is needed to keep the group “on track” and functioning productively towards the goal.
● Questionnaires. Although paper or electronic questionnaires are often used, in reality these can have a limited value. Many respondents hurry through a questionnaire without giving it adequate thought. In addition, although questionnaire results can be statistically tabulated, these numbers many not reflect the reasons behind specific responses or provide deeper insight into the questions.
Questionnaires should be used for gathering quick statistics to get a sense of the relative priority of issues. They should not be a substi- tute for interviews.
● Shadowing. Although the most time-consuming for both the interviewer and the inter- viewee, following the interviewee around while he performs his normal duties gives the interviewer opportunities to ask questions and receive answers as actual practices occur. This is helpful when work routines have become so ingrained that people have a hard time explaining why they do what they do.
Defining Physical and Security Requirements Because WLANs use unsecured radio waves to transmit data, security is an important consideration when gathering data for a site survey. It is necessary to consider what type of data encryption will be used and the type of authentication that will take place across the WLAN. In addition, it is critical to understand current security policies and procedures that are already in force. The WLAN must fit into the organization’s overall security scheme in order to provide the best protec- tion for all data resources.
WLAN security is covered in detail in Chapters 9 and 10.
In addition to security requirements, the physical requirements must be examined as well. Where will the APs be located? Can they be secured? Is there a sufficient cable infrastructure for connecting the APs to the wired network? Will additional switches, routers, and other physical equipment need to be installed?
Gathering Site-Specific Documentation Once the business and physical and security requirements are understood, the next step is to gather site-specific documentation. This information is generally accumulated in two ways.
First, blueprints, facility drawings, and other documents can be obtained that show specific building infrastructure components. These include electrical outlets for APs, potential sources of RF interference like elevator shafts, and the type of ventilation system that may dictate the placement of APs.
296 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
However, blueprints and other similar documents may not reveal the current state of the building, particularly if it is older. Walls may have been changed or added, additional elec- trical outlets installed, and offices carved out of what was once open space. The only way to gather current information is through the second method, inspecting the site. The purpose of this walk-through is to document any changes to the blueprints and also to gain a visual perspective of the site. When conducting an inspection it may be necessary to have equip- ment available such as a ladder, flashlight, cellular telephone, and other resources for peer- ing into remote locations. For a larger organization, it may be necessary to have an approved escort from the organization accompany the team. This person should be autho- rized to enter offices and closets. It may be necessary for the escort to have a set of master keys in order to provide access to locked areas.
Documenting Existing Network Characteristics Another task is to document the existing wireless and wired networks. The reason for this is to ensure that the new or expanded WLAN will dovetail into what is already in place. Questions that should be asked include:
● How does the current network support the organization’s mission? ● What applications run on the network? ● How many users does it support? ● What are the strengths and weaknesses of the current network? ● What is the anticipated growth in network technology?
How the network supports the organization is an important consideration. Examining the current status of the network, especially the applications that run on the network and the number of users, can reveal much of this information. The question regarding the strengths and weaknesses of the network can begin to identify why a new or expanded wireless net- work may be needed.
With the rapid growth of networks it is not uncommon for servers and clients to be added to the network to meet an immediate need without properly documenting the changes. Doc- umentation of the current network may include a table that summarizes information about the network. Some of the types of information that should be included in the current network document include:
● Number of clients ● Types of clients ● Number of servers ● The topology of the network ● What media is being used ● Performance of the network ● Types of devices connected to the network
A sample current network table is seen in Table 8-3. Depending on the complexity of the network, a diagram of the network may also be necessary.
Procedures for Performing a Site Survey 297
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Analyzing Technical Requirements Gathering data to determine the technical requirements for the WLAN is also important. Table 8-4 list several WLAN requirements while Table 8-5 lists wireless technical considerations. These questions should be answered before proceeding with the selection of the type of wireless network to install.
Category Description
Number of clients 28
Types of clients 26 – Microsoft Windows 7 Professional 2 – Red Hat Linux
Number of servers 1 – Windows Server 2010
Type of network Ethernet 1GB switched
Type of media being used Category 6 UTP
Types of devices connected to network 6 laser printers; 1 scanner; switch connects to 10-Gigabit Ethernet campus backbone
Table 8-3 Current network table
© Cengage Learning 2013
WLAN Requirement Questions
Client connectivity requirements What speed and coverage areas are needed for the various stations in the wireless network?
Indoor- or Outdoor-specific information Are there special building or topographical issues that must be taken into consideration?
Identifying infrastructure connectivity and power requirements
Will the new/expanded WLAN interface with any existing networks? Is adequate electrical power available where equipment will be located?
Defining physical and data security requirements
What types of physical and network data security is needed to protect the network? Are there any specific aesthetics requirements?
Table 8-4 WLAN requirements
© Cengage Learning 2013
Technical Consideration Questions
Understanding RF coverage requirements How large is the physical area that the wireless network will serve? What type of AP and antenna should be used?
Understanding data capacity and client density requirements
Will there be adequate bandwidth for the stations? Are enough cells available to support the number of stations?
Voice over WiFi (VoWiFi) If VoWiFi will be used, what is the correct quality of service (QoS) technique to support it?
Tracking system considerations How will the location of wireless devices be tracked?
RF security considerations Should a system to monitor the RF frequency to ensure security be implemented?
Table 8-5 Wireless technical considerations
© Cengage Learning 2013
298 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Performing the Survey Once the necessary data has been accumulated, the next step is to actually perform the sur- vey. This involves not only AP configuration and location but also identifying interference. In addition, understanding the difference between outdoor surveys and indoor surveys is important.
Access Point Configuration and Location The first step is to decide on the type of AP that will be used. These options typically include autonomous APs, controller-based architectures (lightweight, mesh, or captive portal APs), WLAN arrays, cooperative control, and mesh networks. In addition, the correct type of antenna (omnidirectional or semidirec- tional) must be determined and matched with the AP.
The next step is to configure the AP for the optimum power output and channel assign- ments. Enterprise-class APs often have the ability to adjust the power levels with a slider bar, in specific increments, or using a predefined setting. With IEEE 802.11b/g the available frequency spectrum (2.412 to 2.484 GHz) is divided into 11 channels, and only three of which are nonoverlapping channels are available for simultaneous operation. Within each 802.11a frequency channel there is a channel 20-MHz wide that supports 52 carrier signals, with each signal 300 KHz wide. IEEE 802.11a networks have 555 MHz spread across 23 nonoverlapping channels.
Once the configuration is complete the AP can be placed in a temporary location. This may not be the final location for the AP, but it will give a starting point. If an omnidirectional antenna is being used, then the AP should be placed in the center of the room or coverage area as much as possible; if a semidirectional antenna is used then the AP should be posi- tioned in one corner of the room. Once the AP is placed, its position should be noted along with the orientation of the antennas. This can be done by drawing it on a blueprint or map of the room along with a narrative description. Recording the position of APs and antennas with a digital camera is also helpful.
When performing a manual site survey, using a portable device with the appropriate soft- ware measurement tools running, the surveyor should start at the closest point to the AP and slowly walk away in one direction. While walking, it is important to observe the data being displayed by the software measurement tools. As the surveyor continues to move, the data can be recorded.
In addition to walking through the site with the software measure- ment tools running, it is important to test the actual applications to be used in the network.
Identifying Interference It is rare for a site survey not to detect any interference that would impede the RF signal. One consideration is the interference of radio signals from other objects. Table 8-6 lists different types of objects and the degree of interference that they may cause. Based on the amount of interference, it may be necessary to relocate the AP or reorient the antenna in order to reduce interference.
Another type of interference can come from another nearby WLAN, when either both net- works attempt to use the same channel or an adjacent channel. If all of the APs were set to
Procedures for Performing a Site Survey 299
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
the same channel number then it would result in reduced throughput because each station must wait a longer period of time for their turn to transmit (cochannel interference). To eliminate this it is necessary to arrange the coverage areas of the APs so that one channel does not interfere with an adjacent channel. Each cell is separated from other cells so that no two adjacent cells have the same channel number in order to reduce interference (adjacent channel interference).
Outdoor Surveys Outdoor surveys follow the same basic steps listed for a WLAN indoor site survey, with some additional considerations. For example, if the survey is taken in the fall or winter after deciduous trees and bushes have lost their foliage, it should be noted that the leaves could impact the RF signal after they have grown back. In addition, climatic conditions may need to be taken into account. In areas with large amounts of rain- fall or fog, these elements should be taken into account when placing APs or transmitters. And, if the antenna must be installed on a rooftop, there should be ready access to that location.
Object Example Type of interference
Open space Courtyard or open cafeteria None
Wood Door or floor Low
Plaster Inner wall Low
Synthetic materials Office partition Low
Cinder block Exterior wall Low
Asbestos Ceiling insulation Low
Glass Clear window Low
Wire mesh in glass Security window Medium
Human body Large group of people Medium
Water Aquarium Medium
Brick Outer wall Medium
Marble Floor Medium
Ceramic Floor High
Paper Roll or stack of paper stock High
Concrete Floor, pillar High
Bulletproof glass Security booth High
Silvering Mirror Very high
Metal Elevator shaft or filing cabinet Very high
Table 8-6 Interference by objects
© Cengage Learning 2013
300 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Outdoor antennas are usually affixed to a pole or mast, which serves the dual purpose of improved reception and a discouragement to thieves. Antenna mounting systems are avail- able that can secure the antenna yet can quickly be unlocked to lower the antenna for repair or maintenance. Just as an antenna is designed to pick up RF signals, it also can inadver- tently pick up high electrical discharges from a nearby lightning strike (or contact with a high-voltage electrical source). A lightning arrestor, which limits the amplitude and disturb- ing interference voltages by channeling them to the ground, should always be used with out- door antennas.
Prior to any installation of an outdoor antenna the necessary permits must be secured from the local municipality. In addition, all zoning requirements must be met. Because outdoor antennas can be unattractive, camouflaging the antenna in order to provide the proper aesthetics is always desirable.
Creating the Site Survey Report The final step is to create the site survey report. Although the reporting methodology may differ, site survey reports generally have two parts: a narrative section and a graphical section.
The narrative section should begin by stating the requirements from the customer regarding what they wanted from the site survey. This ensures that the material in the report focuses on the problems to be addressed. The narrative section should also outline how the survey was conducted, known as the methodology. It is important to clearly outline in this section all of the steps that were taken in preparation for the survey and in the course of conducting the survey itself. This makes it clear to the reader that the survey follows a recognized and methodical pattern, and shortcuts or questionable actions were not taken. The narrative sec- tion should also clearly state the results of the measurements as well as an analysis for the capacity and a verification of the coverage.
The final part of the site survey narrative should include hardware, software, and networking recommendations regarding the WLAN. Typically a bill of materials (BOM) is included. A BOM itemizes every software and/or hardware component that is needed for the new WLAN. In addition, options regarding how best to install and configure the wireless net- work. The report should also include an analysis for the capacity of the network and a verifi- cation of the coverage area.
The graphic section generally includes maps and diagrams of the coverage area. A data rate coverage map, as seen in Figure 8-12, is typical. More sophisticated maps, such as a 3-D SNR plot like that in Figure 8-13 can also be supplied if the customer specifically requested that type of information in advance.
Procedures for Performing a Site Survey 301
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Figure 8-12 Data rate coverage map
© Cengage Learning 2013
302 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Chapter Summary ■ One of the challenges of setting up a WLAN is determining the best location for APs
and other wireless devices. Obstacles such as walls, floors, elevator shafts, and even people can impact the RF signal. This makes it important to take these into consider- ation prior to installing equipment. In addition, as conditions continue to change in the office environment, it is important to monitor and adjust the WLAN. A site survey is an in-depth examination and analysis of a WLAN site.
■ Although a site survey should be performed prior to installing a WLAN, conducting a site survey is important other times as well. This is because a variety of factors can
Figure 8-13 3-D SNR plot
© Cengage Learning 2013
Chapter Summary 303
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
change the performance of the wireless network, and these factors may not have been in existence or may have significantly changed since the original survey.
■ A manual site survey typically involves walking through the area of the WLAN while carrying a wireless client like a laptop or tablet computer. A site survey software application installed on the computer allows for different network measurements to be taken and recorded as the surveyor moves through the area. Instead of walking through an area with a portable wireless device, a predictive site survey is a virtual survey of the area that uses modeling techniques to design the wireless network. When conducting a predictive site survey, it’s necessary to load the building floor plans into the predictive analysis simulation application survey software. This software is then used to develop a wireless network design.
■ Different tools can be used when conducting a site survey. For a predictive site survey all that is needed is the predictive analysis simulation application survey software along with the area’s floor plans. For manual site surveys, a wider variety of tools are useful. Access points and wireless network interface card adapters generally include software tools that can be used to perform a basic site survey. However, these tools are rudimentary at best and should not substitute for more sophisticated tools. Dedicated site survey application software can also send packets and then analyze both transmit- ting and receiving data. A spectrum analyzer is a device that scans the RF spectrum and can locate potential sources of interference. A protocol analyzer is hardware or software that captures packets to decode and analyze its contents. Documentation tools can be used to record the site survey results so they will be available for future reference. Voice over WiFi (VoWiFi), which is the implementation of Voice over IP (VoIP) telephony on a WLAN, requires special considerations when performing a site survey.
■ There are three basic steps in conducting a site survey. The first is gathering the back- ground data. Gathering data for a site survey involves examining business require- ments, defining physical and security requirements, gathering site-specific documenta- tion, documenting existing network characteristics, and analyzing technical requirements. Once the necessary data has been accumulated, the next step is to actu- ally perform the survey. This involves not only AP configuration and location but also identifying interference. When performing a manual site survey using a portable device with the appropriate software measurement tools running, the surveyor should start at the closest point to the AP and slowly walk away in one direction. While walking, it is important to observe the data being displayed by the software measurement tools. It is rare that a site survey would not detect any interference that would impede the RF signal. This information should be analyzed so that the AP can be relocated if necessary.
■ Outdoor surveys follow the same basic steps listed for a WLAN indoor site survey yet there are additional considerations. If the survey is taken in the fall or winter after deciduous trees and bushes have lost their foliage, it should be noted that the leaves could impact the RF signal after they have grown back. In addition, climatic condi- tions may need to be taken into account. In areas with large amounts of rainfall or fog, these elements should be taken into account when placing APs or transmitters. And, if the antenna must be installed on a rooftop, there should be ready access to that location.
304 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
■ The final step is to create the site survey report. Although the reporting methodology may differ, site survey reports generally have two parts, a narrative section and a graphical section. The narrative section should begin by stating the requirements from the customer regarding what they wanted from the site survey. This ensures that the material in the report focuses on the problems to be addressed. The narrative section should also outline how the survey was conducted, known as the methodology. The final part of the site survey narrative should include hardware, software, and net- working recommendations regarding the WLAN.
Key Terms automated RF resource management A dynamic self-managing WLAN in which the wireless devices monitor the environment and then automatically adjust power levels or channels to compensate for changes. bill of materials (BOM) A list of itemized software and/or hardware components that are needed for a new WLAN. delay The amount of acceptable time that a late packet can arrive and still be used. jitter The measure of delay between packets. manual site survey A site survey that requires walking through the area of the WLAN while carrying a wireless client like a laptop or tablet computer. predictive analysis simulation application Site survey software used in a predictive site survey that allows for building floor plans to be loaded and analyzed. predictive site survey A site survey that is a virtual survey of the area that uses modeling techniques to design the wireless network. protocol analyzer Hardware or software that captures packets to decode and analyze its contents. RF planning and management tools See predictive analysis simulation application. site survey An in-depth examination and analysis of a WLAN site. spectrum analyzer A device that scans the RF spectrum to can locate potential sources of interference.
Review Questions 1. Each of these should be taken into consideration when installing an indoor WLAN
except:
a. open or closed doors.
b. location of microwave oven.
c. room temperature.
d. relocation of machinery.
2. Which of the following is not a design goal of a site survey?
a. minimize bandwidth utilization
b. determine the best location for the APs in the WLAN
Review Questions 305
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
c. develop wireless networks that are optimized for the applications used on the network
d. locate any unauthorized APs
3. A site survey should be performed in all of the following situations except:
a. when there are physical changes to the building.
b. when there are changes in network needs.
c. when there are software updates available to client utilities.
d. when there are significant changes in personnel.
4. A dynamic “self-managing” WLAN that can monitor the environment and then automatically adjust power levels or channels to compensate for changes uses tools.
a. automated RF resource management
b. WNMS Dynamic Protocol (WNMS-DyPro)
c. Resource Modification (ResMod)
d. AP segregated configuration
5. A(n) site survey does not require the surveyor to walk through a site with a mobile device to determine coverage areas and interference.
a. passive manual
b. active manual
c. simulated
d. predictive
6. Each of the following should be considered when performing an outdoor site survey except:
a. height and material of the buildings, light poles, or other structures that are to host an AP.
b. availability of power at buildings, light poles, or outbuilding to power the APs.
c. trees, foliage, hills or other obstacles.
d. time of day.
7. Which device can be used to power an AP from a battery?
a. DC-to-AC converter
b. AC-to-DC converter
c. power over Wi-Fi module
d. AP capacitor
8. Which of the following is false regarding a spectrum analyzer?
a. It scans the RF spectrum of 2.4 GHz or 5 GHz for WLANs.
b. It is an active device that makes changes to the RF signal.
306 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
c. It usually displays the raw and unprocessed signal information.
d. The most common measurements are modulation, distortion, and noise.
9. A(n) captures packets to decode and analyze its contents.
a. spectrum analyzer
b. protocol analyzer
c. reverse packet accumulator (RPA)
d. HTTP filter
10. Which is not typically found on a site survey documentation form?
a. purpose of the report
b. throughput findings
c. AP configuration
d. wired network topology
11. What is jitter?
a. The measure of delay between packets.
b. The amount of acceptable time that a late packet can arrive and still be used.
c. Three or more consecutive packets identified by a spectrum analyzer.
d. The minimum number of lost packets that VoWiFi can tolerate.
12. When performing a site survey for a WLAN environment that will support VoWiFi, it is recommended that the primary tools used are .
a. packet transfer devices
b. AP signal strength meters
c. manufacturer client utilities on a laptop
d. the built-in tools in the VoWiFi handset
13. In an indoor office environment, it is recommended that the radio signal strength at the cell coverage boundary for VoWiFi does not drop below dBm.
a. �1 b. �7 c. �70 d. �700
14. Which of the follow types of interviews only provide statistical summaries of answered questions?
a. one-on-one interviews
b. group interviews
c. facilitated sessions
d. questionnaires
Review Questions 307
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
15. When documenting the current network, each of the following items is important except:
a. the number of USB ports on each client.
b. the number of clients.
c. the type of media.
d. the types of clients.
16. Which type of devices has the ability to adjust power levels?
a. Enterprise-class APs
b. consumer-grade APs
c. wireless routers
d. wireless network interface card adapters
17. IEEE 802.11a networks have 555 MHz spread across nonoverlapping channels.
a. 11
b. 23
c. 52
d. 128
18. Each of the following is an example of an object that may cause a high degree of RF interference except:
a. bulletproof glass.
b. concrete.
c. ceramic.
d. cinder block.
19. If all APs were set to the same channel number, the result would be .
a. adjacent channel interference
b. cochannel interference
c. RF overlap interference
d. channel bonding interference
20. A itemizes every software and/or hardware component that is needed for the new WLAN in a site survey report.
a. bill of materials (BOM)
b. product specification listing (PSL)
c. device specification explosion report (DSEP)
d. client handsheet specification listing (CHSL)
308 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Hands-On Projects
Project 8-1: Using Vistumbler as a Site Survey Tool Although it is not considered to be a site survey tool, Vistumbler can also be used for gathering RF information that could be used in a rudimentary site survey. In this project you will use the Vistumbler software installed in Hands-On Project 3-2 to collect data.
1. Click Start, click All Programs, click the Vistumbler folder, and then click Vistumbler.
2. Expand the window to full screen.
3. Click Scan APs if necessary. If no networks appear, click Interface and then select the appropriate wireless NIC interface.
4. Note the columns Signal and High Signal. Why does the Signal column change?
5. Click View.
6. Click Show Signal dB (Estimated). The columns Signal and High Signal now provide the estimated db. Carry the mobile device away from the AP and monitor the signal strength graph. Note the obstructions between the AP and the laptop.
7. Save the results of this session. Click File and Export and then Export To CSV.
8. Click All APs.
9. Click Detailed.
10. Change the filename from the default name to Site-Survey.csv. Be careful to only change the filename, not the location. Click Ok twice.
11. Close Vistumbler.
12. Launch Microsoft Excel and open the Site-Survey.csv file. How could this data be help- ful in performing a site survey?
13. Close all windows.
Project 8-2: Online Site Survey Tool—WLAN Coverage Estimator An increasing number of Web-based online site survey tools are available to help you design a WLAN. One tool is the AirTight WLAN Coverage
Estimator. This tool allows you see coverage areas within a large space. In this project you will use this tool and evaluate it. Before you begin, make sure you know the dimen- sions of the area you want to survey.
1. Use your Web browser to go to www.airtightnetworks.com/home/solutions/80211n/ 80211n-wlan-coverage-estimator.html.
Hands-On Projects 309
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
It is not unusual for Web sites to change the location where files are stored. If the URL above no longer functions then open a search engine and search for “AirTight WLAN Coverage Estimator”.
2. Click Get Started.
3. Under RF Environment scroll through the different options. Select Indoor Office.
4. The center grid area is where you will draw your survey area. Depending on your set- ting, you may need to change the dimensions under Design Controls. The default dimensions are 600 feet in length and 300 feet in width. If necessary, change the Length and Width settings that create a grid large enough to contain your survey area.
5. Beginning at the upper left corner, click the intersection of a horizontal and vertical line on the grid, and then drag the mouse to draw a line that indicates an outer wall. Con- tinue to click and drag lines to create the remaining outer walls, leaving space for doors. Remember that doors are approximately 3 feet in width.
6. Now you are ready add the APs. In the right pane, under Legacy Access Points, drag a bg AP (“bg” stands for IEEE 802.11b/g) to the upper-left quadrant of your grid. Note that the coverage area is shown as a maximum area with an inner circle of optimum coverage of 54 Mbps.
7. Move the slider under Link Speed (Mbps) from 54 to 18. What happens to the optimum coverage area? What is the trade-off of providing all users 18 Mbps instead of users closer to the AP with 54?
8. Move the slider from 18 to 9. What happens now? Move the slider back to 54.
9. Under RF Controls change the antenna transmit power from 100 (mW) to 40. What is the impact?
10. Under 802.11n Access Points, add an 802.11n AP by dragging the abgn icon to an area on the grid. How does its coverage area compare with that of the 802.11b/g AP?
11. Adjust the slider under Link Speed (Mbps) from 130 to 52. What happens?
12. Next change the channel width from 20 MHz to 40 MHz. What impact does this have?
13. Click the Estimate Cost button to see an approximation of the costs for this WLAN in the Input Project Costs window.
14. Click the Cancel button to close the Input Project Costs window.
15. Click the Generate Report button. Accept Use default costs for creating bill of material. Enter your e-mail address to have the report sent to you, and then click Submit. What can you say about the contents of this report?
16. Close all windows.
17. What is your opinion of this tool? Is it easy to use? Would you recommend it?
310 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
Project 8-3: Online Site Survey Tool—Wi-Fi Planning Tool (Part 1) The Wi-Fi Planning Tool from Aerohive is another Web-based online site sur- vey tools that can help you design a WLAN. In this project you will configure the settings for this online tool.
1. Use your Web browser to go to www.smartdraw.com/examples/view/office+layout +with+meeting+room/.
It is not unusual for Web sites to change the location where files are stored. If the URL above no longer functions then open a search engine and search for “Smartdraw office layout example”.
2. Capture this image as a Portable Network Graphics (.png). Click Start and type Snipping Tool. Click on this application to launch it.
3. Under New select Rectangular Snip.
4. The background will now change to a lighter color indicating that you can capture this image. Drag the cursor around the office layout example and release the mouse button.
5. In the Snipping Tool click File and Save As.
6. Be sure that Portable Network Graphics (PNG) is the file type. Enter the name Office- Download as the filename.
7. Close the Snipping Tool.
8. Use your Web browser to go to www.aerohive.com/planner.
It is not unusual for Web sites to change the location where files are stored. If the URL above no longer functions then open a search engine and search for “Aerohive Wi-Fi Planning Tool”.
9. You will need to create an account to upload the floor plan for an indoor site survey.
10. Enter the requested information and click Submit. Open the e-mail sent to your account and click the activation link. Open the new e-mail sent to your account to retrieve your login information.
11. Use your browser to proceed to the Login URL provided in the email, type your e-mail address in the Admin box, type your password in the Password box, click Log in and then click Agree.
12. The Planning Tool Settings dialog box appears.
13. Click Import an existing floor plan image, click Import, and then click Upload. Navi- gate to the file Office-Download, select the file and click Open.
14. In the middle of the dialog box, change coverage from 90 to 80.
15. In the upper-left corner of the dialog box, click the Update button.
Hands-On Projects 311
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
16. The Topology settings appear. Right-click Planning map and click Add Building.
17. Enter Building1 as the name of the building and click Create.
18. Right-click Building1 and select Add Floor.
19. Enter Office1 as the name of the floor. Under Background Image select the file that you uploaded. Click Create.
20. Click Office1 in the left pane.
21. The Scale Map Section dialog box appears, asking you to create a scale for your floor plan. Change meters to feet.
22. Click Height.
23. Drag one of the crosshairs to the edge of the door in Office 1 in the floor plan.
24. Drag the other crosshair to the opposite edge of the door in Office 1.
25. In the dialog box enter 3 for the distance between the crosshairs. Click Update.
26. There are four tabs across the top—View, Walls, APs, and Auto Placement—which rep- resent the sequence of steps to be taken. Click Walls.
27. Click Draw Perimeter to draw the outside walls.
28. Change Wall Type to Concrete (12dB) to represent the outer walls.
29. Click the upper-left corner of the Conference Room and drag and click the blue line around the outer edge of the entire floor to create the perimeter. (Click once to anchor the line to a corner and then move the mouse to the next corner and click again.) Double-click when the entire perimeter is finished.
30. Now you can enter the composition of the interior walls. Click Wall Type. The different types of walls along with their estimated RF signal loss is displayed. Click Dry Wall (3dB).
31. Click the single line icon next to Draw Wall.
32. Office 1, 2 and 3 are all enclosed by drywall, as is the Conference Room and Reception Area. Use the tool to draw drywall on these areas.
33. Change Wall Type to Cubicle (1dB). Draw the walls around the two pods of cubicles (6 cubicles and 4 cubicles).
34. Leave this application open for the next project.
Project 8-4: Online Site Survey Tool—Wi-Fi Planning Tool (Part 2) Now that you have configured the Wi-Fi Planning Tool, you will place APs for the site survey.
1. Click the APs tab. If necessary, under AP Type, select 802.11a/b/g-HiveAP20.
2. Click Add AP to add an AP to an empty space. Notice the coverage area of the AP.
312 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
3. Now drag and drop the AP to a new location to see how the coverage area changes based on the wall composition.
4. Click Add AP until the entire floor plan has sufficient coverage. How many APs were needed?
5. Click Remove All APs and then confirm by clicking Yes.
6. Now change the type of AP. Under AP Type, select 802.11n 3x3:3 HiveAP350.
7. Click Add AP. Notice the difference in the coverage areas and the increased signal strength compared to the 802.11a/b/g AP.
8. Click Remove All APs and then confirm by clicking Yes.
9. Click Auto Placement.
10. Note that you can change the type of application that will be primarily used in this setting. Under Application click Basic Connectivity. The Signal Strength changes to –80.
11. Click Auto Place APs. How many APs are needed?
12. Under Application click High Speed Connectivity. What is the change that takes place?
13. Under Application now click Voice. Why does it change?
14. Change Band from 5 GHz to 2.4 GHz. What happens? Why?
15. Click Remove All APs and then confirm by clicking Yes.
16. Click the APs tab.
17. If necessary, under AP Type, select 802.11a/b/g-HiveAP20.
18. Click Add AP three times to add three APs to this floor plan. Place them where you think best.
19. Click the View tab.
20. Change Band from 2.4 GHz to 5 GHz.
21. Click Data Rates to see the throughput from this site survey.
22. Finally create a site survey report. Click the Operation button.
23. Click Export PDF Report.
24. When the report has been generated, click Download and then open and view the report.
25. Click Log Out.
26. What is your opinion of this tool? Is it easy to use? Would you recommend it?
Hands-On Projects 313
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Case Projects
Case Project 8-1: Automated RF Resource Management There are several wireless network management systems (WNMS) using lightweight APs and wireless LAN controllers (WLCs) that can monitor the environment and make changes on the fly by using automated RF resource
management tools. Use the Internet to research automated RF resource management tools. How do they work? What are their advantages and disadvantages? Would you recommend using one? Write a one-page paper on your findings.
Case Project 8-2: Predictive Site Survey Application Use the Internet to research three predictive site survey application. Create a table that com- pares the features of each one. How do they work? What are their advantages over manual site surveys? What file types can be used to import building floor plans? Write a one-page paper about your research.
Case Project 8-3: Inexpensive Spectrum Analyzers The drawback to using spectrum analyzer devices has been their high cost, ranging from $10,000 to $40,000. Recently, low-cost spectrum analyzers in the form of a USB device that is inserted into a computer have made spectrum analysis much more affordable. Research inexpensive spectrum analyzers and identify three different models. Compare their features in a table, including system requirements and costs. Next compare them to a full- featured spectrum analyzer. In your opinion, could the inexpensive spectrum analyzers be used as an alternative to the full-featured models, or only as a supplement? Why? Write a one-page paper on your research.
Case Project 8-4: Open Source Protocol Analyzers Whereas at one time protocol analyzers were proprietary and expensive, today there are sev- eral excellent protocol analyzers that are their open source or free products. Research these protocol analyzers, such as Wireshark, Colasoft’s Capsa, Packetyzer, and others. Which product would you recommend for capturing and analyzing wireless traffic? Why? Write a paper on the information that you find.
Case Project 8-5: Nautilus IT Consulting Nautilus IT Consulting (NITC), a computer technology business, needs your assistance with one of their new clients.
Gabe’s Grill is a chain of restaurants with several locations in the area. The owners have been hesitant to provide free wireless access to their customers, but with increased competi- tion from other restaurants in the area they believe that they should now seriously consider installing a WLAN. Gabe’s Grills are constructed with thick concrete, glass, and other mate- rials that can impact a WLAN signal, and they are typically located in areas in which other wireless RF signals can be picked up from nearby businesses. Although each Gabe’s Grill location will need a separate site survey, the owners are resistant to hiring NITC to perform them. Instead, they want only one survey, conducted at a single location, which can then be used for all the other locations.
314 Chapter 8 Conducting a Site Survey
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8
1. Create a PowerPoint presentation of eight or more slides that explains what a site sur- vey is, how they are conducted, and what the results of the survey will provide to Gabe’s Grill owners.
2. Write a one-page memo that explains the reasons why a separate site survey should be conducted at each location, and what problems could arise if a single survey taken at one location was used in another restaurant.
Case Projects 315
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
chapter9
Wireless LAN Security Vulnerabilities
After completing this chapter you should be able to:
• Define information security • Describe the different types of wireless attacks • List the legacy IEEE security protections • Explain the vulnerabilities of wireless transmissions
317 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
One of the most shocking attacks using a wireless network still has authorities shaking their heads in disbelief. Was this an attack on a corporate wireless network that stole sensitive company secrets? No. Was it a breach that allowed attackers to steal credit card information from customers and then charge purchases to their accounts? No. Instead, it was one neighbor attacking another neighbor using wireless technology.
In 2009 a couple moved into a new house in Minnesota. The next day their four- year-old son wandered into the yard of their neighbor Barry. When Barry returned the child to his house he gave the boy a kiss on the lips. This shocked and frightened the couple, so they filed a police report. The police interviewed Barry but no charges were pressed. Yet Barry was irate with his new neighbors and decided to take revenge on them.
Barry downloaded wireless attack software and purchased books on cracking wireless networks. He soon was able to crack the couple’s wireless Wired Equivalent Privacy (WEP) security (WEP is notoriously weak and can easily be broken). Barry then acted like a "depraved criminal," according to the prosecutors, and started a "calculated campaign to terrorize his neighbors, doing whatever he could to destroy the careers and professional reputations of [the couple], to damage [their] marriage, and to generally wreak havoc on their lives.”
Barry broke into the couple’s wireless LAN from his home. He then created a ficti- tious MySpace page with the husband’s name on it and posted pictures of explicit child pornography. He also posted a brash note that pretended to be from the husband stating he was a lawyer and could get away with "doing anything." Barry e-mailed the same pornography to the husband’s coworkers and sent flirtatious e-mail to women in the husband’s office. He even sent threatening e-mails to the Vice President of the United States from the husband’s Yahoo account. The e-mails claimed that he was a terrorist and would kill the VP (this prompted a visit from the Secret Service). There were many other similar attacks on the couple and their relatives.
The law office where the husband worked hired a forensics investigator who, with permission, installed a protocol analyzer to "sniff" the wireless home traffic. In the data surrounding the threatening VP e-mail was Barry’s name and account informa- tion. The FBI searched Barry’s house, found the evidence (along with other evidence that he had done the same to a previous neighbor), and arrested Barry. He was offered a two-year sentence but turned it down. So, the prosecutors piled on more charges. He finally pled guilty. Barry, who had children himself, was ultimately sentenced to 18 years in prison and even had to forfeit his house.
Real World Wireless
318 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The list of advantages for a wireless LAN (WLAN) is impressive. WLANs provide true mobil- ity for users and do not force them to be restricted to one location in order to access network resources. This greater flexibility can result in substantial productivity increases for employees. Another advantage of wireless technology is the relative ease of installation. No longer are cable drops required for each computer on the network; instead, a single connection to an access point (AP) is all that it is needed to provide network connectivity to multiple devices. This both decreases installation costs and allows for wireless networks to be installed in loca- tions where previously it would have been difficult or impossible to install wiring, such as in older buildings or large warehouses.
Yet despite these advantages, a single element has proven to be a major stumbling block to wireless technology: wireless security. Security has long been the Achilles heel of wireless networking. Compared to wired networks, wireless LANs have several characteristics that make them more vulnerable. In addition, wireless security in the original IEEE 802.11 stan- dard was not properly implemented, thus further exposing wireless networks to a variety of attacks. However, much of that is now changing. According to many experts, by properly implementing new wireless security technologies, WLANs can be made as secure as their wired counterparts.
In this chapter you will look at wireless security and vulnerabilities. You will start by briefly reviewing security in general. Then you will explore the possible types of attacks against a WLAN. Finally, you will examine the basic IEEE 802.11 security protections and study the vulnerabilities in that protection mechanism.
The techniques for implementing WLAN security is covered in Chapter 10.
Principles of Information Security When historians reflect back on the early part of this twenty-first century, it is likely that one word will figure prominently: security. Perhaps at no other time in the world’s history have we been forced to protect ourselves and our property from continual attacks by covert or invisible foes as we do today. Suicide car bombings, subway massacres, airplane hijackings,
After the sentencing Barry filed an appeal stating that he was innocent. He said that his attorney coerced him into pleading guilty and that he was sharing a jail cell with a double-murderer who was terrorizing him, which caused him to lose sleep and not be aware of the charges against him. He also claimed that the couple he terror- ized had actually framed him by infecting his computer with fictitious evidence by breaking into his computer through his wireless network. The judge rejected the appeal.
9
Principles of Information Security 319
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
random shootings, and guerrilla commando raids have become all-too-familiar events around the world. To counteract this violence, governments and other organizations have implemen- ted new types of security defenses. Passengers using public transportation are routinely searched. Fences are erected along borders. Telephone calls are monitored. As a result, these attacks and the security defenses designed to prevent them impact almost every element of our daily lives and significantly affect how all of us work, play, and live.
One area that has been an especially frequent target of attacks is information technology (IT). Seemingly endless arrays of attacks are directed at corporations, banks, schools, and indivi- duals through their computers, laptops, tablet computers, smartphones, and other devices. Internet Web servers must resist thousands of attacks daily. Identity theft has skyrocketed. An unprotected computer connected to the Internet can be infected in less than one minute. One study found that over 48 percent of 22.7 million computers analyzed were infected with malware.i Phishing, rootkits, back doors, social engineering, zombies, and botnets— virtually unheard of just a few years ago—are now part of our everyday information security vocabulary.
The need to defend against these attacks on technology devices has created a new ele- ment of IT known as information security. Information security is now at the very core of the entire industry that is focused on protecting the electronic information of organiza- tions and users. Understanding the basic principles of defense is an important first step in understanding WLAN security and its vulnerabilities. In the next section, we start by exploring the concept of information security along with the challenges of securing information.
What Is Information Security? The term information security is frequently used to describe the tasks of securing information that is in a digital format. This digital information is typically manipulated by a microproces- sor (such as on a personal computer), stored on a magnetic, optical, or solid-state storage device (like a hard drive, DVD, or flash drive), and transmitted over a network (such as a WLAN or the Internet).
Security may be viewed as sacrificing convenience for safety. Although it may be inconvenient to lock all the doors of the house or use long and complex passwords, the tradeoff is that these steps result in a higher level of safety. Another way to think of security is giving up short-term ease for long-term protection. In any case, secu- rity usually requires making sacrifices to achieve a greater good.
What exactly is information security? First, information security ensures that protective mea- sures are properly implemented. Just as the security measures taken for a house can never guarantee complete safety, information security cannot completely prevent attacks or guaran- tee that a system is totally secure. Rather, information security creates a defense that attempts to ward off attacks and prevents the collapse of the system when a successful attack occurs. Thus, information security is protection.
Second, information security is intended to protect information that provides value to people and organizations. There are three protections that must be extended over information. These three protections are “CIA”: confidentiality, integrity, and availability.
320 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
1. Confidentiality. It is important that only approved individuals are able to access impor- tant information. For example, the credit card number used to make an online purchase must be kept secure and not made available to other parties. Confidentiality ensures that only authorized parties can view the information. Ensuring confidentiality can involve several different tools, ranging from software to “scramble” the credit card number stored on the Web server to door locks to prevent access to the server.
2. Integrity. Integrity ensures that the information is correct and that no unauthorized per- son or malicious software has altered it. For example, an attacker who could change the amount of an online purchase from $1,000.00 to $1.00 would violate the integrity of the information.
3. Availability. Information cannot be “locked up” so tight that no one can access it; oth- erwise, the information would not be useful. Availability ensures that data is accessible to authorized users. The total number of items ordered as the result of an online pur- chase must be made available to an employee in a warehouse so that the correct items can be shipped to the customer.
Yet information security involves more than protecting the information itself. Because this information is stored on computer hardware, manipulated by software, and transmitted by communication devices, each of these areas must also be protected. The third objective of information security is to protect the integrity, confidentiality, and availability of information on the devices that store, manipulate, and transmit the information.
Information security is achieved through a combination of three entities. As shown in Figure 9-1 and summarized Table 9-1, information, hardware, software, and communications are protected in three interactive layers: products, people, and procedures. For example, proce- dures enable people to understand how to use products to protect information. Thus, a more comprehensive definition of information security is that which protects the integrity, confidentiality, and availability of information on the devices that store, manipulate, and transmit the information through products, people, and procedures.
Challenges of Information Security The challenge of keeping computers secure has never been greater, not only because of the number of attacks but also because of the difficulties faced in defending against these attacks. These difficulties include the following:
● Universally connected devices. It is virtually unheard of today for a computer to not be connected to the Internet. Although this greatly expands the functionality of that device, it also makes it easy for an attacker halfway around the world to silently launch an attack on any connected device.
● Increased speed of attacks. With modern tools at their disposal, attackers can quickly scan thousands of systems to find weaknesses and launch attacks with unprecedented speed. Many tools can even initiate new attacks without any human participation, thus increasing the speed at which systems are attacked.
● Greater sophistication of attacks. Attacks are becoming more complex, making it more difficult to detect and defend against them. Attackers today use common Internet tools and protocols to send malicious data or commands to strike computers, making it difficult to distinguish an attack from legitimate traffic. Other attack tools vary their behavior so the same attack appears differently each time, further complicating detection.
Principles of Information Security 321
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Availability and simplicity of attack tools. In the past, an attacker needed to have an extensive technical knowledge of networks and computers as well as the ability to write a program to generate the attack. Today’s attack tools do not require any sophisticated knowledge. In fact, many tools have a graphical user interface (GUI)
Communications
Confidentiality Integrity
Information
Availability
Hardware Software
Peop le (personnel security)
Pro ducts
(physical security)
ity
Software
Av
Hardware
vailabil
y
Pro cedu
res (organizational security)
Figure 9-1 Information security components
© Cengage Learning 2013
Layer Description
Products The physical security around the data. May be as basic as door locks or as complicated as network security equipment.
People Personnel who implement and properly use security products to protect data.
Procedures Plans and policies established by an organization to ensure that people correctly use the products.
Table 9-1 Information security layers
© Cengage Learning 2013
322 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
that allows the user to select options easily from a menu, as seen in Figure 9-2. These tools are freely available or can be purchased from other attackers at a low cost.
● Faster detection of vulnerabilities. Weakness in software can be more quickly uncov- ered and exploited with new software tools and techniques.
● Delays in patching. Hardware and software vendors are overwhelmed trying to keep pace with updating their products against attacks. One antivirus software vendor receives over 200,000 submissions of potential malware each month.ii At this rate, the antivirus vendors would have to update and distribute their updates every 10 minutes to keep users protected. The delay in vendors patching their own products adds to the difficulties in defending against attacks.
● Distributed attacks. Attackers can use tens of thousands of computers under their con- trol in an attack against a single server or network. This “many against one” approach makes it virtually impossible to stop an attack by identifying and blocking a single source.
● User confusion. Increasingly, users are called upon to make difficult security decisions regarding their computer systems, sometimes with little or no information to guide them. It is not uncommon for a user to be asked security questions such as Do you want to implement WPA2 or WEP? or Do you want to install this add-on? With little or no direction, users are inclined to provide answers to questions without under- standing the security risks.
Figure 9-2 Menu of attack tools
© Cengage Learning 2013
Principles of Information Security 323
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Table 9-2 summarizes the reasons why it is difficult to defend against today’s attacks.
Wireless Attacks The variety of attacks that can be launched against wireless networks can be divided into three categories: attacks against enterprise organizations, attacks against mobile users, and attacks against home users.
Enterprise Attacks Several different wireless attacks are targeted at business enterprises. One reason for the number of different attacks is the variety of attack vectors, or paths, that can be exploited.
Attack Vectors In a traditional wired network a well-defined boundary or “hard edge” protects data and resources. There are two types of these hard edges. The first is a network hard edge. A wired network typically has one point (or a limited number of points) through which data must pass from an external network to the secure internal network. This single data entry point it makes it easier to defend against attacks because any attack must likewise pass through this one point. A device like a firewall can be used to block attacks from enter- ing the network. The combination of a single entry point plus security devices that can defend it make up a network’s hard edge, which protects important data and resources. This is illustrated in Figure 9-3.
The second hard edge is made up of the walls of the building that houses the enterprise. Because these walls keep out unauthorized personnel, attackers cannot physically access computing
Reason Description
Universally connected devices Attackers from anywhere in the world can send attacks.
Increased speed of attacks Attackers can launch attacks against millions of computers within minutes.
Greater sophistication of attacks Attack tools vary their behavior so the same attack appears differently each time.
Availability and simplicity of attack tools
Attacks no longer limited to highly skilled attackers.
Faster detection of vulnerabilities Attackers can discover security holes and hardware or software more quickly.
Delays in patching Vendors are overwhelmed trying to keep pace by updating their products against attacks.
Distributed attacks Attackers use thousands of computers in an attack against a single computer or network.
User confusion Users are required to make difficult security decisions with little or no instruction.
Table 9-2 Difficulties in defending against attacks
© Cengage Learning 2013
324 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
devices or network equipment to steal data or infect computers. In other words, the walls serve to physically separate computing resources from attackers. This forces attackers to resort to launch- ing attacks through the network’s single data entry point, which is defended by a firewall.
However, the introduction of wireless LANs in enterprises has changed hard edges to “blurred edges.” Instead of a network hard edge with a single data entry point, a WLAN can contain multiple entry points. As shown in Figure 9-4, the radio frequency (RF) signals from APs create several data entry points into the network from which attackers can inject attacks or steal data. This makes it virtually impossible to create a hard network edge. In addition, because RF signals extend beyond the boundaries of the building the walls cannot be considered as a physical hard edge to keep away attackers. An attacker sitting in a car well outside of the building’s security perimeter can still easily pick up a wireless RF signal.
A wireless device in an enterprise may create multiple enterprise attack vectors. These include:
● Open or misconfigured AP. An AP whose security settings have not been set (an open AP) or one whose security settings have been improperly configured can allow attack- ers access to the network.
● Rogue AP. Due to the low cost and easy availability of wireless routers, an employee may bring a device from home and connect it to the enterprise network by simply plug- ging it into an open network connection in an office or break room. This unauthorized AP, called a rogue AP, allows attackers to access its RF signal to enter the corporate network. To complicate matters, rogue APs do not have to be separate network devices. For example, the wireless Hosted Network function in Microsoft Windows 7 makes it possible to virtualize the physical wireless network interface card (NIC) into multiple virtual wireless NICs (Virtual WiFi) that can be accessed by a software-based wireless
Server
Network device
Single entry point
Firewall
Desktop Corporate laptop
Desktop
Network hard edge
Printer
Internet
Figure 9-3 Network hard edge
© Cengage Learning 2013
Wireless Attacks 325
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
AP (SoftAP). This means that any laptop computer can quickly be turned into a rogue AP. In addition, smartphone apps allow even a cell phone to function as a rogue AP.
The Chapter 2 Hands-On Projects 2-3 and 2-4 illustrate how to set up and use a SoftAP in Windows.
● Evil twin. Whereas a rogue AP is set up by an internal user, an evil twin is an AP that is set up by an attacker. This AP is designed to mimic an authorized AP, so a user’s mobile device like a laptop or tablet will unknowingly connect to this evil twin instead. Attackers can then capture the transmissions from users to the evil twin AP.
Figure 9-5 illustrates some of the challenges of protecting an enterprise network that uses WLAN technology.
Wireless Enterprise Attacks A variety of attacks can be launched against wireless enterprise networks. These include reading data, hijacking wireless connections, inserting traffic, and performing denial-of-service attacks.
Reading Data One of the most common attacks is very basic: reading data that is being transmitted wirelessly. An attacker can pick up the RF signal from an open or misconfigured AP and read any confidential wireless transmissions. To make matters worse, if the attacker manages to connect to the enterprise wired network through a rogue AP, she could also read broadcast and multicast wired network traffic that leaks from the wired network to the wireless network. The type of wired network traffic that could be read through the wireless network
Listens to
data
transmissions
Access
pointDesktop
Corporate laptop
Access point
Network blurred edge
Injects infections
behind firewall
Server
Network deviceFirewall
Desktop
Internet
Printer
Attacker
laptop
Attacker laptop
Figure 9-4 Network blurred edge
© Cengage Learning 2013
326 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9 R
u n n in
g s
o ft w
a re
-b a s e d
ro g u e A
P
C o n n e c ts
t o
n e tw
o rk
t h ro
u g h
la p to
p r
o g
u e A
P
C o n n e c ts
t o e
v il
tw in
b y m
is ta
k e
E v il t
w in
A c c e s s
p o in
t
A tt a c k e r
la p to
p
R o
g u
e A
P
C o rp
o ra
te
la p to
p
C o rp
o ra
te
la p to
p
L is
te n s t o d
a ta
tr a n s m
is s io
n s
A c c e s s
p o in
t D
e s k to
p
C o rp
o ra
te
la p to
p
N e tw
o rk
b lu
rr e d
e d
g e
In je
c ts
in fe
c ti o n s
b e h in
d f ir e w
a ll
S e
rv e
r
N e
tw o
rk d
e v ic
e F
ir e w
a ll
D e
s k to
p
In te
rn e t
P ri
n te
r
A tt a c k e r
la p to
p
A tt a c k e r
la p to
p
A tt a c k e r
la p to
p
9-5
Fi g u re
9 -5
E n te rp ri se
n e tw
o rk
W LA
N ch
a ll e n g e s
© C en
g ag
e Le ar n in g 2 0 1 3
Wireless Attacks 327
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
includes Internet Group Management Protocol (IGMP), Interior Gateway Routing Protocol (IGRP), Open Shortest Path First (OSPF), Spanning Tree Protocol (STP), Cisco’s Hot Standby Router Protocol (HSRP),Virtual Router Redundancy Protocol (VRRP), and NetBios traffic.
Although a discussion of these protocols and traffic types are beyond the scope of this textbook, using a WLAN to read this data could yield significant information to an attacker regarding the wired enterprise network.
Hijacking Wireless Connections Another potential attack is hijacking the wireless connection. Using an evil twin, an attacker can trick a corporate mobile device to connect the imposter device instead. The attacker could then perform a wireless man-in-the-middle attack. This type of attack makes it appear that the wireless device and the network computers are com- municating with each other, when actually they are sending and receiving data through an evil twin AP (the “man-in-the-middle”). As the man-in-the-middle receives data from the devices it passes it on to the recipient so that neither computer is aware of the man-in-the-middle’s existence.
Man-in-the-middle attacks can be active or passive. In a passive attack, the attacker captures the data that is being transmitted (such as usernames and passwords), records it, and then sends it on to the original recipient without their presence being detected. In an active attack, the contents are intercepted and altered before they are forwarded to the recipient.
Inserting Network Traffic Just as an active man-in-the-middle attack will modify or inject content into a message, another type of wireless attack can actually inject wireless packets into the enterprise network. For example, an attacker’s application could examine incoming wireless packets, and, if the packet data matches a pattern specified in a configura- tion file, inject custom content onto the network to redirect traffic to an attacker’s server. In yet another type of attack, a routing protocol attack, the attacker injects specific packets into the network to redirect a traffic stream through another router that controlled by the attacker.
Denial of Service (DoS) A denial of service (DoS) attack attempts to prevent a device from performing its normal functions. A wireless DoS attack prevents the transmission of data to or from network devices. In one type of DoS attack, an attacker can flood the RF spectrum with extraneous RF signal “noise” that prevents communications from occurring (called RF jamming).
Another wireless DoS attack takes advantage of an IEEE 802.11 design weakness. This weakness is the implicit trust of frames that are transmitted across the wireless network, which includes information such as the sender’s source address. Because IEEE 802.11 requires no verification of the source device’s identity (and so all management frames are sent in an unencrypted format), an attacker can easily craft a fictitious frame that pretends to come from a trusted client when in reality it is from a malicious attacker. Different types of frames can be “spoofed” by an attacker to prevent a client from being able to remain con- nected to the WLAN. A client must be both authenticated and associated with an AP before being accepted into the wireless network, and when the client leaves the network this is accomplished through the exchange of deauthentication and disassociation management frames. An attacker can create false deauthentication or disassociation frames that are sent to an AP that appear to come from another client device, causing the client to disconnect
328 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
from the AP. Although the client device can send another authentication request to an AP, an attacker can continue to send spoofed frames to sever any reconnections.
The amendment IEEE 802.11w was designed to protect against wire- less DoS attacks. However, it only protects specific management frames instead of all management frames, it requires updates to both the AP and the wireless clients, and it may interfere with other secu- rity devices. For these reasons it has not been widely implemented.
Manipulating duration field values is another wireless DoS attack. The 802.11 standard pro- vides optional virtual carrier sensing through the Request to Send/Clear to Send (RTS/CTS) protocol. A Request to Send (RTS) frame is transmitted by a mobile device to an AP that contains a duration field indicating the length of time needed for both the transmission and the returning acknowledgement frame. The AP, as well as all stations that receive the RTS frame, are alerted that the medium will be reserved for a specific period of time. Each receiv- ing station stores that information in its net allocation vector (NAV) field and no station can transmit if the NAV contains a value other than zero. An attacker can send a frame with the duration field set to an arbitrarily high value (the maximum is 32,767), thus preventing other devices from transmitting for lengthy periods of time.
Deauthentication and disassociation frames and virtual carrier sens- ing are covered in Chapter 6.
Mobile User Attacks Mobile wireless users face several risks from attackers. Table 9-3 lists these risks, along with the concerns that a user faces when using a WLAN in an unsecure environment. Note that the attacker’s tools for these types of attacks are very rudimentary.
Typical Location Attacker’s Tool Attack Description User’s Concern
Hotel Wireless protocol analyzer
Read unencrypted transmissions from user’s device to hotel AP
What confidential information could an attacker read from my wireless transmissions?
Airport Laptop with wireless network interface adapter card
Set up an ad-hoc connection in a laptop so that a user connects directly to attacker’s computer
Am I connected to a legitimate AP or is this an ad-hoc network?
Coffee shop Laptop with software- based wireless AP
Configures software-based evil twin
Is my device actually connected to the coffee shop’s hotspot?
School campus Access point Install evil twin AP in open commons area
Is my laptop probing for WLANs that are not on my safe list?
Remote office Laptop with wireless network interface adapter card
Read broadcast and multicast wired network traffic
Do I have wired and wireless connections operating simultaneously?
Table 9-3 Mobile user attacks
© Cengage Learning 2013
Wireless Attacks 329
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Home Attacks Attacks against home WLANs are easy due to the fact that most home users fail to configure any security on their home networks. Many home users consider it to be an inconvenience to properly set the security on their wireless router. Such home users face several risks from attacks on their insecure wireless networks. Among other things, attackers can:
● Steal data. On a computer in the home WLAN, an attacker could access any folder with file sharing enabled. This essentially provides an attacker full access to steal sen- sitive data from the computer.
● Read wireless transmissions. Usernames, passwords, credit card numbers, and other information sent over the WLAN could be captured by an attacker.
● Inject malware. Because attackers could access the network behind a firewall, they could inject viruses and other malware onto the computer.
● Download harmful content. In several instances, attackers have accessed a home com- puter through an unprotected WLAN and downloaded child pornography to the com- puter, and then turned that computer into a file server to distribute the content. When authorities have traced the files back to that computer the unsuspecting owner has been arrested and his equipment confiscated.
Attackers can easily identify unprotected home wireless networks through war driving. War driving is searching for wireless signals from an automobile or on foot using a portable com- puting device.
War driving is derived from the term war dialing. When telephone modems were popular in the 1980s and 1990s, an attacker could program the device to randomly dial telephone numbers until a computer answered the call. This random process of searching for a connection was known as war dialing, so the word for randomly searching for a wireless signal became known as war driving.
In order to properly conduct war driving, several tools are necessary. These tools are listed in Table 9-4.
Tool Purpose
Mobile computing device A mobile computing device with a wireless NIC can be used for war driving. This includes a standard portable computer, a pad computer, or a smartphone.
Wireless NIC adapter Many war drivers prefer an external wireless NIC adapter that connects into a USB or other port and has an external antenna jack.
Antenna(s) Although all wireless NIC adapters have embedded antennas, attaching an external antenna will significantly increase the ability to detect a wireless signal.
Software Client utilities and integrated operating system tools provide limited information about a discovered WLAN. Serious war drivers use more specialized software.
Global positioning system (GPS) receiver
Although this is not required, it does help to pinpoint the location more precisely if this information will be recorded or shared with others.
Table 9-4 War driving tools
© Cengage Learning 2013
330 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
After the wireless signal has been detected, the next step is to docu- ment and then advertise the location of the wireless LANs for others to use. Early WLAN users copied a system that hobos used during the Great Depression to indicate friendly locations. Wireless networks were identified by drawing on sidewalks or walls around the area of
the network known as war chalking. Today the location of WLANs discovered through war driving are posted on Web sites.
Legacy IEEE 802.11 Security Protections
C W N A
5.1.1. Identify and describe the strengths, weaknesses, appropriate uses, and implementation of the IEEE 802.11 security-related items.
The IEEE implemented several protections in the original 1997 802.11 standard. These pro- tections can be divided into three categories: access control, wired equivalent privacy, and authentication.
Access Control Access control is granting or denying approval to use specific resources; other words, it is the process of controlling access. Although access control is frequently viewed as physical, such as door locks and fencing, in an information system it is the mechanism used to allow or restrict access to data or devices. Wireless access control is intended to limit a user’s admis- sion to the AP: only those who are authorized are able to connect to the AP and thus become part of the wireless LAN.
The most common type of access control is Media Access Control (MAC) address filtering. The MAC address is a hardware address that uniquely identifies each node of a network. The MAC address is a unique 48-bit number that is “burned” into the NIC adapter when it is manufactured. This number consists of two parts: a 24-bit organizationally unique identifier (OUI), sometimes called a “company ID,” which references the company that produced the adapter, and a 24-bit individual address block (IAB), which uniquely identifies the card itself. A typical MAC address is illustrated in Figure 9-6.
Other names for the MAC address are vendor address, vendor ID, NIC address, Ethernet address, hardware address, and physical address.
00-50-F2-7C-62-E1
Organizationally Unique Identifier (OUI)
Individual Address Block (IAB)
Figure 9-6 MAC address
© Cengage Learning 2013
Legacy IEEE 802.11 Security Protections 331
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The IEEE 802.11 standard does not specify how access control is to be implemented. How- ever, since a wireless device can be identified by its MAC address, virtually all wireless AP vendors implement MAC address filtering as the means of access control. A wireless client device’s MAC address is entered into software running on the AP, which then is used to per- mit or deny a device from connecting to the network. As shown in Figure 9-7, restrictions can be implemented in one of two ways: a specific device can be permitted access into the network or the device can be blocked.
Wired Equivalent Privacy (WEP) Wired equivalent privacy (WEP) is intended to guard another of the three CIA characteristics of information, namely confidentiality. This ensures that only authorized parties can view the information. WEP protects confidentiality by “scrambling” the wireless data as it is transmit- ted so that it cannot be viewed. The process of scrambling and how WEP is implemented are discussed in detail next.
Cryptography An important means of protecting information is to change or scramble it so that even if attackers reach the data, they cannot read it. This scrambling is a process known as cryptography (from Greek words meaning hidden writing). Cryptography is the science of transforming information into a secure form while it is being transmitted or stored so that unauthorized persons cannot access it.
Cryptography’s origins date back centuries. One of the most famous ancient cryptographers was Julius Caesar. In messages to his commanders, Caesar shifted each letter of his messages three places down in the alphabet, so that an A was replaced by a D, a B was replaced by an E, and so forth. Changing the original text into a secret message using cryptography is known as encryption. When Caesar’s commanders received his messages, they reversed the process (such as substituting a D for an A) to change the secret message back to its original form. This is called decryption. Data in an unencrypted form is called cleartext data. Clear- text data is data that is either stored or transmitted “in the clear,” without any encryption. Cleartext data that is to be encrypted is called plaintext. Plaintext data is input into an encryption algorithm, which consists of procedures based on a mathematical formula used to encrypt the data. A key is a mathematical value entered into the algorithm to produce ciphertext, or text that is “scrambled.” Just as a key is inserted into a lock to secure a door, in cryptography a unique mathematical key is input into the encryption algorithm to create
Keep out only these devices
Allow in only these devices
Figure 9-7 MAC address filtering
© Cengage Learning 2013
332 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
the ciphertext. Once the ciphertext is transmitted or needs to be returned to cleartext, the reverse process occurs with a decryption algorithm. The cryptography process is illustrated in Figure 9-8.
Cleartext data becomes plaintext when it is entered into an algo- rithm in the encryption process. Plaintext should not be confused with “plain text,” which is text that has no formatting (such as bold- ing or underlining) applied.
A substitution algorithm like Caesar’s is too simple for contemporary use because the key creates a repeating pattern. When a detectable pattern or structure can be detected it pro- vides an attacker with valuable information to break the encryption. Keys that create this type of repeating pattern are known as weak keys.
WEP Implementation Implementation of WEP can be understood by considering the IEEE 802.11 cryptography objectives as outlined in the standard. These objectives include the following:
● Efficient. The WEP algorithm must be proficient enough to be implemented in either hardware or software.
● Exportable. WEP must meet the guidelines set by the U.S. Department of Commerce so that the wireless device using WEP can be exported overseas.
● Optional. The implementation of WEP in wireless LANs is an optional feature.
Decryption
algorithm
Encryption algorithm
Confidential Memo Layoffs at the Lakeview store will begin...
Confidential Memo
Layoffs at the Lakeview
store will begin...
626vscc*7&5 2#hdkP0)...
626vscc*7&5
2#hdkP0)...
Transmitted to remote user
Plaintext
Cleartext
Ciphertext
Ciphertext
Key
Key
Figure 9-8 Cryptography process
© Cengage Learning 2013
Legacy IEEE 802.11 Security Protections 333
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Reasonably strong. The security of the algorithm lies in the difficulty of determining the secret keys through attacks. This in turn is related to the length of the secret key and the frequency of changing keys. WEP was to be “reasonably” strong in resisting attacks.
● Self-synchronizing. When using WEP each packet must be separately encrypted. This is to prevent a single lost packet from making subsequent packets indecipherable.
WEP relies on a shared secret key that is entered into both the wireless client device and the AP in advance. (In other words, they “share” the same key value.) WEP keys must be a min- imum of 64 bits in length. Most vendors add an option to use a larger 128-bit WEP key for added security, because a longer key is more difficult to break.
The IEEE standard also provides for the AP and client devices to hold up to four separate WEP keys simultaneously. However, due to the difficulty of managing multiple keys for each device, this feature is rarely used.
The mechanics of how WEP performs encryption is illustrated in Figure 9-9. The steps are as follows:
1. The plaintext to be transmitted has a cyclic redundancy check (CRC) value calculated, which is a checksum based on the contents of the text. WEP calls this the integrity check value (ICV) and appends it to the end of the text.
2. The shared secret key is combined with an initialization vector (IV). The IV is a 24-bit value used in WEP that changes each time a packet is encrypted. The IV and the default key are combined and used as a “seed” for generating a random number in Step 3. If only the default key were used as a seed, then the number generated would be the same each time. Varying the IV for each packet ensures that the random number created from it is indeed random.
3. The default key and IV are then entered as the seed values into a pseudo-random num- ber generator (PRNG) that creates a random number. The PRNG is based on the RC4 cipher algorithm. RC4 accepts keys up to 128 bits in length and takes one character and replaces it with one character. This output is known as the keystream. The key- stream is essentially a series of 1s and 0s equal in length to the text plus the ICV.
4. The two values (text plus ICV and the keystream) are then combined through the exclu- sive OR (XOR) operation to create the encrypted text. The Boolean operation of XOR yields the result TRUE (1) when only one of its operands is TRUE (1); otherwise, the result
Step 2
+
Step 1
Step 3
Step 5
Initialization Vector (IV)
Secret Key Key Stream
CRCText Text
IV Ciphertext
PRNG
Step 4 XOR
=
=
ICV
Figure 9-9 WEP encryption process
© Cengage Learning 2013
334 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
is FALSE (0). The four XOR results are 0 XOR 0 ¼ 0, 0 XOR 1 ¼ 1, 1 XOR 0 ¼ 1, and 1 XOR 1 ¼ 0.
5. The IV is added to the front of the ciphertext (“pre-pended”) and the packet is ready for transmission. The pre-pended IV is not encrypted. The reason why the IV is transmitted in an unencrypted format is because the receiving device needs it in this form in order to decrypt the transmission.
When the encrypted frame arrives at its destination the receiving device first separates the IV from the ciphertext and then combines the IV with its appropriate secret key to create a key- stream. This is then used to extract the text and ICV. The text is finally run through the CRC to ensure that the ICV’s match and that nothing was lost in the transmission process.
Authentication Because wireless LANs cannot limit access to the RF signal by walls or doors, wireless authentication requires the wireless device (and not the individual user) to be authenticated prior to being connected to the network. IEEE 802.11 authentication is a process in which the AP accepts a station.
Wireless authentication is covered in Chapter 6.
Two types of authentication are supported by the 802.11 standard. Open system authentication is the basic (and the default) method. After discovering the network through passive scanning or active scanning and then receiving the necessary information, the wireless client device sends an association request frame to the AP that carries information about the data rates that the device can support along with the service set identifier (SSID) of the network it wants to join. After receiving the association request, the AP considers the request by comparing the SSID received with the SSID of the network. If the two match, the wireless device is authenticated.
The second type of authentication method (which is optional) is shared key authentication. Shared key authentication uses WEP keys. The AP sends to a device wanting to join the net- work a block of text known as the challenge text. The wireless device encrypts with its WEP key and returns it to the AP, which then decrypts what was returned to see if it matches the original challenge text. If it does, the device is accepted into the network.
When WEP is used for shared key authentication, it is serving a dual function of encryption and authentication.
Vulnerabilities of IEEE 802.11 Security
C W N A
5.1.1. Identify and describe the strengths, weaknesses, appropriate uses, and implementation of the IEEE 802.11 security-related items.
Vulnerabilities of IEEE 802.11 Security 335
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Although the IEEE 802.11 standard does provide security mechanisms for wireless networks, these mechanisms have fallen far short of their goal. Significant security vulnerabilities have exposed wireless networking to a variety of attacks. These vulnerabilities are especially troubling because users who implement the security features may assume they are protected when in reality they are not. This section explores the vulnerabilities of authentication, address filtering, and WEP.
Authentication Open system authentication is weak because authentication is based on only one factor: a match of SSIDs. An attacker only has to determine a valid SSID in order to be authenticated. There are several ways that SSIDs can be discovered, such as looking at the SSID on a device that is already authenticated. However, the easiest way to discover the SSID is to actually do nothing: because the SSID is beaconed from the AP in passive scanning, there is nothing that the attacker has to do other than roam into the area of the AP, accept the SSID in the beacon frame, and become authenticated.
For a degree of protection, some users configure their APs to prevent the beacon frame from including the SSID, known as SSID hiding. SSID hiding requires the user to enter the SSID manually on the wireless device. Although this may seem to provide protection by not advertising the SSID, it only provides a weak degree of security and has several limitations:
● The SSID can be easily discovered even when it is not contained in beacon frames because it is transmitted in other management frames sent by the AP. Attackers with protocol analyzers can still detect the SSID even when SSID hiding is being used.
● The SSID is initially transmitted in plaintext (unencrypted) form when the device is negotiating with the AP. If an attacker cannot capture an initial negotiation process, it can force one to occur. An attacker can send a forged disassociation frame to a wire- less device. This will cause the device to disassociate from the AP. When the device immediately attempts to reconnect to the AP, the attacker can capturing frames and see the SSID transmitted in plaintext.
● SSID hiding may prevent users from being able to freely roam one AP coverage area to another.
● Turning off SSID beaconing is not always possible or convenient. SSID beaconing is the default mode in every AP. Even more so, not all APs allow beaconing to be turned off, and those that do often discourage users from making this change.
● Versions of Microsoft Windows XP, when receiving signals from both a wireless net- work that is broadcasting an SSID and one that is not broadcasting the SSID, will always connect to the AP that is broadcasting its SSID. If a Windows XP device is connected to an AP that is not broadcasting its SSID, and another AP is turned on that is broadcasting its SSID, the device will automatically disconnect from the first AP and connect to the AP that is broadcasting.
● The SSID can be retrieved from an authenticated device. ● Because many users do not change the default SSID, an attacker can simply try using
default SSIDs until the correct value is accepted.
336 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
In order to prevent attackers from guessing default SSIDs one brand of AP can produce random SSIDs that are made up of two unrelated words, such as quickdolphin.
The shared key authentication technique, using challenge text, is likewise vulnerable. The first vulnerability is based on the fact that key management can be very difficult when a large number of wireless devices must be supported. Because the WEP key must be entered on each wireless device, an attacker can view the key on an approved device (by stealing a device or “shoulder surfing”—looking over someone’s shoulder) and install it on his own wireless device.
Another weakness of shared key authentication is that the AP sends the challenge text to a device as cleartext. An attacker can capture the challenge text along with the device’s response (encrypted text and IV). The attacker than has everything necessary to mathemati- cally derive the keystream.
Address Filtering MAC address filtering likewise has several vulnerabilities. First, much like managing WEP keys, managing the number of MAC addresses in a medium to large sized wireless network can pose significant challenges. As new users are added to the network and old users leave, MAC address filtering demands constant attention. The sheer number of users makes it diffi- cult to manage all of the MAC addresses and thus creates avenues for attackers. In addition, there is no provision for temporarily adding a guest user to the network
A second disadvantage to MAC address filtering is that, like SSIDs, MAC addresses are ini- tially exchanged in cleartext. This means that an attacker can easily see the MAC address of an approved device and use it to join the network. Also, as with open system authentication, an attacker can send a disassociation frame to force a device to reassociate and send the MAC address so that it can be captured.
A third disadvantage of MAC address filtering is that a MAC address can be “spoofed” or substituted in two ways. First, some wireless NICs allow for a substitute MAC address to be used. Second, there are programs available that allow users to spoof a MAC address. This is possible because Microsoft Windows reads the MAC address of the wireless NIC and stores that value in the Windows registry database. A MAC address spoof program changes the set- ting in the registry but does not change the address on the wireless NIC itself.
WEP Although authentication and MAC address filtering have serious security vulnerabilities, the vulnerability that attracts the most attention focuses on how WEP is implemented.
WEP has several security vulnerabilities. First, to encrypt packets, WEP can use only a 64-bit or 128-bit number, which is made up of a 24-bit IV and either a 40-bit or 104-bit default key. Even if a longer 128-bit number is used, the length of the IV still remains at 24 bits. The relatively short length of the IV limits its strength (shorter keys are easier to break than longer keys).
Second, WEP implementation violates a cardinal rule of cryptography: anything that creates a detectable pattern must be avoided at all costs. This is because patterns provide an attacker
Vulnerabilities of IEEE 802.11 Security 337
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
with valuable information to break the encryption. The implementation of WEP creates a detectable pattern for attackers. Because IVs are 24-bit numbers, there are only 16,777,216 pos- sible values. An AP transmitting at only 11 Mbps can send and receive 700 packets each second. If a different IV were used for each packet, then the IVs would start repeating in fewer than seven hours (a “busy” AP can produce duplicates in fewer than five hours). An attacker who captures packets for this length of time can see the duplication and use it to crack the code.
Recent techniques have reduced the amount of time to crack WEP down to minutes.
Because of the weaknesses of WEP, it is possible for an attacker to identify two packets derived from the same IV (called a collision). With that information, the attacker can begin what is called a keystream attack or IV attack. A keystream attack is a method of determin- ing the keystream by analyzing two packets that were created from the same IV.
The basis for a keystream attack is as follows: performing an XOR on two ciphertexts will equal an XOR on the two plaintexts. This is shown in Figure 9-10. In Operation 1, Plaintext A and Keystream X are XOR’ed together to create Ciphertext A. In Operation 2, Plaintext B and Keystream X are also XOR’ed to create Ciphertext B. Notice that in Operation 3, if Ciphertext A and Ciphertext B are XOR’ed, they create the same result as when Plaintext A and Plaintext B are XOR’ed in Operation 4.
Figure 9-11 illustrates how an attacker can take advantage of this. If the attack captures Packet 1’s IV and keystream, and then captures the IV and keystream from Packet 222 that uses the same IV, then the attacker knows two keystreams that were created by the same IV. An XOR of those two keystreams finds the same value as an XOR of the plaintext of Packet 1 and Packet 222. The attacker can now work backwards; if even part of the plaintext of
Operation 1
Plaintext A
Keystream X
Ciphertext A
11010011
10100110
01110101
Keystream X
Ciphertext B
Plaintext B
XOR
XOR 00101101
10100110
10001011
Operation 2
Operation 3 Operation 4
Plaintext A
Plaintext B Ciphertext B
Ciphertext A 01110101 XOR
10001011
11111110 11111110
XOR
11010011
00101101
Values match
Figure 9-10 XOR operations
© Cengage Learning 2013
338 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
Packet 1 can be discovered, then the attacker can derive the plaintext of Packet 222 by doing an XOR operation on the keystream of Ciphertext 1 and Ciphertext 222 (11111110) and plaintext of Packet 1 (11010011). In fact, once the plaintext of Packet 1 has been dis- covered, the plaintext of any packet that uses that IV can be found.
How can the attacker find enough of Plaintext 1 to decrypt Plaintext 222? There are several ways:
● Some of the values of the frames are definitely known, such as certain fields in the header. In other fields the value may not be known but the purpose is known (for example, the IP address fields have a limited set of possible values in most networks).
● The body portion of the text often encodes ASCII text, again giving some possible clues. An attacker can collect enough samples of duplicated IVs, guess at substantial portions of the keystream, and then decode more and more.
● An attacker can capture an encrypted packet and, based on its size (28 bytes), the attacker knows that it is an Address Resolution Protocol (ARP) request. The attacker can then flood the network with the reinjected ARP request, which results in a flood of ARP responses, supplying a wealth of data to use.
● A computer on the Internet can send traffic from the outside to a device on the wire- less network. Because the content of the message is known to the attacker, when the WEP-encrypted version of the message is sent over wireless LAN, the attacker will have all the necessary data to decrypt all packets that use the same IV.
Chapter Summary ■ Information security is a term that describes the tasks of securing information that is in a
digital format, whether it is manipulated by a microprocessor, stored on a magnetic, optical, or solid-state storage device, or transmitted over a network. Information security creates a defense that attempts to ward off attacks and prevents the collapse of the system when a successful attack occurs. It is intended to provide three protections over information: confidentiality, integrity, and availability (CIA). And because this informa- tion is stored on computer hardware, manipulated by software, and transmitted by communication devices, each of these areas must also be protected. Information security protects the integrity, confidentiality, and availability of information on the devices that store, manipulate, and transmit the information through products, people, and procedures.
Packet 1: 01110101
Plaintext 1
Plaintext 222
Ciphertext 1
10001011
11111110 11111110
XOR
11010011
00101101
Ciphertext 222Packet 222:
IV 12345-
IV 12345-
Figure 9-11 Capturing packets
© Cengage Learning 2013
Chapter Summary 339
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
■ There are several challenges to information security. These include universally con- nected devices, an increased speed of attacks and greater sophistication of attacks, readily available attack tools, faster detection of vulnerabilities by attackers, delays in patching, more distributed attacks, and general user confusion over how to be secure.
■ Several different wireless attacks are targeted at business enterprises. This is because there are several attack vectors that attackers can target. The incorporation of a WLAN into an enterprise network means the enterprise network is no longer protected by a single entry point through which all data must pass, nor is it protected by the walls of the building. Instead, the nature of the RF signal opens multiple attack points. These points include open or misconfigured APs, rogue APs, and evil twins. The dif- ferent types of attacks that can be launched against wireless enterprise networks include reading data, hijacking wireless connections, inserting traffic, and performing denial-of-service attacks.
■ Both mobile users and home users face attacks as well. Many home users consider it to be an inconvenience to properly set the security on their wireless router. Such home users face several risks from attackers. Attackers can easily identify unprotected home wireless networks through war driving. War driving is searching for wireless signals from an automobile or on foot using a portable computing device.
■ The IEEE implemented several protections in the original 1997 802.11 standard. Wireless access control is intended to limit a user’s admission to the AP: only those who are authorized are able to connect to the AP and thus become part of the wireless LAN. The most common type of access control is Media Access Control (MAC) address filtering. Virtually all wireless AP vendors implement MAC address filtering as the means of access control. A wireless client device’s MAC address is entered into software running on the AP, which then is used to permit or deny a device from con- necting to the network. Wired equivalent privacy (WEP) is intended to guard the confidentiality of the data being transmitted by encrypting it. WEP relies on a shared secret key that is entered into both the wireless client device and the AP in advance. WEP keys must be a minimum of 64 bits in length. Most vendors add an option to use a larger 128-bit WEP key for added security.
■ Because wireless LANs cannot limit access to the RF signal by walls or doors, wireless authentication requires the wireless device to be authenticated prior to being connected to the network. Open system authentication only requires that the client device send to the AP the SSID of the network for which it wants to join. Shared key authentication uses WEP keys to encrypt and decrypt challenge text.
■ Despite the fact that the IEEE 802.11 standard provided security mechanisms for wireless networks, these mechanisms have fallen far short of their goal. Open sys- tem authentication is weak because authentication is based on only one factor: a match of SSIDs. An attacker only has to determine a valid SSID in order to be authenticated. There are several ways that SSIDs can be discovered. A weakness of shared key authentication is when the AP sends to a device the challenge text it is sent as cleartext. MAC address filtering likewise has several vulnerabilities, one of which is that MAC addresses are initially exchanged in cleartext.
340 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
■ WEP has several security vulnerabilities. First, to encrypt packets, WEP can use only a 64-bit or 128-bit number, which is made up of a 24-bit IV and either a 40-bit or 104-bit default key. Even if a longer 128-bit number is used, the length of the IV still remains at 24 bits. In addition, WEP creates a detectable pattern for attackers that can be used to then break the encryption so that wireless transmissions can be read.
Key Terms access control Granting or denying approval to use specific resources. algorithm Procedures based on a mathematical formula; used to encrypt the data. availability Security actions that ensure that data is accessible to authorized users. ciphertext Data that has been encrypted. cleartext Unencrypted data. confidentiality Security actions that ensure only authorized parties can view the information. cryptography The science of transforming information into a secure form while it is being transmitted or stored so that unauthorized persons cannot access it. cyclic redundancy check (CRC) A checksum value that is based on the contents of the text. decryption The process of changing ciphertext into plaintext. denial of service (DoS) An attack that attempts to prevent a device from performing its normal functions. encryption The process of changing plaintext into ciphertext. evil twin An imposter AP that is set up by an attacker. information security The tasks of securing information that is in a digital format. initialization vector (IV) A 24-bit WEP value that changes each time a packet is encrypted. integrity Security actions that ensure that the information is correct and no unauthorized person or malicious software has altered the data. integrity check value (ICV) The checksum value generated by WEP. IV attack An attack that determines the keystream by analyzing two packets that were created from the same IV. key A mathematical value entered into the algorithm to produce ciphertext. keystream The output from a pseudo-random number generator (PRNG). keystream attack An attack that determines the keystream by analyzing two packets that were created from the same IV. man-in-the-middle An attack that makes it appear that the wireless device and the network computers are communicating with each other, when actually they are sending and receiving data with an evil twin AP between them. Media Access Control (MAC) address filtering Restricting admission to a WLAN based on the client device’s MAC address. open system authentication The process of a client connecting to a WLAN by sending a request to the AP with the SSID of the network it wants to join. plaintext Data input into an encryption algorithm.
Key Terms 341
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
pseudo-random number generator (PRNG) A WEP mechanism for creating a random number. RF jamming A DoS attack that floods the RF spectrum with extraneous RF signal “noise” that prevents communications from occurring. rogue AP An unauthorized AP. SSID hiding Configuring an AP to prevent the beacon frame from including the SSID. war driving The process of searching for wireless signals from an automobile or on foot using a portable computing device. weak keys Cryptographic keys that create a repeating pattern. wired equivalent privacy (WEP) A wireless security mechanism that is intended to guard the confidentiality of information as it is transmitted.
Review Questions 1. Each of the following is a reason why it is difficult to defend against today’s attackers
except:
a. complexity of attack tools.
b. weak patch distribution.
c. greater sophistication of attacks.
d. delays in patching hardware and software products.
2. ensures that only authorized parties can view the information.
a. Confidentiality
b. Availability
c. Integrity
d. Authorization
3. Each of the following is a layer that protects security except:
a. products.
b. people.
c. communication.
d. procedures.
4. Which of the following is true regarding a rogue AP?
a. It is an unauthorized AP installed by an employee.
b. It is a hardware-only device.
c. It requires SoftAP to function.
d. It cannot be used by attackers but only by internal employees.
342 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
5. Which of the following is false regarding a man-in-the-middle attack?
a. It makes it appear that the wireless device and the network computers are commu- nicating with each other.
b. As it receives data from the devices it passes it on to the recipient.
c. It can only be active.
d. It requires a rogue AP.
6. Which of the following is not a wireless DoS attack?
a. RF jamming
b. creating false deauthentication or disassociation frames
c. manipulating duration field values
d. SSID hiding
7. Which of the following is not a wireless LAN attack faced by a home user?
a. steal data
b. upload harmful content
c. read wireless transmissions
d. inject malware
8. Each of the following can be used in war driving except:
a. global positioning system (GPS).
b. laptop computer.
c. antennas.
d. wired NIC.
9. What is access control in a WLAN?
a. authorizing devices
b. authorizing users
c. restricting direct access to a Web server
d. requiring a user to enter a password on the AP
10. Each of the following is a name for the Media Access Control (MAC) address except:
a. physical address.
b. logical address.
c. hardware address.
d. Ethernet address.
11. WEP stands for .
a. wired equivalent privacy
b. wireless equality protection
c. wardriving early protection
d. wave equilibrium penetration
Review Questions 343
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12. What is data called that is to be encrypted by inputting into an encryption algorithm?
a. plaintext
b. cleartext
c. opentext
d. ciphertext
13. A mathematical value used to produce ciphertext is called a(n) .
a. algorithm
b. key
c. link
d. cipher-log
14. What is a weak key?
a. a key that creates a repeating pattern
b. a key that is fewer than 12 characters in length
c. an IV that is over 128 characters long
d. a CRC that cannot be produced by a PRNG
15. What is the minimum length for a WEP key?
a. 8 bits
b. 16 bits
c. 32 bits
d. 64 bits
16. The is a 24-bit value used in WEP that changes each time a packet is encrypted.
a. CRC
b. PRNG
c. IV
d. WPE
17. Which of authentication is a match of SSIDs?
a. closed system authentication
b. shared key authentication
c. open system authentication
d. SSID matching authentication
18. Each of the following is a limitation of SSID hiding except:
a. it may prevent users from being able to freely roam one AP coverage area to another.
b. the SSID can be retrieved from an authenticated device.
c. the SSID can be discovered in other management frames sent by the AP.
d. it requires the WEP key to be changed.
344 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
19. Which of the following is not a limitation to MAC address filtering?
a. Managing keys for multiple devices can be difficult.
b. Not all client devices have MAC addresses.
c. MAC addresses are initially exchanged in cleartext.
d. MAC addresses can be “spoofed” or substituted.
20. What is the basis for a keystream attack?
a. Performing an XOR on two ciphertexts will equal an XOR on the two plaintexts.
b. Performing an XOR on two WEP keys will equal an XOR on two IVs.
c. Performing an XOR on two plaintext keys will equal an XOR on WEP keys.
d. Performing an XOR on all plaintext keys will equal an XOR on the two most significant WEP keys.
Hands-On Projects
Project 9-1: Substitute a MAC Address Using SMAC Although MAC address filters are often relied upon to prevent unauthorized users from accessing a wireless LAN, MAC addresses can easily be spoofed. In this project, you will substitute a MAC address.
1. Open your Web browser and enter the URL www.klcconsulting.net/smac.
The location of content on the Internet, such as this program, may change without warning. If you are no longer able to access the pro- gram through the above URL, then use a search engine and search for “KLC Consulting SMAC”.
2. Click Free Download.
3. Click Download Site 3.
4. When the file finishes downloading run the program and follow the default installation procedures.
5. Click Finish to launch SMAC and accept the license agreement.
6. When prompted for a Registration ID, click Proceed. SMAC displays the NIC adapters that it discovers, as seen in Figure 9-12.
If the message SMAC has determined that you have insufficient registry access appears then close the SMAC application if neces- sary. Single click on the SMAC icon and then click the right mouse button. Click Run as administrator.
7. If there are multiple NIC adapters listed, click on each adapter. Does the Active MAC Address change? Why?
Hands-On Projects 345
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8. Click on a network adapter to change the MAC address. Then click on the up arrow next to Active MAC Address. It is displayed in the New Spoofed MAC Address.
9. Click the Random button to create a new MAC address.
10. Click the down arrow under the New Spoofed MAC address to view the manufacturer associated with this OUI.
11. Click the down arrow under the New Spoofed MAC address to view the manufacturers again. Select a different manufacturer. What happens to the OUI?
12. Click the Random button several more times to create new MAC addresses based on this manufacturer.
Because this is an Evaluation mode copy of SMAC you are not able to actually change the MAC address. In the Full Feature mode you would click on Update MAC as the next step.
13. Close all windows.
Project 9-2: Configuring APs—MAC Address Filtering The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this proj- ect you will use an online emulator from D-Link to configure an AP’s legacy security settings.
Figure 9-12 SMAC main window
© Cengage Learning 2013
346 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you, if necessary.
3. If you are asked to select the preferred D-Link home page click No, Thank you and then click Continue.
4. Click the Support tab.
5. Click Go next to Emulators.
6. Locate DAP-1522 in the list and click on it.
7. Click DAP-1522 AP Mode.
8. In the emulated login screen, click Login without entering a password.
9. An emulated Setup screen displaying what a user would see when configuring an actual DAP-1522 is displayed.
10. Click ADVANCED on the horizontal menu bar.
11. If necessary, click MAC ADDRESS FILTER in the left pane to display the MAC ADDRESS FILTER section.
12. In the MAC FILTERING SETUP section, click the down arrow below Configure MAC Filtering below.
13. Click Turn MAC Filtering ON and ALLOW computers listed to access the network. When would this option be used instead of listing the devices that should be denied access to the WLAN?
14. Now you need to enter the MAC address of your computer. To find your computer’s MAC address, click Start and type cmd in the search box, and press Enter to launch the command prompt window.
15. Type ipconfig/all and press Enter.
16. Scroll through the information listed and locate the Physical Address of the wireless net- work adapter.
17. Return to the DAP-1522 emulator and enter this information.
18. Click the Add button and then click Save Settings. Note that in this emulator the actual MAC address will not be listed under MAC FILTERING RULES.
19. How difficult would it be to manage three MAC addresses using this facility? What about 30 addresses?
20. Close all windows.
Hands-On Projects 347
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Project 9-3: Configuring APs—SSID and WEP Security In this project you will use the online emulator from D-Link to configure an AP’s WEP settings.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you, if necessary.
3. Click Support.
4. Click Go next to Emulators.
5. Locate DAP-1522 in the list and click it.
6. Click DAP-1522 AP Mode
7. The emulated login screen appears. Click Login without entering a password.
8. An emulated Home screen displays what a user would see when configuring an actual DAP-1350.
9. In the left pane, click Wireless Setup.
10. Note that the Wireless Network Name is set by default. What are the security risks involved when using the default network name? Change the name to one that you would use at home that does not identify you. Why is it important to use a generic SSID?
11. Under Enable Hidden Wireless, what is the default setting? What level of increased secu- rity would changing this option provide? Explain your answer.
12. Under Wireless Security Mode, click the down arrow.
13. Select Enable WEP Wireless Security (basic).
14. Read the information regarding WEP. What is the default authentication method? What does that mean?
15. Next to WEP Key Length, change the value to 128 bit. Does this give any increased level of security? Does it change the IV length?
16. Next to Key Format, change the value to ASCII.
17. Why are there four WEP key values that can be entered?
18. Next to WEP Key 1, enter a string of 13 alphanumeric characters.
19. Where else would you also have to enter this key? Why?
20. Close all windows.
348 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
Project 9-4: Crack WEP Encryption One of the best ways to see the weakness of WEP is to use a tool to crack WEP encryption on your own WLAN. There are several tools available online to crack WEP encryption, yet most of them require a series of com-
mands to be entered at a command prompt and may be difficult to use. A smaller number of tools have GUI, making it much easier for the user. In this project you set up your own WLAN using WEP and then will use Gerix Wifi Cracker, which is part of Backtrack 5, to break your WEP encryption. You will need the USB flash drive that was created in Hands- On Project 6-1. You will also need either an AP or a computer that is running the Connectify software that was configured in Hands-On Project 2-4. Note that Backtrack 5 does not support all wireless LAN adapters. It may be necessary to use a USB wireless adapter if your internal adapter cannot be recognized.
This tool should never be used to crack WEP encryption on a WLAN that is not part of your own network.
1. Configure an AP or wireless router to use WEP. (See Hands-On Project 9-3 for an illus- tration of how WEP is implemented on a WLAN.) Create an SSID of WEP-WLAN and enter a WEP key. As an option, you can use the Connectify software that was installed in Hands-On Project 2-4. Launch Connectify and, under Internet, select No Internet Sharing. Under Sharing Mode, select Wi-Fi Ad-Hoc, Encrypted (WEP). Enter aaaaafffff under Password as the WEP key and click Start Hotspot.
2. If possible, configure another client to use WEP in order to increase the amount of traf- fic. Click Start and then click Control Panel.
3. Click Network and Internet.
4. Click Connect to a network.
5. Click the name of the SSID (WEP-WLAN or Connectify-me).
6. Click Connect. When asked for the Security key enter your WEP key.
7. Insert the USB flash drive that contains Backtrack 5 created in Hands-On Project 6-1 into a computer that contains a wireless NIC adapter.
8. Reboot the computer.
9. If the computer is not configured to launch from a USB flash drive, press the appro- priate key to change the boot sequence so that the USB drive is the first drive from which the computer launches. If that is not available, press the appropriate key to enter the ROM BIOS and change the boot order settings so that the USB drive is first.
10. Press Enter to select Default.
Hands-On Projects 349
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11. When the root@root:~# prompt appears, type iwconfig and press Enter. Note the inter- face that is associated with IEEE 802.11.
12. When the root@root:~# prompt appears, type iwlist scan and press Enter. Note the channel number of the WLAN.
13. When the root@root:~# prompt appears, type iwconfig interface channel number. For example, if the interface is wlan0 on channel 11 type iwconfig wlan0 channel 11. When you are finished, press Enter.
14. When the root@root:~# prompt appears, type airmon-ng start interface. For example, if the interface is wlan0 type airmon-ng start wlan0. When you are finished, press Enter.
15. When the root@bt:~# prompt appears, type startx and press Enter.
16. Click the K Menu icon (the first icon in the lower left corner).
17. Click Backtrack and Exploitation Tools and Wireless Exploitation and WLAN Exploi- tation and finally gerix-wifi-cracker-ng.
18. Click Configuration.
19. Scroll down and, if necessary, set Channel: to all channels.
20. Click Rescan networks. Be sure that your network lists WEP under Enc (Encryption).
21. Click the WEP tab.
22. Click the Start Sniffing and Logging button. A window will open and show the number of frames that are being captured.
23. Note that a client is associated with WLAN using WEP. Click WEP Attacks (with cli- ents) and then Associate with AP using fake auth. Wait 10 seconds and click WEP Attacks (with clients) and then ARP request replay.
24. On the client that is part of the WLAN using WEP, generate traffic by visiting Web sites, reading e-mail messages, etc.
25. Watch the window that is collecting wireless traffic. The value under Data is the num- ber of IVs that are being collected. Once this value exceeds 5,000, click the Cracking tab. Do not close the window collecting traffic.
The amount of time needed to collect the necessary amount of traffic will depend on the traffic that is being generated by the client.
26. Click Aircrack-ng – Decrypt WEP password. If enough IV values have been collected, the WEP key will appear. If it cannot be cracked, wait for another 5,000 values to be collected and try again.
27. Close all windows.
350 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9
Case Projects
Case Project 9-1: Exposing WEP Vulnerabilities The vulnerabilities of WEP were brought to light by several different research- ers shortly after the 802.11b standard was ratified and products began to be introduced. Using the Internet and other sources, research and record a brief
chronology of how these vulnerabilities were exposed and by whom. A good starting place is the University of Maryland’s site at www.cs.umd.edu/~waa/wireless.html.
Case Project 9-2: Latest Wireless Attacks What are some of the most recent attacks that have been launched against wireless systems? What vulnerabilities did they exploit? How much damage was caused? What was the esti- mated dollar amount of the loss? How could they have been better protected? Write a one- page paper about your research.
Case Project 9-3: Wireless Security Web Sites It is important to keep abreast of the latest wireless security vulnerabilities and attacks so that your wireless network can be made secure. Using Internet search engines, research Web sites that contain information about wireless security. Find the top three sites that you would recommend. Which sites have the most up-to-date information? Who sponsors these sites? What other types of valuable information are on the sites? Write a one-page paper on what you find and comparing the sites.
Case Project 9-4: WEP Attack Tools How available are WEP attack tools? Use the Internet to search for WEP attack tools. Com- pile a list of the top three tools and list their features. What are the system requirements? How quickly can they crack WEP? What are their advantages and disadvantages? Write a paper on the information that you find.
Case Project 9-5: War Driving Use the Internet to research the legality of war driving. Is it considered illegal? Why or why not? If it is not illegal, do you think it should be? What should be the penalties? Create a report on your research.
Case Project 9-6: Nautilus IT Consulting Nautilus IT Consulting (NITC), a computer technology business, needs your assistance with one of their new clients.
New Resolutions Fitness Centers (NRFC) manages multiple fitness centers and weight loss clinics in the region. NRFC had installed a wireless network that their associates used when recording information on their client’s workouts. A second WLAN was available for the general public. Recently, NRFC became aware that unauthorized persons were using the office’s wireless signal to access confidential client information. The office manager is con- cerned about wireless security and has asked NITC to conduct an executive briefing on
Case Projects 351
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
wireless security at their home office for their top-level managers. You have been asked to prepare the presentation.
1. Create a PowerPoint presentation of eight or more slides that explains why wireless security is important and the risks associated with using a WLAN. Because this will be delivered to executives and not IT personnel, it should not be too technical in its scope.
2. During the presentation, it was revealed that one of the NRFC locations was using an AP with WEP turned on. Write a one-page follow-up memo that explains to the execu- tives the vulnerabilities of WEP.
Notes
i. Dancho Danchev, “Report: 48% of 22 million scanned computers infected with malware,” ZDNet Zero Day (blog), January 27, 2010, http://www.zdnet.com/blog/security/report-48- of-22-million-scanned-computers-infected-with-malware/5365 (accessed February 28, 2011).
ii. Erik larkin, “Services are Tapping PeoplePower to Spot Malware,” PCWorld, February 20, 2008, http://www.pcworld.com/article/142653/services_are_tapping_people_power_to_spot_ malware.html (accessed February 28, 2011).
352 Chapter 9 Wireless LAN Security Vulnerabilities
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
chapter10
Implementing Wireless LAN Security
After completing this chapter you should be able to:
• Describe the transitional security solutions • Describe the encryption and authentication features of IEEE 802.11i/WPA2 • List the features of wireless intrusion detection and wireless intrusion prevention systems • Explain the features of wireless security tools
353 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
One of the most highly publicized security breaches in recent memory resulted in over 94 million consumer credit and debit card accounts being affected with losses for the company involved exceeding $1 billion. And the starting point of the attack was a wireless LAN using weak security.
Sometime in mid-2005 attackers used a simple telescope-shaped antenna and a laptop computer to capture wireless LAN transmissions at a Marshalls retail clothing store. These transmissions were only marginally protected by the weak Wired Equiva- lent Privacy (WEP) standard, which had been known to be defective for almost four years prior to this time. The attackers quickly broke the WEP encryption and were then able to eavesdrop on employees logging into a server of TJX, Marshall’s parent company. Soon the attackers had enough information to set up their own accounts on TJX’s data center in Massachusetts so that they could access the network online from anywhere in the world.
The main target of the attack was TJX’s Retail Transaction Switch (RTS) servers, which were responsible for processing and storing information related to customer transactions at TJX stores. Attackers stole credit and debit card information and then charged purchases at other online stores totaling hundreds of millions of dollars to the accounts of unsuspecting victims. In one case, a single gang using stolen TJX card data charged $8 million in transactions at Wal-Mart stores and other outlets in Florida. Yet that was not the only consumer information stolen. Because TJX required a driver’s license number and other personally identifiable information when custo- mers made merchandise returns without a receipt, this data was also stored on TJX servers and was taken by the attackers, affecting another 500,000 consumers. The attackers even used the TJX network as a communication post, leaving each other messages so that one attacker would not duplicate the work of another. Yet unlike TJX, these messages the attackers left for one another were encrypted so they could not be read by anyone else.
Of the 12 requirements mandated by the credit card companies to ensure that TJX and other retailers protected consumer information, TJX met only three. TJX also failed to install firewalls to protect its networks and did not update its server soft- ware on a timely basis. According to one report on the incident, TJX’s lax security turned the company’s network into “an open bank vault with the money exposed.”
The theft of data from TJX lasted for over 18 months. Stolen cards were used in at least seven U.S. states and eight foreign countries, including Mexico, China, Italy, Australia, and Japan. When the thefts were finally uncovered the results were costly for both the attackers as well as TJX. Two of the leaders of the crime spree were con- victed, one of whom had to pay $171.5 million in restitution and was sentenced
Real World Wireless
354 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
Despite the advantages of wireless networking, weak security has long been considered a seri- ous problem of this technology. Not only do wireless LANs have several features that make them more vulnerable to attacks than wired networks, but the wireless security protocols in the original IEEE 802.11 standard were not properly implemented. However, this landscape has now changed. If properly configured, new wireless security technologies can make WLANs secure for even the most important transactions.
In this chapter you will look at implementing wireless security. First, you will start by examin- ing different transitional security solutions. Next, the secure features of IEEE 802.1x/WPA2 authentication and encryption will be presented. After a discussion of wireless intrusion detec- tion and prevention systems, other security defenses will be explored.
The vulnerabilities of WLAN security are covered in Chapter 9.
Transitional Solutions
C W N A
5.1.1. Identify and describe the strengths, weaknesses, appropriate uses, and implementation of the IEEE 802.11 security-related items.
In September 1999 the IEEE committee ratified the 802.11b and 802.11a WLAN standards, which included WEP technology for authentication and encryption. However, by early 2001,
to two years in prison, while another attacker was sentenced to between 17 and 25 years in prison for his role in this and other thefts of credit card information. TJX disclosed in its earnings report that the direct cost to its organization was esti- mated to exceed $256 million. (These costs related to the data theft lowered TJX’s profit by $118 million, or 25 cents per share.) In addition, fraud losses to banks and other institutions that issued the stolen cards was an additional $68 million to $83 million. The company also announced that a $9.75 million settlement had been reached between it and 41 state attorneys general. This money went towards cover- ing the states’ investigations into the incident, creating a “comprehensive infor- mation security program” to correct any weaknesses in TJX’s security systems, and paying for a new data security fund for the states to create more effective data security. TJX was also required to meet data security requirements specified by the states. All told, it is estimated that the security breach—which was made possible by an insecure WLAN—ended up costing TJX $1 billion in expenses for consultants, security upgrades, attorney fees, and special marketing.
Transitional Solutions 355
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
independent studies from universities and other organizations had identified serious weaknesses in WEP, including:
● The RC4 pseudo-random number generator (PRNG) is not properly implemented. ● Initialization vector (IV) keys are reused. ● WEP does not prevent passive or active man-in-the-middle attacks.
An attacker with freely available tools and even limited technical knowledge could easily circumvent WEP and launch attacks against WLANs.
To address these WEP vulnerabilities, several transitional solutions were quickly developed. These solutions were only designed to be temporary until a more secure and permanent fix could be made. The transitional solutions included WEP2, dynamic WEP, and Wi-Fi Protected Access (WPA).
WEP2 After the security flaws in WEP were publicized, the IEEE TGi task group (known as Task Group i), which was responsible for the implementation of the original WEP, released a new implementation of WEP known as WEP2 (WEP Version 2). WEP2 attempted to overcome the limitations of WEP by adding two new security enhancements.
The original implementation of WEP itself was hindered by the limited processing capabilities of APs at that time. For example, the weaker PRNG RC4 was chosen in part due to hardware processing constraints.
First, the IV was increased to 128 bits from 64 bits to address the weakness of encryption. Second, a different authentication system known as Kerberos was used. Kerberos was devel- oped by the Massachusetts Institute of Technology (MIT) and used to verify the identity of networked users. Named after a three-headed dog in Greek mythology that guarded the gates of Hades, Kerberos is typically used when a user attempts to access a network service that requires authentication. The Kerberos authentication server issues the user a ticket, much like a driver’s license is issued by a state’s Department of Motor Vehicles. Kerberos tickets share some of the same characteristics as a driver’s license: tickets are difficult to copy (because they are encrypted), they contain specific user information, they restrict what a user can do, and they expire after a few hours or a day. This ticket contains information linking it to the user. The user presents this ticket to the network for a service, where the service then examines the ticket to verify the identity of the user. If the user is verified, they are then authenticated. Issuing and submitting tickets in a Kerberos system is handled internally and is transparent to the user.
Kerberos is available as a free download from the MIT Web site and will function under Windows, Windows Server, Apple Mac OS, and Linux.
However, it soon became apparent that WEP2 had its own security vulnerabilities. First, collisions, or two packets derived from the same IV, were still common. Second, Kerberos is known to be susceptible to an offline cracking password attack called a dictionary attack.
356 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
A dictionary attack begins with the attacker creating encrypted versions of common dictio- nary words and then compares them against data captured through the wireless exchange of encrypted Kerberos information. If a match occurs between the encrypted dictionary word and the wireless data, the password can be revealed. A dictionary attack is illustrated in Figure 10-1.
A dictionary attack is successful because users often create passwords that are simple dictionary words. It was estimated that up to 10 percent of Kerberos-protected user passwords can be cracked within 24 hours using a dictionary attack mounted by an inexpensive net- work of computers.
Because of these weaknesses WEP2 was rarely implemented.
Dynamic WEP Another security solution, called dynamic WEP, was developed. Dynamic WEP solves the weak IV problem by rotating the keys frequently, making it much more difficult to crack the encrypted wireless transmissions. Dynamic WEP uses different keys for different types of traffic. For unicast traffic (traffic destined for only one address) a unicast WEP key is used, which is unique to each user’s session, dynamically generated, and changed frequently. This key is also changed every time the user roams to a new access point (AP) or logs in. A separate key is used for broadcast traffic (traffic sent to all users on the network). The broad- cast WEP key is the same for all wireless devices connected to an AP. Keys can be set to change frequently, such as every 30 minutes. Dynamic WEP is illustrated in Figure 10-2.
A major advantage of using dynamic WEP is its straightforward deployment: dynamic WEP can be implemented without upgrading device drivers or AP firmware, making it a no-cost solution with minimal effort. However, dynamic WEP was still only a partial solution. Dynamic WEP does not protect against man-in-the-middle attacks and is susceptible to DoS attacks. Because it only offered a partial security solution, dynamic WEP was never widely implemented.
Wi-Fi Protected Access (WPA) As the IEEE TGi worked on the 802.11i standard, the Wi-Fi Alliance grew impatient and decided that security could no longer wait. In October 2003 it introduced Wi-Fi Protected Access (WPA). There were two modes of WPA. WPA Personal was designed for individuals
Dictionary words
abacus
acorn
after
agree
ajar
alarm
ameliorate
$58ufj54d9
3#fdRt{p)9
@#%fbGTw93
qAzX43%67s
45RgdFE3&6
22$%RfNUOp
Lo)(*^%rtE
56U84$65@f
0(*7GFKLNO
4%tGBVi9*2
qAzX43%67s
9*&uJTRF64
mia2%&2RNN
Match
Encrypted results Captured wireless data
Figure 10-1 Dictionary attack
© Cengage Learning 2013
Transitional Solutions 357
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
or small office/home office (SOHO) settings, which typically has ten or fewer employees. A more robust WPA Enterprise was intended for larger enterprises, schools, and government agencies. WPA addresses both encryption and authentication.
WPA operates at the media access control (MAC) layer.
The heart and soul of WPA is a new encryption technology called Temporal Key Integrity Protocol (TKIP). TKIP functions as a “wrapper” around WEP by adding an additional layer of security but still preserving WEP’s basic functionality. TKIP’s enhancements are in three basic areas: the required key length is increased from 64 bits to 128 bits (making it harder to break), the IV is increased from 24 bits to 48 bits (effectively eliminating collisions), and a unique “base key” is created for each wireless device using a master key derived in the authentication process along with the sender’s unique MAC address (this key is used with the IV to create unique keys for each packet).
With WEP, a small 40-bit encryption key must be manually entered on APs and devices. This key does not change and is the basis for encryption for all transmissions. By contrast, TKIP uses a longer 128-bit per-packet key. The per-packet functionality of TKIP means that it dynamically generates a new key for each packet, thus preventing collisions. The result is that TKIP dynamically generates unique keys to encrypt every data packet that is wirelessly communicated during a session.
Laptop A Laptop B
Access point
Broadcast WEP Key 1wa3sedazs
Laptop A Unicast WEP Key : 98siKjfud& 8:00 AM–8:30 AM Unicast WEP Key : 234TgdbYuw 8:30 AM–9:00 AM
Laptop B Unicast WEP Key : 8uji98s7af 8:00 AM–8:30 AM Unicast WEP Key : nb&67jsMni 8:30 AM–9:00 AM
Broadcast WEP Key 1wa3sedazs
Unicast WEP Key : 98siKjfud& 8:00 AM–8:30 AM
Unicast WEP Key : 234TgdbYuw 8:30 AM–9:00 AM
Broadcast WEP Key 1wa3sedazs
Unicast WEP Key : 8uji98s7af 8:00 AM–8:30 AM
Unicast WEP Key : nb&67jsMni 8:30 AM–9:00 AM
Figure 10-2 Dynamic WEP
© Cengage Learning 2013
358 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
When using TKIP there are 280 trillion possible keys that can be gen- erated for a given data packet.
WPA also includes a Message Integrity Check (MIC), designed to prevent an attacker from conducting active or passive man-in-the-middle attacks by capturing, altering, and resending data packets. The MIC replaces the Cyclic Redundancy Check (CRC) function in WEP. While CRC is designed to detect any changes in a packet, whether accidental or intentional, it does not adequately protect the integrity of the packet: an attacker could modify a packet and the CRC, making it appear that the packet contents were the original because the altered CRC is correct for that packet. MIC provides a strong mathematical function in which the receiver and the transmitter each compute and then compare the MIC. If it does not match, the data is assumed to have been tampered with and the packet is dropped. There is also an optional MIC countermeasure in which all clients are deauthenticated and new associations are prevented for one minute if a MIC error occurs.
Although a device to protect against forgeries is technically called a message authentication code (MAC) the IEEE 802 had already used the acronym MAC to refer to “media access control.” The TGi com- mittee substituted message integrity code (MIC), and it is sometimes referred to as Michael.
The mechanics of how TKIP performs encryption is illustrated in Figure 10-3 with the parts of the previous WEP procedure that are no longer used crossed out. The wireless device starts with having two keys, a 128-bit encryption key called the temporal key and a 64-bit MIC. The steps are as follows:
● Step 1. Instead of using an IV and secret key as with WEP, the temporal key is XORed with the sender’s MAC address to create an intermediate Value 1.
Step 3
Step 1 Step 2
Value 2 Sequence
Number Value 1
Sender's
MAC
Temporal
Key
Initialization
Vector Secret Key
Ciphertext
Text Text MI C
Keystream
XOR = + =
=PRNG
XOR
CRC
MIC
+
=
MIC Key
Sender's MAC
Receiver's MAC
Figure 10-3 TKIP encryption, with WEP procedures that are not used with TKIP crossed out
© Cengage Learning 2013
Transitional Solutions 359
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Step 2. Value 1 is then mixed with a sequence number to produce Value 2, which is the per-packet key. Value 2 is entered into the PRNG, just as with WEP.
● Step 3. Instead of running the text through the CRC generator, the MIC key, the sender’s MAC address, and the receiver’s MAC address are all run through a MIC function. This creates text with the MIC key appended. This value is then XORed with the keystream to create the ciphertext.
TKIP has three major components that address security vulnerabilities:
● MIC. MIC protects against forgeries by ensuring that the message has not been tampered with. CRC under WEP could not provide this kind of protection. The original WEP design used a 24-bit IV along with a secret key to generate a keystream. TKIP creates a different key for each packet.
● IV sequence. TKIP reuses the WEP IV field as a sequence number for each packet. Both the transmitter and receiver initialize the packet sequence space to zero whenever new TKIP keys are set, and the transmitter increments the sequence number with each packet it sends. This ensures that an attacker does not record a valid packet and then retransmit it. Also, the length of the sequence number IV has been doubled, from 24 bits to 48 bits.
● TKIP key mixing. WEP constructs a per-packet RC4 key by concatenating a key and the packet IV. The new per-packet key construction, called the TKIP key mixing function, substitutes a temporary (temporal) key for the WEP base key and constructs a per-packet key that changes with each packet. Temporal keys have a limited life and are replaced frequently.
If a wireless device was transmitting 10,000 packets per second with original WEP IV, collisions could occur in 90 minutes; TKIP ensures that collisions would not occur for over 900 years.
Authentication for WPA Personal is accomplished by using a preshared key (PSK). In cryp- tography, a PSK is a value that has been previously shared using a secure communication channel between two parties (sometimes also called a “shared secret”). In a WLAN, a PSK is slightly different. It is a secret value that is manually entered on both the AP and each wireless device. Because this secret key is not widely known, it may be assumed that only approved devices have the key value. Devices that have the secret key are then automati- cally authenticated by the AP. Although using PSK has several weaknesses—the key must be kept secret, it can be difficult to manage multiple devices, the key itself may be weak, keys must be entered manually—the alternative requires a significant investment in hard- ware and software. Authentication for WPA Enterprise uses a higher-level authentication process.
Some references confuse shared key authentication with PSK. They are not the same. With shared key authentication, the AP sends to a device wanting to join the network a block of text known as the challenge text, which it then encrypts with its WEP key and returns it to the AP. By contrast, with PSK, the same secret key value is
manually distributed to any approved device.
360 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
Although an improvement over WEP, WPA nevertheless has weaknesses. One of the design goals of WPA was to fit into the existing WEP engine without requiring extensive hardware upgrades or replacements. Because most existing WEP devices at the time WPA was released had very limited central processing unit (CPU) capabilities—with many APs operating at less than 40 MHz—a series of compromises made to be made. Although this allowed WEP to be modified to run WPA through software-based firmware upgrades on the AP and software upgrades on wireless devices, these constraints limited the security of WPA. WPA was only designed as an interim short-term solution to address the critical WEP vulnerabilities and was not seen as a long-term solution.
One of the serious limitations of WPA was even noted in the IEEE standard. It says, “A passphrase typically has about 2.5 bits of security per character, so the passphrase of n bytes equates to a key with about 2.5n 1 12 bits of security. Hence, it provides a relatively low level of security, with keys generated from short passwords subject to
dictionary attack. Use of the key hash is recommended only where it is impractical to make use of a stronger form of user authentication. A key generated from a passphrase of less than about 20 characters is unlikely to deter attacks.”
IEEE 802.11i/WPA2
C W N A
5.1.1. Identify and describe the strengths, weaknesses, appropriate uses, and implementation of the IEEE 802.11 security-related items.
In March 2001 the IEEE TGi task group voted to split into two separate groups, one to address Quality of Service (QoS) issues, known as TGe, and one to address security. The security group, still designated TGi, started work on new wireless security mechanisms (as opposed to transitional solutions such as WEP2). After three years of effort, in June 2004 the IEEE 802.11i wireless security standard was ratified. Also known as the robust security network (RSN), 802.11i provides a solid wireless security model. In September 2004 the Wi-Fi Alliance introduced WPA2, which was the second generation of WPA security. WPA2 is based on the final IEEE 802.11i standard and is almost identical to it. As with WPA there are two modes of WPA2, WPA2 Personal for individuals or small office/home offices (SOHOs) and WPA2 Enterprise for larger enterprises, schools, and government agencies.
The difference between WPA2 and IEEE 802.11i is that WPA2 allows wireless clients using TKIP to operate in the same WLAN whereas IEEE 802.11i does not permit them.
IEEE 802.11i/WPA2 addresses the two major security areas of WLANs, namely encryption and authentication.
IEEE 802.11i/WPA2 361
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Encryption The 802.11i/WPA2 standard addresses encryption by replacing the RC4 stream cipher algorithm with a more secure block cipher. A stream cipher takes one character and replaces it with another character, as shown in Figure 10-4. A block cipher manipulates an entire block of plaintext at one time. The plaintext message is divided into separate blocks of 8 to 16 bytes, and then each block is encrypted independently. For additional security, the blocks can be random- ized. Stream ciphers are more prone to attack because the engine that generates the stream does not vary; the only change is the plaintext itself. Because of this consistency, an attacker can examine the streams and may be able to determine the key. Block ciphers are considered more secure because the output is more random. When using a block cipher, the cipher is reset to its original state after each block is processed. This results in the ciphertext being more difficult to break.
The Advanced Encryption Standard (AES) is the block cipher used in IEEE 802.11i/WPA2. AES performs three steps on every block (128 bits) of plaintext. Within the second step, multiple iterations (called rounds) are performed depending upon the key size: a 128-bit key performs 9 rounds, a 192-bit key performs 11 rounds, and a 256-bit key, known as AES-256, uses 13 rounds. Within each round, bytes are substituted and rearranged, and then special multiplication is performed based on the new arrangement. For the 802.11i/WPA2 implementation of AES, a 128-bit key length is used in four stages that make up one round, and each round is then performed 10 times.
AES is the official encryption standard for the U.S. government.
The encryption protocol used for 802.11i/WPA2 is the Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) and specifies the use of CCM (a general-purpose cipher mode algorithm providing data privacy) with AES. The Cipher Block Chaining Message Authentication Code (CBC-MAC) component of CCMP provides data integrity and authentication.
Stream cipherPlaintext
T
Input 1
h
Input 2
e
Input 3
Ciphertext
#
Output 1
&
Output 2
1
Output 3
Input
Plaintext
The
Ciphertext
Output
$rt52#a9e
Block cipher
Figure 10-4 Stream cipher vs. block cipher
© Cengage Learning 2013
362 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
CCM itself does not require that a specific block cipher be used, but the most secure cipher AES is mandated by the IEEE 802.11i/WPA2 standard. For this reason CCMP for WLANs is sometimes designated as AES-CCMP.
Although CCMP uses a completely different encryption algorithm than TKIP, there are simi- larities to the process. Both CCMP and TKIP use a 128-bit key for encryption. Also, CCMP includes a 48-bit value that is sent in cleartext as does TKIP. Although TKIP calls this value a TKIP sequence counter (TSC), CCMP more properly calls it a packet number (PN). Finally, both methods use a 64-bit MIC value. However, CCMP’s MIC protects everything in the 802.11 media access control (MAC) header (except for the duration field) while the TKIP MIC protects only the source and destination addresses.
The steps in the CCMP encryption process are illustrated in Figure 10-5.
1. The Logical Link Control (LLC) sublayer of the Data Layer (Layer 2) sends the data unit to the MAC sublayer where the MAC header information is added. This data unit becomes the MAC Protocol Data Unit (MPDU).
2. The MAC header is split apart from the MPDU and the 64-bit CCMP header is calculated and added.
3. Information from the MAC header is used to create the 64-bit MIC value, which protects the CCMP header, the data, and parts of the MAC header. The MIC is then appended to the end of the data payload.
4. The data payload and the MIC are encrypted to create the ciphertext, after which the CCMP header is prepended to the ciphertext.
5. Finally the MAC header is added back to the MPDU.
MAC header1
2
3
4
5
Data payload
MAC header CCMP header Data payload
MAC header CCMP header Ciphertext
MAC header CCMP header Ciphertext
Encryption
MAC header CCMP header MICData payload
MIC creation
Figure 10-5 CCMP encryption process
© Cengage Learning 2013
IEEE 802.11i/WPA2 363
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Despite the fact that AES is an efficient block cipher, CCMP still requires a separate encryption processor.
Authentication Authentication for the IEEE 802.11i/WPA2 Personal model uses the same as WPA Personal, namely PSK. Authentication for the IEEE 802.11i/WPA2 Enterprise model uses the IEEE 802.1X standard. This standard, originally developed for wired networks, provides a greater degree of security by implementing port-based authentication. IEEE 802.1X blocks all traffic on a port-by-port basis until the client is authenticated using credentials stored on an authen- tication server. This prevents an unauthenticated device from receiving any network traffic until its identity can be verified. It also strictly limits access to the device that provides the authentication to prevent attackers from reaching it.
IEEE 802.1X is often used in conjunction with RADIUS, or Remote Authentication Dial In User Service. This was developed in 1992 and quickly became the industry standard with widespread support across nearly all vendors of networking equipment. RADIUS is suitable for what are called “high-volume service control applications.”
The word Remote in RADIUS’ name is now almost a misnomer because RADIUS authentication is used for more than just dial-in networks.
A RADIUS client is not the device requesting authentication, such as a wireless laptop. Instead, a RADIUS client is typically a device such as an AP that is responsible for sending user credentials and connection parameters in the form of a RADIUS message to a RADIUS server. The RADIUS server authenticates and authorizes the RADIUS client request, and sends back a RADIUS message response. RADIUS clients also send RADIUS accounting mes- sages to RADIUS servers. The strength of RADIUS is that messages are never directly sent between the wireless device and the RADIUS server. This prevents an attacker from penetrat- ing the RADIUS server and compromising security.
The detailed steps for RADIUS authentication with a wireless device in an IEEE 802.1X net- work are illustrated in Figure 10-6:
1. A wireless device, called the supplicant (it makes an “appeal” for access), sends a request to an AP requesting permission to join the WLAN. The AP prompts the user for the user ID and password.
2. The AP, serving as the authenticator that will accept or reject the wireless device, creates a data packet from this information called the authentication request. This packet includes information such as identifying the specific AP that is sending the authentication request and the user name and password. For protection from eavesdropping, the AP (acting as a RADIUS client) encrypts the password before it is sent to the RADIUS server. The authentication request is sent over the network from the AP to the RADIUS server. This communication can be done either over a local area network or a wide area network. This allows the RADIUS clients to be remotely located from the RADIUS server. If the RADIUS server cannot be reached, the AP can usually route the request to an alternate server.
364 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10 3. When an authentication request is received, the RADIUS server validates that the
request is from an approved AP and then decrypts the data packet to access the user name and password information. This information is passed on to the appropriate security user database. This could be a text file, a password file, a commercially available security system, or a custom database.
4. If the user name and password are correct, the RADIUS server sends an authentication acknowledgment that includes information on the user’s network system and service requirements. For example, the RADIUS server may tell the AP that the user needs TCP/IP. The acknowledgment can even contain filtering information to limit a user’s access to specific resources on the network. If the user name and password are not correct, the RADIUS server sends an authentication reject message to the AP and the user is denied access to the network. To ensure that requests are not responded to by unauthorized persons or devices on the network, the RADIUS server sends an authenti- cation key, or signature, identifying itself to the RADIUS client.
5. If accounting is also supported by the RADIUS server, an entry is started in the account- ing database.
6. Once the server information is received and verified by the AP, it enables the necessary configuration to deliver the wireless services to the user.
RADIUS allows an organization to maintain user profiles in a central database that all remote servers can share. Doing so increases security, allowing a company to set up a policy that can be applied at a single administered network point. Having a central service also means that it is easier to track usage for billing and for keeping network statistics.
RADIUS server
Wired network
1. UserID=Gabriel110311 Password=63rxw8&32m
Access
point
4. Authentication
acknowledgment
User database Accounting database
6. Approval to Laptop
3. Compares with
user database
5. Records in
accounting database
2. Authentication request
Laptop
Figure 10-6 RADIUS authentication using IEEE 802.1X
© Cengage Learning 2013
IEEE 802.11i/WPA2 365
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
It is important that the communication between the supplicant, authenticator, and authenti- cation server in an IEEE 802.1X configuration be secure. A framework for transporting the authentication protocols is known as the Extensible Authentication Protocol (EAP). Despite its name, EAP is a framework for transporting authentication protocols instead of the authentication protocol itself. EAP essentially defines the format of the messages. EAP uses four types of packets: request, response, success and failure. Request packets are issued by the authenticator and ask for a response packet from the supplicant. Any number of request-response exchanges may be used to complete the authentication. If the authentication is successful, a success packet is sent to the supplicant; if not, a failure packet is sent.
An EAP packet contains a field that indicates the function of the packet (such as response or request) and an identifier field used to match requests and responses. Response and request packets also have a field that indicates the type of data being transported (such as an authentication protocol) along with the data itself.
The seven different EAP protocols supported in WPA2 Enterprise are listed in Table 10-1. WPA2 can even support new EAP types as they become available.
A relatively new technology combines many of the advantages of 802.1X with the ease of use of PSK. Known as Per-User Preshared Keys (PPSK), unique passphrases can be assigned individually to each user on a WLAN while still using a common SSID. This allows users to be separately authenticated (as with 802.1X) only by entering a passphrase on the user’s wireless device (as with PSK). When using PPSK different profiles can be created for each user so that the users can have different levels of service. In addition, one user’s credentials can be revoked without impacting other users.
A summary of the WPA2 security models is listed in Table 10-2.
EAP Name Description
EAP-TLS An Internet Engineering Task Force (IETF) global standard protocol that uses digital certificates for authentication
EAP-TTLS/MSCHAPv2 This EAP protocol securely tunnels client password authentication within Transport Layer Security (TLS) records
PEAPv0/EAP-MSCHAPv2 This version of EAP uses password-based authentication
PEAPv1/EAP-GTC PEAPv1 uses a changing token value for authentication
EAP-FAST This EAP protocol securely tunnels any credential form for authentication (such as a password or a token) using TLS
EAP-SIM EAP-SIM is based on the subscriber identity module (SIM) card installed in mobile phones and other devices that use Global System for Mobile Communications (GSM) networks
EAP-AKA This EAP uses the Universal Mobile Telecommunications System (UMTS) Subscriber Identity Module (USIM) for authentication
Table 10-1 EAP protocols supported by WPA2 Enterprise
© Cengage Learning 2013
366 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
Despite the fact that IEEE 802.11i/WPA2 provides the optimum level of wireless security and has been mandatory for all wireless devices certified by the Wi-Fi Alliance since March 2006, there are still a surpris- ing number of WLAN networks that do not implement it. In a recent analysis by this author, 23 different WLANs were discovered in
one residential neighborhood. Thirteen of those networks, or 56 percent, used the weak WEP encryption and open key authentication. The other WLANs used WPA (4) or had no security (3) and only three networks used the secure WPA2. In another test, 26 WLANs were found with six running WPA2, three using WPA, and 17 were open.
Wireless Intrusion Detection and Prevention Systems
C W N A
4.5.1. Understand WLAN design and deployment considerations for commonly supported WLAN applications and devices
5.2.1. Describe, explain, and illustrate the appropriate applications for the wireless security solution Wireless Intrusion Protection System.
In an enterprise setting, the likelihood of more sophisticated wireless attacks is always present. This is due to the higher rewards of an attacker reading sensitive data, hijacking wireless connections, inserting network traffic, or performing DoS attacks. It is important that wireless security systems be in place with sophisticated tools for monitoring and containing wireless attacks.
Wireless Security Systems An intrusion system is a security management system that compiles information from a com- puter network or individual computer and then analyzes it to identify security vulnerabilities and attacks. Although similar in nature to a firewall, an intrusion system differs in that a fire- wall limits access from external networks by silently filtering packets based on such criteria as the sender’s IP address or whether the packet was requested by a device on the protected network. An intrusion system, on the other hand, watches for systematic attacks instead of just a single malicious packet and then takes specified action.
Model Category Security Mechanism Security Level
WPA2 Personal Encryption CCMP High
WPA2 Personal Authentication PSK Medium
WPA2 Enterprise Encryption CCMP High
WPA2 Enterprise Authentication IEEE 802.1X High
Table 10-2 WPA2 security models
© Cengage Learning 2013
Wireless Intrusion Detection and Prevention Systems 367
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
There are two types of intrusion systems for wireless LANs. The first is a wireless intrusion detection system while the second is a more sophisticated wireless intrusion prevention system. Each of these types use wireless sensors to accumulate data.
Wireless Intrusion Detection Systems (WIDS) The first generation of intrusion detection systems for wired networks monitored the overall activity of network traffic and focused on detection of attacks. In wireless networks a wireless intrusion detection system (WIDS) serves a similar function by constantly monitoring the radio frequency (RF) for attacks. If an attack is detected, the WIDS sends information about what just occurred.
There are different methods used for detecting a wireless attack. One method for auditing usage is to examine network traffic, activity, and transactions and look for well-known patterns, much like anti-virus scanning. This is known as signature-based monitoring because it compares activities against a predefined signature. Signature-based monitoring requires access to an updated database of signatures along with a means to actively compare and match current behavior against a collection of signatures. One of the weaknesses of signature-based monitoring is that the signature databases must be constantly updated, and as the number of signatures grows the behaviors must be compared against an increasingly large number of signatures. Also, if the signature definitions are too specific, signature-based monitoring can miss variations. A signature-based WIDS is illustrated in Figure 10-7.
A signature-based WIDS is looking for a specific attack that has already been documented.
Wired network
nsc42606
gha23126
Attack database
ctb87000
Attack matches
signature database
Laptop Laptop
AP
Attack = nsc42606
Figure 10-7 Signature-based WIDS
© Cengage Learning 2013
368 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
A second method, anomaly-based monitoring, is designed for detecting statistical anomalies. First, a baseline of normal activities is compiled over time. (A baseline is a reference set of data against which operational data is compared.) Then, whenever there is a significant deviation from this baseline, an alarm is raised. An advantage of this approach is that it can detect the anomalies quickly without trying to first determine the underlying cause. However, normal behavior can change easily and even quickly, so anomaly-based monitoring is subject to false positives, or alarms that are raised when there is no actual abnormal behavior. In addition, anomaly-based monitoring can impose heavy processing loads on the systems where they are being used. This is because it requires large numbers of CPU cycles to process the data. Finally, because anomaly-based monitoring takes time to create statistical baselines, it can fail to detect events before the baseline is completed. An anomaly-based WIDS is shown in Figure 10-8.
When creating baselines, it is important to measure the performance parameters under normal network conditions and not when there is an unusual amount of traffic, number of users, or other abnormal circumstances.
Behavior-based monitoring attempts to overcome the limitations of both anomaly-based moni- toring and signature-based monitoring by being more adaptive and proactive, instead of reactive. Rather than using statistics or signatures as the standard by which comparisons are made, behavior-based monitoring uses the “normal” processes and actions as the standard. Behavior- based monitoring continuously analyzes the behavior of processes and programs on a system and alerts the user if it detects any abnormal actions, at which point the user can decide whether to allow or block the activity. One of the advantages of behavior-based monitoring is that it is not necessary to update signature files or compile a baseline of statistical behavior before monitor- ing can take place. In addition, behavior-based monitoring can more quickly stop new attacks.
The final method takes a completely different approach and does not try to compare actions against previously determined standards (like anomaly-based monitoring and signature-based
Wired network
Baseline
Attack =
Normal network characteristics
differ from baseline
Laptop
Laptop
AP
Figure 10-8 Anomaly-based WIDS © Cengage Learning 2013
Wireless Intrusion Detection and Prevention Systems 369
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
monitoring) or behavior (like behavior-based monitoring). Instead, it is founded on experience- based techniques. Known as heuristic monitoring, it attempts to answer the question, Will this do something harmful if it is allowed to execute? Heuristic (from the Greek word for find or discover) uses an algorithm to determine if a threat exists.
Once a wireless attack is detected, a WIDS can perform different actions. A passive WIDS will simply sound an alarm and log the event. These alarms may include sending e-mail, page, or a cell phone message to the network administrator or even playing an audio file that says “Attack is taking place.” An active WIDS will both sound an alarm and take action. The actions may include configuring the firewall to filter out the IP address of the intruder, launching a separate program to handle the event, or terminating the TCP session.
Wireless Intrusion Prevention Systems (WIPS) Although WIDS are sophisticated devices, they have disadvantages:
● WIDS cannot prevent an attack. Because a passive WIDS only identifies that an attack has started, it does nothing to prevent the attack from occurring. The system adminis- trator must make a decision about how to proceed after receiving the WIDS notification.
● WIDS only issues an alert after an attack has started. A WIDS only knows that an attack has started after the attack has commenced. By then damage may have already occurred.
● WIDS is dependent upon signatures. A signature-based WIDS relies entirely upon the database of known attack signatures in order to recognize an attack. If a new attack is launched for which this is no attack signature or if the database is not constantly updated, the WIDS provides no protection.
● WIDS produces a high number of false positives. Due to the analytic nature of anomaly- based WIDS, a large number of attack alerts are issued that turn out to be false positives. This creates a tremendous burden on security administrators, especially for WLANs.
A more proactive approach than intrusion detection is a wireless intrusion prevention system (WIPS). A WIPS monitors network traffic to immediately react to block a malicious attack. One of the major differences between a WIDS and a WIPS is its location. A WIDS has sensors that monitor the traffic entering and leaving a firewall, and reports back to the central device for analysis. A WIPS, on the other hand, could be located “in line” on the device itself. This can allow the WIPS to more quickly take action to block an attack.
WIDS/WIPS Sensors Both WIDS and WIPS rely upon a series of sensors to monitor wireless network traffic and send traffic summaries to a central analysis server for examina- tion. There are two types of sensors: integrated and overlay.
Integrated An integrated sensor (sometimes called an AP sensor or embedded sensor) uses existing APs to monitor the RF. This approach is generally used to reduce costs by decreasing or eliminating the need for separate sensors and infrastructure (wired cabling to connect devices, power connections, etc.). Although an integrated-sensor WIDS/WIPS may seem to have several advantages, requiring an AP to perform its normal functions as well as addi- tional RF monitoring has significant drawbacks:
● In an environment where the AP is supporting a large number of users, the additional time needed to stop its normal functions and perform sensor tasks can negatively impact throughput.
370 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
● Because the AP is not dedicated to the task of watching for attacks, it is more likely that an attack can slip through while the AP is performing its normal duties.
● A basic IEEE 802.11b/g AP cannot monitor IEEE 802.11a channels and vice versa. ● Integrated sensors have less spare time to perform other WIPS functions such as
blocking rogue APs. ● Integrated sensors sequentially sample traffic on every available channel, trying to
listen long enough and frequently enough to detect an attack. An attack could slip in on Channel 2 while the AP is scanning Channel 5. Also, attacks of short duration and “quiet” rogue devices like wireless bridges are more likely to be missed in scanning.
Overlay An overlay sensor uses dedicated sensors for scanning the RF for attacks. Although this results in higher costs, it does not impact WLAN throughput by placing an additional load on the AP. Also, overlay sensors can scan more frequencies, provide broader coverage, and detect more attacks. Another advantage of overlay sensors is that they can also be used to troubleshoot WLAN performance issues.
There are disadvantages to an overlay sensor for WIDS/WIPS. Overlay sensors require addi- tional user interfaces, consoles, and databases that must be integrated to avoid duplication. An integrated sensor may be more likely to provide a single, integrated management interface for configuring and monitoring the network. Also, some integrated sensors may have built-in crite- ria to differentiate between legitimate APs and rogue APs, while an overlay sensor must be con- figured with a list of authorized APs. Another disadvantage of overlay sensors is that if a regular AP fails, the dedicated sensor cannot be pulled into emergency duty to provide coverage.
Features A number of important features or attributes are found in WIDS/WIPS. These include AP identification and categorization, device tracking, event action and notification, RF scanning, and protocol analysis.
AP Identification and Categorization One of the most important features of a WIDS/WIPS is its ability to learn about the other APs that are in the area and classify those APs. This ability to “pre-classify” all known APs enables the WIDS/WIPS to recognize rogue APs without delay. Using sensors, the existing APs in the area can be determined. Next the APs can be tagged as to their status. The indicators are usually:
● Authorized AP. This is an AP that has been installed and configured by the organiza- tion and is part of the WLAN infrastructure.
● Known AP. This is a “foreign” yet “friendly” AP (one not owned by the organization) in which the RF signal is detected yet it is not considered as being dangerous. Known APs may be those that belong to other organizations (such as on another floor of a rented office building that houses multiple businesses).
● Monitored AP. A monitored AP may be one in that the signal is usually detected when scans are conducted. However, it is not owned by the organization (Authorized AP) or another organization (Known AP) yet it cannot be verified that it is suspect. An AP that is owned by a user in a nearby apartment complex may be tagged as a Monitored AP.
● Rogue AP. Any AP that does not fit the profile of the above three types will be designated as a rogue AP.
Wireless Intrusion Detection and Prevention Systems 371
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
It is important for a wireless LAN administrator to thoroughly investi- gate an AP before designating it as a “Known AP” to ensure that it is not a rogue AP masquerading as a known AP.
Once specific parameters are assigned, most WIDS/WIPSs are able to perform automatic classification and differentiate between authorized, known, monitored, and rogue APs. The ability to perform this type of activity minimizes false positives and unnecessary alarms to security administrators.
Device Tracking Whereas AP identification is primarily concerned with locating rogue APs, device tracking involves the simultaneous tracking of all wireless devices within the WLAN. Not only can device tracking be used to identify unauthorized device, but it also can be beneficial for other uses such as:
● Asset tracking of wireless equipment that has a high value or that have been stolen or misplaced (called Real-Time Location Services or RTLS)
● Finding an emergency Voice Over WiFi (VoWiFi) telephone caller ● Troubleshooting sources of wireless network interference ● Conducting a site survey ● Determining a wireless user’s availability status based on location
Event Action and Notification An active WIDS or WIPS that identifies an attack must immediately and automatically block any malicious wireless activity that has been detected by its wireless sensors. These malicious activities include wireless DoS attacks, MAC address spoofing, or allowing a device to associate with a rogue AP. In addition, it must block multiple simultaneous attacks as well as continue to scan the RF looking for new attacks. And, once an attack is detected it must notify security administrators through cell phone or e-mail alerts.
Not only must an active WIDS or WIPS stop all types of attacks, it must do so while not disrupting legitimate wireless users or disturbing another WLAN.
RF Scanning It is important that the entire RF spectrum be scanned for potential attacks. This means that all channels in the 2.4-GHz range and the 5 GHz must be scanned.
Protocol Analysis Just as an attacker can use a protocol analyzer to detect what an authorized user is doing, so can a WIDS/WIPS do the same to attackers. Several WIDS/ WIPS products offer remote packet capture and decode capabilities. The WIDS/WIPS can view WLAN network traffic to determine exactly what is happening on the network and help determine what actions need to be taken.
The features of a WIDS/WIPS are summarized in Table 10-3.
WIDS/WIPS security is not inexpensive. The cost for installing a system to cover an environment of 250 APs can exceed $70,000.
372 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
Other Wireless Security Tools
C W N A
5.1.1. Identify and describe the strengths, weaknesses, appropriate uses, and implementation of the IEEE 802.11 security-related items.
There are other wireless security tools that can be used to protect a WLAN. These include a virtual private network, secure device management protocols, Wi-Fi Protected Setup, role- based access control, and rogue AP discovery tools.
Virtual Private Network (VPN) A virtual private network (VPN) uses an unsecured public network, such as the Internet, as if it were a secure private network. It does this by encrypting all data that is transmitted between the remote device and the network. This ensures that any transmissions that are intercepted will be indecipherable. There are two common types of VPNs. A remote-access VPN or virtual private dial-up network (VPDN) is a user-to-LAN connection used by remote users. The second type is a site-to-site VPN, in which multiple sites can connect to other sites over the Internet.
Several “tunneling” protocols (when a packet is encrypted and enclosed within another packet) can be used for VPN transmissions.
VPN transmissions are achieved through communicating with endpoints. An endpoint is the end of the tunnel between VPN devices. An endpoint can be software on a local computer, a dedicated hardware device such as a VPN concentrator (which aggregates hundreds or thousands of VPN connections), or integrated into another networking device such as a firewall. Depending upon the type of endpoint that is being used, client software may be required on the devices that are connecting to the VPN. Hardware devices that have a built-in VPN endpoint handle all the VPN tunnel setup, encapsulation, and encryption in the endpoint. Client devices are not required to run any special software and the entire VPN process is transparent to them.
Attribute Description
AP identification and categorization All APs should detected and be automatically classified.
Device tracking WIDS/WIPS must provide tracking of all wireless devices that are associated with the WLAN.
Event actions and notification An attack must automatically be stopped and security personnel notified immediately.
RF scanning The entire spectrum should be scanned by sensors.
Protocol analysis An integrated protocol analyzer and decoder can reveal what is happening on the WLAN.
Table 10-3 Features of WIDS/WIPS
© Cengage Learning 2013
Other Wireless Security Tools 373
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
VPNs can be software-based or hardware-based. Software-based VPNs, in which the VPN endpoint is actually software running on the device itself, offer the most flexibility in how network traffic is managed. However, software-based VPNs do not provide the same perfor- mance or security as a hardware-based VPN, generally speaking. Hardware-based VPNs are more secure, have better performance, and can offer more features because only the network devices manage the VPN functions, relieving the device from performing any VPN activities. Hardware-based VPNs are generally used for connecting two local area networks through the VPN tunnel.
VPNs can also be used in a wireless LAN setting as well. Because of WLAN vulnerabilities, a wireless user can “tunnel” through the less-than-secure wireless network using a VPN, relying on its security advantages. For example, a user may access a public wireless hotspot at an airport or coffee shop and use VPN to “tunnel” through it to reach a secure corporate network.
Secure Device Management Protocols When managing wireless devices such as APs, it is important to keep these transmissions secure; otherwise, an attacker could capture the password to access an AP and reconfigure it for his purposes. Cryptography can be used to protect this data as it is being transported across a wireless network.
Perhaps the most common transport encryption algorithm is Secure Sockets Layer (SSL), which is a protocol developed by Netscape for securely transmitting documents over the Internet. Transport Layer Security (TLS) is a protocol that guarantees privacy and data integrity between applications communicating over the Internet. TLS is an extension of SSL, and they are often referred to as SSL/TLS. SSL/TLS provides server authentication, client authentication, and data encryption.
One widespread use of SSL is to secure Web Hypertext Transport Protocol (HTTP) commu- nications between a browser and a remote device. This secure version is actually “plain” HTTP sent over SSL/TLS and is called Hypertext Transport Protocol over Secure Sockets Layer (HTTPS). HTTPS uses port 443 instead of HTTP’s port 80. Users must enter URLs with https:// instead of http://. Because many APs and wireless routers are configured using a Web browser, the transmissions between these devices can usually be configured to use HTTPS, as illustrated in Figure 10-9.
Another option is to use Secure Shell (SSH), which is an encrypted alternative to the Telnet pro- tocol that is used to access remote computers. It provides an encrypted channel for logging into another computer over a network, executing commands on a remote computer, and moving files from one computer to another. The current version of SSH is Secure Shell 2 (SSH2).
The Simple Network Management Protocol (SNMP), which was first introduced in 1988, is supported by most network equipment manufacturers and is a popular protocol used to manage network equipment. It allows network administrators to remotely monitor, manage, and configure devices on the network. SNMP functions by exchanging management informa- tion between networked devices.
SNMP can be found not only on core network devices such as switches, routers, hubs, and wireless APs, but also on some printers, copiers, fax machines, and even uninterruptible power supplies (UPSs).
374 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
Each SNMP-managed device must have an agent or a service that listens for commands and then executes them. These agents are protected with a password known as a community string in order to prevent unauthorized users from taking control over a device. There are two types of community strings: a read-only string will allow information from the agent to be viewed, and a read-write string allows settings on the device to be changed.
There were several security vulnerabilities with the use of community strings in the first two versions of SNMP, known as SNMPv1 and SNMPv2. First, the default SNMP community strings for read-only and read-write were public and private, respectively. Administrators who did not change these default strings left open the possibility of an attacker taking control of the network device. Also, community strings were transmitted “in the clear” with no attempt to encrypt the contents. An attacker with a protocol analyzer could view the contents of the strings as they were being transmitted. Because of the security vulnerabilities of SNMPv1 and SNMPv2, SNMPv3 was introduced in 1998. SNMPv3 uses user names and passwords along with encryption to foil any attempts to view the contents.
Wi-Fi Protected Setup Wi-Fi Protected Setup (WPS) is an optional means of configuring security on wireless local area networks. Introduced by the Wi-Fi Alliance in early 2007, it is designed to help users who have little or no knowledge of security to quickly and easily implement WPA2 on their WLANs.
Figure 10-9 HTTPS option
© Cengage Learning 2013
Other Wireless Security Tools 375
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
There are two common WPS methods. The PIN method utilizes a Personal Identification Number (PIN) printed on a sticker of the wireless router or displayed through a software setup wizard. The user types in the PIN into the wireless device (like a wireless tablet or laptop com- puter) and the security configuration automatically occurs. This is the mandatory model and all devices certified for WPS must support it. The second method is the Push-Button method: the user pushes a button (usually an actual button on the wireless router and a virtual one displayed through a software setup wizard on the wireless device) and the security configuration takes place. Support for this model is mandatory for wireless routers and optional for connecting devices. Behind the scenes of these two methods a series of EAP message exchanges occur.
Over 700 different wireless devices have been certified by the Wi-Fi Alliance to run WPS.
However, in late 2011 it was revealed that there are significant design and implementation flaws in WPS using the PIN method:
● There is no lockout limit for entering PINs, so an attacker can make an unlimited number of PIN attempts.
● The last PIN character is only a checksum. ● The wireless router reports the validity of the first and second halves of the PIN sepa-
rately, so essentially an attacker only has to break two short PIN values (a 4-character PIN and a 3-character PIN).
Due to the PIN being broken down into two shorter values only 11,000 different PINs must be attempted before determining the correct value. If the attacker’s computer can generate 1.3 PIN attempts per second (or 46 attempts per minute) he can crack the PIN in less than four hours and become connected to the WLAN, effectively defeating WPA2.
It is recommended that all users should disable WPS in the wireless router’s configuration menu.
Role-Based Access Control (RBAC) In a wired network, the network can be segmented through constructing a virtual local area network (VLAN). A VLAN is a logical grouping of network devices within a larger physical network. For example, a VLAN group may consist of all the accounting department employ- ees even if they are scattered across different floors of an office building or even in different buildings. Wireless VLANs can also be used in a WLAN. This allows different users to con- nect to different wireless VLANs based on different criteria. One method is to use Role-Based Access Control (RBAC). Access under RBAC is based on a user’s job function within an organization. Instead of setting security permissions for each user or group, the RBAC model assigns permissions to particular roles in the organization, and then assigns users to those roles. For example, instead of creating a user account for Ahmed and assigning specific security settings to that account, the role Business_Manager can be created based on the privileges an individual in that job function should have. Then Ahmed and all other business
376 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
managers in the organization can be assigned to that role. The users and objects inherit all of the permissions for the role.
Roles are different than groups. While users may belong to multiple groups, a user under RBAC can be assigned only one role. In addi- tion, under RBAC, users cannot be given permissions beyond those available for their role.
Rogue AP Discovery Tools The problem of rogue (unauthorized) APs is of increasing concern to organizations. Due to the low cost of home wireless APs, an employee can bring a device to their office and plug it into an open network connection to provide wireless access for themself and other employ- ees. However, rogue APs are serious threats to network security because they allow attackers to intercept the RF signal and bypass network security to attack the network or capture sen- sitive data.
There are several ways to detect a rogue AP. The most basic method for identifying and locating a rogue AP is for security personnel to manually audit the airwaves using a wireless protocol analyzer. As the personnel walk through the building or area, the protocol analyzer captures wireless traffic, which is then compared with a list of known approved devices. However, this manual approach can be extremely time-consuming and haphazard when scanning several buildings or a large geographical area. Most organizations elect to use a more reliable approach of continuously monitoring the RF airspace. Monitoring the RF frequency requires a special sensor called a wireless probe, a device that can monitor the air- waves for traffic.
There are four types of wireless probes:
● Wireless device probe. A standard wireless device, such as a portable laptop computer, can be configured to act as a wireless probe. At regular intervals during the normal course of operation, the device can scan and record wireless signals within its range and report this information to a centralized database. This scanning is performed when the device is idle and not receiving any transmissions. When a large number of mobile devices are used as wireless device probes, it can provide a high degree of accuracy in identifying rogue APs. However, there are limitations. First, because a wireless device cannot simultaneously listen and send, there can be gaps in the coverage. Also, not all wireless network interface card adapters can act as a wireless device probe.
● Desktop probe. Instead of using a mobile wireless device as a probe, a desktop probe utilizes a standard desktop PC. A universal serial bus (USB) wireless network interface card adapter is plugged into the desktop computer and it monitors the RF frequency in the area for transmissions.
● AP probe. Some APs can detect neighboring APs, which may include both friendly APs as well as rogue APs. However, AP probes are not widely implemented. The range for a single AP to recognize other APs is limited because APs are typically located so that their signals only overlap in such a way to provide roaming to wireless users. Also, not all vendors support AP probing.
● Dedicated probe. A dedicated probe is designed to exclusively monitor the RF frequency for transmissions. Unlike AP probes that serve as both an AP and a probe,
Other Wireless Security Tools 377
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
dedicated probes only monitor the airwaves. Dedicated probes look very similar to standard APs.
Once a suspicious wireless signal is detected by a wireless probe, the information is sent to a centralized database where WLAN management system software compares it to a list of approved APs. If the device is not on the list, then it is considered a rogue AP. The managed switch is “aware” of approved APs and the ports to which they are connected. The WLAN management system can cause the switch to disable the port to which the rogue AP is connected, thus severing its connection to the wired network.
Chapter Summary ■ To address WEP vulnerabilities, several transitional solutions were developed. WEP2
attempted to overcome the limitations of WEP by adding two new security enhancements: the WEP key was increased to 128 bits from 64 bits to address the weakness of encryp- tion and a different authentication system, known as Kerberos, was used. However, it became apparent that WEP2 had its own security vulnerabilities, so WEP2 was rarely implemented. Dynamic WEP solves the weak IV problem by rotating the keys frequently, making it much more difficult to crack the encrypted wireless transmissions. Dynamic WEP uses different keys for different types of traffic.
■ The Wi-Fi Alliance in 2003 introduced Wi-Fi Protected Access (WPA) as a transitional solution. The basis of WPA is a new encryption technology called Temporal Key Integrity Protocol (TKIP). TKIP adds an additional layer of security while still preserving WEP’s basic functionality. TKIP uses a longer 128-bit per-packet key that dynamically generates a new key for each packet, thus preventing collisions. WPA also includes a Message Integrity Check (MIC), designed to prevent an attacker from conducting active or passive man-in-the-middle attacks by capturing, altering, and resending data packets. Authentication for WPA Personal is accomplished by using a preshared key (PSK), which is a secret value that is manually entered on both the AP and each wireless device. Although an improvement over WEP, WPA nevertheless has weaknesses. WPA was only designed as an interim short-term solution to address the critical WEP vulnerabilities.
■ The IEEE 802.11i wireless security standard provides a solid wireless security model. The Wi-Fi Alliance Wi-Fi Protected Access 2 (WPA2) is the second generation of WPA security; WPA2 is based on the final IEEE 802.11i standard and is almost identical to it. There are two modes of WPA2: WPA2 Personal for individuals or small office/home offices (SOHOs) and WPA Enterprise for larger enterprises, schools, and government agencies. The 802.11i/WPA2 standard replaces the RC4 stream cipher with a more secure block cipher that manipulates an entire block of plaintext at one time. The Advanced Encryption Standard (AES) is the block cipher. The encryption protocol used for 802.11i/WPA2 is the Counter Mode with Cipher Block Chaining Message Authen- tication Code Protocol (CCMP) with AES. Authentication for IEEE 802.11i/WPA2 Enterprise model uses the IEEE 802.1X standard. This standard, originally developed for wired networks, provides a greater degree of security by implementing port-based authentication. IEEE 802.1X is often used in conjunction with RADIUS, or Remote Authentication Dial In User Service. A framework for transporting the authentication protocols is known as the Extensible Authentication Protocol (EAP).
378 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
■ A wireless intrusion detection system (WIDS) constantly monitors the radio frequency (RF) for attacks. There are different methods used for detecting a wireless attack. Signature-based monitoring compares activities against a predefined signature. Anomaly- based monitoring is designed to detect statistical anomalies by comparing actions against a baseline of normal activities. Behavior-based monitoring uses the “normal” processes and actions as the standard. Heuristic monitoring looks deeper and attempts to answer the question, Will this do something harmful if it is allowed to execute?
■ A more proactive approach than intrusion detection is a wireless intrusion prevention sys- tem (WIPS). A WIPS monitors network traffic to immediately react to block a malicious attack. Both WIDS and WIPS rely upon a series of sensors to monitor wireless network traffic and send traffic summaries to a central analysis server for examination. There are two types of sensors, integrated and overlay. There are a number of important features or attributes that are found in WIDS/WIPS. These include AP identification and categoriza- tion, device tracking, event action and notification, RF scanning, and protocol analysis.
■ There are other wireless security tools that can be used to protect a WLAN. A virtual private network (VPN) uses an unsecured public network, such as the Internet, as if it were a secure private network. VPNs can be used in a wireless LAN to protect transmissions. When managing wireless devices such as APs it is important that these transmissions remain secure. WLAN vulnerabilities make it possible for a wireless user to “tunnel” through the less-than-secure wireless network using a VPN, relying on its security advantages. Hypertext Transport Protocol over Secure Sockets Layer (HTTPS) can be used to protect transmissions, as can Secure Shell (SSH2), an encrypted alternative to the Telnet protocol that is used to access remote computers. The Simple Network Management Protocol (SNMP) is supported by most network equipment manufacturers and is a popular protocol used to manage network equipment. The Wi-Fi Protected Setup is an optional means to simplify the configuration and activation of WPA2 Personal. Role-Based Access Control (RBAC) can be used to assign permissions to particular roles in the organization, and then assign users to those roles. The problem of rogue (unauthorized) APs is of increasing concern to organizations. A rogue AP can be detected via a manual audit of an area’s airwaves or via a wireless probe.
Key Terms Advanced Encryption Standard (AES) The block cipher used in IEEE 802.11i/WPA2. anomaly-based monitoring A method for auditing usage by detecting statistical anomalies. authentication request A data packet in an IEEE 802.1X network that contains the specific AP that is sending the authentication request and the user name and password. authenticator A device in an IEEE 802.1X network that accepts or rejects a supplicant. behavior-based monitoring A method for auditing usage by using the normal processes and actions as the standard. block cipher An encryption cipher that manipulates an entire block of plaintext at one time. broadcast Network traffic sent to all users on the network. Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) The encryption protocol used for 802.11i/WPA2.
Key Terms 379
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
dictionary attack An attack that compares encrypted versions of common dictionary words against data captured through wireless transmissions. dynamic WEP An enhancement to WEP that uses rotating keys. Extensible Authentication Protocol (EAP) A framework for transporting the authentication protocols in an IEEE 802.1X network. heuristic monitoring A method for auditing usage by using an algorithm to determine if a threat exists. Hypertext Transport Protocol over Secure Sockets Layer (HTTPS) A security protocol that uses HTTP sent over SSL/TLS. IEEE 802.11i (also known as robust security network (RSN)) The current wireless security standard ratified by the IEEE in 2004. IEEE 802.1X A standard originally developed for wired networks that blocks all traffic on a port-by-port basis until the client is authenticated. integrated sensor (also AP sensor or embedded sensor) A WIDS/WIPS sensor that uses existing APs to monitor the RF. intrusion system A security management system that compiles information from a computer network or individual computer and then analyzes it to identify security vulnerabilities and attacks. Kerberos An authentication system developed by the Massachusetts Institute of Technology (MIT) and used to verify the identity of networked users. Message Integrity Check (MIC) Part of the WPA standard designed to prevent an attacker from conducting active or passive man-in-the-middle attacks. overlay sensor A WIDS/WIPS sensor that uses separate dedicated sensors for scanning the RF for attacks. per-packet key Dynamically generating a new key for each packet to preventing collisions. Per-User Preshared Keys (PPSK) A technology that combines many of the advantages of 802.1X with the ease of use of PSK. preshared key (PSK) A secret value that is manually entered on both the AP and each wireless device. Real-Time Location Services (RTLS) Using wireless technologies for asset tracking of wireless equipment. Remote Authentication Dial In User Service (RADIUS) The industry standard with widespread support suitable for high-volume service control applications. Role-Based Access Control (RBAC) Providing access based on a user’s job function within an organization. rounds An iteration used in AES encryption. Secure Shell (SSH) An encrypted alternative to the Telnet protocol that is used to access remote computers. Secure Shell 2 (SSH2) The current version of the Secure Shell (SSH) protocol. Secure Sockets Layer (SSL) A protocol developed by Netscape for securely transmitting documents over the Internet. signature-based monitoring A method for auditing usage by examining network traffic, activity, transactions, or behavior to compare against well-known patterns. stream cipher An encryption cipher that takes one character and replaces it with another character.
380 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
supplicant A device in an IEEE 802.1X network that makes an appeal for access. temporal key A 128-bit encryption key used in TKIP. Temporal Key Integrity Protocol (TKIP) Part of the WPA standard that adds an additional layer of security while still preserving WEP’s basic functionality. Transport Layer Security (TLS) A protocol that guarantees privacy and data integrity unicast Network traffic destined for only one address. virtual private network (VPN) A technology that uses an unsecured public network as if it were a secure private network. VPN concentrator A device that aggregates VPN connections. WEP2 (WEP Version 2) An enhancement to WEP that attempted to overcome WEP’s limitations by adding a longer key value and a different authentication system. Wi-Fi Protected Access (WPA) A temporary security solution developed by the Wi-Fi Alliance in 2003. Wi-Fi Protected Access 2 (WPA2) The Wi-Fi Alliance’s security standard based on IEEE 802.11i. Wi-Fi Protected Setup (WPS) An optional means of configuring security on wireless local area networks designed to help users who have little or no knowledge of security. wireless intrusion detection system (WIDS) A security management system that constantly monitors the RF for attacks and sounds an alert if one is detected. wireless intrusion prevention system (WIPS) A security management system that monitors network traffic to immediately react to block a malicious attack. WPA Enterprise A temporary security solution intended for large enterprises, schools, and government agencies. WPA2 Enterprise The current Wi-Fi Alliance standard designed for large enterprises, schools, and government agencies. WPA Personal A temporary security solution designed for individuals or small office/home office settings. WPA2 Personal The current Wi-Fi Alliance standard designed for individuals or small office/home offices.
Review Questions 1. Each of the following is a weakness of WEP except:
a. cannot prevent man-in-the-middle attacks.
b. RC4 PRNG improperly implemented.
c. reuse of IV keys.
d. cannot function in WIDS.
2. Which of the following was a security enhancement introduced by WEP2?
a. upgrade AP firmware with more robust TKIP
b. reduce WEP key to more manageable length of 32 bits
c. multiple IVs
d. Kerberos
Review Questions 381
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3. Dynamic WEP uses rotating .
a. keys
b. IVs
c. packets
d. dictionaries
4. Which of the following is a temporary security model for a small office/home office?
a. WPA Personal
b. WPA2 Enterprise
c. WEP Level 4
d. WIDS Version H
5. functions as a “wrapper” around WEP by adding an additional layer of security but still preserving WEP’s basic functionality in WPA.
a. TKIP
b. CRC
c. WEP2
d. BIV
6. Which of the following replaces the Cyclic Redundancy Check (CRC) function in WEP in WPA?
a. Message Integrity Check (MIC)
b. Checksum Integrity Verifier (CIV)
c. Parity Bit
d. Longitudinal Parity Check (LPC)
7. Which of the following is not a weakness of preshared key (PSK)?
a. It can be difficult to manage multiple devices.
b. Keys are entered automatically but cannot be verified.
c. Weak keys could be used.
d. The key must be kept secret.
8. Another name for the robust security network (RSN) is .
a. IEEE 802.11i
b. IEEE 802.1X
c. RADIUS
d. WPA Enterprise
9. Which of the following is false about the Advanced Encryption Standard (AES)?
a. It is a stream cipher.
b. It is used with the Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) in WPA2.
382 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
c. It performs multiple iterations on the block of text.
d. One of its options is to use a 128-bit key length.
10. Authentication for the IEEE 802.11i/WPA2 Enterprise model is achieved by using .
a. CCMP
b. preshared key (PSK)
c. TKIP
d. IEEE 802.1X
11. In a RADIUS authentication with a wireless device in an IEEE 802.1X network, the AP serves as the .
a. supplicant
b. authenticator
c. validation server
d. database verifier (DV)
12. Which of the following is not an Extensible Authentication Protocol (EAP) used in IEEE 802.1X?
a. SSL/TLS
b. EAP-TLS
c. PEAPv0/EAP-MSCHAPv2
d. EAP-FAST
13. Which of the following security models has the lowest level of security?
a. WPA2 Personal
b. WPA2 Enterprise
c. WPA Personal
d. IEEE 802.1r
14. Which IDS monitoring technique compares network traffic, activity, and transactions against those of known attacks?
a. anomaly-based monitoring
b. behavior-based monitoring
c. heuristic monitoring
d. signature-based monitoring
15. Which of the following WIDS sensors uses existing APs to monitor the RF?
a. integrated sensors
b. overlay sensors
c. converged sensors
d. combined sensors
Review Questions 383
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
16. Each of the following is a label used to tag an AP by a sensor except:
a. detected AP.
b. authorized AP.
c. monitored AP.
d. known AP.
17. Which of the following is false regarding a virtual private network (VPN)?
a. It uses an unsecured public network as if it were a secure private network.
b. A user-to-LAN is called a remote-access VPN.
c. VPN requires the use of special hardware for the client.
d. A VPN concentrator can aggregate multiple VPN connections.
18. Each of the following can be used as a secure device management technology except:
a. Hypertext Transport Protocol over Secure Sockets Layer (HTTPS).
b. Secure Shell 2 (SSH2).
c. Simple Network Management Protocol (SNMP) v3.
d. File Transfer Protocol (FTP).
19. is an optional means of configuring security designed to help users who have little or no knowledge of security to quickly and easily implement it on their WLANs.
a. Wi-Fi Protected Setup (WPS)
b. Wi-Fi Protected Access (WPA)
c. Wi-Fi Protected Access 2 (WPA2)
d. WEP2
20. Each of the following is a type of wireless probe that can be used to detect a rogue AP except:
a. wireless device probe.
b. desktop probe.
c. dedicated probe.
d. remote probe.
Hands-On Projects
Project 10-1: Viewing Security Information with Vistumbler Vistumbler can be used to display the security information that is beaconed out from WLANs. Note that Vistumbler does not allow you to “crack” any
WLANs but instead only displays information. In this project, you will use Vistumbler to view this information. This project works best when you are in an area in which you can pick up multiple WLAN signals.
384 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
1. Use the computer on which you installed Vistumbler in Hands-On Project 3-2.
If that computer is not available then return to Hands-On Project 3-2 to download and install the software again.
2. Launch the Vistumbler application. If necessary expand the window to full screen.
3. If the Scan APs button is displayed, click it. If no networks appear, click Interface and then select the appropriate wireless NIC interface.
4. Use the horizontal scroll bar to move to the right. Note the columns Authentication, Encryption, Manufacturer, and Radio Type. How would this information be useful to an attacker?
5. Use the horizontal scroll bar to move back to the far left.
6. In the left pane, expand the information under Authentication. What types are listed?
7. Expand the information under these types and note the information given for the wireless LAN signals. What device does Mac Address point to? How could this be useful to an attacker?
8. In the left pane, expand the information under Encryption. What types are listed? Which types are most secure? Which types are least secure?
9. Expand the information under these types and note the information given for each WLAN.
10. Record the total number of different WLANs that you are able to detect, along with the number of encryption types. Which type is most common?
11. Compile all of the information from other students regarding the total number of different WLANs and the number of encryption types. Does it surprise you? Why?
12. Close Vistumbler.
Project 10-2: Configuring Access Points—WPA2 and WPS The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this proj- ect you will use an online emulator from D-Link to configure an AP’s legacy
security settings.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you if necessary.
3. If you are asked to select the preferred D-Link home page, click No, Thank you and then click Continue.
Hands-On Projects 385
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
4. Click the Support tab.
5. Click GO next to Emulators.
6. Click DAP-1522.
7. Click DAP-1522 AP Mode.
8. The emulated login screen will appear. Click Login without entering a password.
9. An emulated Setup screen appears, displaying what a user would see when configuring an actual DAP-1522.
10. Under MANUAL WIRELESS NETWORK SETUP click the button Manual Wireless Network Setup.
11. Under WIRELESS SECURITY MODE, click the down arrow next to Security Mode. What are the choices listed? Click WPA-Personal.
12. Under WPA, click the down arrow next to WPA Mode. What are the choices listed? When would you use Auto (WPA or WPA2)?
13. Press the Escape key to close the dropdown menu, and then click the down arrow next to Cipher Type. What options are listed? When would you use TKIP and AES? Press the Escape key to close the dropdown menu.
14. The Passphrase box under PRE-SHARED KEY is where you would enter the PSK. Because it is important that this value be strong, it is recommended that you use an password gener- ation program. Leave this D-Link site link up and open another tab on your Web browser.
15. Open a separate browser window or tab and go to www.grc.com/passwords.htm.
16. Select the value under 63 random printable ASCII characters and copy it into your clip- board by right-clicking and selecting Copy.
17. Return to the D-Link page.
18. Click in the Passphrase box and paste this value from the clipboard by right-clicking and selecting Paste.
Because the passphrase only has to be entered once on the AP and once on each wireless device it does not have to be a pass- phrase that must be committed to memory. Instead, it can be a long and complicated passphrase to enhance security. Under nor- mal circumstances the passphrase now would be entered on each
wireless device and saved in a password management application so it can be retrieved when needed.
19. Click the Security Mode down arrow and then click WPA-Enterprise. What new infor- mation is requested? Why?
20. Under WI-FI PROTECTED SETUP (also called WNC 2.0 in Windows Vista) note that it is enabled by default. Is this good or bad? Why?
21. Uncheck the box next to Enable:.
22. Close all windows.
386 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
Project 10-3: Use SSH Application When managing wireless devices such as APs it is important that these transmis- sions remain secure; otherwise, an attacker could capture the password to access an AP and reconfigure it for his purposes. One option is to use Secure Shell (SSH),
which is an encrypted alternative to the Telnet protocol that is used to access remote computers. The current version of SSH is Secure Shell 2 (SSH2). In this project you will download and install an SSH application called PuTTY. To complete all of the steps of this project, you need the address of your e-mail server. See your lab manager or instructor for more information
1. Go to www.putty.org.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “PuTTY”.
2. Under Download PuTTY click here.
3. Scroll down to A Windows installer for everything except PuTTYtel.
4. Click on the current filename and download it to your computer.
5. Launch the installer application and follow the default steps to install PuTTY.
6. Click Start, point to All Programs, click the PuTTY folder, and then click PuTTY. The PuTTY Configuration dialog box opens, as shown in Figure 10-10.
Figure 10-10 PuTTY Configuration dialog box
© Cengage Learning 2013
Hands-On Projects 387
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
7. In the Host Name (or IP address) text box, enter the address of your mailserver, such as mailserver.my_isp.com.
8. Under Connection type, click SSH, if necessary. The Port field will automatically change to 22, which is the normal port that SSH listens on.
9. Under Saved Sessions enter Mail.
10. Expand Connection in the left pane.
11. Expand SSH in the left pane.
12. Click Tunnels in the left pane.
13. Under Add new forwarded port, enter 110 for the Source port, the port that e-mail is typically received over.
14. Under Destination, enter the address and port of your e-mail server, such as smtp_server.my_isp.com:25. Click Add.
15. Click Session in the left pane.
16. Click Save.
17. Double-click Mail in the lower Saved Sessions box. You will be connected to your e-mail server and asked to authenticate yourself. You can then read your e-mail over SSH.
18. Close all windows.
If you have a wireless router you can configure SSH to access it by entering the IP address and if necessary the port number.
Project 10-4: Documenting BackTrack 5 Wireless Tools Knowing which tools an attacker has is important to creating a strong defense. In this project you will explore the tools on BackTrack 5.
These tools should never be used to attack a WLAN that is not part of your own network.
1. Insert the USB flash drive that contains Backtrack 5 created in Hands-On Project 6-1 into a computer that contains a wireless network interface card adapter.
2. Reboot the computer.
3. If the computer is not configured to launch from a USB flash drive, press the appropri- ate key to change the boot sequence so that the USB drive is the first drive from which the computer launches. If that is not available, press the appropriate key to enter the ROM BIOS and change the boot order settings so that the USB drive is first.
4. Press Enter to select Default.
388 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10
5. When the root@root:~# prompt appears, type iwconfig and press Enter. Note the inter- face that is associated with IEEE 802.11.
6. When the root@root:~# prompt appears, type iwlist scan and press Enter. Note the channel number of the WLAN.
7. When the root@root:~# prompt appears, type iwconfig interface channel number. For example, if the interface is wlan0 on channel 11 type iwconfig wlan0 channel 11. When you are finished, press Enter.
8. When the root@root:~# prompt appears, type airmon-ng start interface. For example, if the interface is wlan0 type airmon-ng start wlan0. When you are finished, press Enter.
9. When the root@bt:~# prompt appears, type startx and press Enter.
10. Click the K Menu icon (the first icon in the lower left corner).
11. Click BackTrack.
12. Explore each of the wireless applications and record the application and where it is found on the backtrack menu. For example: Information Gathering | Network Analysis | WLAN Analysis: airodump-ng, giskismet, kismet, and so on. Note that there are an extensive number of wireless applications in Backtrack 5.
13. Close all windows.
14. Create a table that lists each application, its location in Backtrack 5, a brief description of its purpose, and finally a link to an online video or a textual explanation of how it is used.
Case Projects
Case Project 10-1: Firesheep A wireless LAN attack that illustrates the vulnerabilities of using an unen- crypted public hotspot is called Firesheep. Firesheep, a free open-source Firefox browser extension, allows a user to connect to an unencrypted wireless net-
work and then imitate any other person who is connected to the same network through a technique known as “sidejacking.”Use the Internet to research Firesheep. How does it work? What are the defenses against it? What are the risks of using an unencrypted hotspot? Write a one-page paper about Firesheep.
Case Project 10-2: EAP Use the Internet to research information about the seven different EAP protocols that are supported in WPA2 Enterprise listed in Table 10-1. Write a brief description of each and indicate the relative strength of its security. Write a one-page paper on your research.
Case Project 10-3: IEEE 802.1X Why is IEEE 802.1X considered to be most secure type of authentication? Using the Internet and other print sources, research IEEE 802.1X and RADIUS servers. When was this standard developed? Why? Where is it being used today? Write a one-page paper on your research.
Case Projects 389
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Case Project 10-4: Your Wireless Security Model Is the wireless network you own as secure as it should be? Examine your wireless network or that of a friend or neighbor and determine which security model it uses. Next, outline the steps it would take to move it to the next highest level. Estimate how much it would cost and how much time it would take to increase the level. Finally, estimate how long it would take you to replace all of the data on your computer if it was corrupted by an attacker, and what you might lose. Would this be motivation to increase your current wireless security model?
Case Project 10-5: Wi-Fi Protected Setup (WPS) Wi-Fi Protected Setup (WPS) is an optional means of configuring security on wireless local area networks designed to help users who have little or no knowledge of security to quickly and easily implement WPA2 on their WLANs. Use the Internet to research WPS. How does it work? Describe the four WPS models (note that the USB model is now discontinued). What are the EAP message types that are exchanged? Finally, describe its security vulner- abilities. What recommendations would you make to the vendors to increase the strength of WPS? Write a one-page paper on your research.
Case Project 10-6: Wi-Fi Alliance Certificates Is your wireless router Wi-Fi certified? If so, what are its features? The Wi-Fi Alliance makes the certificates of approved devices available for download. Determine the brand and model of your wireless router and then point your Web browser to certifications.wi-fi.org/search_ products.php. Click Access Point for Home or Small Office (Wireless Router). Locate your wireless router (or if it’s not listed select a similar model). Right-click on Certificate and download the PDF file. Open the file and view the information about your device. Is this information helpful? Would you use this information before purchasing your next wireless device? Why or why not?
Case Project 10-7: Nautilus IT Consulting A computer technology business called Nautilus IT Consulting (NITC) needs your assistance with one of their clients.
Hair Emporium, a regional chain of upscale hair salons, provides free wireless access to its patrons and also uses it for all of their inventory and point-of-sale systems. Recently an attacker compromised the wireless LAN at one of their salons. Hair Emporium discovered that the person who set up their WLAN used WEP for security. Emporium has turned to Nautilus IT Consulting for help.
1. Prepare a PowerPoint presentation that outlines the weaknesses of WEP along with the different models of wireless security and the features included in each model. Also, create a graph of “Most Vulnerable” to “Least Vulnerable” with each model listed. Identify where Hair Emporium would fit on the graph. Your presentation should be at least eight slides in length.
2. Hair Emporium is also interested in an IDS but cannot decide if a WIDS or a WIPS should be purchased. Write a one-page member with your recommendation. Justify your reasons.
390 Chapter 10 Implementing Wireless LAN Security
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
chapter11
Managing a Wireless LAN
After completing this chapter you should be able to:
• Describe security defenses for WLANS • List the tools used for monitoring a wireless network • Explain how to maintain a WLAN
391 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Since the economic downturn of 2008, shoppers don’t shop like they used to. This is primarily due to two factors. First, in the postrecession age, consumers are much more frugal. Second, online resources have had a dramatic impact on how consumers shop. Instead of visiting the mall and walking store-to-store in search of merchandise, many shoppers instead turn first to the Web. Online shoppers can search for an item, compare similar products, read reviews, and see a list comparing prices from online retailers. All that is left to do is select the lowest-priced item, pay for it online, and have it directly shipped to them.
These two factors have also impacted consumer shopping habits when they do visit traditional brick-and-mortar stores. Not only do shoppers visit these stores less often, but when they do go on a shopping trip, they visit fewer stores. Today consumers on average only visit three different stores per trip, whereas five stores per trip used to be the norm. Some shoppers come to stores only to see and touch the merchandise before returning back home to order it online. Other shoppers come with their online research in hand so they know all about specific brands, prices, and availability. And instead of purchasing the first product they see, they may instead use a smartphone app and scan the item’s bar code to bring up a list of comparison prices in other nearby stores to be sure they are getting the best deal.
With all of these tools available, most consumers today directly target the mer- chandise they want to purchase and resist general browsing or impulse shopping. Known as “mission shoppers,” these thrifty, tech-savvy consumers have made it much more difficult for stores to maintain their desired sales per square foot of floor space, a common metric used in retailing.
Several retailers are trying to change shoppers’ habits by using wireless LAN tech- nology in new ways. One clothing retailer now gives all of its sales clerks tablet computers that are connected to the store’s WLAN. These tablets can be used by the clerks to help a customer determine if an item is currently in inventory or located at another store. In clothing stores, instead of focusing on a single item, sales clerks can create entire outfits for customers on their mobile devices. If any of the apparel items are not in stock, they can be immediately ordered and shipped to the customer’s home. Wireless tablets are also being used to show customers items that are only available online. This helps stores reduce the amount of inventory they must carry. In addition, these tablets can be used as portable handheld checkout devices as well. The customer can simply hand the mobile sales clerk her plastic credit card to ring up the sale instead of getting into a line at the checkout counter.
Real World Wireless
392 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
In the realm of wireless networks, properly designing, installing, and securing a wireless LAN are important tasks. Yet an equally important job is managing the WLAN. Wireless networks require more management than wired networks. This is because of the nature of wireless net- works. Even activities that appear unrelated to computer networks may have an impact upon the WLAN. For example, the installation of a new photocopy machine or the relocation of a large potted plant may affect the WLAN’s radio frequency (RF) signal, resulting in poor con- nectivity or slow transmission speeds. Wireless LAN managers should constantly monitor and adjust wireless network settings in order to provide optimum performance to their users. It’s also important to understand that the security required to keep a wireless network safe is dif- ferent from a wired LAN.
In this chapter you explore some of the tasks involved in managing a wireless LAN. First, you will explore procedural security defenses. Next, steps for monitoring the network’s perfor- mance will be explored. Finally, you will look at what it takes to maintain a WLAN.
Procedural Security Defenses
C W N A
5.3.1. Describe General Security Policy elements.
5.3.2. Describe Functional Security Policy elements.
The technical aspects of securing a wireless network—such as implementing IEEE 802.11i/WPA2, installing the latest wireless intrusion detection and prevention systems, and using rogue access point (AP) discovery tools—are important steps for making a WLAN safe. But security defenses go beyond technical solutions. They also involve implementing the correct security procedures within the organization to ensure that the technical defenses remain solid. These procedural security defenses include managing risk and creating defenses against attacks.
The technical defenses of securing a WLAN are covered in Chapter 10.
Yet even one large retailer is moving beyond that. It has rolled out new tech- nology in almost half of its 900 stores that lets shoppers use their own mobile phones instead of relying on sales clerks with tablets. After installing an app on a smart- phone, a shopper can simply scan a bar code of the item in a store using the phone’s camera. The item is instantly paid for by using the customer’s credit card number on file. Information is then sent to a dedicated pick-up area in the store where the customer can retrieve the item before going home. Despite the convenience these new shopping technologies have introduced, there are security risks associated with them that must be managed.
Procedural Security Defenses 393
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Managing Risk One of the first steps in implementing procedural security defenses is to manage risk. This involves understanding what risk is and the role that it plays in security defenses. One exam- ple of risk is social engineering attacks.
Some security defenses may differ based on the size of the organiza- tion. Most organizations can be classified as Small Office/Home Office (SOHO), Small and Medium Business (SMB), and Enterprise.
What Is Risk? Suppose that Gabe wants to purchase a new set of rims for his car. How- ever, because several cars have had their rims stolen near his condo, he is concerned about someone stealing his rims. Although he parks the car in the gated parking lot, a hole in the fence surrounding his condo makes it possible for someone to access the parking lot without restriction. Gabe’s car and the threats to the rims are illustrated in Figure 11-1, along with their corresponding information security component.
Gabe’s new rims are an asset, which is defined as an item that has value. In an organization, assets have the following qualities: they provide value to the organization; they cannot easily be replaced without a significant investment in expense, time, worker skill, and/or resources; and they can form part of the organization’s corporate identity.
Not all elements of an organization’s information technology infra- structure may be classified as an asset. For example, a faulty desktop computer that can easily be replaced would generally not be consid- ered an asset, yet the information contained on that computer can be an asset.
Gabe is trying to protect his rims from a threat, which is a type of action that has the poten- tial to cause harm. Information security threats are events or actions that represent a danger
Fence hole (vulnerability)
Stolen rims (risk)
Exploit
(go through fence hole)
Loss of rims (threat)
Thief (threat agent)
Rims (asset)
Figure 11-1 Information security components analogy
© Cengage Learning 2013
394 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
to information assets. The mere existence of a threat does not mean that security has been compromised; rather, it simply means that the potential for loss is real. For Gabe, the loss would be the theft of his rims. In information security, a loss could take the form of infor- mation theft, a delay in information being transmitted, or even the loss of good will or reputation.
A threat agent is a person or element that has the power to carry out a threat. For Gabe the threat agent is a thief. In information security, a threat agent could be a person attempting to break into a secure computer network. It could also be a force of nature, such as a tornado or flood that could destroy computer equipment and thus destroy information, or it could be malicious software that attacks the computer network.
Gabe wants to protect his rims and is concerned about a hole in the fencing around his condo. The hole in the fencing is a vulnerability, which is a flaw or weakness that allows a threat agent to bypass security. An example of a vulnerability in the world of information security is a software defect in an operating system that allows an unauthorized user to gain control of a computer without the user’s knowledge or permission.
If a thief can get to Gabe’s car because of the hole in the fence, then that thief is taking advantage of the vulnerability. This is known as exploiting the security weakness. An attacker, knowing that an e-mail system does not scan attachments for a virus, is exploiting the vulnerability by sending infected e-mail messages to its users.
Gabe must decide if the risk of theft is too high for him to purchase the new rims. A risk is the likelihood that the threat agent will exploit the vulnerability; that is, that the rims will be stolen. Realistically, risk can never be entirely eliminated as it would cost too much and take too long. Rather, some degree of risk must always be assumed. An organization generally asks, “How much risk can we tolerate?”
Sometimes risk is illustrated as the calculation Risk 5 Threat × Vulnerability × Cost.
There are three options when dealing with risks: accept the risk, diminish the risk, or trans- fer the risk. In Gabe’s case, he could accept the risk and buy the new rims, knowing there is the chance of them being stolen. Or he could diminish the risk by parking the car in a rented locked garage. A third option is for Gabe to transfer the risk to someone else. He can do this by purchasing additional car insurance; the insurance company then absorbs the loss and pays if the rims are stolen. In information security, most risks should be diminished if possible.
Social Engineering Attacks One morning a small group of strangers walked into the corporate offices of a large shipping firm and soon walked out with access to the firm’s entire computer network, which contained valuable and highly sensitive information. They were able to accomplish this feat with no technical tools or skills:
1. Before entering the building, one member of the group called the company’s Human Resource (HR) office and asked for the names of key employees. The office willingly gave out the information without asking any questions.
Procedural Security Defenses 395
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2. As the group walked up to the building one of them pretended to have lost their key code to the door, so a friendly employee let them in. When they entered a secured area on the third floor, they claimed to have misplaced their identity badges so another smil- ing employee opened the door for them.
3. Because these strangers knew that the chief financial officer (CFO) was out of town due to his voicemail greeting message, they walked unchallenged into his office and gathered information from his unprotected computer. They also dug through trash receptacles and retrieved useful documents. A janitor was stopped and asked for a garbage pail in which to place these documents so they could be carried out of the building.
4. One of the group’s members then called the company’s Help Desk from the CFO’s office and pretended to be the CFO (they had listened to his voice from his voicemail greeting message and knew how he spoke). The imposter CFO claimed that he desperately needed his password because he had forgotten it and was on his way to an important meeting. The Help Desk gave out the password, and the group left the building with complete access to the network.
This true story illustrates that more than technology is needed to repel attacks.i Social engineering is a means of launching an attack or gathering information for an attack by relying on the weaknesses of individuals. It represents one of the greatest risks that organiza- tions today face. At its core, social engineering relies on an attacker’s clever manipulation of human nature in order to persuade the victim to provide information or take actions. These basic methods of persuasion include ingratiation (flattery or insincerity), conformity (every- one else is doing it), and friendliness. Through these means the attacker attempts to convince the victim that the attacker can be trusted.
Attackers use a variety of techniques in social engineering. An attacker works to “push the envelope” just far enough when prob- ing for information before the victim suspects anything unusual. He generally will not ask for too much information at one time, but instead will gather small amounts (even from several different
victims) in order to maintain the appearance of credibility. Also, the request from the attacker needs to be believable. Slight flattery or flirtation can be helpful to soften up the victim to cooperate. And a smile along with a simple question such as “I’m confused, can you please help me?” often achieves the desired results.
One common form of social engineering is impersonation, which means to create a ficti- tious character and then play out the role of that person on a victim. Common roles that are often impersonated include a repairperson, IT support, a manager, a trusted third party, or a fellow employee. For example, an attacker could impersonate a Help Desk sup- port technician who calls the victim, pretends that there is a problem with the network, and asks her for her password to reset an account. Sometimes attackers will impersonate individuals whose roles are authoritative because victims generally resist saying “no” to anyone in power.
Another common form of social engineering is phishing. Phishing is sending an e-mail or displaying a Web announcement that falsely claims to be from a legitimate sender in an attempt to trick the user into surrendering private information. Users are asked to respond
396 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
to an e-mail or are directed to a Web site where they are requested to update personal infor- mation, such as passwords, credit card numbers, Social Security numbers, bank account numbers, or other information. However, the Web site is actually an imposter site and is set up to steal what information the user enters.
The word phishing is a variation on the word “fishing,” with the idea being that bait is thrown out knowing that while most will ignore it, some will “bite.”
One of the reasons that phishing succeeds is that the e-mails and the fake Web sites appear to be legitimate. Figure 11-2 illustrates a Web site used in phishing. These messages contain the logos, color schemes, and wording used by the legitimate site so that it is difficult to determine that they are fraudulent.
Figure 11-2 Phishing message
© Cengage Learning 2013
Procedural Security Defenses 397
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The average phishing site only exists for 3.8 days to prevent law enforcement agencies from tracking the attackers. In that short period, a phishing attack can net over $50,000.ii
Defenses Against Attacks There are several defenses against these and other types of attacks. They include using security policies, conducting effective security training for users, and implementing physical secu- rity procedures.
Security Policy One means of reducing risks is through a security policy. It is important to know what a security policy is, the security policy cycle and types of policies, and how to implement a security policy.
Definition of Security Policy At its core, a security policy is a document that outlines the protections that should be enacted to ensure that the organization’s assets face minimal risks. At one level, a security policy can be viewed as a set of management statements that defines an organization’s philosophy of how to safeguard its information. At a more techni- cal and detailed level, a security policy can be seen as the rules for computer access combined with detailed plans for carrying them out. In short, a security policy is a written document that states how an organization plans to protect the company’s information technology assets.
There are several terms used to describe the rules that a user follows in an organization. A standard is a collection of requirements specific to the system or procedure that must be met by everyone. For exam- ple, a standard might describe how to secure a computer at home that remotely connects to the organization’s network. A guideline is
a collection of suggestions that should be implemented. A policy is a document that outlines specific requirements or rules that must be met. A policy is considered the correct tool for an organization to use when it is establishing security. This is because a policy applies to a wide range of hardware or software (and is not a standard) and a policy is required (it is not just a guideline).
An organization’s information security policy can serve several functions:
● It can describe an overall intention and direction, formally expressed by the organiza- tion’s management. A security policy is a vehicle for communicating an organization’s information security culture and acceptable information security behavior.
● It details specific risks and explains how to address them, and provides controls that executives can use to direct employee behavior.
● It can help to instill security awareness in the organization’s culture. ● It can help to ensure that employee behavior is directed and monitored to ensure com-
pliance with security requirements.
The Security Policy Cycle Most organizations follow a three-phase cycle in the develop- ment and maintenance of a security policy. The first phase involves a vulnerability assessment
398 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
(also called an impact analysis), which is a systematic evaluation of the exposure of assets to attackers, forces of nature, or any other entity that is a potential harm. Vulnerability assess- ment attempts to identify what needs to be protected (asset identification), what the pressures are against it (threat evaluation), how susceptible the current protection is (vulnerability apprai- sal), what damages could result from the threats (risk assessment), and what to do about it (risk mitigation). The assessment includes:
1. Asset identification. Asset identification determines the items that have a positive economic value and may include data, hardware, personnel, physical assets, and soft- ware. Along with the assets, the attributes of the assets need to be compiled and their relative value. The task of identifying and categorizing assets is known as asset management.
2. Threat evaluation. After the assets have been inventoried and given a relative value, the next step is to determine the threats from threat agents. A threat agent is any person or thing with the power to carry out a threat against an asset.
3. Vulnerability appraisal. After the assets have been inventoried and prioritized, and the threats have been determined, the next question is to determine what current security weaknesses might expose the assets to these threats. This is known as vulnerability appraisal and in effect takes a snapshot of the security of the organization as it now stands.
4. Risk assessment. A risk assessment involves determining the damage that would result from an attack and the likelihood that the vulnerability is a risk to the organization.
5. Risk mitigation. Once the risks are determined and ranked, the final step is to determine what to do about the risks. It is important to recognize that security weaknesses can never be entirely eliminated; some degree of risk must always be assumed.
The second phase of the security policy cycle is to use the information from the vulnerability assessment study to create the policy. A security policy is a document or series of documents that clearly defines the defense mechanisms an organization will employ to keep information secure. It also outlines how the organization will respond to attacks and the duties and responsibilities of its employees for information security.
The final phase is to review the policy for compliance. Because new assets are added continually to an organization, and because new threats can also arise against assets con- tinually, compliance monitoring and evaluation must be conducted regularly. When the results of the monitoring and evaluation phase identifies new assets to be protected or new risks to be addressed, the cycle begins over again. The security policy cycle is illustrated in Figure 11-3.
The security policy cycle is a never-ending process of identifying what needs to be protected, determining how to protect it, and evaluating the protection.
Types of Security Policies Because a security policy is so comprehensive and is often detailed, most organizations choose to break their security policies down into smaller subpo- licies that can easily be referenced. The term security policy then becomes an umbrella term for all of the subpolicies included within it.
Procedural Security Defenses 399
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
There are a number of different types of security policies. An acceptable use policy (AUP) defines the actions users may perform while accessing systems and networking equipment. The users are not limited to employees; it can also include vendors, contractors, or visitors, each with different privileges. AUPs typically cover all computer use, including Internet, e-mail, Web, and password security.
An AUP may include an overview regarding what is covered by this policy. For example, an AUP might include the following:
Internet/intranet/extranet-related systems, including but not limited to computer equipment, software, operating systems, storage media, network accounts provid- ing electronic mail, Web browsing, and FTP, are the property of Organization A. These systems are to be used for business purposes in serving the interests of the company, and of our clients and customers in the course of normal operations.
The AUP usually provides explicit prohibitions regarding security and proprietary information:
Keep passwords secure and do not share accounts. Authorized users are respon- sible for the security of their passwords and accounts. System level passwords should be changed every 30 days; user level passwords should be changed every 45 days.
All computers and laptops should be secured with a password-protected screensaver with the automatic activation feature set at 10 minutes or less, or by logging off when the host is unattended.
Postings by employees from an Organization A e-mail address to newsgroups should contain a disclaimer stating that the opinions expressed are strictly their own and not necessarily those of Organization A, unless posting is in the course of business duties.
Unacceptable use may also be outlined by the AUP, as in the following example:
The following actions are not acceptable ways to use the system:
1. Introduction of malicious programs into the network or server.
2. Revealing your account password to others or allowing use of your account by others. This includes family and other household members when work is being done at home.
Vulnerability assessment
Security policy
Compliance monitoring and evaluation
Figure 11-3 Security policy cycle
© Cengage Learning 2013
400 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
3. Using an Organization A computing asset to actively engage in procuring or transmitting material that is in violation of sexual harassment or hostile workplace laws in the user’s local jurisdiction.
4. Any form of harassment via e-mail, telephone or paging, whether through language, frequency, or size of messages.
5. Unauthorized use, or forging, of e-mail header information.
Another typical policy manages passwords. Although passwords often form the weakest link in information security, they are still the most widely used form of authentication. A password pol- icy should clearly address how passwords are created and managed. In addition to requiring con- trols implemented through technology (such as setting passwords to expire after 90 days and not allowing them to be recycled), a password policy should remind users how to select and use pass- words. For example, it could list the characteristics of weak passwords, as shown in Figure 11-4. The policy should also specify what makes up a strong password, as shown in Figure 11-5.
Many organizations also have a wireless policy. This policy specifies the conditions that wire- less devices must satisfy in order to connect to the organization’s network. Generally all employees, contractors, consultants, temporary and other workers, including any personnel that are affiliated with third parties working on behalf of the organization, are required to follow the policy. The wireless policy applies to all wireless mobile devices that connect to the company’s WLAN and usually require the following:
● Any wireless device must be installed, supported, and maintained by the approved IT support team.
Strong Passwords Have the Following Characteristics
● Contain both uppercase and lowercase characters (a-z, A-Z) ● Have digits and punctuation characters as well as letters (0-9, !@#$%^& *()_+={}[]) ● Are at least 12 characters long ● Are not words in any language, slang, dialect, or jargon ● Are not based on personal information
Figure 11-5 Strong password information
© Cengage Learning 2013
Weak Passwords Have the Following Characteristics
● Contains fewer than 12 characters ● Is a word found in a dictionary (English or foreign) ● Is a common usage word such as names of family, pets, friends, coworkers, fantasy characters, and
so on, or computer terms and names, commands, sites, companies, hardware, and software ● Contains birthdays and other personal information such as addresses and phone numbers ● Contains word or number patterns like qwerty, 123321, and so on ● Contains any of the preceding spelled backward or preceded or followed by a digit (e.g., secret1, 1secret)
Figure 11-4 Weak password information
© Cengage Learning 2013
Procedural Security Defenses 401
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Specific encryption protocols and authentication protocols must be used. ● Devices must maintain a MAC address that can be registered and tracked. ● Wireless devices must not interfere with wireless access deployments maintained by
other support organizations. ● Remote wireless devices that provide direct access to the corporate network must
conform to the home wireless device requirements.
Balancing Trust and Control An effective security policy must carefully balance two key elements: trust and control. First, consider the issue of trust. There are three approaches to trust:
1. Trust everyone all of the time. This is the easiest model to enforce because there are no restrictions. However, this is impractical because it leaves systems vulnerable to attack.
2. Trust no one at any time. This model is the most restrictive, but is also impractical. Few individuals would work for an organization that did not trust its employees.
3. Trust some people some of the time. This approach exercises caution in the amount of trust given. Access is provided as needed with technical controls to ensure the trust is not violated.
The approach of trusting no one at any time is mostly found in high- security government organizations.
A security policy attempts to provide the right amount of trust by balancing no trust and too much trust. It does this by trusting some of the people some of the time and by building trust over time. Deciding on the level of trust may be a delicate matter; too much trust may lead to security problems, while too little trust may make it difficult to find and keep good employees.
Control must also be balanced. Although one of the goals of a security policy is to implement control, deciding on the correct level of that control for a specific policy is not always easy. If policies are too restrictive or too hard to implement and comply with, employees will either ignore them or find a way to circumvent the controls. The security needs and the culture of the organization play a major role when deciding what level of control is appropriate. Because security policies are a balancing act between trust and control, not all users have positive attitudes toward security policies. Users sometimes view security policies as a barrier to their productivity, a way to control their behavior, or requirements that will be difficult to follow and implement. This is particularly true if in the past policies did not exist or were loosely enforced. This makes it necessary to ensure that security policies are properly enforced for all users. There should be steps in place for monitoring compliance through auditing proce- dures, making the necessary responses when a policy is violated, and reporting any incidents.
The purpose of security policies is not to serve as a motivational tool to force users to practice safe security techniques. The results from research have indicated that the specific elements of a security policy do not have an impact on user behavior. Relying on a security policy as the exclusive defense mechanism will not provide adequate security for an organization.
402 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
Awareness and Training Another of the key defenses in security is to train users to be aware of security issues and to follow all necessary security procedures. All computer users in an organization have a shared responsibility to protect the organization’s assets. But it cannot be assumed that all users have the knowledge and skill to protect these assets. Users need training in the importance of securing information, the roles that they play in security, and the steps they need to take to prevent attacks. And because new attacks arise regularly, and new security vulnerabilities are continually being exposed, user aware- ness and training must be ongoing. User awareness is an essential element of security.
All users need continuous training in new security defenses and regular reminders of company security policies and procedures. Opportunities for security education and training can occur:
1. When a new employee is hired
2. After a computer attack has occurred
3. When an employee is promoted or given new responsibilities
4. During an annual departmental retreat
5. When new user software is installed
6. When user hardware is upgraded
Education in an enterprise is not limited to a certain group of employees. Human resource personnel also need to keep abreast of security issues, because in many organizations it is their role to train new employees on all aspects of the organization, including security. Even upper management needs to be aware of the security
threats and attacks that the organization faces, if only to acknowledge the necessity of security in planning, staffing, and budgeting.
One of the challenges of organizational education and training is to understand the traits of learners. Table 11-1 lists general traits of individuals born in the United States since 1946.
Training styles also impact how people learn. A style that works for one person may not be the best for everyone. Most people are taught using a pedagogical approach (from a Greek word meaning to lead a child). However, for adult learners, an andragogical approach (the art of helping an adult learn) is often preferred. Some of the differences between pedagogical and andragogical approaches are summarized in Table 11-2.
It is also important to be mindful of different learning styles. Visual learners learn through taking notes, being at the front of the class, and watching presentations. Auditory learners
Year Born Traits Number in U.S. Population
Prior to 1946 Patriotic, loyal, faith in institutions 75 million
1946–1964 Idealistic, competitive, question authority 80 million
1965–1981 Self-reliant, distrustful of institutions, adaptive to technology 46 million
1982–2000 Pragmatic, globally concerned, computer literate, media savvy 76 million
Table 11-1 Traits of learners
© Cengage Learning 2013
Procedural Security Defenses 403
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
tend to sit in the middle of the class and learn best through lectures and discussions. The third style, kinesthetic, is common among information technology professionals. These students learn through a lab environment or other hands-on approaches. Most people use a combination of learning styles, with one style being dominant.
To aid in knowledge retention, trainers should incorporate all three learning styles and present the same information using different techniques. For example, a course could include a lecture, PowerPoint slides, and an opportunity to work directly with software and replicate what is being taught.
Physical Security One of the most important aspects of security is also the most obvi- ous: securing the devices themselves, such as APs, so that unauthorized users are prohibited from gaining physical access to the equipment. Although securing devices seems obvious, in practice it can be overlooked because so much attention is focused on preventing attackers from reaching a computer electronically. However, ensuring that devices—and the data stored on those devices—cannot be reached physically is equally important. Physical security involves restricting access to the areas in which equipment is located. This includes hard- ware locks, video surveillance, fencing, and cable locks.
Door Locks Hardware door locks in residences generally fall in four categories. Most resi- dences have keyed entry locks (use a key to open the lock from the outside), privacy locks (lock the door but have access to unlock from the outside via a small hole; typically used on bedroom and bathroom doors), patio locks (lock the door from the inside but cannot be unlocked from the outside), and passage locks (latch a door closed yet do not lock; typically used on hall and closet doors). The standard keyed entry lock, shown in Figure 11-6, is the most common type of door lock for keeping out intruders, but its security is minimal. Because it does not automatically lock when the door is closed, a user may mistakenly think they are locking a door by closing it when they are not. Also a thin piece of plastic such as a credit card can sometimes be wedged between the lock and the door casing to open it; or the knob itself can be broken off with a sharp blow, such as by a hammer, and then the door can be opened.
Door locks in commercial buildings are different from residential door locks. For rooms that require enhanced security, a lever coupled with a deadbolt lock is common. This lock extends a solid metal bar into the door frame for extra security as shown in Figure 11-7.
Subject Pedagogical Approach Andragogical Approach
Desire Motivated by external pressures to get good grades or pass on to next grade
Motivated by higher self-esteem, more recognition, desire for better quality of life
Student Dependent upon teacher for all learning Student is self-directed and responsible for own learning
Subject matter Defined by what the teacher wants to give Learning is organized around situations in life or at work
Willingness to learn Students are informed about what they must learn
A change triggers a readiness to learn or students perceive a gap between where they are and where they want to be
Table 11-2 Approaches to training
© Cengage Learning 2013
404 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
Deadbolt locks are much more difficult to defeat than keyed entry locks. The lock cannot be broken from the outside like a preset lock, and the extension of the bar prevents a credit card from being inserted to open it. Deadbolt locks can also require that a key be used to both open and lock the door.
The categories of commercial door locks include storeroom (the out- side is always locked, entry is by key only, and the inside lever is always unlocked), classroom (the outside can be locked or unlocked, and the inside lever is always unlocked), store entry double cylinder (includes a keyed cylinder in both the outside and inside knobs so
that a key in either knob locks or unlocks both at the same time), and communicating double cylinder lock (includes a keyed cylinder in both outside and inside knobs and the key unlocks its own knob independently).
Figure 11-7 Deadbolt lock
© Cengage Learning 2013
+
+
Figure 11-6 Residential keyed entry lock
© Cengage Learning 2013
Procedural Security Defenses 405
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Video Surveillance Monitoring activity with a video camera can also provide a degree of security. Using video cameras to transmit a signal to a specific and limited set of receivers is called closed circuit television (CCTV). CCTV is frequently used for surveillance in areas that require security monitoring such as banks, casinos, airports, and military installations.
Some CCTV cameras are fixed in a single position pointed at a door or a hallway. Other cameras resemble a small dome and allow the security technician to move the camera 360 degrees for a full panoramic view. High-end video surveillance cameras are motion-tracking and will automatically follow any movement.
Fencing Securing a restricted area by erecting a barrier, called fencing, can be an effective method for maintaining security. However, standard chain link fencing offers limited security because it can easily be circumvented by climbing over it or cutting the links. Most modern perimeter security consists of a fence equipped with other deterrents such as those listed in Table 11-3.
Cable Locks For wireless mobile devices, such as portable laptops, netbooks, and tablet devices, it is important to protect them from being stolen. Most portable devices (as well as many expensive computer monitors) have a special steel bracket security slot built into the case. A cable lock can be inserted into the security slot of a portable device and rotated so that the cable lock is secured to the device, while a cable connected to the lock can then be secured to a desk or chair. A cable lock is illustrated in Figure 11-8.
Software can be installed on a mobile device to identify the device’s location in the event that it is stolen. While hiding itself from the attackers, this software can report back the internal IP address, external IP address, nearby routers, and the name of the wireless AP that the device is connected to. Any devices that
have built-in Web cams can also be instructed to take pictures, presumably of the thief.
Technology Description Comments
Anticlimb paint A nontoxic petroleum gel-based paint that is thickly applied and does not harden, making any coated surface very difficult to climb.
Typically used on poles, down-pipes, wall tops, and railings above head height (8 feet or 2.4 meters).
Anticlimb collar Spiked collars that extend horizontally for up to 3 feet (1 meter) from the pole to prevent anyone from climbing; serves as both a practical and visual deterrent.
Used for protecting equipment mounted on poles like CCTV or in areas where climbing a pole can be an easy point of access over a security fence.
Roller barrier Independently rotating large cups (in diameter of 5 inches or 115 millimeters) affixed to the top of a fence prevents the hands of intruders from gripping the top of a fence to climb over it.
Often found around public grounds and schools where a nonaggressive barrier is the important.
Rotating spikes Tri-wing spike collars that rotate around a central spindle; installed at the top of walls, gates or fences.
Can be painted to blend into fencing.
Table 11-3 Fencing deterrents
© Cengage Learning 2013
406 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
Monitoring the Wireless Network It is difficult to manage a network without monitoring what is occurring on the network. Net- work monitoring provides valuable data regarding the current state of the network. This data can be used to establish a baseline of network performance and can also reveal emerging net- work problems. Monitoring a wireless network can best be performed with two sets of tools: utilities designed specifically for WLANs and standard networking monitoring tools.
WLAN Monitoring Tools Virtually all operating systems and many WLAN vendors provide utilities to assist in moni- toring the wireless network. However, the level of information provided by these tools can vary dramatically, with some tools providing only rudimentary information while others give more detailed statistics. The WLAN monitoring tools can be classified as those that operate on the wireless device itself and those that function on the AP.
Mobile Device Utilities Operating systems provide basic tools for monitoring the cur- rent status of the mobile wireless device. Figure 11-9 illustrates the Windows 7 Wireless Network Connection Status window, which shows the signal quality and the number of bytes sent and received over the WLAN. Yet this provides little useable information for a WLAN technician regarding the device.
Some vendors provide supplemental device utilities that give more detailed information. Figure 11-10 shows a utility that provides the number of bytes sent and received grouped by transmission speed. However, this information only covers the wireless device itself and provides no status of the overall wireless network.
Access Point Utilities All APs include the ability to provide information about the status of the wireless LAN. Most enterprise-level APs provide three types of information.
Figure 11-8 Cable lock
© Cengage Learning 2013
Monitoring the Wireless Network 407
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Figure 11-9 Windows 7 Wireless Network Connection Status
© Cengage Learning 2013
Figure 11-10 Transmit and receive statistics displayed in AirConnect
© Cengage Learning 2013
408 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
The first is a record of events (usually called an event log), such as devices associating with the AP. The second type of information is statistics on wireless transmissions, as shown in Figure 11-11. The final type of information regards the connection to the wired network, which is illustrated in Figure 11-12.
Figure 11-12 AP wired network statistics on Cisco AP
© Cengage Learning 2013
Figure 11-11 AP wireless network statistics on Cisco AP
© Cengage Learning 2013
Monitoring the Wireless Network 409
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Another type of log that is important when maintaining a WLAN is a manual log that contains a record all of the activities, problems, solutions, and configuration changes. Wireless system administrators should develop the habit of keeping a regular technical “diary” of the system.
Standard Network Monitoring Tools Although data from devices and APs are beneficial, there are drawbacks to relying solely on these sources of information:
● Data collection. Acquiring data from each AP and each wireless device across the network can be a labor- and time-intensive task.
● Timeliness. Unless a person is constantly monitoring this data, it cannot be used to warn of an impending wireless issue. Rather, the data can only be used after a problem occurs when trying to identify what may have caused it.
● Retention of data. Data gathered from the AP and devices is collected in real time but often there is not always the facility for creating a large repository for that data. Without the ability to retain the data it is difficult to establish a baseline.
A supplement to WLAN monitoring tools are the standard network monitoring tools. The two tools often used are Simple Network Management Protocol and Remote Network Monitoring.
Simple Network Management Protocol (SNMP) One of the most common software tools used for monitoring a network, wired or wireless, is the Simple Network Management Protocol (SNMP). SNMP is a protocol that allows computers and network equipment to gather data about network performance and is part of the TCP/IP protocol suite.
The security vulnerabilities of SNMP are covered in Chapter 10.
In order to use SNMP, a software agent is loaded onto each network device that will be managed using SNMP. Each agent monitors network traffic and stores that information in its management information base (MIB). In addition, a computer with the SNMP manage- ment software, known as the SNMP management station, must also be on the network. The SNMP configuration is shown in Figure 11-13.
The SNMP management station communicates with the software agents on each net- work device and collects the data stored in the MIBs. It then combines all of the data and produces statistics about the network. This data includes transmission or connectiv- ity errors, the number of bytes or data packets sent, and information on IP activity and addressing.
An SNMP alarm can be set using the network statistics. Whenever the network exceeds a predefined limit, it triggers an alert message, called an SNMP trap, which is sent to the man- agement station. The management station then queries all stations for details of that specific
410 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
event, including when and where the event took place and the current status of that network node. An SNMP trap for a wireless network is illustrated in Figure 11-14.
Remote Network Monitoring (RMON) One of the limitations of SNMP is that the devices using SNMP, such as APs and routers, are called upon for dual duty: not only must
Figure 11-14 SNMP trap on Cisco AP
© Cengage Learning 2013
Server A Client 1
Client 2 Client 3 SNMP management station
MIB
Software agent
MIB
Software agent
MIB
Software agent
MIB
Software agent
MIB
Software agent
MIB
Software agent
MIB
Software agent
Access
point
Figure 11-13 Simple Network Management Protocol (SNMP)
© Cengage Learning 2013
Monitoring the Wireless Network 411
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
they perform their regular tasks but they must at the same time monitor the network status. This may place a heavy load upon devices. An alternative is to install dedicated hardware devices that do nothing but gather network statistics and watch for events to occur while still using SNMP.
Remote Network Monitoring (RMON) is an SNMP-based tool that monitors networks using dedicated hardware devices. However, RMON is not a separate TCP/IP protocol; instead, it is part of SNMP. RMON uses SNMP but also incorporates a special database for remote monitoring that includes different groups of statistics. RMON at its core is simply a MIB module that defines a set of objects that are used by the hardware probes that permit advanced network management capabilities.
RMON is actually one of many MIP modules that can make up the SNMP framework.
In a WLAN, the AP can be monitored using RMON. The statistics gathered can contain data measured for both the wired LAN and the wireless LAN interfaces. It can also compare these statistical samples to previously configured thresholds. If the monitored variable crosses a threshold, an event alarm can be generated.
Like SNMP, RMON capabilities are only found on enterprise-level APs.
Maintaining the Wireless Network A wireless network is anything but a static system. Instead, it requires continual modifications, adjustments, and “tweaks.” Often these are the result of feedback from monitoring the network. Although wireless network maintenance can cover many different functions, two important functions are to upgrade the AP firmware and perform RF site tuning.
Upgrade Firmware Firmware, or software that is embedded into hardware to control the device, is the electronic brains of a hardware device. Coded instructions relating to the functions of the device such as data processing algorithms are embedded as integral portions of the internal circuitry. The circuitry on which the firmware resides is EEPROM, or Electrically-Erasable Programmable Read-Only Memory. EEPROM is a nonvolatile storage chip used in computers and other devices. An EEPROM chip can be programmed and erased multiple times electrically. Although EEPROM may be erased and reprogrammed only a certain number of times (ranging from 100,000 to 1,000,000) it can be read an unlimited number of times.
Flash memory typically found in portable USB devices is a later form of EEPROM. EEPROMs are byte-wise writable memories, compared to block-wise writable flash memories. EEPROM chips are larger than flash memory for the same capacity because each EEPROM cell usually needs both a read and a write transistor where flash memory needs only one.
412 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
Virtually all APs use a browser-based management system. The AP settings are contained on HTML-based Web pages stored in the AP that are accessed with a browser on a client device. Unlike Web pages found on the Internet, the AP Web pages are not stored on a file server that can be changed by modifying the HTML code. Instead, the AP Web pages are stored on the AP as firmware in EEPROM circuitry.
As WLAN vendors continue to make improvements and modifications to their AP products, users can keep these devices current with the latest changes by downloading the changes to the APs. Vendors regularly post firmware upgrades on their Internet sites. Updating AP firm- ware generally involves downloading the firmware from vendor’s Web site, selecting the “Upgrade Firmware” or similar option on the AP, and then launching the update. On some older APs the firmware update is a separate file that is downloaded and then the file is located and executed, as shown in Figure 11-15. Most modern APs transparently download the update and then automatically install it.
It is important that the process not be interrupted when a firmware upgrade is taking place. A loss of electrical power may stop the upgrade and make the device unusable.
Enterprise-level APs often have enhanced firmware upgrade capabilities. For example, some APs have three different categories of firmware: system firmware, Web page firmware, and radio firm- ware, as seen in Figure 11-16. These can be upgraded separately if necessary in order to keep all of the APs running the same configuration until a system-wide upgrade can be performed.
Another feature of enterprise-level APs is the ability to distribute upgrades locally. Once a single AP has been upgraded to the latest firmware, this firmware can then be easily distrib- uted to all other APs on the WLAN. The upgraded AP (distribution AP) sends out the update
Figure 11-15 Firmware upgrade with separate file download
© Cengage Learning 2013
Maintaining the Wireless Network 413
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
to all other APs (receiving APs) on the network. Each receiving AP must be configured as follows:
1. The receiving AP must be able to hear the IP multicast issued by the distribution AP. Some network devices such as routers can block multicast messages. This blocking feature must be temporarily turned off at the router.
2. The receiving AP must be set to allow access through a Web browser.
3. If the receiving AP has specific security capabilities enabled, it must contain in its approved user lists a user with the same user name, password, and capabilities as the user who is logged into the distribution AP.
Once the distribution AP has been updated and the receiving APs are correctly configured, the new firmware update can be “pushed” out to all APs on the wireless network. Each AP will automatically reboot after the firmware has been distributed.
RF Site Tuning Once an AP’s firmware has been upgraded, several settings may require adjustment as part of routine maintenance. Sometimes known as RF site tuning, the process of adjusting these settings is similar to conducting some of the steps of a site survey. However, instead of attempting to locate where APs should be mounted, the point of RF site tuning is to readjust the settings of the AP. Important RF site tuning settings include:
● Adjust radio power levels on all APs. Because firmware upgrades may increase the RF coverage areas, it may be necessary to readdress the power settings on all APs.
Figure 11-16 Separate firmware upgrades
© Cengage Learning 2013
414 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
● Adjust channel settings. It may be necessary to restore the channel settings to their orig- inal configuration. Once the original channel plan is restored, channels may be adjusted based on adjacent channels, cellular overlap, and adjusted radio power settings.
● Validate coverage area. As a part of the RF site tuning, it is important to redetermine the perimeter of each APs RF coverage area. Each AP should be measured independently of all other APs and then the overall coverage of the WLAN should be measured. During this process additional configuration adjustments may be required on different APs.
● Modify integrity and throughput. Once the RF coverage cells have been determined, throughput rates and proper cellular overlap may need to be determined and adjusted.
● Document changes. Any changes should be clearly documented. The edited entries should include channel selection, power settings, firmware version, and modulation corrections. Additionally, maps should be created that offer a visual representation of the RF coverage cells and AP placement.
Documentation should be available in both electronic format and hard copy.
Chapter Summary ■ The technical aspects of securing a wireless network are important, but security defenses
go beyond technical solutions. They also involve implementing the correct security procedures within the organization. One of the first steps in implementing procedural security defenses is to manage risk, which is the likelihood that a threat agent will exploit a vulnerability. Risk can never be entirely eliminated; it would cost too much and take too long. Rather, some degree of risk must always be assumed. There are three options when dealing with risks: accept the risk, diminish the risk, or transfer the risk.
■ One of the greatest risks that organizations face today are social engineering attacks. Social engineering is a means of launching an attack or gathering information for an attack by relying on the weaknesses of individuals. It relies on an attacker’s clever manipulation of human nature in order to persuade the victim to provide information or take actions. One common form of social engineering is impersonation, which means to create a fictitious character and then play out the role of that person on a victim. Another common form of social engineering is phishing, or sending an e-mail or displaying a Web announcement that falsely claims to be from a legitimate sender in an attempt to trick the user into surrendering private information.
■ There are several defenses against these attacks. One means of reducing risks is through a security policy. A security policy is a written document that states how an organization plans to protect the company’s information technology assets. An organization’s informa- tion security policy can serve several functions. Most organizations follow a three-phase cycle in the development and maintenance of a security policy. The first phase involves a vulnerability assessment, which is a systematic and methodical evaluation of the exposure of assets to any entity that is a potential harm. The second phase of the security policy cycle is to use the information from the vulnerability assessment study to create the policy. The final phase is to review the policy for compliance. There are a number of different
Chapter Summary 415
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
types of security policies. An acceptable use policy (AUP) defines the actions users may perform while accessing systems and networking equipment. A password policy can clearly address how passwords are created and managed. A wireless policy specifies the conditions that wireless devices must satisfy in order to connect to the organization’s net- work. It necessary to ensure that security policies are properly enforced for all users. There should be steps in place for monitoring compliance through auditing procedures, making the necessary responses when a policy is violated, and reporting any incidents.
■ Another defense is to provide training that encourages users to be aware of security issues and procedures. All computer users in an organization have a shared responsibility to protect the assets of the organization, but it cannot be assumed that all users have the knowledge and skill to protect these assets. Users need training in the importance of securing information, the roles that they play in security, and the steps they need to take to prevent attacks. And because new attacks arise regularly, this training must be ongoing.
■ Securing the devices themselves, such as APs, so that unauthorized users are prohibited from gaining physical access to the equipment is an important security procedure. Door locks in commercial buildings are typically different from residential door locks. For rooms that require enhanced security, a lever coupled with a deadbolt lock is common. This lock extends a solid metal bar into the door frame for extra security. Monitoring activity with a video camera can also provide a degree of security. Using video cameras to transmit a signal to a specific and limited set of receivers is called closed circuit television (CCTV). Securing a restricted area by erecting a barrier, called fencing, can be an effective method for maintaining security. Most modern perimeter security consists of a fence equipped with other deterrents. Most portable devices have a special steel bracket security slot built into the case. A cable lock can be inserted into the security slot of a portable device and rotated so that the cable lock is secured to the device, while a cable connected to the lock can then be secured to a desk or chair.
■ Network monitoring provides valuable data regarding the current state of the network. This data can be used to establish a baseline of network performance and can also reveal emerging network problems. Virtually all operating systems and many WLAN vendors provide utilities to assist in monitoring the wireless network. However, the level of infor- mation provided by these tools can vary dramatically, with some tools providing only rudimentary data while others give more detailed statistics. Most enterprise-level APs provide detailed data such as a record of events, statistics on wireless transmissions, and information regards the connection to the wired network. Although data from the devices and AP are beneficial, there are drawbacks to relying solely on these sources of informa- tion. A supplement to WLAN monitoring tools are the standard network monitoring tools. One of the most common software tools used for monitoring a network, wired or wireless, is the Simple Network Management Protocol (SNMP). SNMP is a protocol that allows computers and network equipment to gather data about network performance and is part of the TCP/IP protocol suite. Remote Network Monitoring (RMON) is an SNMP- based tool that monitors networks using dedicated hardware devices.
■ A WLAN requires continual modifications. Virtually all APs rely on a browser-based management system in which HTML-based Web pages stored in the AP are accessed with a browser on a client device. These AP Web pages are stored on the AP as firmware in EEPROM circuitry. Vendors regularly post firmware upgrades on their Internet sites. Enterprise-level APs often have enhanced firmware upgrade capabilities. Once an AP’s firmware has been upgraded, several settings may require adjustment
416 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
as part of routine maintenance. Sometimes known as RF site tuning, this process is similar to conducting some of the steps of a site survey.
Key Terms acceptable use policy (AUP) A policy that defines the actions users may perform while accessing systems and networking equipment. asset An item that has value. asset management The task of identifying and categorizing assets. cable lock A lock inserted into the security slot of a portable device and the cable connected to the lock that is secured to a desk or chair. closed circuit television (CCTV) Using video cameras to transmit a signal to a specific and limited set of receivers for security. deadbolt lock A door lock that extends a solid metal bar into the door frame for extra security. Electrically-Erasable Programmable Read-Only Memory (EEPROM) The circuitry on which firmware resides. event log A record of events. exploiting Taking advantage of a vulnerability. fencing Securing a restricted area by erecting a barrier. firmware Software that is embedded into hardware to control the device. management information base (MIB) The storage area in which SNMP software agents store their data. password policy A policy that address how passwords are created and managed. phishing Sending an e-mail or displaying a Web announcement that falsely claims to be from a legitimate sender in an attempt to trick the user into surrendering private information. Remote Network Monitoring (RMON) An SNMP-based tool that monitors networks using dedicated hardware devices. RF site tuning Adjustments to a WLAN performed as part of routine maintenance. risk The likelihood that a threat agent will exploit a vulnerability. security policy A written document that states how an organization plans to protect the company’s information technology assets. SNMP management station A computer running SNMP management software. SNMP trap An alert message generated on a network using SNMP. social engineering A means of launching an attack or gathering information for an attack by relying on the weaknesses of individuals. software agent Software used in SNMP to monitor network traffic. threat A type of action that has the potential to cause harm. threat agent A person or element that has the power to carry out a threat. vulnerability A flaw or weakness that allows a threat agent to bypass security. vulnerability assessment (impact analysis) A systematic and methodical evaluation of the exposure of assets to attackers, forces of nature, or any other entity that is a potential harm. wireless policy A policy that specifies the conditions that wireless devices must satisfy in order to connect to the organization’s network.
Key Terms 417
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Review Questions 1. By definition a(n) is a person or thing that has the power to carry out
a threat.
a. vulnerability
b. exploit
c. threat agent
d. risk
2. Each of the following is an option when dealing with risk except .
a. preventing the risk
b. accepting the risk
c. diminishing the risk
d. transfering the risk
3. Which of the following is a social engineering technique that uses flattery on a victim?
a. conformity
b. friendliness
c. fear
d. ingratiation
4. What is the purpose of phishing?
a. to persuade the user to distribute spam
b. to trick the user into surrendering private information
c. to ask the user to contact friends
d. to influence the user to purchase a product
5. Which of the following is not a characteristic of a policy?
a. Policies communicate a unanimous agreement of judgment.
b. Policies may be helpful in the event that it is necessary to prosecute violators.
c. Policies identify what tools and procedures are needed.
d. Policies define appropriate user behavior.
6. Which of the following is not an approach to trust?
a. Trust all people all the time.
b. Trust everyone all of the time.
c. Trust authorized individuals only.
d. Trust some people some of the time.
7. What is a collection of suggestions that should be implemented?
a. policy
b. guideline
418 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
c. standard
d. code
8. Which policy defines the actions users may perform while accessing systems and networking equipment?
a. end user policy
b. Internet use policy
c. user permission policy
d. acceptable use policy
9. Each of the following is a step in a vulnerability assessment except .
a. asset identification
b. vulnerability appraisal
c. risk mitigation
d. risk avoidance
10. What is the primary purpose of a wireless security policy?
a. It specifies the conditions that wireless devices must satisfy in order to connect to the organization’s network.
b. It requires that all mobile devices use a specific operating system.
c. It requests that users implement WPA.
d. It outlines the length and strength of passwords.
11. Which of the following would not be found in a password management and complexity policy?
a. Do not use alphabetic characters.
b. Do not use a password that is a word found in a dictionary.
c. Do not use the name of a pet.
d. Do not use personally identifiable information.
12. For adult learners a(n) approach (the art of helping an adult learn) is often preferred.
a. andragogical
b. institutional
c. proactive
d. pedagogical
13. Each of these occasions is an opportunity for security education and training except .
a. after an employee is terminated
b. after a computer attack has occurred
c. during an annual departmental retreat
d. when new user hardware or software is installed
Review Questions 419
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
14. The residential lock most often used for keeping out intruders is the .
a. privacy lock
b. passage lock
c. keyed entry lock
d. encrypted key lock
15. A lock that extends a solid metal bar into the door frame for extra security is the .
a. deadman’s lock
b. full bar lock
c. deadbolt lock
d. triple bar lock
16. Which of the following cannot be used along with fencing as a security perimeter?
a. vapor barrier
b. rotating spikes
c. roller barrier
d. anti-climb paint
17. A can be used to secure a mobile device.
a. cable lock
b. mobile chain
c. security tab
d. mobile connector
18. Which of the following is not data provided by enterprise-level APs?
a. signal strength to one specific client
b. event log
c. statistics on wireless transmissions
d. statistics on wired transmissions
19. Which of the following is not a drawback to relying only on device and AP tools for monitoring the WLAN?
a. Acquiring data from each AP and each wireless device across the network can be a labor- and time-intensive task.
b. Unless a person is constantly monitoring this data, it cannot be used to warn of an impending wireless issue.
c. Data gathered from the AP and devices is collected in real time, but often organiza- tions lack the facility to store a large repository of data.
d. Device and AP monitoring tools are very expensive to purchase.
420 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
20. is simply a MIB module that defines a set of objects that are used by the hardware probes that permit advanced network management capabilities.
a. Remote Network Monitoring (RMON)
b. Simple Network Management Protocol (SNMP)
c. RADIUS
d. VRK-Packet Analysis
Hands-On Projects
Project 11-1: Viewing SNMP MIBs The contents of an SNMP MIB can illustrate the type of data that it can gather. In this activity you will use the online mibDepot site to view MIBs.
1. Use your Web browser to go to www.mibdepot.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “mibdepot”.
2. Click Single MIB View in the left pane.
3. Scroll down and click Linksys in the right pane. This displays the Linksys MIBs infor- mation. Note the number of Linksys MIBs.
4. In the left pane, click v1&2 MIBs to select the SNMP Version 1 and Version 2 MIBs.
5. In the right pane click LINKSYS-MIB under MIB Name (File Name). This displays a list of the Linksys MIBs.
6. Click Tree under Viewing Mode in the left pane. The MIBs are now categorized by Object Identifier (OID). Each object in a MIB file has an OID associated with it, which is a series of numbers separated by dots that represent where on the MIB “tree” the object is located.
7. Click Text in the left pane to display textual information about the Linksys MIBs. Scroll through the Linksys MIBs and read several of the descriptions. How could this information be useful in troubleshooting?
8. Now look at the Cisco AP MIBs. Click Vendors in the left pane to return to a vendor list.
9. Scroll down and click Cisco Systems in the right pane. How many total Cisco MIB objects listed? How does this compare to the Linksys MIBs?
Because the lengthy list of Cisco products there may be a slight delay as they are listed.
10. In the right pane click Traps.
Hands-On Projects 421
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11. Scroll down to trap 114, which is the trap name broadcastStormStartTrap for the module name AIRESPACE-SWITCHING-MIB. Scroll down to view other wireless traps. Notice the descriptive names assigned to the wireless traps.
12. Click Vendors in the left pane to return to a vendor list.
13. Scroll down and click Cisco Systems in the right pane.
14. Scroll down and click AIRESPACE-SWITCHING-MIB, which is #21.
15. Click Text in the left pane. Read the description for this SNMP trap. What can you tell about it? When would it be invoked?
16. Continue to explore additional traps for wireless products.
17. Close all windows.
Project 11-2: Configuring APs—Firmware Upgrade and WPS The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this project
you will use an online emulator from D-Link to upgrade an AP’s firmware.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. If necessary click the nation most appropriate for you.
3. If you are asked to select the preferred D-Link home page click No, Thank you and then click Continue.
4. Click the Support tab.
5. Click Go next to Emulators.
6. Click DAP-1522.
7. Click DAP-1522 AP Mode. The emulated login screen appears.
8. Click Login without entering a user name or password. An emulated Setup screen displaying what a user would see when configuring an actual DAP-1522 is displayed.
9. Click the MAINTENANCE tab.
10. In the left pane click SYSTEM to display system settings.
11. Although not all APs allow you to display system settings, some APs allow you to perform a backup of the current AP settings. Why would this be important?
12. Locate the Save Configuration button and note that you could click this button to save current settings to a file on a computer’s hard drive.
13. In the left pane click FIRMWARE.
422 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11
14. Note that with this model AP, it would be necessary to visit the vendor’s Web site, locate the firmware upgrade, and download it as a separate file. What is the process for a more modern AP?
15. What would the Browse button do? When would you click the Upload button?
16. Keep this page open in your Web browser for the next project.
Project 11-3: Configuring APs—Event Logs The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this project you will continue to use the online emulator from D-Link that you first
accessed in Project 11-2. In this project, you will use the emulator to access AP event logs.
1. Click the STATUS tab.
2. In the left pane click STATISTICS. What information is provided here?
3. Explain how this information could be useful in monitoring the WLAN for each of these settings:
a. TX Packets
b. RX Packets
c. TX Packets Dropped
d. RX Packets Dropped
e. TX Packets Bytes
f. RX Packets Bytes
4. In the left pane click LOGS.
5. Under LOG OPTIONS, note the different options regarding data that can be capture for the event log. Explain what information would be captured under each of these settings:
a. System Activity
b. Wireless Activity
c. Notice
6. Select the Enable Remote Log checkbox. This can be used if you want to record log events on a remote System Log Server. Why would that be useful?
7. Note the information under LOG DETAILS. Would this information be helpful? Why?
8. Close all windows.
Case Projects
Case Project 11-1: AUP Create your own AUP for the computers and network access for your school or organization. Be sure to cover computer use, Internet surfing, e-mail, Web, and password security. Compare your policies with other students in the class.
Case Projects 423
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Finally, locate the AUP for your school or organization. How does it compare with yours? Which policy is stricter? Why? What changes would you recommend in your school’s or organization’s policy? Write a one-page paper on your findings.
Case Project 11-2: User Awareness and Training What user security awareness and training is available at your school or place of business? How frequently is it performed? It is available online or in person? Is it required? Are the topics up to date? On a scale of 1–10, how would you rate the training? Write a one-page summary.
Case Project 11-3: Risk Management Study Perform an abbreviated risk management study on your personal WLAN or one at your place of business or school. Conduct an asset identification, threat identification, vulnerabil- ity appraisal, risk assessment, and risk mitigation. Under each category list the elements that pertain to your system. What major vulnerabilities did you uncover? How can you mitigate the risks? Write a one-page paper on your analysis.
Case Project 11-4: Wireless Policy Create a wireless use policy that you could recommend for your school or place of business. Be sure to include statements regarding the specific encryption protocols and authentication protocols must be used, MAC addresses, and interference. Then use the Internet to locate three wireless security policies that are used for organizations. Finally locate the wireless policy that is already in place (if one exists). Compare all of the different policies. Which features are common? Which policy statements are the most restrictive? Which are the least restrictive? Write a one-page paper on your findings.
Case Project 11-5: Nautilus IT Consulting A computer technology business called Nautilus IT Consulting (NITC) needs your assistance with one of their clients.
Knight Furniture is a regional retailer that was recently purchased by new owners, who want to create new security policies. Because they have no experience in this area, they have hired NITC to help them.
1. Create a PowerPoint presentation that explains what a security policy is, the security policy cycle, and the steps in developing a security policy. The presentation contain ten slides.
2. Knight Furniture is ready to start developing security policies and wants to create a wireless policy first. Write a one-page draft of a policy for them.
Notes
i. Granger, Sarah, “Social Engineering Fundamentals, Part 1: Hacker Tactics.” Symantec. Dec. 18, 2001. Accessed Mar. 3, 2011. http://www.symantec.com/connect/articles/ social-engineering-fundamentals-part-i-hacker-tactics.
ii. Danchev, Dancho, “Average Online Time for Phishing Sites,” DanchoDanchev’s Blog - Mind Streams of Information Security Knowledge, Jul. 31, 2007, accessed Mar. 3, 2011, http://ddanchev.blogspot.com/2007/07/average-online-time-for-phishing-sites.html.
424 Chapter 11 Managing a Wireless LAN
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
chapter12
Wireless Network Troubleshooting and Optimization
After completing this chapter you should be able to:
• Describe the steps in troubleshooting RF interference • Explain the techniques in troubleshooting a WLAN configuration • List the steps in troubleshooting wireless devices • Describe how to optimize a WLAN
425 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Troubleshooting and diagnosing problems on a wireless LAN is necessary to keep the network operating at peak efficiency. In a recent turnaround, however, WLANs themselves are now being used to diagnose problems on other types of devices, as well as to maintain and monitor these devices.
LG Electronics (LG) recently introduced a range of smart household appliances using LG THINQ™ Technology, which is composed of several elements, including Smart Grid, Smart Diagnosis™, Smart Access, and Smart Adapt. This technology is designed to provide a means by which consumers can manage their homes in a more centralized and convenient way. WLANs are at the core of LG THINQ™ Technol- ogy: all of the smart appliances can communicate with the homeowner’s wireless router. This opens the door for several new features.
Smart Grid uses a smart electric meter to ensure that household appliances use the minimum amount of energy at the least expensive rates. When using a washing machine with Smart Grid technology occupants are given the choice of using Recom- mend Time (which automatically starts the washing at the next most cost-effective time) or Lowest Rate (which turns on the washer when the electricity rates are at their lowest). Users can also override the Smart Grid and wash clothes immediately (although the washing machine will recommend the most energy-efficient cycle). Additional uses for Smart Grid include adjusting the power used by other appliances such as ovens (taking into account the duration of the cooking cycle and varying costs of electricity) and refrigerators (adjusting functions such as defrost time and even displaying the frequency at which the refrigerator door has been opened and closed). And an LCD display on the smart appliance shows daily, weekly, or monthly reports detailing the appliance’s overall levels of energy consumption and associated costs, while daily totals for electricity usage can be accessed via a smartphone or tablet PC over the wireless network. This is all done using a WLAN. For any minor problems, such as a refrigerator door that has been left open, an ice-maker that is turned off, or a washing machine that is off-balance, the appliance alerts the owner with a message on its display panel as well by as sending a message through the WLAN. This alert is then displayed on the consumer’s smartphone or tablet PC.
Of course, there is a downside to all these features. As appliances gain more advanced features, more problems can arise, such as a faulty display or a defective sensor. The usual course of action is to contact the appliance’s customer service repre- sentative, schedule a service call by a repair technician, and then wait for him to arrive in order to diagnose and repair the unit. Then, if a part must be ordered, yet another service call is required, and during the meantime the consumer cannot use the appliance. However, the Smart Diagnosis™ feature helps customer service representatives speed
Real World Wireless
426 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
Even though you’ve spent weeks or months designing and installing a wireless LAN, it is inevitable that something will go wrong and must be fixed. Finding the problem and correcting it—a process known as troubleshooting—is sometimes difficult on a WLAN due to the nature of radio frequency (RF) communications. Troubleshooting often involves a systematic approach along with a good “sixth sense” that is honed by experience. Thus, it is important that wireless network administrators and technicians develop good wireless trouble- shooting skills.
Equally important is the ability to optimize a wireless network so that it works in top form. It’s the rare WLAN that, once configured, requires no future changes. Instead, wireless networks should continually be optimized to fit its users’ changing needs.
In this chapter you will first learn how to troubleshoot WLANs by locating and correct wireless network problems. Next, you will explore the various ways in which a WLAN can be optimized for peak performance.
Troubleshooting a Wireless Network
C W N A
4.2.1. Identify and explain how to solve WLAN implementation chal- lenges using features available in enterprise class WLAN equipment.
The first step in troubleshooting a WLAN is to identify the source of the problem. The many WLAN problem sources can be grouped into three categories: RF interference, WLAN configuration settings, and problems related to the wireless device itself.
up the repair process by troubleshooting mechanical issues over the phone, thus possibly limiting or even eliminating service calls. The homeowner can telephone a customer ser- vice center, where a technician might instruct him to press a sequence of buttons on the appliance. This triggers a series of tones that lets the technician identify the issue and determine how to correct the problem. Consumers can also diagnose appliances at home using a smartphone application. If a service visit is required, the field repairperson can arrive with the correct parts, ensuring that a repair is resolved in a single visit.
Because all of the devices are connected through the WLAN, Smart Access makes it possible for homeowners to also control appliances remotely. Using a smartphone or tablet PC, a user can manage a washing cycle from the office or change his refrigerator temperature while out of town. Alert messages can be sent back to the user at the end of a washing cycle or when a potential issue arises. The Smart Adapt feature allows consumers to download the latest services and technology upgrades for their appli- ances through the WLAN connection. Consumers then can access new preprogrammed instruction sets, as well as updated advanced cycles for washing machines, allowing them to take advantage of these new features without upgrading to new appliances.
Troubleshooting a Wireless Network 427
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
RF Interference One of the main sources of WLAN problems is RF interference. This interference can be a result of external interference or intersymbol interference.
External Interference Many different objects produce unintended and unwanted RF signals that can interfere with a WLAN transmission. Electromagnetic interference (EMI) is an electronic disturbance, either man-made or natural, which causes an undesirable degrading in the performance of electrical equipment. Virtually all electronic devices give off some type of electromagnetic emission as a byproduct of an electrical or magnetic activity. For example, something as simple as the motor in a refrigerator can create EMI that impacts the picture quality on a television. Radio frequency interference (RFI), on the other hand, is any undesirable electrical energy emitted within the frequency range dedicated to RF transmissions.
These unwanted RF signals are called noise. The noise floor is a measure of the total noise from different systems. The noise floor indicates the weakest signal that can be received. For example, if Alice were to stand two feet away from Bob in a quiet room and whisper to him, Bob would normally be able to hear what she says because the total level of unwanted noise (noise floor) would be very low. However, if Alice were to stand two feet away from Bob on an airport tarmac and whisper while an airplane takes off, it is unlikely that Bob could hear Alice because the noise floor would be much higher. The graph in Figure 12-1 shows a noise floor and indicates that any signal must exceed approximately �125 dB in order to be effective.
Figure 12-1 Noise floor
© Cengage Learning 2013
428 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
A spectrum analyzer is a device that scans the RF spectrum and that can locate RFI that causes a high noise floor. Spectrum analyzers usually display the raw and unprocessed signal information such as frequency, voltage, power, period, and the shape of the RF “wave.” The most common spectrum analyzer measurements are modulation, distortion, and noise. Spectrum analyzers are covered in Chapter 8.
There are four categories of external noise interference on a WLAN: narrowband interference, wideband interference, all-band interference, and weather interference.
Narrowband Interference Narrowband interference is usually generated by television, radio, and satellite transmitters. This signal, as its name implies, impacts only a narrow por- tion of the spectrum, leaving most of the band (such as the entire 2.4-GHz band) unaffected. Whereas some types of RF interference are only occasional or sporadic (called intermittent), generally narrowband interference is continual (constant). This is because its source is coming from a transmitter that is continuously sending out a signal. Narrowband interference is often from a signal that is so strong it completely disrupts all communication.
The troubleshooting solution for narrowband interference in a WLAN is to use a spectrum analyzer to determine the affected WLAN channel(s), which all operate at a different frequency. Because narrowband only significantly impacts a narrow portion of the spectrum, often an alternative channel (frequency) can be chosen on which to transmit. Figure 12-2 illustrates narrowband interference on an IEEE 802.11b/g WLAN. Because the interference is centered on channel 6, the solution is to change the channel to either 1 or 11.
Wideband Interference Unlike narrowband interference that only impacts a small portion of the spectrum, wideband interference affects the entire frequency band, such as the entire 2.4-GHz band. Because the entire band is impacted changing to an alternative channel is not a solution. Instead, the only mitigation is to locate the source of the interfering signal and remove it.
Figure 12-2 Narrowband interference
© Cengage Learning 2013
Troubleshooting a Wireless Network 429
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
All-band Interference Instead of transmitting on just one frequency, frequency-hopping spread spectrum (FHSS) uses a range of frequencies that change during the transmission. With FHSS, a short burst is transmitted at one frequency, then a short burst is transmitted at another frequency, and so on, until the entire transmission is completed. Competing tech- nologies that use FHSS to “hop” across the spectrum, such as 2.4 GHz, can create all-band interference (it covers all bands of the RF spectrum) with IEEE 802.11 WLANs.
Several solutions have been proposed for these two technologies to work together. These include:
● Change the RF spectrum used. A change to rules governing the frequency spectrum would require the FHSS technology to hop over only part of the band, leaving the other part clear for WLANs.
● Modify power levels. Because FHSS devices transmit typically over short distances, lowering or using variable power would lessen the interference impact on WLANs.
● Add switching software. Software could be installed that allows a device with both WLAN and FHSS installed to switch between the two modes. However, both devices could not transmit simultaneously.
● Change the MAC layer. The media access control (MAC) layer is an attractive place to focus attention on improving the coexistence between FHSS technologies and WLANs because it is where such techniques as carrier sense multiple access/collision avoidance (CSMA/CA) and data rates are determined. Although changes here would be relatively inexpensive to implement, not all problems can be solved in the MAC layer. For example, the MAC layer has no control over timing under some conditions, such as when a WLAN device is required to respond with an ACK after successfully receiving a packet.
● Change PHY layer. Using special signal-processing techniques in the PHY layer can permit the FHSS signal be sent at times when WLANs are silent. However, PHY-layer techniques tend to directly affect system costs more than MAC-layer techniques.
None of these proposals have received widespread support and all-band interference between FHSS devices and WLANs can be a problem. The only solutions are to not use the two devices together or migrate to a WLAN that uses another RF frequency spectrum, such as moving from 802.11b/g (2.4 GHz) to 802.11a/n (5 GHz).
Weather Interference Weather can have an impact on wireless transmissions outdoors. Over a long distance an RF signal may move through different atmospheric conditions. For example, it may start out in a relatively transparent condition, such as in bright sunshine, then go through a much denser condition, such as cold damp air. When an RF signal moves from one medium to another of a different density the signal actually bends instead of traveling in a straight line. This is known as refraction.
Refraction is covered in Chapter 3.
430 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
There is little that can be done regarding the impact of weather on RF interference.
In addition to affecting RF signals, severe weather can have other impacts on wireless networks as well. For example, lightning can strike anten- nas or other equipment, wind can shift antennas, and rain can impact frayed cabling and loose connectors.
RF Interference Troubleshooting One of the most important steps in troubleshooting RF interference is to understand the truths and myths regarding RF interference. Table 12-1 lists some of these truths and myths.
The following best practices should be considered in order to reduce RF interference:
● Be wary of noise and recognize situations where noise may impact transmissions. RF noise may come from many different sources, such as high frequency digital products, forms of other radio communications, and even solar activity. In addition, outdoor antennas are virtually everywhere, including the sides of buildings, water towers, billboards, chimneys, church steeples, and even disguised as trees. Many sources of interference may not be obvious.
Myth Truth
“The only significant interference problems are from other IEEE 802.11 networks.”
While other 802.11 WLANs can cause network interference, the overwhelming majority of RF interference is caused by other devices. These include microwave ovens, cordless phones, FHSS devices, wireless video cameras, outdoor microwave links, and wireless game controllers. In addition, these devices may cause other problems that are difficult to detect, such as making the WLAN use lower data transmission rates due to the interference.
“The network seems to be working OK so there must not be any RF interference.”
Because the IEEE 802.11 protocol is designed to resist interference to a degree, it may not always be apparent that RF interference is impacting the network. For example, when a wireless device senses an interference burst occurring before it has started its own transmission, it will wait on transmitting until the interference is finished. Yet if the interference burst starts in the middle of a transmission, so that an acknowledgement packet is not received, it will cause the transmitter to resend the entire packet. This can reduce the throughput of a WLAN and can be difficult to diagnose.
“We already used a spectrum analyzer and found all of the sources of interference before we installed the WLAN.”
Wideband and all-band RF interference is intermittent in nature, often occurring only at certain times of day or on specific days of the week. And, interference that was not present when the network was installed could now be present.
“I can look for any RF interference issues with my free open-source packet sniffer.”
A protocol analyzer captures packets to decode and analyze its contents and can be used to detect and diagnose network problems such as addressing errors and protocol configuration mistakes. However, they cannot detect RF interference. A spectrum analyzer scans the RF spectrum (2.4 GHz or 5 GHz for WLANs) and can locate potential sources of interference.
“There is no RF interference at 5 GHz so we’ll install IEEE 802.11a/n WLANs to eliminate any problems.”
While fewer devices currently operate at 5 GHz, this is beginning to change. Just as new 2.4-GHz devices were introduced in order to avoid the interference problems with 900 MHz, the same is happening with 5 GHz. Some devices that already exist at 5 GHz include cordless phones, radar, perimeter sensors, and digital satellite devices.
Table 12-1 Myths and truths about RF interference
© Cengage Learning 2013
Troubleshooting a Wireless Network 431
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Maintain a system operating margin. The system operating margin (SOM, also called the fade margin) is the difference measured in decibels between the received signal level and the signal level that is required by that radio to assure the transmission can be decoded without errors. SOM is the difference between the signal received and the radio’s specified receiver sensitivity. For outdoor transmissions a SOM of no less than 10 dB in good weather conditions will protect against weather and other RF interference.
SOM is covered in Chapter 4.
● Maintain proper power. For outdoor installations with a clear path, the radio signals attenuate with the square of distance, so that doubling the range requires a four-fold increase in power. Doubling the distance increases path loss by 6 dB. For indoor installations, doubling the distance increases path loss by 9 dB. It is important that the proper power be used to generate the signal.
● Separate antennas as much as possible. Antennas increase the effective power by focusing the radiated energy in the desired direction. Using the correct antenna not only focuses power into the desired area but it also reduces the amount of power broadcast into areas where it is not needed. However, not all antennas for other installations have been correctly selected. It is good to install antennas as high as possible and far away from other antennas.
Intersymbol Interference When an RF signal is transmitted, it does not take a direct path straight to the receiver. Instead, multiple copies of the signal are transmitted, and these various copies may bounce off objects in the area before reaching the receiver at slightly dif- ferent times having traveled along different paths, a phenomenon known as multipath. Although the difference between the signals, called delay spread, is so small as to be measured in nanoseconds, it can still affect reception because these copies are “added” to the primary signal. Known as intersymbol interference (ISI), this adding of signals to the primary signal can result in downfade, corruption, or nulling.
Multipath and delay spread are covered in Chapter 3, and ISI is discussed in Chapter 5.
There is no solution for eliminating ISI, since it is a natural part of RF transmissions. However, there are two ways to reduce its impact. The first way is to switch to a WLAN that supports multiple-input multiple-output (MIMO). A wireless system that uses a single antenna, called a single-input single-output (SISO) system, is characterized by having only one radio with the supporting infrastructure (a radio chain). MIMO wireless systems use multiple antennas. By sending the same transmission out from different antennas in a MIMO system will cause the signals to take different paths. These different paths improve reliability because it is unlikely that all of the paths will be degraded in the same way. Thus, switching to a WLAN that uses MIMO—such as IEEE 802.11a/n—may reduce ISI.
432 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
SISO and MIMO are covered in Chapter 4, while OFDM is discussed in Chapter 5.
The second way to reduce the impact of ISI is use the correct antenna. For outdoor settings, a highly-directional antenna that sends a narrowly focused signal beam long distances may help reduce ISI.
Highly-directional antennas are discussed in Chapter 4.
WLAN Configuration Another category of problem sources of WLANs are the WLAN configuration settings. These include cochannel interference, adjacent-channel interference, power settings, system throughput, and incorrect AP configuration settings.
Cochannel Interference WLANs that are in the same area can be a source of interfer- ence. Cochannel interference can result when two or more networks attempt to use the same channel. This is because if all of the APs were set to the same channel number then it would result in reduced throughput by forcing each station to wait a longer period of time for their turn to transmit. The solution for cochannel interference is first to use an application to identify if any other WLANs are in the area and on which channel they are transmitting. Then the channel number of the WLAN can be changed to one that is not being used.
An application such as Vistumbler, covered in Project 3-2, or in SSIDer, used in Project 3-4, can identify any nearby WLANs and their channel numbers.
However, free channels may not always be available. On an IEEE 802.11b/g network in the 2.4-GHz frequency, there are only three nonoverlapping 20-MHz channels: 1, 6, and 11. If cochannel interference exists with no free channels available, moving to a protocol with more non-overlapping channels may be the only option. IEEE 802.11a and 802.11n, both operating in the 5-GHz frequency, have 8 and 23 nonoverlapping channels, respectively.
Adjacent Channel Interference It is not uncommon for a transmission on one channel to encroach upon another channel. For example, when using IEEE 802.11b/g in the 2.4-GHz frequency channels are designed to be þ/�11 MHz from the channel center frequency, yet some of the transmission may still encroach onto other frequencies up to 30 MHz from the channel center. This results in the channel actually consuming five over- lapping channels so that, for example, transmitting on channel 6 may cause interference on channels 5 and 7 as well as limited interference on channels 4 and 8. When a WLAN is transmitting on one channel (such as channel 1) and a nearby WLAN is transmitting on an adjacent channel (channel 2) this may cause what is known as adjacent channel interference.
Troubleshooting a Wireless Network 433
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The adjacent channel interference by extraneous power from a signal in an adjacent channel is often the result of inadequate filtering or improper tuning.
The solution for adjacent channel interference is the same as that with cochannel interference, namely identify the channel that is being used by a nearby WLAN and switch to a different channel.
It is not recommended that adjacent channels be used in WLANs. For example, with 802.11b/g only the nonoverlapping channels of 1, 6, and 11 should be used.
Incorrect Power Settings In Figure 12-3, the AP is transmitting at 100 milliwatts (mW). Laptops A, B, and C are all within its coverage area and also can transmit at 100 mW. However, Smartphone 1, which can transmit only at 40mW, is outside of the coverage area because it is too far away and thus cannot detect the AP’s signal. To solve this problem, a wireless LAN administrator decides to replace the AP with a more powerful unit that can transmit at 200 mW, thus increasing the coverage area to include Smartphone 1, as depicted in Figure 12-4. Smartphone 1 can now pick up the AP’s signal and recognize that the WLAN exists (when it could not before). However, whenever it attempts to transmit to the AP, its transmission is never recognized. In addition, Laptops A, B, and C also are suddenly unable to send to the AP, although they can receive its transmissions. What has just happened?
Laptop A
Laptop B
Edge of
coverage
area
100 mW
100 mW
100 mW
Smartphone 1
40 mW
Transmitting 100 mW
Access point
100 mW
Laptop C
Figure 12-3 100 mW AP
© Cengage Learning 2013
434 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
By replacing the 100-mW AP with a stronger 200-mW AP, the wireless LAN administrator forgot a fundamental rule: an AP should not have an output power level higher than the output power level of the wireless device. In Figure 12-4, the 200-mW AP did extend the coverage area but it also exceeded the power level of all the devices. In a WLAN, the output power of the AP must be matched to that of the lowest-powered mobile device.
In this example, instead of replacing the 100-mW AP with a stronger 200-mW AP the wireless LAN administrator should have installed an antenna that would amplify and direct the signal towards Smart- phone 1 as well as select an AP with a lower output power level.
Troubleshooting incorrect power settings can be accomplished by using a spectrum analyzer. When positioned near the client device frames that are transmitted and read by the spectrum analyzer should appear normal. However, when standing next to the AP frames that are received from a station with a mismatched power setting will appear corrupted. The solution is to change the output power level of the WLAN so that the AP matches the lowest-powered device.
System Throughput Problems While the data rate is the theoretical maximum rated speed of a network, the throughput is the measure of how much actual data can be sent per unit of time across a network. Throughput is often used to measure the amount of data actually sent across a network in a “real world” setting. If two 802.11 devices are 30 feet (10 meters) apart the throughput may only be 5.5 Mbps.
When a WLAN is acting “sluggishly” that could be the result of several different influences and may not always indicate a malfunctioning system. Before attempting to reconfigure
Smartphone 1
40 mW
Laptop A
100 mW
Laptop B
100 mW
Laptop C
100 mW
200 mW
Access point
Edge of coverage area
Figure 12-4 200 mW AP
© Cengage Learning 2013
Troubleshooting a Wireless Network 435
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
devices so as to troubleshoot slow system throughput, the first step should be to review the many factors that can influence WLAN transmission speed. These factors include:
● AP processor speed ● Distance from the AP ● Implementing security solutions (WPA and WPA2) ● Number of users associated with an AP ● Packet size ● Request to send/clear to send (RTS/CTS) protocol ● Types of RF interference ● Using Point Coordination Function (PCF) protocol
Any one or a combination of these factors can influence system throughput. A good trouble- shooting approach is to first determine if all devices are experiencing the problem or only a single device. Next, identify the potential causes that may have the least impact on the system if they are changed. For example, the AP processor speed can only be improved by purchasing and installing a new AP, which is an expensive and time-consuming option. However, turning off the RTS/CTS protocol is a simple solution that may result in higher throughput.
AP Configuration Settings Often WLAN problems are the result of incorrect or incompatible AP settings with other devices. One way in which to troubleshoot these problems is to watch the external light emitting diodes (LEDs) that are present on most APs. The number of lights may range anywhere from three to six, show different colors, and per- form different functions (blink, solid, etc.) to indicate the AP status. Table 12-2 illustrates typical information that can be shown through AP LED status lights.
One of the common causes of lost connectivity is mismatched settings between the AP and the wireless devices. If there is no connectivity the following two areas are often the primary sources of the problem:
● SSID. Wireless clients attempting to associate with the AP must use the same SSID as the AP. If a client device’s SSID does not match the SSID of an AP in radio range the client device will not associate.
LED Light Activity Description
Power Solid amber The AP is starting up after being powered on.
Power Blinking amber Firmware is upgrading.
2.4-GHz mode Blinking green Data is being transmitted over WLAN.
2.4-GHz mode Off The IEEE 802.11n is not using 2.4 GHz.
Internet Blinking amber Initializing connection and obtaining an IP address.
LAN Solid green The LAN port has detected a 100-Mbps link with an attached device.
LAN Blinking green Data is being transmitted at 100 Mbps.
Table 12-2 Typical AP LED status lights
© Cengage Learning 2013
436 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
● Security settings. Wireless clients attempting to authenticate with the AP must support the same security options configured in the AP, such as MAC address authentication, preshared key (PSK) and 802.1X settings.
In extreme circumstances it may be necessary to delete the current AP configuration and return all of the settings to the factory default settings so the configuration process can start all over again.
Wireless Device Troubleshooting The last category of problem sources of WLANs involves the wireless mobile devices. Potential problems include the device location and resolving connectivity issues.
Device Location Two problems are associated with the location of the wireless device: near/far and hidden nodes.
Near/Far In Figure 12-5, Laptop A is transmitting at 100 mW and is located only 5 feet (1.5 meters) away from the AP, while Laptop B is separated from the AP by a distance of 50 feet (15.2 meters) and is transmitting at only 10 mW. The stronger signal from Laptop A “drowns out” the weaker signal from Laptop B. This is known as the near/far transmission problem.
Laptop A
Laptop B
Access point
10 mW power
100 mW power
5 feet
50 feet
Figure 12-5 Near/far
© Cengage Learning 2013
Troubleshooting a Wireless Network 437
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Identifying a device that is a victim of the near/far transmission problem can be accomplished by using a wireless protocol analyzer to determine the signal strength. There are different solutions to near/far transmission problems:
● Move the device with the stronger transmission power farther away from the AP ● Reduce the transmission power of devices that are closer to the AP ● Increase the transmission power of devices that are farther away from the AP
Near/far transmission problems are not common due to the nature of CSMA/CA.
Hidden Nodes In a WLAN all stations need to be able to detect transmissions from all other stations at all times. However, in a wireless environment, a station might be in range of the AP but not be in range of all other stations. For example, wireless Devices 1 and 2 may be within range of the AP but not within range of each other. If Device 2 “listens” and hears no traffic, it might assume no transmissions are taking place, while actually Device 1 is already transmitting, resulting in a collision. This is known as the hidden node problem.
Hidden nodes are covered in Chapter 6.
There are several ways to resolve a hidden node problem:
● Move the hidden node device ● Remove any physical obstacles that may be interfering with devices communicating
with each other ● Increase the client device’s power level ● Add an additional AP to the WLAN
Resolving Connectivity Issues A failure to connect to an existing network or a con- nection with poor throughput often is the result of an incorrect configuration on the wireless device. Resolving these problems on a device using Microsoft Windows involves knowing how a Windows device connects to a WLAN, using the available Windows wireless tools, and considering a list of troubleshooting steps.
Windows Connection Process When a wireless device using Windows attempts to connect to a WLAN, it goes through a multistep process. In general the process is:
1. Scan for wireless networks. The wireless client network adapter performs a scan (about once every 60 seconds) for the available wireless networks within range. When scanning, the wireless network adapter sends a series of Probe Request frames and the APs that receive the frames respond with a Beacon frame that contains the capabilities of the wireless AP, such as the supported speeds, SSID, and security options.
438 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
Dual band wireless adapters are common in laptops, tablets, and smartphones. Windows defaults to a channel search that starts with the 5-GHz channel 36 and continues searching through all of the 5-GHz channels that the client is capable of using. If no 5-GHz AP is found, it will next search the 2.4 GHz starting at channel 1. This
means that unless the Windows default is changed or the user has chosen a third party utility to set the preference to 2.4 GHz, the device will always first try to associate to a 5-GHz AP. Apple devices likewise search 5 GHz first.
2. Choose an AP. After receiving the frames from the AP, the wireless device chooses a wireless AP with which it will attempt to authenticate and associate. The decision of which AP to choose is based on the following factors:
● Wireless AP capabilities. Based on the AP capabilities in the Beacon frame, the wireless device must be able to support those capabilities. If the device’s abilities do not match those of the AP, then the device cannot choose that AP. For exam- ple, if the AP is configured to only support Wi-Fi Protected Access 2 (WPA2) while the wireless NIC adapter on the device can only support WPA, then AP capabilities do not match those of the device and the device cannot associate with that AP.
● Preferred networks. Users can create a list of preferred wireless networks based on SSID. If the device receives Beacon frames from multiple APs that are in the pre- ferred list, then the most preferred wireless network (the highest one in the list) is chosen. If the SSID of the received Beacon frames does not match a preferred network, Windows prompts the user with a message in the notification area of the Windows desktop giving them the option to connect to the new wireless network.
● Signal strength. The wireless network adapter of the wireless client chooses the AP with the highest signal strength for the wireless network name that is highest in the preferred list.
3. Authenticate. After choosing the AP with which to connect, the device and AP perform authentication. The type of authentication depends on the security capabilities of the wire- less AP and how the wireless device has been configured to authenticate with the AP.
4. Associate. After authentication has successfully completed, the wireless network adapter and the wireless AP exchange a series of messages to create an association.
5. Obtain an IP address. The final step is for the wireless device to obtain an IP address. Depending upon the configuration this can be accomplished in several ways:
● Manual addressing. The device can be configured manually with a static IP address that allows the device to communicate with other computers on the network and to reach the Internet.
● DHCP addressing. The device may be configured to use the Dynamic Host Config- uration Protocol (DHCP) to request an IP address.
● APIPA addressing. If the wireless device is configured for DHCP yet no DHCP server is active, then Windows assigns an Automatic Private IP Addressing (APIPA) address that begins with the IP range 169.254.x.x. If an APIPA address is assigned, the wireless device may not be able to reach other devices on the network and will not be able to reach the Internet. If an APIPA address is assigned to a wireless
Troubleshooting a Wireless Network 439
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
device, Windows displays “Limited or no connectivity” for the status of the wireless connection.
Because the 5-GHz spectrum is less crowded and can provide higher data rates, many organizations want to direct devices that have dual band wireless adapters away from connecting to a slower 2.4 GHz 802.11b/g WLAN to a faster 5 GHz 802.11a/n network. One way to do this is to take advantage of a new technology available in some
APs called band steering: when a dual band device sends a probe request frame to the AP on the 5-GHz spectrum the AP will temporarily “hide” the 2.4-GHz band so it appears that the 5 GHz is the only connection available. Another way is to add “slow” and “fast” to the SSID names (such as “Network-Slow” and “Network-Fast”) to persuade users to manually choose the faster network.
Microsoft Windows Tools The Microsoft Windows operating system provides tools that can be used to view the wireless connection as well as make changes. Windows 7 has several separate tools. The first tool is the Network and Sharing Center, shown in Figure 12-6, which provides information regarding all active network connections as well as links to other tools.
Figure 12-6 Windows Network and Sharing Center
© Cengage Learning 2013
440 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
Another tool is the Wireless Network Connection Status dialog box, shown in Figure 12-7. This dialog box provides an overview of the current status by displaying the Layer 3 connec- tivity status (for both IPv4 and IPv6), the media state, the SSID being used, the length of time the connection has been active, the negotiated connection speed, and the signal quality. The Details button gives more information including the Layer 2 physical address, the Layer 3 logical address, dynamic addressing parameters (DHCP), and name resolution items. The Network Connection Details dialog box is shown in Figure 12-8.
The third tool is the Wireless Network Connection Properties dialog box, shown in Figure 12-9. This tool provides comprehensive information and the ability to adjust configurations. Important areas of this dialog box include:
● Networking tab. The information on this tab shows which wireless network adapter is being used for this connection. If multiple adapters are installed, they can be changed.
● Sharing tab. This tab includes settings for a type of configuration known as Internet Connection Sharing (ICS) that allows other users on the network to access resources through this computer’s connection.
● This connection uses the following items list. This list, on the Networking tab, displays different clients, services, and protocols that are currently available for this connection. By deselecting an item in this list, and then clicking the appropriate button below the list, users can install or uninstall network clients, network services, and network pro- tocols. Users can also view the client, service, or protocol properties for a selected item
Figure 12-7 Wireless Network Connection Status
© Cengage Learning 2013
Troubleshooting a Wireless Network 441
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Figure 12-8 Network Connection Details
© Cengage Learning 2013
Figure 12-9 Wireless Network Connection Properties
© Cengage Learning 2013
442 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
by clicking the Properties button. (If the Properties button is gray, a Properties page is not available for that item.) Users can also access the network adapters’ hardware configuration property pages.
The network adapters’ hardware configuration property pages are the same pages that can be accessed from the Device Manager.
The Windows 8 operating system handles wireless networking differently than Windows 7. It uses a simpler and more integrated radio and connection management interface. The Windows 8 network settings allows users to turn on and off installed wireless radios, such as IEEE 802.11 devices, as well as other types of devices individually or all at the same time. Windows 8 also supports native radio management to eliminate conflicts between applications, and allows users to prioritize WLANs over other types of wireless networks, such as telephone broadband. Because WLANs are typically faster without data limitations imposed by the carriers, when con- necting to a WLAN, Windows 8 will automatically disconnect a device from the user’s mobile broadband network and power down the mobile broadband device to increase battery life. Windows 8 also includes support for different WLAN hotspot authentication types, including WISPr (Wireless Internet Service Provider roaming), EAP-SIM/AKA/AKA Prime, and EAP-TTLS.
Microsoft also claims that, when resuming a device from standby, Windows 8 will reconnect faster to a WLAN networks by optimizing operations in the networking stack as well as providing existing con- nection information. In fact, Microsoft says that a Windows 8 device will reconnect to a WLAN in 1 second as opposed to 12 seconds when using Windows 7.
Another Windows tool available in all versions of Windows, the Event Viewer, allows for log files to be examined. A log is simply a record of events. Logs are composed of log entries, with each entry containing information related to a specific event. Logs have been used in informa- tion technology since its inception, primarily for troubleshooting problems. Logs have now evolved to contain information related to many different types of events within hosts and net- works. Log files can often be analyzed to determine the underlying cause of wireless issues.
The types of information that can be recorded in a log might include the date and time of the event, a description of the event, its status, error codes, service name, and user or system that was responsible for launching the event.
Troubleshooting Steps If there is a problem making a wireless connection, the following list of troubleshooting steps may be considered:
● Incompatible IEEE 802.11 standards. Although some APs can support more than one of the IEEE 802.11a/b/g/n standards, not all APs support multiple standards. It is possible for a mismatch to take place between the AP and a wireless device: for example, an 802.11a AP will not connect to a wireless device with 802.11b/g wireless adapter cards.
● Mismatched authentication methods. The wireless device will not be able to authenticate if it does not use the same authentication method as the AP.
Troubleshooting a Wireless Network 443
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Mismatched preshared key. When using PSK authentication, the key value must be correctly entered in the device to match the key on the AP.
● Conflict between operating system configuration and a third-party configuration tool. Most operating systems have a wireless configuration tool that is enabled by default, yet it may conflict with a network adapter vendor’s configuration tool. This results in both tools sending their settings to the wireless network adapter, which may result in configuration mismatches. One of the tools must be turned off.
● Incorrect MAC address. If the AP is using MAC address filtering, the MAC address of each wireless device must be entered correctly.
● Disabled wireless adapter. Many laptops and tablets have either a switch or a hot-key set- ting that enables and disables the wireless adapter. The switch may have accidentally been turned off or the user may have erroneously pressed the key sequence to turn off the adapter.
● Legacy wireless NIC driver. Older wireless NIC drivers tend to be poorly written or fail to take advantage of new enhancements. Simply updating a driver can often solve a wireless connection problem.
● Outdated profiles. The configuration settings for a WLAN can be stored so that whenever the wireless device comes into the range of the AP, a connection is established, as illustrated in Figure 12-10. If the network configuration changes, as often happens, profiles will be outdated.
Figure 12-10 Network profiles
© Cengage Learning 2013
444 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
Another common problem is that the wireless device intermittently disconnects from the AP. If this occurs, check the following list of possible causes and apply these troubleshooting steps:
● Incompatible 802.1X authentication. If 802.1X authentication is enabled, yet does not properly complete, the connection is then dropped. This typically happens three minutes after the connection has been made using open system authentication.
● Duplicate SSID. If the same SSID is used on another AP, then both APs are considered to be part of the same network and must share the same security settings. However, in instances where a default SSID has not been changed, it is possible that two separate devices not intended to be part of the same WLAN (such as two devices in the same apartment building) are broadcasting the same SSID. The wireless device may then choose the remote AP of another wireless network instead of the local AP. Because that remote device will not be configured for the same authentication method and keys of the main wireless network, the wireless device will not be able to connect to it.
To determine if the SSID is being duplicated by another wireless network that is within range, turn off the local AP and use a wireless protocol analyzer or another computer to scan for avail- able wireless networks. If the local SSID appears in the list of available networks when the AP is turned off, then there is a
duplicate wireless network name. Reconfigure the local wireless AP for a unique SSID. Duplicate SSIDs are generally the result of the default SSID being used on an AP, which may also be a security vulnerability.
● Interference from nontraditional devices. As wireless technology is incorporated into other types of devices besides laptop and tablet computers, these devices may interfere with a “standard” WLAN. For example, game consoles and streaming television Internet devices today often have WLAN capabilities built in. It is important not to overlook any of these devices as a source of potential interference.
WLAN Optimization Unlike with wired networks, a variety of techniques can be used to optimize a WLAN. These help to ensure that the wireless network is adequately providing services for its users. WLAN optimization includes optimizing the channel, the AP, and the wireless devices.
Channel Optimization Because most WLANs are designed so that users can freely move through buildings or large areas while continuing to maintain a connection, optimizing the channel for roaming is a primary concern. A wireless device can only roam from the coverage area of one AP to another AP if the SSID and security settings are identical, although the channel number will be different to avoid cochannel and adjacent-channel interference. As a wireless device begins to move farther away from the AP to which it is associated, the device will monitor RF signal strength or packet error rates to determine if it should search for a new AP. Generally, when the signal strength drops to �75 dB or packet error rates exceed 8 percent, a wireless device will begin looking for another AP.
WLAN Optimization 445
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Roaming is covered in Chapter 6.
Ensuring smooth roaming is primarily based on cell overlap. Cell overlap is the area between two APs, as shown in Figure 12-11, in which a wireless device begins to search for a new AP with which to associate. Recommended settings for cell overlap vary. Some vendors recom- mend an overlap of 20 percent when using 802.11b/g and 15 percent when using 802.11a/n is desirable. Other vendors use dB instead of percentage and recommend 10 dBm of overlap, which means that when a device is in this cell overlap area and begins the handoff process the new AP should have a signal that is 10 dB stronger than the old AP.
Another consideration for channel optimization has to do with areas in which client devices may, on occasion, exceed the normal expectations. In a typical office setting, a site survey may indicate that AP should be deployed for 2,500 to 5,000 square feet with a signal of �67 dBm supporting a maximum of 20 users per cell. That would mean that a density of one user every 120 square feet would yield a minimum acceptable signal of �67 dBm. However, what about in a high-density environment, such as a lecture hall or auditorium on a school campus? In these areas, users are clustered very close together in seating areas, with intervening open spaces such as aisle ways, stages, and podiums that are much less occupied. Each student might use multiple wireless devices (smartphones, tablets, laptops, etc.) for performing a wide range of different tasks. All of these tasks require different amounts of bandwidth, as listed in Table 12-3. How can adequate throughput be achieved for these high-density areas?
The solution is to optimize the channel by installing high-density WLANs. These wireless networks, using several APs, have several characteristics:
● More APs are clustered closer together in order to provide the resources to users. ● APs are positioned in different locations, such as floor mounted or high on walls.
Cell overlap
Access point
Laptop Laptop
Access point
Laptop Laptop
File Server PC
Figure 12-11 Cell overlap
© Cengage Learning 2013
446 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
● Newer standards are utilized to maximize throughput, as illustrated in Table 12-4. ● Older standards such as IEEE 802.11b are not implemented due to their impact on
throughput.
Access Point Optimization Steps for optimizing APs include:
● Never accept the default configuration of an AP. Always configure it for a unique SSID, a channel to minimize cochannel and adjacent-channel interference, and the highest level of security authentication and encryption settings.
● Install lightweight APs to minimize the total cost of ownership (TCO). ● Configure wireless VLANs for additional security.
Task Bandwidth (per second)
Casual Web surfing 500 Kbps
Instructional Web use 1 Mbps
Casual audio listening 100 Kbps
Instructional audio listening 1 Mbps
Casual streaming video 1 Mbps
Instructional streaming video 2–4 Mbps
Printing 1 Mbps
Casual file sharing 1 Mbps
Instructional file sharing 2–8 Mbps
Online testing 2–4 Mbps
Table 12-3 Bandwidth required for typical online tasks
© Cengage Learning 2013
Standard Advertised Data Rate (Mbps)
Actual Throughput (Mbps) Number of users
Average throughput per user
802.11b 11 7.2 10 720 Kbps
802.11b 11 7.2 30 240 Kbps
802.11g 54 13 10 1.3 Mbps
802.11g 54 13 30 430 Kbps
802.11a 54 25 10 2.5 Mbps
802.11a 54 25 30 833 Kbps
802.11n (MCS7) 72 35 10 3.5 Mbps
802.11n (MCS7) 72 35 30 1.16 Mbps
Table 12-4 Throughput for different standards
© Cengage Learning 2013
WLAN Optimization 447
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Take advantage of wireless network management systems (WNMS). ● For guest accounts use a captive portal AP. ● Use picocells when necessary. A picocell is a WLAN that uses a reduced power
output from the AP that results in a smaller coverage area but can allow for increased performance due to channel reuse.
● Size the coverage area to the corresponding standard. Figure 12-12 compares the coverage area of a 5 GHz (802.11a) with a 2 GHz (802.11b) with no obstacles to create interference. Note that higher data rates do not extend as far from the AP.
Because obstacles such as walls, doors, filing cabinets, and other indoor objects can have such an impact on signal strength, it is desirable to keep in mind the distances in an outdoor setting with no attenuation factors. These outdoor distances are illustrated in Figure 12-12.
Wireless Device Optimization Optimizing the wireless device is also important. Some wireless devices, such as Voice over Wi-Fi (VoWiFi), can be configured based on their roaming tendencies. Devices that rely on time-dependent applications, such as voice or video streaming, perform better with less roam- ing. These devices may be configured as “conservative roaming,” while other devices that do not normally use these applications can be set to “aggressive roaming.”
450´ 440´ 420´ 360´
325´300´275´250´225´200´150´
54 Mbps
11 Mbps
5.5 Mbps
2 Mbps
1 Mbps
48 Mbps
36 Mbps
24 Mbps
18 Mbps
12 Mbps
9 Mbps
6 Mbps
80´
802.11a
5 GHz at 40 mW
802.11b
2.4 GHz at
100 mW
Figure 12-12 Coverage area comparison
© Cengage Learning 2013
448 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
Different solutions have been proposed to facilitate fast and secure roaming, particularly while using VoWiFi with IEEE 802.11X. Several vendors have their own unique proprietary solutions, while the IEEE 802.11r-2008 (Fast Basic Service Set Transition) amendment is an attempt to standardize these differences.
When possible a wireless device should be set to “disable upon wired connect.” This turns off the wireless connection whenever the device connects to a standard wired network by using a cable connection. This provides a higher degree of security so that the device cannot be used as a rogue AP to circumvent security.
Chapter Summary ■ Troubleshooting requires both a systematic approach and a “sixth sense” that is sharp-
ened by experience. It is important that wireless network administrators and technicians develop good wireless troubleshooting skills. The first step in troubleshooting a WLAN is to identify the source of the problem. One of the main sources of WLAN problems is RF interference. Radio frequency interference (RFI) is any undesirable electrical energy emitted within the frequency range dedicated to RF transmissions. These unwanted RF signals are called noise. There are four categories of external noise interference on a WLAN. Narrowband interference is usually generated by television, radio, and satellite transmitters and impacts a narrow portion of the spectrum and does not affect the entire band. Wideband interference affects the entire frequency band, such as the entire 2.4-GHz band. Competing technologies that use FHSS to “hop” across the spectrum can create all-band interference that covers all bands of the RF spectrum. Weather can have an impact on wireless transmissions outdoors. Over a long distance, an RF signal may move through different atmospheric conditions.
■ Multiple copies of a WLAN signal arrive at the receiver at different times, having traveled along different paths, in a phenomenon known as multipath. Although the difference between the signals, called delay spread, is so small as to be measured in nanoseconds, nevertheless it can have an impact upon the reception because these copies are “added” to the primary signal. Known as intersymbol interference (ISI), this adding of signals to the primary signal can result in downfade, corruption, or nulling.
■ Another category of WLAN problem sources has to do with WLAN configuration settings. Cochannel interference can result when two or more networks attempt to use the same channel. If all of the APs are set to the same channel number, throughput is reduced because each station is forced to wait a longer period of time for its turn to transmit. A WLAN transmitting on one channel while a nearby WLAN is transmitting on an adjacent channel can cause adjacent channel interference. Incorrect power settings can be another problem source. An AP should not have an output power level higher than the output power level of the wireless device.
■ While the data rate is the theoretical maximum rated speed of a network, the throughput is the measure of how much actual data can be sent per unit of time across a network. Throughput is often used to measure the amount of data actually sent across a network in a “real world” setting. Any one factor, or a combination of factors, can influence system throughput. Often WLAN problems are the result of incorrect AP settings, or AP settings
Chapter Summary 449
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
that are incompatible with other devices. One way to troubleshoot these problems is to watch the external light emitting diodes (LEDs) that are present on most APs.
■ When troubleshooting wireless mobile devices, one problem area is the location of devices. If one device is transmitting at 100 mW and is located fairly close to the AP, while another device is farther away and transmitting at only 10 mW, the stronger signal from the first device may overwhelm the weaker signal from distant device. This is known as the near/far transmission problem. In addition, in a WLAN, all stations need to be able to detect transmissions from all other stations at all times; however, in a wireless environment, a station might be in range of the AP but not be in range of all other stations and could transmit while other stations are already transmitting. This is known as the hidden node problem.
■ A failure to connect to an existing network or a connection with poor throughput is often the result of an incorrect configuration on the wireless device. The Microsoft Windows operating system provides tools can be used to view the wireless connection as well as make changes. For Windows 7 these include the Network and Sharing Center, the Wireless Network Connection Status, and the Wireless Network Connection Properties window. The Windows 8 operating system makes several changes by using a simpler and more integrated radio and connection management interface. If there is a problem making a wireless connection, several troubleshooting steps may be considered to resolve the problem.
■ Unlike with wired networks, a variety of techniques can be used to optimize a WLAN to ensure that it is adequately providing services for its users. Ensuring smooth roaming between WLAN cells is primarily based on cell overlap, which is the area between two APs in which a wireless device begins to search for a new AP with which to associate. Recommended settings for cell overlap vary are given as either a percentage or a recommended dBm of overlap. In a high-density environment such as a lecture hall or auditorium on a school campus, where users are clustered very close together in a seating area, a solution is to optimize the channel by installing high-density WLANs.
■ Several steps can be taken to optimize APs. These include never accepting the default configuration of an AP, installing lightweight APs to minimize the TCO, configuring wireless VLANs for additional security, taking advantage of WNMS, for guest accounts use a captive portal AP, and using picocells when necessary. Optimizing the wireless device is also important. Some wireless devices can be configured based on their roam- ing tendencies: devices that rely on time-dependent applications perform better with less roaming while other devices that do not normally use these applications can be set to more aggressive roaming. When possible, a wireless device should be set to “disable upon wired connect.” This turns off the wireless connection whenever the device con- nects to a standard wired network by using a cable connection. This provides a higher degree of security so that the device cannot be used as a rogue AP to circumvent security
Key Terms all-band interference RF interference that covers all bands of the RF spectrum. Automatic Private IP Addressing (APIPA) An IP address that begins with the IP range 169.254.x.x and is assigned if a device cannot receive a valid IP.
450 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
cell overlap The area between two APs in which a wireless device begins to search for a new AP with which to associate. electromagnetic interference (EMI) An undesirable electronic disturbance, either man- made or natural, which causes an undesirable degrading in the performance of electrical equipment. high-density WLANs Wireless networks that are used in areas in which large numbers of device are clustered close together. narrowband interference RF interference that is usually generated by television, radio, and satellite transmitters and that impacts a narrow portion of the spectrum, without affecting the rest of the band. near/far A transmission problem involving two wireless devices, in which the wireless device closest to the AP transmits at a higher power than the other, more distant device, thereby overwhelming the weaker signal from the distant device. noise Unwanted RF signals. noise floor A measure of the total of all the noise from different systems. picocell A WLAN that uses a reduced power output from the AP; results in a smaller coverage area but can allow for increased performance due to channel reuse. radio frequency interference (RFI) Any undesirable electrical energy emitted within the frequency range dedicated to RF transmissions. wideband interference RF interference that affects the entire frequency band, such as the entire 2.4-GHz band.
Review Questions 1. Which of the following is not part of troubleshooting?
a. A systematic approach
b. A “sixth sense”
c. Experience
d. Optimization
2. is any undesirable electrical energy emitted within the frequency range dedicated to RF transmissions.
a. Electromagnetic interference (EMI)
b. Sidebar interference (SBI)
c. Radio frequency interference (RFI)
d. Overlap interference (OI)
3. The weakest signal that can be received is the .
a. throughput signal
b. delicate RF (DRF)
c. faint signal (FS)
d. noise floor
Review Questions 451
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
4. What type of interference is generated by television, radio, and satellite transmitters?
a. narrowband interference
b. broadcast signal interference (BSI)
c. spectral interference
d. remote device interference (RDI)
5. If RF interference affected the entire 2.4-GHz band it would be called .
a. all-band interference
b. wideband interference
c. narrow spectrum interference
d. UNII interference
6. Which of the following is not a solution for mitigating all-band interference?
a. add switching software
b. change the RF spectrum used
c. increase power levels of the devices
d. change the MAC or PHY layer
7. Which of the following is not a solution to reduce RF interference?
a. maintain a system operating margin
b. maintain proper power
c. move antennas as close together as possible
d. recognize situations where noise is a factor
8. Which of these actions can reduce the impact of ISI?
a. switch to a WLAN that uses MIMO
b. change the security configuration to WPA2 from WPA
c. increase power settings in the AP but not the wireless devices
d. use IEEE 802.11b technology
9. If cochannel interference is detected on an IEEE 802.11g network with both WLANs using channel 6, the solution is to switch one network to channel .
a. 1
b. 3
c. 7
d. 9
10. Why is cochannel interference less of an issue with IEEE 802.11n networks?
a. 802.11n networks have more nonoverlapping channels.
b. Cochannel interference rarely occurs on faster networks like 802.11n.
c. MIMO used in 802.11n virtually eliminates cochannel interference.
d. 802.11n networks transmit at a lower power level so there is less interference.
452 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
11. The output power level of an AP should be to the output power level of the wireless devices in the WLAN.
a. less than
b. less than or equal to
c. greater than
d. greater than or equal to
12. Troubleshooting incorrect power settings can be accomplished by using a .
a. protocol analyzer
b. wireless switch
c. wired router
d. spectrum analyzer
13. Each of the following can be a reason why a WLAN is experiencing slow throughput except:
a. distance from the AP
b. packet size
c. number of APs in the WLAN
d. types of RF interference
14. AP LED status lights can provide all of the following information except:
a. the type of security protocol used in the WLAN
b. whether the AP firmware is being updated
c. whether the AP is initializing the connection and obtaining an IP address
d. whether data is being transmitted over the WLAN
15. What is a near/far transmission problem?
a. When one of two devices is closer to the AP and transmits at a higher output power, thereby overwhelming the signal of the more distant device, which is transmits at a weaker output level.
b. When one wireless device cannot detect all other wireless devices in the WLAN because it is too far away.
c. When an AP cannot communicate with another AP because it is either too close or too far away.
d. When all wireless devices transmit at different power levels.
16. Which of these does a Windows computer perform last in the sequence of steps when connecting to a WLAN?
a. associate
b. authenticate
c. obtain an IP address
d. choose an AP
Review Questions 453
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
17. Which Windows wireless tool displays the Layer 3 connectivity status, the media state, the SSID, the length of time the connection has been active, the negotiated connection speed, and the signal quality?
a. Wireless Network Connection Status
b. Network and Sharing Center
c. Wireless Network Connection Properties
d. Windows Device Manager
18. Which of the following is not something that can cause a problem on a WLAN?
a. using an 802.11b device in an 802.11g network
b. using an 802.11a device with 802.11g AP
c. authentications that are not identical
d. using outdated profiles
19. Which of the following is false about roaming?
a. Channel numbers for all cells must be identical.
b. The SSIDs must be the same for all cells.
c. The cell overlap area is where a wireless device begins to search for a new AP with which to associate.
d. The security settings should match for all cells.
20. Which of the following is false about high-density WLANs?
a. Older 802.11 standards are utilized because they are more stable.
b. More APs are clustered closer together in order to provide the resources to users.
c. APs are positioned in different locations.
d. They are often found in lecture halls and auditoriums.
Hands-On Projects
Project 12-1: Viewing Logs Using the Microsoft Windows Event Viewer The Windows Event Viewer allows log files to be examined. Logs are com- posed of log entries, with each entry containing information related to a specific
event. They can be useful in determining the underlying cause of wireless issues. In this proj- ect, you will view logs on a Windows 7 computer.
1. Launch Event Viewer by clicking Start and then typing Administrative Tools in the Search box.
2. Click the Administrative Tools link and then double-click Event Viewer. Maximize this window, if necessary.
454 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
3. The Event Viewer opens to the Overview and Summary page that displays all events from all Windows logs on the system. The list below “Summary of Administrative Events” shows the total number of events for each type, along with the number of events of each type that have occurred over the last seven days, the last 24 hours, or the last hour. Under “Summary of Administrative Events,” click the + (plus) sign next to each type of event to view events that have occurred on this system.
4. Double-click a specific event to display detailed information on the event. Is this infor- mation in a format that a system administrator could use when examining a system? Is it in a format that an end-user would find helpful?
5. When finished, click the Back arrow to return to the Overview and Summary page.
6. In the left pane under Event Viewer (Local), double-click Windows Logs to display the default generated logs, if necessary.
7. Click System in the left pane.
8. Scroll down to the last entry. How far back in time do the log entries go?
9. Select a specific event and then double-click it to display detailed information on the event. When finished, click Close.
10. In the right pane click Filter Current Log.
11. The Filter Current Log dialog box opens, as shown in Figure 12-13.
Figure 12-13 Filter Current Log dialog box
© Cengage Learning 2013
Hands-On Projects 455
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12. To the right of Event level, select all five checkboxes (Critical, Error, Warning, Information, and Verbose).
13. Click the down arrow next to Event sources.
14. Scroll down and select the WLAN-AutoConfig, WlanConn, and WlanPref checkboxes, which are all related to WLAN processes.
15. Click outside the dropdown menu to close it, and then click OK.
16. Scroll through the events in the top pane. Click one event.
17. Note the description in the bottom pane.
18. Click the Details tab in the bottom pane for additional information.
19. Would this information be helpful in troubleshooting a WLAN problem on a client?
20. Close all windows.
Project 12-2: Configuring Access Points—IP Address Distribution The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this project
you will use an online emulator from D-Link to explore distributing IP addresses through the AP.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you, if necessary.
3. If you are asked to select the preferred D-Link home page, click No, Thank you and then click Continue.
4. Click the Support tab.
5. Click Go next to Emulators.
6. Scroll down and click DAP-3520. The emulated login screen appears.
7. Click Login. An emulated Setup screen displaying what a user would see when configuring an actual DAP-3520 is displayed.
8. Click the plus sign (+) next to Basic Settings in the left pane to expand the options.
9. Click Wireless to display the Wireless Settings screen.
10. This allows the AP to automatically find the best channel to use. How would this be helpful? How could it result in a problem?
456 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
11. Change Auto Channel Selection to Enable if necessary. What happens to the Channel setting when Auto Channel Selection is enabled? Why?
12. Click the down arrow next to Channel Width. What are the options? When would Auto 20/40 MHz be used? (Hint: Consider different devices in an IEEE 802.11n WLAN.)
13. Click LAN in the left pane under Basic Settings.
14. Click the down arrow next to Get IP From. This is the source from which the AP obtains its IP address. What are the options available?
15. Now explore how the wireless devices receive their IP addresses. Click the plus sign (+) next to Advanced Settings in the left pane to expand the options.
16. Click the plus sign (+) next to DHCP Server in the left pane to expand the options.
17. Click Dynamic Pool Setting. In the right pane next to Function Enable/Disable click the down arrow and then click Enable if necessary. Note that there is a Lease Time (60-31536000 sec) available. What is the maximum time in hours?
18. In the left pane click Static Pool Setting. This defines the IP addresses that can be distributed to specific wireless devices through the AP.
19. In the right pane next to Function Enable/Disable click the down arrow and then click Enable if necessary.
20. Note that each device can be identified by the Computer Name and Assigned MAC Address. When would this option be preferable instead of the AP distributing IPs as a DHCP server? (Hint: Is there a lease time associated with static pool settings?
21. What happens if a valid IP address cannot be obtained?
22. Leave the current settings for the next project.
Project 12-3: Configuring Access Points—Overlap, VLANs, and Guest Networks The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this project
you will continue using an online emulator from D-Link to configure overlap, VLANs, and guest networks.
1. In the left pane under Advanced Settings click Performance.
2. In the right pane, the Transmit Power value can be adjusted to change the overlap between two WLANs in order to achieve optimum roaming. Click the down arrow and note the different options:
● 100% ● 50% (or �3dB) ● 25% (or �6dB) ● 12.5% (or �9dB)
Hands-On Projects 457
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3. How would you determine what the optimum overlap percentage/dB would be?
4. Wireless VLANs can be configured for additional security. In the left pane click VLAN.
5. In the right pane, next to VLAN Status, click Enable.
6. Click the Add/Edit VLAN tab.
7. Next to VLAN ID (VID) enter 1234.
8. Next to VLAN Name enter Accounting.
9. Another security option is to create separate guest networks for visitors. This allows guests to share the same channel but still remain segregated. In the left pane under Advanced Settings click Multi-SSID.
10. In the right pane click Enable Multi-SSID.
11. Click Enable Priority.
12. Click the down arrow next to Priority. Based on the priority levels available, how many guest SSIDs can be configured?
13. Close all windows.
Case Projects
Case Project 12-1: Troubleshooting Table Use what you have learned regarding troubleshooting to create a troubleshoot- ing table that lists WLAN problems along with potential solutions. Create specific categories of problems, such as RF interference, configuration, etc., the source of the problem, and steps that can be taken to mitigate it.
Case Project 12-2: More Truths and Myths Expand on Table 12-1 by creating your own list of truths and myths regarding RF interfer- ence. Create 3–5 additional entries. Compare these with lists compiled by other learners.
Case Project 12-3: Rank Sluggish Performance Factors A WLAN can perform “sluggishly” for several reasons. Research the factors listed below and create a list of which factor you think would have the greatest impact on performance down to the least impact. Then create a solution for each of these factors on how to change it so there is no longer a negative impact on the WLAN.
● Distance from the AP ● Implementing security solutions (WPA, and WPA2) ● Number of users associated with an AP ● Packet size ● Request to send/Clear to send (RTS/CTS) protocol
458 Chapter 12 Wireless Network Troubleshooting and Optimization
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12
● Types of RF interference ● Using Point Coordination Function (PCF) protocol
Case Project 12-4: AP LED Indicators Research the AP LED indicators of a device in your school’s lab or a wireless router (if these devices do not have LED indicators then use the Internet to locate a brand and model that has at least six different LED indicators. Using the printed documentation that came with the product or information on the manufacturer’s Web site, create a complete table like Table 12-2 that lists the light, activity, and description. Would this be useful in trouble- shooting? Why?
Case Project 12-5: Windows Troubleshooting Guide Write a guide that walks through the steps of using various Microsoft Windows tools to troubleshoot a problem with a wireless device. For each tool, the guide should explain how to access the tool, the types of problems the tool can identify, and whether the tool could be used to solve the problems it identifies. Create the guide to cover both Windows 7 and Windows 8.
Case Project 12-6: Nautilus IT Consulting Nautilus IT Consulting (NITC), a computer technology business, has asked for your assis- tance with one of their new clients.
Croce Community College (CCC) has several different campuses located in the area. CCC provides wireless service to students on campus but is experiencing complaints from students in large lecture halls that they do not receive adequate throughput while in class. CCC wants to address this problem.
1. Create a PowerPoint presentation that explains what a high-density WLAN is, how it works, its advantages and disadvantages, along with some sample layouts for a lecture hall. The presentation should be eight to ten slides in length.
2. CCC is interested in installing a high-density WLAN for the lecture halls. However, the finance manager wants to use the existing IEEE 802.11g network to save money while the IT manager insists that a higher-capacity 802.11n network should be installed instead in the lecture halls. CCC has turned to you in order to settle the dispute. Write a one-page memo explaining whether 802.11g or 802.11n should be used and giving your reasons for the decision.
Case Projects 459
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
chapter13
Other Wireless Networks
After completing this chapter you should be able to:
• Describe the technologies found in a wireless personal area network • Explain the uses of a wireless metropolitan area network • List the technologies of a wireless wide area network • Describe the IEEE 802.11ac proposed standard
461 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The prospect of having someone constantly monitor your location throughout the day conjures up the image of Big Brother spying on our activities. But there are advantages to knowing where someone is located, and wireless indoor location track- ing is being implemented on a wider scale to help consumers and patients.
Stores, airports, museums, colleges, hospitals, sports stadiums, and large conven- tion centers are turning to wireless indoor location tracking to help guide users to their destination. Instead of having to refer to large and often confusing “You Are Here” signs, individuals can turn to smartphone apps for guidance instead. In one large four-story bookstore, a shopper can use an app to type the title of the book she is searching for and check a box to indicate her current location in the store. She will then immediately receive turn-by-turn instructions to navigate through the aisles to the book’s exact location. In an Australian art museum, each visitor is provided with a wireless device that can be worn around the neck with a lanyard. Tapping on the screen of the device brings up a list of all the pieces of art in the vicinity of where the visitor is standing. Selecting one of the items causes the wireless device to display a history of the piece along with a critical analysis of that work.
Although the technology for finding outdoor locations, such as a store or a house, has been available for several years, wireless indoor location mapping had to over- come several significant challenges. The process of creating a building’s floor plan online can be very time-consuming. Stores and businesses must submit to mapping companies their architectural drawings, engineering files, and even photos so that teams of programmers can create a “clickable” digital diagram. Also, determining a user’s indoor location can be difficult. While satellite Global Positioning System (GPS) technology can be used outdoors to pinpoint a user’s cell phone to within a few yards of its location, GPS can be spotty or even nonexistent indoors. Mapping compa- nies are hiring workers to walk through every square foot of an indoor venue three to four times while carrying a smartphone or tablet computer. Workers are instructed to stop every few feet, manually tap their location on a map of the venue, and then spin around so their device can register all the wireless signals in that area. This creates a database that can then be used for tracking. Some stores are installing Bluetooth wireless networks for increased accuracy in tracking customers.
Despite its challenges, indoor location mapping provides several new benefits. Sports fans can order concessions through their smartphone and have them delivered right to their seats so that they do not miss a minute of the big game. One large retailer has released a trip-planning app that allows a shopper to enter a shopping list and receive a map of the shortest path through the store to complete his shop- ping. At the parking garage of a large mall, cameras record a car’s license plate
Real World Wireless
462 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
The popularity of wireless local area networks (WLANs) continues to surge. By some esti- mates there will be 1.4 billion devices shipped in the year 2014 that support the IEEE 802.11 standards.i These include smartphones, laptops, desktops, and tablets.
However, WLANs are not the only wireless network technology in use today. Several other wireless technologies are also associated with IEEE standards. These technologies can be cate- gorized by the geographical distance that they cover. There are four broad wireless technology categories:
● Wireless personal area network. A wireless personal area network (WPAN) is designed for hand-held and portable devices at slow to moderate transmission speeds. The maximum distance range between devices is generally 33 feet (10 meters) transmitted at 1 Mbps.
● Wireless local area network. WLANs such as IEEE 802.11a/b/g/n are for portable or stationary devices that are within a few hundred feet of each other or a centrally located access point (AP) (the maximum distance is usually 350 feet or 107 meters). Depending upon the standard, transmission speeds may range up to 600 Mbps.
number at each parking spot; shoppers can then enter their license number into a smartphone app and receive step-by-step directions back to their car. Soon users will be able to follow their phone to their seat at a 75,000-seat stadium, to their computer class on a large college campus, or directly to a pair of jeans at a store in the mall.
Retailers are using indoor wireless location tracking in order to understand a shop- per’s behavior so that they can deploy more salespeople, alter displays, or put out different merchandise in order to meet an immediate demand. Radio frequency identification chips and motion sensors are used to track how often a pair of jeans is picked up or how many customers turn left when they enter a store. One large retailer used wireless indoor location tracking to generate maps showing which parts of the store received the most traffic and then used it to make decisions about where to place in-store decorations, salespeople, and merchandise. These decisions were made in a week instead of the usual six months. The result was a 20-percent increase in sales. Some stores are now testing facial-recognition software that can identify a shopper’s gender and approximate age as she enters a store, and then beam coupons to her for specific items she might be interested in purchasing.
Wireless location tracking is not limited to shopping. Hospitals are using it to track patients. Researchers have found that cell phone data can indicate when someone is ill. For example, those who have the flu tend to move around much less, and those who are depressed have fewer calls and text messages with others. One hospital is tracking teens and young adults who suffer from an inflammatory bowel disease. This illness is typically treated with a two-week course of steroids, but these can be harmful when used for too long. By monitoring the behavior of patients through wireless location tracking—such as when the patient leaves the house for the first time after several days (indicating they are improving)—doctors can reduce the time patients are on the steroids.
13
Chapter 13 Other Wireless Networks 463
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Wireless metropolitan area network. A wireless metropolitan area network (WMAN) is designed for devices in a range of up to 35 miles (56 kilometers) using radio frequency (RF) or infrared transmission technology at different speeds.
● Wireless wide area network. Wireless facilities that connect networks in different parts of a country or of the world are known as wireless wide area networks (WWANs). The transmission speeds again vary, although often are slower than those for a WMAN.
The categories of wireless technologies are covered in Chapter 1.
Figure 13-1 compares the distance range of these four technologies.
In this chapter you will explore these other wireless networks: WPAN, WMAN, and WWAN. In addition, the next IEEE WLAN standard, IEEE 802.11ac, will also be examined.
Wireless Personal Area Networks (IEEE 802.15) There are several WPAN technologies, each of which either has an IEEE standard or a stan- dard is being developed in the 802.15 family of standards. These technologies are Bluetooth (802.15.1-2005), Ultrawideband (802.15.3c-2009), low rate technologies (802.15.4), Body Area Networks (802.15.6), and Visible Light Communications (802.15.7).
Bluetooth (802.15.1-2005) Bluetooth is a wireless technology that uses short-range RF transmissions and provides for rapid ad hoc device pairings. Bluetooth technology enables users to connect wirelessly to a wide range of computing and telecommunications devices. Several of these Bluetooth-enabled product pairings are listed in Table 13-1.
Wireless Personal Area Networks (WPAN)
Range Short Long
Wireless Local Area Networks (WLAN)
Wireless Metropolitan Area Networks (WMAN)
Wireless Wide Area Networks (WWAN)
Figure 13-1 Range of wireless technologies
© Cengage Learning 2013
464 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Bluetooth is covered in Chapter 1.
The current version is Bluetooth v4.0 (a subset is known as Bluetooth Low Energy), yet all Bluetooth devices are backward compatible with previous versions. Most Bluetooth devices have a range of 33 feet (10 meters). The rate of transmission is 1 million bits per second (Mbps).
The IEEE 802.15.1-2005 Wireless Personal Area Network standard was based on the Bluetooth v1.2 specifications. However, the IEEE has discontinued its relationship with Bluetooth, so that any future Bluetooth versions will not become IEEE standards.
There are two types of Bluetooth network topologies. The first is known as a Bluetooth piconet. In this topology, when two Bluetooth devices come within range of each other, they automatically connect to each another. One device is the master, and controls all of the wireless traffic. The other device is known as a slave, which takes commands from the master. Slave devices that are connected to the piconet and are sending transmissions are known as active slaves; devices that are connected but are not actively participating are called parked slaves. An example of a Bluetooth piconet is illustrated in Figure 13-2. Figure 13-3 illustrates a slave device that is detected by a master.
Devices in a Bluetooth piconet can be in one of five different modes:
● Standby. A device in standby mode is waiting to join a piconet. ● Inquire. In inquire mode another device is looking for other devices with which to connect.
Category Bluetooth Pairing Usage
Automobile Hands-free car system with cell phone
Drivers can speak commands to browse the cell phone’s contact list, make hands-free phone calls, or use its navigation system.
Home entertainment Stereo headphones with portable music player
Users can create a playlist on a portable music player and listen through a set of wireless headphones or speakers.
Photography Digital camera with printer Digital photos can be sent directly to a photo printer or from pictures taken on one cell phone to another phone.
Computer accessories Computer with keyboard and mouse
Small travel mouse can be linked to a laptop or a full- size mouse and keyboard that can be connected to a desktop computer.
Gaming Video game system with controller
Gaming devices and video game systems can support multiple controllers, while Bluetooth headsets allow gamers to chat as they play.
Medical and health Blood pressure monitors with smartphones
Patient information can be sent to a smartphone, which can then send an emergency phone message if necessary.
Table 13-1 Bluetooth products
© Cengage Learning 2013
Wireless Personal Area Networks (IEEE 802.15) 465
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Page. Page mode is when a master device is asking to connect to a specific slave. ● Connected. When a device is either an active slave or a master it is in connected mode. ● Park/Hold. A device in park/hold mode is part of the piconet but is in a low-power
state.
If multiple piconets cover the same area, a Bluetooth device can be a member in two or more overlaying piconets. A group of piconets in which connections exist between different piconets makes up the second type of Bluetooth network topology and is called a Bluetooth scatternet. A scatternet is illustrated in Figure 13-4.
Figure 13-3 Slave device detected by master
© Cengage Learning 2013
M = Master
AS = Active slave
PS = Parked slave
M
AS
PS AS AS AS AS
M
Figure 13-2 Bluetooth piconet
© Cengage Learning 2013
466 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
A Bluetooth device can be a slave in several piconets but can be a master in only one piconet.
Bluetooth uses frequency hopping spread spectrum (FHSS) so that all devices in a Bluetooth net- work must change frequencies at the same time and in the same sequence in order for commu- nications to take place. The timing in the hopping sequence is determined by the master’s clock, to which each active slave is synchronized. All 79 channels on which Bluetooth transmits are divided into time slots of 625 microseconds. The hopping sequence—that is, which slot will be used next—is unique for each piconet and is determined by the device address of the master.
Because Bluetooth and certain IEEE 802.11 WLANs share the same 2.4 GHz spectrum, a conflict between devices can arise. An IEEE task group known as 802.15.2 was formed to create a means by which these two technologies could coexist. Two theoretical solutions were proposed but were never implemented, and the group is currently in official “hibernation.”
Bluetooth technology is a short-range wireless technology designed for interconnecting computers and peripherals, hand-held devices, or cell phones. It can be used for almost any short-range application where low cost is essential. However, its major drawback is its slow speed. This is because the original Bluetooth standard was designed as a simple cable replace- ment for computers and other devices.
Bluetooth is also finding its way into unlikely devices. A Victorinox Swiss Army pocketknife model has Bluetooth technology that can be used to remotely control a computer when projecting a PowerPoint presentation. The pocketknife also serves as a 32 GB USB flash drive that has a biometric fingerprint scanner. And since pocketknives cannot be carried onto an airplane, one version of the pocketknife lacks a sharp blade.
ASAS AS
PS
AS AS
AS
PS
M = Master
AS = Active slave
PS = Parked slave
M M
Figure 13-4 Bluetooth scatternet
© Cengage Learning 2013
Wireless Personal Area Networks (IEEE 802.15) 467
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Due to the ad hoc nature of Bluetooth piconets and scatternets, attacks on wireless Bluetooth technology are not uncommon. Two Bluetooth attacks are bluejacking and bluesnarfing. Bluejacking is an attack that sends unsolicited messages to Bluetooth-enabled devices. Usually bluejacking involves sending text messages, but images and sounds can also be transmitted. Bluejacking is usually considered more annoying than harmful because no data is stolen. However, many Bluetooth users resent receiving unsolicited messages. Bluesnarfing is an attack that accesses unauthorized information from a wireless device through a Bluetooth connection, often between cell phones and laptop computers. In a bluesnarfing attack the attacker copies e-mails, calendars, contact lists, cell phone pictures, or videos by connecting to the Bluetooth device without the owner’s knowledge or permission.
To prevent bluesnarfing, Bluetooth devices should be turned off when not being used or when in a room with unknown people. Another option is to set Bluetooth on the device as undiscoverable, which keeps Bluetooth turned on yet it cannot be detected by another device.
Ultra-Wideband (802.15.3c-2009) Because of the limitations of Bluetooth, the IEEE established a group to investigate high-rate WPANs. The result became known as Ultra-wideband (UWB) or 802.15.3c-2009. Two main applications are intended for UWB. The first is video and audio distribution for home enter- tainment systems, which includes high-speed digital video transfer from a digital camcorder to a screen and interactive video gaming. The second application is higher-speed data transfer intended for MP3 players, personal home storage devices, printers, scanners, and transfers to and from digital still cameras and kiosks.
Several significant features designed for UWB are summarized in Table 13-2.
While work on the 802.15.3 standard was ongoing, it was decided that an alternative IEEE study group—802.15.3a—would be formed to look at data rates even higher than 55 Mbps, but this standard was later withdrawn. IEEE 802.15.3b-2005 addressed improving the imple- mentation and interoperability of the 802.15.3 standard. The current standard is 802.15.c-2009 with speeds over 2 Gbps.
UWB has not been widely implemented. Because it distributes a signal across a wide range of spectrum (sometimes several gigahertz), widespread interference on other transmissions is a con- cern. Among the opponents were the Federal Aviation Association (FAA) and other Federal agencies who claimed that UWB could interfere with critical safety equipment, such as aircraft radar and communications, and thereby pose a threat to the public.
As an alternative to using UWB for wireless home entertainment systems, a new technology known as Wireless Display (WiDi) is gaining popularity. WiDi enables a user to project a display from a WiDi-enabled portable device like a notebook or tablet to a WiDi adapter connected to a television using 802.11n. A user can
share documents or stream movies on the portable device and display them onto the TV screen. WiDi does not even require that the image on the device’s screen be the same as that that being projected, so that a user can stream a movie while checking e-mail at the same time.
468 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Low Rate Technologies (802.15.4) Although it might appear that the trend for wireless devices is to transmit faster and farther, that is not always the case. In many settings, low speed and low power are more desirable. A WPAN device using low power can be much smaller in size, even down to the size of a penny. Applica- tions using low rate technologies include motion sensors that control lights or alarms, light wall switches, meter reader devices, game controllers for interactive toys, tire pressure monitors in cars, passive infrared sensors for building automation systems, and inventory tracking devices.
Power consumption is so low for these devices that it is estimated that batteries powering the devices can last up to five years.
Recognizing the need for these smaller, low-power devices, the IEEE 802.15.4 standard was approved in 2003. This standard addresses requirements for RF transmissions that require low power consumption as well as low cost. The 802.15.4 devices operate up to 164 feet (50 meters) at different frequencies, depending upon the data rate. Table 13-3 illustrates the 802.15.4 frequencies and data rates.
Data Rate Frequency
250 Kbps 2.4 GHz
40 Kbps 915 MHz
20 Kbps 868 MHz
Table 13-3 IEEE 802.15.4 data rates and frequencies
© Cengage Learning 2013
UWB Feature Description
Quality of Service (QoS) Because UWB was to be used extensively in audio and video applications, it is essential that QoS be implemented.
Security The security features for the 802.15.3 standard include key distribution and encryption using AES. The standard supports four modes (levels) of security.
High data rates The standard specifies raw data rates of 11 Mbps, 22 Mbps, 33 Mbps, 44 Mbps and 55 Mbps at distances of 33 feet (10 meters). The highest rate supports low-latency multimedia connections and large file transfers, while 11 Mbps and 22 Mbps rates target long-range connectivity for audio devices.
Spectrum utilization The UWB standard uses the 2.4 GHz spectrum and supports either three or four nonoverlapping channels 15 MHz wide.
Coexistence The standard was designed to coexist with IEEE 802.11 WLANs. It causes less interference because it occupied a smaller bandwidth and transmits at a lower power level. It also monitors the channels that are being used by other devices and will dynamically select the best channel available.
Table 13-2 UWB features
© Cengage Learning 2013
Wireless Personal Area Networks (IEEE 802.15) 469
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Two popular low rate 802.15.4 technologies are ZigBee and radio frequency ID (802.15.4f).
ZigBee ZigBee is a low-power, short-range, and low-data rate specification. It is based on 802.15.4 but includes standards for network configuration, security and other higher-level features that are not covered by the IEEE standard. ZigBee’s data rate is 250 kbps and is best designed for occasional data or signal transmission from a sensor or input device. ZigBee is typically found in the following applications:
● Smart lighting ● Advanced temperature control ● Medical data collection ● Smoke and intruder detection
The ZigBee name comes from the peculiar behavior of bees. After zigging and zagging through fields when collecting nectar, bees return to the hive and perform a waggle dance to communicate the distance, direction and type of food to other bees in the hive. After receiving this information, the other bees then fly off directly to the source of food.
Radio Frequency Identification (RFID) Although currently not governed by an established IEEE standard, the 802.15.4f group is working on standards that relate to radio frequency identification (RFID). The theoretical foundation for RFID was first proposed in the mid-1940s; however, it took over 30 years for the technology to become available to apply the theory. RFID tags are able to receive and respond to queries from an RFID transceiver.
RFID is covered in Chapter 1 and an image of an RFID tag can be seen in Figure 1-4 of Chapter 1.
RFID tags can be either active or passive. Passive RFID tags do not have their own power supply. Instead, the tiny electrical current induced in the antenna by the incoming signal from the transceiver provides enough power for the tag to send a response. Because it does not require a power supply, passive RFID tags can be very small—some are only 0.4 millimeters (mm) � 0.4 mm and thinner than a sheet of paper. However, with a passive tag the amount of data sent back must also be very small, typically just an ID number. Passive tags have ranges from about 10 mm up to 19 feet (6 meters). Active RFID tags must have their own power source. Although this makes the tags larger (about the size of a coin), the tags have longer ranges and larger memo- ries than passive tags, as well as the ability to store additional information sent by the transceiver. Many active tags have a range of 98 feet (30 meters) or more and a battery life of several years.
Four different kinds of RFID tags are commonly used. They are categorized by their radio frequency, as listed in Table 13-4.
Common applications for RFID tags include:
● Automobile toll booths in many states use RFID tags for electronic toll collection. The tags are embedded in a device in the vehicle and are read as the vehicle passes through the toll booth. The toll amount is automatically deducted from a prepaid account. The system helps to speed traffic through toll plazas.
470 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
● Asset tracking is a common use of RFID tags. They are used to track computers and office equipment, folders in attorney’s offices, samples of construction concrete that must be tested to ensure building safety, and car seats and dashboards used in an assembly line.
● A tire manufacturer embeds RFID tags in its tires to ensure tire-tracking capabilities so the manufacturer can comply with the U.S. Transportation, Recall, Enhancement, Accountability and Documentation Act (TREAD Act).
● Cards with embedded RFID chips are widely used as electronic cash in casinos and to pay mass transit fares.
● A Smart Key, available on cars from select manufacturers, is an active RFID circuit that allows the car to acknowledge the key’s presence within 3 feet of the sensor. The driver can open the doors and start the car while the key remains in the driver’s purse or pocket.
● Major retailers are requiring that cases and pallets of merchandise shipped to their warehouses from large vendors have an RFID tag affixed. However, RFID tags on individual items within the cases or pallets are not required.
● Each U.S. passport has an RFID tag imbedded in the document. It contains the traveler’s name, date of birth, city of origin, and other identifying information, such as a digital photograph or digital fingerprints.
One hotel chain is embedding RFID chips into plastic loyalty program cards in order to turn the cards into room keys. When a guest makes a reservation their room number is sent to them as a text message. The guest can then by-pass the front desk, go directly to that room, and open the door using their loyalty card with the RFID chip.
A similar technology based on RFID standards is near field communication (NFC). NFC is a set of standards primarily for smartphones and smart cards that is used to establish commu- nication between devices. Once the devices are either tapped together or brought into close proximity (several centimeters) to each other a two-way communication is established. NFC devices are used in contactless payment systems where a consumer can pay for a purchase by simply tapping a store’s payment terminal with their phone.
Every major cell phone manufacturer has announced plans to incorporate NFC into its devices.
Tag Name Frequency Application
Microwave tag 2.45 GHz Vehicle tracking
Ultrahigh frequency tag 868-956 MHz Container tracking
High frequency tag 13.56 MHz Airline baggage, library book inventory, building access control
Low frequency tag 125-134 KHz Animal identification, alcohol keg tracking
Table 13-4 RFID tags
© Cengage Learning 2013
Wireless Personal Area Networks (IEEE 802.15) 471
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Body Area Networks (802.15.6) The IEEE 802.15.6 group is currently creating standards for body area networks (BAN). A BAN is formally defined by the IEEE as “a communication standard optimized for low power devices and operation on, in or around the human body (but not limited to humans) to serve a variety of applications including medical, consumer electronics/personal entertain- ment and other.” A BAN is essentially a network system of devices in close proximity to a person’s body that cooperate for the benefit of the user.
BANs are commonly used for sports and fitness monitoring. A runner or cyclist can have her heart rate, respirations, blood pressure, and distance traveled transmitted to her wristwatch or a small device affixed to her clothing. At a higher level, soccer shoes are now available with an 8-gram chip, called a speed cell, inserted beneath the shoe’s sole. The speed cell transmits data on maximum speed, distance covered, and the number of sprints to the ball in all 360-degree movements.
Perhaps the most promising use of BANs involves healthcare applications. Sensors are placed on the human body to monitor electrocardiogram (EKG) impulses, blood pressure, glucose, and other human biological functions. These are then transmitted via computer or smart- phone to a third party physician who can make a decision regarding any medications to prescribe or lifestyle changes to recommend. Known as a managed body sensor network (MBSN), this is illustrated in Figure 13-5.
Hearing
EKG
Vision
Glucose
Blood
pressure
Toxins
Network
Figure 13-5 Managed body sensor network
© Cengage Learning 2013
472 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
A more robust approach is the autonomous body sensor network (ABSN). Instead of only reading and transmitting information, an ABSN introduces actuators in addition to the sensors so that immediate effects can be made on the human body. One type of ABSN has already been approved for use. In late 2011 the Federal Communications Commission (FCC) gave approval for the use of medical micropower networks (MMN). Four blocks of the 400 MHz spectrum (two of the four channels are 426–432 and 438–444 MHz while the other two are above and below the 420–450 MHz band) are allocated for low-power wideband networks. MMN can serve dozens of micro-stimulator implant devices to treat paralysis and other conditions. These devices take in signals from the human nervous system and then stimulate nerves through electrical charges that cause muscles to contract and limbs to move, bypassing areas of the nervous system that have been impaired by strokes or spinal cord or brain injuries. The ABSN MMN can expand the use of functional electric stimulation to restore sensation, mobility, and function to persons with paralyzed limbs and organs.
Another ABSN being tested installs “stretchy” microprocessors on the tips of cardiac catheters, which are threaded through arteries into the heart. These catheters will be used to monitor the heart’s electrical activity to pinpoint the location of irregular heartbeats, and if necessary can treat the heart by “zapping” the tissue that is malfunctioning.
Visible Light Communications (802.15.7) Instead of using RF for the communication media, light can be used instead. Light has some advantages over RF. First, sources of interference that impact RF transmissions have no impact on transmissions that are based on light. Also, unlike RF devices that decrease the throughput as the distance between devices increases, devices that rely on light do not vary the transmission speed.
One of the original WPAN technologies using light is based on a standard known as IrDA. IrDA is an acronym for the Infrared Data Association, which is a nonprofit consortium with over 160 member companies that represent computer and telecommunications hard- ware, software, components, and adapters. The IrDA standards arose from the need to connect different computer and telecommunications devices together using infrared light. Infrared data ports conforming to the IrDA specifications were installed on notebook computers, computers, printers, desktop adapters, cameras, phones, watches, pagers, storage devices, and kiosks. These IrDA devices can transmit from 9.6 Kbps to 16 Mbps.
IrDA devices communicate using infrared light emitting diodes (LEDs) to send and photo- diodes to receive signals. The transceivers are not flush with the edge of the device but instead are recessed into the device. They are then covered with a transparent window surrounded by opaque material, as seen in Figure 13-6. Several design factors, which are not readily apparent, can improve the performance of IrDA devices. The transparent window placed in front of the IR module should be flat instead of curved because a curved window may alter the radiation pattern of the LED. Also, the color of the window is violet because this color will allow for a minimal loss of the signal when transmitting. And, because bright sur- rounding light (known as ambient light) can interfere with the infrared signal, the module is recessed into the device case by several millimeters to create an overhang over the photodiode that will minimize the amount of direct ambient light that the receiver sees. The transparent window will also help reflect ambient light away from the diodes.
Wireless Personal Area Networks (IEEE 802.15) 473
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Although initially IrDA ports were still found on many devices, its popularity significantly diminished due to its drawbacks:
● IrDA technology was designed to work like the standard serial port on a personal computer. These ports are seldom used today.
● IrDA devices cannot send and receive at the same time because the transmitter and receiver are not optically isolated.
● Strong ambient light can negatively impact the transmissions. ● The angle at which the sending and receiving IrDA devices align or face each other
is very important. When the two devices have a deflection angle of no more than 15 degrees, the distance between devices can be up to 3 feet (1 meter).
However, a new type of WPAN based not on infrared light but on visible light (which is adjacent to infrared on the frequency spectrum) is gaining popularity. It is known as visible light communications (VLC) and standards are being developed by the IEEE committee 802.15.7. VLC transmits data by the intensity of the modulating optical source, such as LEDs and laser diodes (LDs). Because this modulation is faster than the human eye can detect, humans cannot perceive a transmission taking place. A comparison of VLC to the frequency and wavelength of other wireless technologies is shown in Figure 13-7, while a comparison of different data rates and distances is provided in Figure 13-8.
The first device for using light for voice communications was devel- oped by Alexander Graham Bell in 1880. Known as the photophone, it used sunlight reflecting off a vibrating mirror to send to a parabolic mirror at a distance of 700 feet (213 meters).
VLC can operate in one of three different topologies. In a peer-to-peer topology, the commu- nication is between only two VLC devices. Each device supports a single light source, while one of the peers acts as a coordinator. This is good for a high data rate over a short distance.
Front view opaque material
IR transparent window
Bottom view opaque material
IR transparent window
Opaque material
Figure 13-6 IrDA diodes in device
© Cengage Learning 2013
474 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
In a star topology, all of the devices communicate with a single central controller, called the coordinator. Each VLC star network operates independently from all other star networks. In a broadcast topology the device in a broadcast mode can transmit a signal to other devices without actually forming a network. This communication is unidirectional and the destination address of the receiving devices is not required.
VLC has several advantages:
● Visible light is harmless to the human body. ● VLC networks can be created to transmit data by adding optical communication
devices to the sockets of existing light fixtures. ● No electromagnetic interference (EMI) impacts VLC. ● There are no regulations regarding the use of light.
100M
D a ta
r a te
( b p s )
50M
16M
4M
VLC
802.11n
115K
1 2 3 6
Distance (m)
11 20 50
802.11a
802.11b
UWB
ZigBee
Bluetooth
Figure 13-8 VLC data rate comparison
© Cengage Learning 2013
Low frequency Long wavelength Good coverage Mobility
Frequency
Wavelength
300MHz
1m
IEEE 802.11
10GHz
3cm 1mm
3THz
100μm
428THz
700nm
750THz
400nm
300PHz
1nm
High frequency Short wavelength Good bandwidth Security
IEEE 802.15.3c IrDA VLC
RF IR UVVisible
300GHz
Figure 13-7 VLC frequency and wavelength comparison
© Cengage Learning 2013
Wireless Personal Area Networks (IEEE 802.15) 475
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● The signals cannot be intercepted because the transmission range is narrowly confined so transmissions are secure.
Wireless Metropolitan Area Networks Wireless metropolitan area networks (WMANs) cover an area of up to about 35 miles (56 kilo- meters) as the distance between devices. WMANs are often used as an alternative (or backup) to an organization’s fiber optic cable connection between two or more remote locations. The two primary WMAN technologies are free space optics and broadband radio service.
The challenges of installing fiber optic cables are covered in Chapter 1.
Free Space Optics (FSO) Whereas VLC is used for indoor communications, free space optics (FSO) is an optical, wireless, point-to-point, line-of-sight wireless technology for outdoor transmissions. It was originally developed over 30 years ago by the military and today serves as an alternative to high-speed fiber optic cable. Currently FSO can transmit at speeds comparable to fiber optic transmissions of up to 1.25 Gbps at a distance of 2.5 miles (4 kilometers).
FSO uses infrared transmission instead of RF, sending low-powered infrared beams through the open air. These beams, which do not harm the human eye, are transmitted by transcei- vers, as shown in Figure 13-9. Because FSO is a line-of-sight technology, the link heads must be mounted high in office buildings to provide a clear transmission path. However, unlike other technologies that require the units to be located on an open roof (which sometimes requires leasing roof space from the building’s owner), FSO link heads can be mounted behind a window in an existing office.
Figure 13-9 FSO transceiver
© Paul Wolf/www.Shutterstock.com
476 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Under ideal conditions, FSO could transmit up to 6.2 miles (10 kilometers).
There are several advantages of FSO:
● Lower installation costs. FSO installations cost significantly less than installing new fiber optic cables or even leasing lines from a local carrier. One project compared the costs of installing fiber optic cables to FSO in three buildings and found the cost of the former was almost $400,000 whereas the cost of FSO was less than $60,000.
● Faster installation. FSO can be installed in days or weeks compared to months and sometimes years for fiber optic cables. In some instances, FSO systems have been installed over a weekend in major office buildings with no disruption of service to the users.
● Scaling transmission speed. The transmission speed can be scaled to meet the user’s needs, anywhere from 10 Mbps to 1.25 Gbps. If high speeds are not required, the user does not have to pay a premium for unused capacity as when leasing a line from a carrier but instead can design the FSO system to match needs.
● Good security. Security is a key advantage in an FSO system. IR transmissions cannot be intercepted and decoded as with some RF transmissions.
The primary disadvantage of FSO is that atmospheric conditions can affect FSO transmissions. Turbulence caused by wind and temperature variations can create pockets of air with rapidly changing densities. These air pockets can act like prisms and lenses to distort an FSO signal. Inclement weather is also a threat. Although rain and snow can distort a signal, fog does the most damage to transmission. Fog is composed of extremely small moisture particles that act like prisms upon the light beam, scattering and breaking up the signal. However, FSO can overcome turbulence by sending the data in parallel streams from several separate laser trans- mitters. These transmitters are mounted in the same link head but separated from one another by several centimeters. It is unlikely that while traveling to the receiver all the parallel beams will encounter the same pocket of turbulence, since the pockets tend to be small.
Broadband Radio Service (BRS) Broadband Radio Service (BRS) is a wireless technology that uses microwave frequencies. Formerly known as Multichannel Multipoint Distribution Service (MMDS), BRS is com- monly used as a wireless alternative to cable television reception. However, BRS can transmit video, voice, or data signals at 1.5 Mbps downstream and 300 Kbps upstream at distances of up to 35 miles (56 kilometers).
BRS/MMDS was originally designed in the 1960s to provide transmission for 33 one-way analog television channels. This multiple-channel (multichannel) technology was designed for educational institutions to provide long-distance learning. However, the original vision was never fully materialized. Later, private companies purchased part of this spectrum to compete against wired cable television companies (BRS is sometimes called wireless cable). In 1998 the Federal Communications Commission (FCC) allowed service providers to use the 200 MHz of bandwidth in the frequency bands to provide two-way services such as wireless Internet access along with voice and video transmissions.
Today BRS is used as an option in both home and business settings. In the home, it can serve as an alternative to wired Internet service (such as cable modems and Digital Subscriber Lines),
Wireless Metropolitan Area Networks 477
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
particularly in rural areas where cabling is scarce. It is also used to transmit over 300 channels of digital video. For businesses, BRS is an alternative to copper or fiber optic connections. MMDS uses the 2.1 GHz and 2.5 GHz through 2.7 GHz bands to offer two-way service.
BRS hubs are typically located on top of mountains, towers, buildings, or other high points. The hub uses a point-to-multipoint architecture that multiplexes communications to multiple users. The tower has a backhaul connection to the carrier’s network, and the carrier network connects with the Internet. Because they operate at a lower frequency, BRS signals can travel longer distances. This means that BRS can provide service to an entire area with only a few radio transmitters. MMDS uses cells like cellular telephony; however, a BRS cell size can cover over 3,800 square miles (6,000 square kilometers) in area.
The advantages to BRS are its long range of transmission, its large cell size, and the fact that it is less vulnerable to poor weather conditions. However, it still requires a direct line of sight and the wireless transmissions are generally not encrypted.
In the near future, WMANs may be using white space spectrum, which consists of the vacant airwaves between television channels that were intended to prevent interference. In 2010, the FCC approved this spec- trum for unlicensed use, and by late 2011 the first WMAN white space device was approved by the FCC. In 2012 a law was passed that autho-
rized the FCC to sell 120 MHz of spectrum from unused TV channels 31 to 51 but the white space spectrum was to remain unlicensed. The IEEE task group 802.11af is currently defining modifica- tions to the 802.11 physical layers (PHY) and the 802.11 Medium Access Control (MAC) layer to meet the legal requirements for channel access and coexistence in this TV white space spectrum.
Wireless Wide Area Networks Wireless networks that transmit beyond the range of WMANs are generally known as wire- less wide area networks (WWANs). Wireless technologies in this category typically supports mobile users with either a WWAN wireless modem in a laptop, a tablet with built-in WWAN connectivity, or a digital cellular smartphone. The primary technologies for WWAN are WiMAX and long term evolution (LTE).
WiMAX (802.16) WiMAX (Worldwide Interoperability for Microwave Access) is based on the IEEE 802.16 standards. The MAC layer of WiMAX is different than that used in IEEE 802.11a/b/g (CSMA/CA) or Ethernet (CSMA/CD). Instead, WiMAX uses a scheduling system and the device only has to compete once for initial entry into the network. Once the device has been accepted it is allocated a time slot. Although this time slot can expand and shrink, it remains assigned to that device and other devices must take their turn. This type of scheduling algo- rithm is more stable under heavy loads and is more efficient with bandwidth. The scheduling algorithm also allows the base station to control Quality of Service (QoS) by balancing the assignments among the needs of the subscriber stations.
WiMAX has counterparts in other nations as well. The WiMAX equivalent in Europe is HIPERMAN. Korea’s standard, WiBro, has already agreed upon interoperability with WiMAX.
478 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
WiMAX can be broken down into two categories. Fixed WiMAX, based on IEEE 802.16-2004, can serve as a substitute for fiber optic connections between buildings similar to FSO and BRS. It provides up to 31 miles (50 kilometers) of linear service area range and does not require line-of-sight. WiMAX also provides shared data rates up to 70 Mbps. Mobile WiMAX, which is based on IEEE 802.16e-2005, can connect mobile devices over a wide area. One mobile WiMAX base station can cover an area of 6 miles (9.6 kilometers). It can also support users traveling at vehicular speeds of 70 miles per hour (112.6 kilometers per hour). Mobile WiMax is often promoted as a solution to the last mile connection.
The last mile connection is covered in Chapter 1.
Long Term Evolution (LTE) Cellular telephones work in a manner that is unlike wired telephones. The coverage area for cellular telephony is divided into cells. In a typical city the cells, which are hexagon-shaped, measure 10 square miles (26 square kilometers). At the center of each cell is a cell transmitter to which the mobile devices in that cell send and receive RF signals. These transmitters are connected to a base station, and each base station is connected to a mobile telecommunica- tions switching office (MTSO). The MTSO is the link between the cellular network and the wired telephone world and controls all of transmitters and base stations in the cellular network. All of the transmitters and cell phones operate at a low power level that enables the signal to stay confined to the cell and not interfere with other cells. Because the signal at a specific frequency does not go outside of the cell area, that same frequency can be used in other cells at the same time. This is illustrated in Figure 13-10.
Because of frequency reuse, a typical cellular telephone network in one city uses only 830 frequencies to handle all callers.
T T T T
T T
T T T T
T T MTSO
T = Transmitter MTSO = Mobile telecommunications switching office
– Uses frequency 50
– Uses frequency 70
T
T
T
T
T
Figure 13-10 Cellular frequency reuse
© Cengage Learning 2013
Wireless Wide Area Networks 479
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
As cellular telephony has evolved from analog to more advanced packet-switching digital sys- tems, digital WWAN technologies can be used to replace these older analog systems. When first introduced, mobile WiMAX was considered to be the logical choice for the next genera- tion of cellular systems. In the mid-2000s one U.S. cellular carrier invested over $5 billion in replacing its infrastructure with WiMAX technology, and later formed a $14.5 billion ven- ture with another company to combine their mobile WiMAX operations.
However, by early 2008, the two largest carriers in North America announced that they would adopt a competing technology instead. These carriers said that this technology, known as 3rd Generation Partnership Project Long Term Evolution (3GPP LTE), was a more natural upgrade for their current network technology and also supported the dominant mobile standard worldwide that serves over three billion global customers.
Although LTE is commonly referred to as a fourth generation (4G) technology, technically the current version of LTE does not meet all the requirements for 4G. It is anticipated that the next generation of LTE, known as LTE Advanced, will meet these requirements.
In order to achieve higher data rates, LTE incorporates several elements found in IEEE 802.11n WLANs. LTE uses orthogonal frequency division multiplexing (OFDM) and breaks down the transmission into separate parts to send each part in parallel simultaneously. Instead of sending one long stream of data, OFDM sends the transmission in parallel across several channels. LTE also utilizes Multiple-Input Multiple-Output (MIMO), which is charac- terized by having a radio chain for each antenna.
OFDM is covered in Chapter 5 and MIMO is covered in Chapter 4.
Table 13-5 lists the technical characteristics of LTE.
IEEE 802.11ac
C W N A
4.5.1. Understand WLAN design and deployment considerations for commonly supported WLAN applications and devices.
Characteristic Explanation
Supported modulation types QPSK, 16-QAM, 64-QAM
Peak download speeds 172 Mbps (MIMO 2x2), 326 Mbps (4x4)
Peak upload speeds 50 Mbps (QPSK), 57 Mbps (16-QAM), 86 Mbps (64-QAM)
Channel bandwidths 1.4, 3, 5, 10, 15, or 20 MHz
Table 13-5 Technical characteristics of LTE
© Cengage Learning 2013
480 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Sixty years ago video content was distributed to homes through broadcast television stations. In the 1980s, a shift occurred with video being delivered through cable and later satellite connections. Today another shift is occurring, with the Internet becoming the popular means for streaming movies and TV shows. It is estimated that global Internet traffic will increase by 32 percent annu- ally through the year 2015, when traffic will reach almost 1 zettabyte (Table 13-6 lists different capacities). Almost 90 percent of global consumer Internet traffic in 2015 will be video content.ii
By 2015, the data equivalent of every movie ever filmed will cross through the Internet every 5 minutes.
Due to the popularity of wireless networking, much of this Internet digital content is carried across WLANs to televisions, set-top boxes, smartphones, and tablets. Current IEEE 802.11a/b/g/n network technology often cannot keep up with delivering this content, particu- larly high-definition (HD) video, and may result in deteriorated performance, choppy videos, and slow load times. Alternatives to IEEE 802.11 WLANs such as Wireless HDMI and WiGig are available but have not proven to be popular.
In January 2011, the IEEE Task Group for 802.11ac published its first draft of IEEE 802.11ac, known as Very High Throughput <6Ghz, to support higher data rates, in part to address the demand for wireless video delivery. Building upon many of the enhancements introduced in 802.11n, this new standard has advertised data rates over 1 Gbps. Some of 802.11ac’s technologies include:
● Spectrum. 802.11ac will operate in the less-crowded 5 GHz spectrum. It will not support the 2.4 GHz spectrum.
● Increased channel bandwidth. Whereas 802.11n uses channels up to 40-MHz-wide channels, the 802.11ac standard uses channel bandwidths up to 80 MHz. To achieve this, it was necessary to adapt automatic radio tuning capabilities so that higher- bandwidth channels are only used when necessary in order to conserve spectrum use.
● MU-MIMO. A variation of MIMO known as Multi-User MIMO (MU MIMO) is implemented in 802.11ac. MU-MIMO enables the simultaneous transmission of different data frames to different clients. This requires that equipment is able to utilize the spatial awareness of the different remote users. It also implements
Name Size Description
Gigabyte (GB) 1,000 Megabytes 1 GB can hold the contents of a shelf of books 30 feet long
Terabyte (TB) 1,000 Gigabytes 10 TB can hold the entire printed collection of the Library of Congress
Petabyte (PB) 1,000 Terabytes The contents of 20 million four-drawer filing cabinets could be stored in 1 PB
Exabyte (EB) 1,000 Petabytes All of the words ever spoken by the whole of mankind throughout history would consume 5 EB
Zettabyte (ZB) 1,000 Exabytes Virtually nothing with which to compare it
Table 13-6 Capacities
© Cengage Learning 2013
IEEE 802.11ac 481
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
sophisticated queuing systems that can take advantage of opportunities to transmit to multiple clients when the conditions are right.
● Error correction coding. Advances in chip manufacturing technology have enabled designers to take advantage of additional levels of processing power so that more sensitive coding techniques that depend on finer distinctions in the received signal can be used. This reduces the number of error correction check bits needed.
● Beam forming. Under 802.11n, transmit beam forming (TxBF) was available, but many products did not take advantage of it. With IEEE 802.11ac, TxBF is a standard feature, and all products that implement it will be interoperable. This can result in increased range and coverage area.
TxBF is covered in Chapter 4.
● Improved battery life. Because of its increased speed in file transfers and similar activities, mobile users may find that by using 802.11ac they can increase their battery life (because it takes less time for activities that require the device to draw significant battery power).
IEEE 802.11ac will be backwards compatible with 802.11n devices only operating in the 5 GHz spectrum.
Table 13-7 lists several of the technologies anticipated in 802.11ac compared to 802.11n.
The advertised data rate of 802.11ac is often stated as 1 Gbps. As with 802.11n, the actual data rate depends on the modulation, cod- ing, and number of spatial streams. For example, 4 spatial streams using 40 MHz channels with 400 ns guard intervals can result in a 600 Mbps data rate for 802.11n. The top speed for 802.11ac is expected to be as high as 3.6 Gbps.
It is anticipated that the final IEEE 802.11ac standard will be released in 2012, with ratifica- tion in late 2013. However, devices from vendors based on the draft standard are expected to appear sooner.
Technology 802.11ac 802.11n
Maximum data rate 3.6 Gbps 600 Mbps
Spectrum 5 GHz 2.4 GHz or 5 GHz
Modulation 256-QAM 16-QAM or 64-QAM
Channel width 80 MHz 40 MHz
Spatial streams 8 4
Primary uses Video Data
Table 13-7 IEEE 802.11ac technologies
© Cengage Learning 2013
482 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Chapter Summary ■ There are four broad categories of wireless technology. Wireless personal area networks
(WPANs) are designed for hand-held and portable devices at slow to moderate (1 Mbps) transmission speeds with the maximum distance range between devices of about 33 feet (10 meters). Wireless local area network (WLANs), such as IEEE 802.11a/b/g/n, are for portable or stationary devices that are within a few hundred feet of each other or a cen- trally located access point (AP). Depending upon the standard, transmission speeds may range up to 600 Mbps. Wireless metropolitan area networks (WMANs) is designed for devices in a range of up to 35 miles (56 kilometers) using radio frequency (RF) or infrared transmission technology at different speeds. Wireless wide area networks (WWANs) are wireless facilities that connect networks in different parts of a country or of the world. The transmission speeds again vary, although often are slower than those for a WMAN.
■ Bluetooth is a wireless technology that uses short-range RF transmissions and provides for rapid ad hoc device pairings. The current version is Bluetooth v4.0 yet all Blue- tooth devices are backward compatible with previous versions. Most Bluetooth devices have a range of 33 feet (10 meters) and a rate of transmission of 1 Mbps. There are two types of Bluetooth network topologies. The first is known as a Bluetooth piconet. When two Bluetooth devices come within range of each other, they automatically connect to each another. A group of piconets in which connections exist between different piconets is called a Bluetooth scatternet, the second type of Bluetooth topology. Bluetooth uses FHSS. The major drawback for Bluetooth is its slow speed. Ultra- wideband (UWB) or 802.15.3c-2009 is considered a high-rate WPAN with speeds over 2 Gbps. UWB has not been widely implemented. Because it distributes a signal across a wide range of spectrum (sometimes several gigahertz) there is concern of widespread interference on other transmissions.
■ There are many settings in which low speed and low power are desirable in a network setting. The IEEE 802.15.4 family of devices operates up to 164 feet (50 meters) at different frequencies, depending upon the data rate. ZigBee is a low-power, short- range, and low-data rate specification. It is based on 802.15.4 but includes standards for network configuration, security and other higher-level features that are not covered by IEEE standard. ZigBee’s data rate is 250 kbps and is best designed for occasional data or signal transmission from a sensor or input device. Although currently not governed by an established IEEE standard, the 802.15.4f group is working on stan- dards that relate to RFID. RFID tags can be either active or passive: passive RFID tags do not have their own power supply while active RFID tags have their own power source. A similar technology based on RFID standards is near field communication (NFC). NFC is a set of standards primarily for smartphones and smart cards that is used to establish communication between devices.
■ The IEEE 802.15.6 group is currently creating standards for body area networks (BAN). A BAN is a network system of devices in close proximity to a person’s body that cooperate for the benefit of the user. BANs are commonly used for sports and fitness monitoring as well as healthcare applications. Instead of using RF for the com- munication media, light can be used instead. One of the original WPAN technologies using light is based on a standard known as IrDA. Infrared data ports conforming to the IrDA specifications were installed on computers and a variety of consumer devices.
Chapter Summary 483
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
However, its popularity diminished due to its drawbacks. A new type of WPAN based not on infrared light but on visible light is gaining popularity. Known as visible light communications (VLC) its standards are being developed by IEEE 802.15.7.
■ WMANs are often used as an alternative (or backup) to an organization’s fiber optic cable connection between two or more remote locations. There are two primary WMAN technologies. Free space optics (FSO) is an optical, wireless, point-to-point, line-of-sight wireless technology for outdoor transmissions. FSO uses infrared transmission instead of RF, sending low-powered infrared beams through the open air. Broadband Radio Service (BRS) is a wireless technology that uses microwave frequencies and is commonly used as a wireless alternative to cable television reception. BRS is used as an option in both home and business settings. In the home, it can serve as an alternative to wired Internet service (such as cable modems and Digital Subscriber Lines), particularly in rural areas where cabling is scarce. For businesses, BRS is an alternative to copper or fiber optic connections.
■ Wireless networks that transmit beyond the range of WMANs are known as wireless wide area networks (WWANs) and the wireless technologies in this category typically supports mobile users with either a WWAN wireless modem in a laptop, a tablet with built-in WWAN connectivity, or a digital cellular smartphone. WiMAX (Worldwide Interoperability for Microwave Access) is based on the IEEE 802.16 standards. Fixed WiMAX, based on IEEE 802.16-2004, can serve as a substitute for fiber optic connections between buildings similar to FSO and BRS. It provides up to 31 miles (50 kilometers) of linear service area range and does not require line-of-sight. Mobile WiMAX, which is based on IEEE 802.16e-2005, can connect mobile devices over a wide area. Another technology is 3rd Generation Partnership Project Long Term Evolution (3GPP LTE). In order to achieve the higher data rates that LTE offers it incorporates several elements that are found in IEEE 802.11n WLANs, such as OFDM and MIMO.
■ The explosion of digital video content on the Internet has resulted in much of this content being carried across WLANs to televisions, set-top boxes, smartphones, and tablets. Current IEEE 802.11a/b/g/n network technology may not be able to keep up with delivering this content, particularly HD video. In early 2011 the IEEE Task Group for 802.11ac published its first draft of IEEE 802.11ac, known as Very High Throughput <6Ghz, to support higher data rates, in part to address the demand for wireless video delivery. Building upon many of the enhancements introduced in 802.11n, this new standard has advertised data rates over 1 Gbps.
Key Terms active RFID tag An RFID tag that must have its own power source. autonomous body sensor network (ABSN) A network that introduces actuators in addition to sensors so that immediate effects can be made on the human body. bluejacking An attack that sends unsolicited messages to Bluetooth-enabled devices. bluesnarfing An attack that accesses unauthorized information from a wireless device through a Bluetooth connection. Bluetooth piconet A Bluetooth network consisting of a master and at least one slave device.
484 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Bluetooth scatternet A Bluetooth network consisting of a group of Bluetooth piconets, with connections between the different piconets. body area networks (BAN) A network system of devices in close proximity to a person’s body that cooperate for the benefit of the user. Broadband Radio Service (BRS) A WMAN technology that uses microwave frequencies to transmit at distances of up to 35 miles (56 kilometers). Fixed WiMAX A WWAN based on IEEE 802.16-2004 that can serve as a substitute for fiber optic connections between buildings. free space optics (FSO) An optical, wireless, point-to-point, line-of-sight wireless technology for outdoor transmissions. IEEE 802.11ac A proposed WLAN standard to support higher data rates in part to address the demand for wireless video delivery. Infrared Data Association (IrDA) A nonprofit consortium that developed standards for connecting different computer and telecommunications devices using infrared light. managed body sensor network (MBSN) A network that utilizes sensors placed on the human body to monitor human biological functions that are transmitted to a third party physician. mobile telecommunications switching office (MTSO) The link between the cellular network and the wired telephone world and controls all of transmitters and base stations in the cellular network. Mobile WiMAX A WWAN based on IEEE 802.16e-2005 that can connect mobile devices over a wide area. Multi-User MIMO (MU MIMO) An IEEE 802.11ac technology that enables the simultaneous transmission of different data frames to different clients. near field communication (NFC) A set of standards primarily for smartphones and smart cards that is used to establish communication between devices. passive RFID tag An RFID tag that does not have its own power supply but uses the tiny electrical current induced in the antenna by the incoming signal. ultra-wideband (UWB) An IEEE 802.15.3c-2009 standard of a high-rate WPAN with speeds over 2 Gbps. visible light communications (VLC) An IEEE 802.15.7 standard that transmits data by the intensity of the modulating optical source. Worldwide Interoperability for Microwave Access (WiMAX) A WWAN based on the IEEE 802.16 standards. ZigBee A low-power, short-range, and low-data rate specification that is based on 802.15.4 but that includes standards for network configuration, security and other higher-level features.
Review Questions 1. Which of the following network types have a maximum distance between devices of
about 350 feet and a top data rate of 600 Mbps?
a. wireless personal area network
b. wireless local area network
c. wireless portable area network
d. wireless piconet area network
Review Questions 485
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2. Which of the following is not true of Bluetooth?
a. Devices have a range of 33 feet (10 meters).
b. The rate of transmission is 1 Mbps.
c. The current version is Bluetooth v4.0.
d. It requires a Bluetooth AP in the network.
3. A group of Bluetooth piconets in which connections exist between different piconets is called a .
a. Bluetooth scatternet
b. Dual Network (DN)
c. Bluetooth Piconet Extension
d. Bluetooth mesh
4. An attack that accesses unauthorized information from a wireless device through a Bluetooth connection is called .
a. bluejacking
b. bluetoothing
c. bluehighjacking
d. bluesnarfing
5. Which of the following is not a feature of ultra-wideband (UWB)?
a. Quality of Service (QoS)
b. security
c. low data rates
d. coexistence
6. Why has ultra-wideband (UWB) not been widely implemented?
a. UWB consumes too much power.
b. UWB’s data rate is too low.
c. Widespread interference on other transmissions is a concern.
d. It is not based on an IEEE standard.
7. Which of the following is not an application for ZigBee?
a. smart lighting
b. wireless laser mouse
c. advanced temperature control
d. smoke detection
8. Which types of RFID tags require their own power source?
a. passive RFID tags
b. powered RFID tags
486 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
c. active RFID tags
d. remote RFID tags
9. A body area networks (BAN) that requires a third-party healthcare provider to evaluate data is called a(n) .
a. autonomous body sensor network (ABSN)
b. managed body sensor network (MBSN)
c. regulated body network sensor (RBNS)
d. remote body area network sensor (RBANS)
10. Which of the following is true regarding IrDA?
a. Devices can transmit only between 300 Kbps and 1,200 Kbps.
b. It uses infrared light to send signals.
c. It is widely used today.
d. It uses the 2.4 GHz spectrum.
11. Which of the following is not a visible light communications (VLC) topology?
a. bus
b. star
c. broadcast
d. peer-to-peer
12. Each of the following is an advantage of visible light communications (VLC) except:
a. visible light is harmless to the human body.
b. the FCC regulates VLC to prevent interference with other networks.
c. the signals cannot be intercepted.
d. there is no electromagnetic interference (EMI).
13. Which of the following is false regarding wireless metropolitan area networks (WMANs)?
a. WMANs cover an area of up to about to 35 miles (56 kilometers).
b. A WMAN can serve as a backup to a fiber optic connection.
c. WMANs are prohibited from being used in rural areas.
d. WMANs are used as an alternative to an organization’s fiber optic cable connection.
14. The data rate of free space optics (FSO) is .
a. 1.25 Kbps
b. 1.25 Mbps
c. 1.25 Gbps
d. 1.25 Tbps
Review Questions 487
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
15. Which of the following is not an advantage of data rate of free space optics (FSO)?
a. FSO link heads can be mounted behind a window in an existing office.
b. Installation costs of FSO is about the same as fiber optic.
c. FSO can be installed in days or weeks.
d. Transmissions speeds can be scaled as necessary.
16. Broadband Radio Service (BRS) is a wireless technology that uses .
a. infrared light
b. visible light
c. bonded light
d. microwaves
17. Each of the following are true regarding mobile WiMAX except:
a. it is not based on any IEEE standard.
b. one mobile WiMAX base station can cover an area of 6 miles (9.6 kilometers).
c. it can support users traveling at vehicular speeds of 70 miles per hour (112.6 kilometers per hour).
d. mobile WiMax is often promoted as a solution to the last mile connection.
18. Which of the following is not true regarding Long Term Evolution (LTE)?
a. It was chosen over WiMAX by carriers because it supported the dominant mobile standard worldwide.
b. LTE uses OFDM.
c. Peak download speeds can exceed 10 Gbps.
d. MIMO is utilized by LTE.
19. Which of the following is false about IEEE 802.11ac?
a. It operates in both 5 GHz and 2.4 GHz.
b. Error correction coding is improved.
c. It enables the simultaneous transmission of different data frames to different clients.
d. Beamforming is a standard feature.
20. The channel bandwidth in 802.11ac is .
a. 20 MHz
b. 40 MHz
c. 60 MHz
d. 80 MHz
488 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Hands-On Projects
Project 13-1: Viewing Bluetooth Devices Using BluetoothView Bluetooth devices are commonly used as a wireless mouse or keyboard for tablet, laptop or desktop computers. In this project you will install software
to view Bluetooth devices in the area that can be detected by the computer. To complete this project, you will need a computer that either has built-in Bluetooth technology or a Bluetooth USB adapter. (If you are already using a Bluetooth mouse or similar device on a computer that does not have integrated Bluetooth, you will have a Bluetooth USB adapter.) In addition, you will need a separate Bluetooth device, such as a Bluetooth mouse, key- board, or smartphone that supports Bluetooth.
1. Turn on or install the Bluetooth mouse, keyboard, or similar device on the computer.
2. Go to www.nirsoft.net/utils/bluetooth_viewer.html.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “NirSoft BluetoothView”.
3. Scroll down and click Download BluetoothView. (Note that this is different from the green button that says “Download”.)
4. When the file finishes downloading, locate the compressed (ZIP) file and extract the files.
5. Return to the NirSoft Web site and scroll up to the section The ‘Company Name’ Column.
6. Right-click http://standards.ieee.org/develop/regauth/oui/oui.txt.
7. Click Save link as (or Save target as, depending on your browser).
8. Save this file as oui.txt in the same folder that contains files extracted above.
9. Launch the application by double-clicking BluetoothView.exe.
10. Wait several seconds for the Bluetooth device to appear. What information about the device is transmitted through this Bluetooth piconet?
11. Scroll across to the Company Name column. Record the company name that was displayed.
12. Open the file oui.txt and then search for that company name. What is the company id for this company name? Note that Bluetooth only transmits the company id and not the full name.
13. Return to the BluetoothView application.
14. Add another Bluetooth device to the Bluetooth piconet, such as a smartphone that supports Bluetooth. It may be necessary to both turn on the Bluetooth capabilities and to make the device discoverable. Then move the device close to the computer so that it can be detected, as illustrated in Figure 13-11.
15. What information about this device is transmitted through the Bluetooth piconet?
16. Close all windows.
Hands-On Projects 489
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Project 13-2: Viewing Bluetooth Devices Using BlueAuditor In this project you will install software to view Bluetooth devices in the area that can be detected by the computer. The same requirements for a computer
and Bluetooth devices as in Hands-On Project 13-1 apply to this activity.
1. Turn on or install the Bluetooth mouse, keyboard, or similar device on the computer.
2. Go to www.wifiauditor.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “BlueAuditor”.
3. Click Download BlueAuditor.
4. When the file finishes downloading, launch the setup file to install BlueAuditor.
5. When the installation is complete, start BlueAuditor if necessary.
6. Click Monitoring.
7. Click Run.
8. Click Run in the Devices Search Parameters Dialog box.
9. Wait several seconds for the Bluetooth device to appear. What information about the device is transmitted through this Bluetooth piconet?
10. Scroll across to identify the different information. How does it compare the Bluetooth- View application in the previous project?
11. Add another Bluetooth device to the Bluetooth piconet, such as a smartphone that supports Bluetooth. It may be necessary to both turn on the Bluetooth capabilities and to make the device discoverable. Then move the device close to the computer so that it can be detected, as illustrated in Figure 13-12.
Figure 13-11 BluetoothView screen
© Cengage Learning 2013
490 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
12. What information about this device is transmitted through the Bluetooth piconet? Which of the two applications do you prefer? Why?
13. Close all windows.
Project 13-3: Configuring Access Points—Performance The ability to properly configure an AP is an important skill for any wireless network professional as well as, to a lesser degree, for end-users. In this project you will use an online emulator from D-Link to explore setting performance
parameters for an AP.
1. Use your Web browser to go to www.dlink.com.
It is not unusual for Web sites to change the location of where files are stored. If the URL above no longer functions then open a search engine and search for “D-Link emulator”.
2. Click the nation most appropriate for you, if necessary.
3. If you are asked to select the preferred D-Link home page click No, Thank you and then click Continue.
4. Click the Support tab.
5. Click Go next to Emulators.
6. Scroll down and click DAP-3520. The emulated login screen will appear.
7. Click Login without entering a new username or password. An emulated Setup screen displaying what a user would see when configuring an actual DAP-3520 is displayed.
8. Click the plus sign (þ) next to Advanced Settings in the left pane to expand the options. 9. Click Performance.
Figure 13-12 BlueAuditor screen
© Cengage Learning 2013
Hands-On Projects 491
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10. The default value next to Beacon Interval (25-500) is 100. Beacons are packets sent by the AP to synchronize the WLAN. Using a higher beacon interval may help to save the battery power of a mobile wireless client. A lower setting can enable a client connect to an AP more quickly. In which type of WLAN would a higher setting be preferable? When would a lower setting be better?
11. The default value next DTIM Interval (1-15) is 1. DTIM Interval indicates the number of AP beacons between each Delivery Traffic Indication Message (DTIM). The DTIM tells the clients of the next window for listening to broadcast and multicast messages. The AP will send the next DTIM with the specified DTIM value to clients if there are any buffered message waiting for them at the AP. Clients will hear the beacons and be prepared to receive the broadcast or multicast messages. The default value for DTIM interval is 1. When would you set this value higher?
12. The Ack TimeOut (2.4GHz, 64~200) indicates a value to optimize throughput over long distance links. When would you set this value higher? When would it be set lower?
13. The Short GI specifies using a short guard interval (400ns) to increase overall throughput. However, enabling this parameter can also have a negative impact. What would be the downside of having a short GI?
14. The Internet Group Management Protocol (IGMP) is a protocol used by devices and routers to exchange information. IGMP snooping allows the AP to recognize IGMP queries and reports sent between routers and wireless devices. When it is enabled the AP can forward multicast packets to the IGMP host based on the IGMP messages that pass through the AP. Would this be desirable?
15. The Connection Limit allows a maximum number of devices to connect to the AP. When should this be set to a low value? When should it be set to a high value?
16. Close all windows.
Case Projects
Case Project 13-1: Bluetooth Security Besides bluejacking and bluesnarfing, there are other security issues that Bluetooth could face as its popularity continues to increase. Use the Internet to research Bluetooth security. What are the attacks that could be launched
against Bluetooth? What are the defenses against these attacks? Will they have an impact on Bluetooth’s popularity? Write a one-page paper on your research.
Case Project 13-2: Future of UWB In addition to concerns regarding interference, other factors have contributed to the stalled growth of UWB. What are these factors? Does UWB have a future or will it be replaced by other technologies? Using the Internet research the problems of UWB, the source of those problems, and what the future holds for UWB. Give your opinion about you believe will happen with this technology. Write a one-page paper on your findings.
492 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13
Case Project 13-3: RFID Passports Although several nations use RFID technology with their paper passports, there was a concern initially voiced that unauthorized individuals could intercept these transmissions and use them in nefarious ways against the passport holders. In response the United States made modifications to the RFID technology in its passports. Research RFID technology in passports, and particularly note the changes the United States made to make them more secure. In your opinion, are these additional security protections adequate? Why or why not? Write a one-page paper on RFID passports.
Case Project 13-4: Body Area Networks Body area networks (BANs) hold the promise of providing significant benefits particularly in the healthcare area to provide patients with more immediate care. Using the Internet, research BANs. What are some ways in which they are being used today? What are some new technologies that may be introduced in the new feature utilizing BANs? And what concerns are there about these networks from a social and a security perspective? Write a one-page paper on BANs.
Case Project 13-5: IEEE 802.11ac The new IEEE 802.11ac standard provides significantly improved data rates and broader coverage areas than previous 802.11 standards. Use the Internet to research this new tech- nology, how it can be used, and what its strengths and weaknesses are. Write a one-page paper on your research.
Case Project 13-6: Nautilus IT Consulting The computer technology business Nautilus IT Consulting (NITC) needs your help with one of their clients.
Hermitage Endoscopy Associates (HEA) is a medical practice in the area. HEA has used IEEE 802.11g technology for both its office use as well as for patients in its waiting room. In addition to standard data utilization, HEA wants to provide both still images as well as video to its physicians on tablet computers as they work with patients. However, it is unsure if IEEE 802.11n or 802.11ac would be the preferred technology.
1. Create a PowerPoint presentation that explains the features of IEEE 802.11ac, how it works, and what its advantages and disadvantages are. Because the HEA is part of a regional hospital the hospital’s healthcare IT staff, who have a strong technology back- ground, will be present so your presentation should be more technical in nature. The presentation should be 8–10 slides in length.
2. HEA has also asked NITC for information regarding BANs and if they could be used in their practice. They already use the video pill but want to know if there are other technologies that would be of benefit in endoscopy. Create a one-page memo about BANs and how they could be used for HEA.
The video pill is covered in Chapter 1.
Case Projects 493
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Notes
i. John Cox, “Wi-Fi client surge forces new look at WLAN designs,”Network World, Jun 20, 2011.
ii. Cisco Visual Networking Index: Forecast and Methodology, 2010–2015, Visual Network- ing Index, http://www.cisco.com/en/US/solutions/collateral/ns341/ns525/ns537/ns705/ns827/ white_paper_c11-481360_ns827_Networking_Solutions_White_Paper.html, accessed Feb 9 2012.
494 Chapter 13 Other Wireless Networks
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
appendixA CWNA Certification Exam Objectives
CWNA Exam Objective Domain Chapter Section
1.0: Radio Frequency (RF) Technologies
1.1.1. Define and explain the basic concepts of RF behavior ● Gain ● Loss ● Reflection ● Refraction ● Diffraction ● Scattering ● VSWR ● Return Loss ● Amplification ● Attenuation ● Absorption ● Wave propagation ● Free Space Path Loss ● Delay Spread
3 4
Radio Frequency Behavior Antenna Installation
1.2.1. Understand and apply the basic components of RF mathematics
● Watt ● Milliwatt ● Decibel (dB) ● dBm ● dBi ● dBd ● SNR ● RSSI ● System Operating Margin (SOM) ● Fade Margin ● Link Budget ● Intentional Radiator ● Equivalent Isotropically Radiated Power (EIRP)
3 4 4
RF Signal Strength Measurements Antenna Concepts Antenna Installation
495 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
CWNA Exam Objective Domain Chapter Section
1.3.1. Identify RF signal characteristics, the applications of basic RF antenna concepts, and the implementation of solutions that require RF antennas
● Visual LOS ● RF LOS ● The Fresnel Zone ● Beamwidths ● Azimuth & Elevation ● Passive Gain ● Isotropic Radiator ● Polarization ● Simple Antenna Diversity ● MIMO Diversity ● Radio Chains ● Spatial Multiplexing (SM) ● Transmit Beam Forming (TxBF) ● Maximal Ratio Combining (MRC) ● Space-Time Block Coding (STBC) ● Cyclic Shift Diversity (CSD) ● Wavelength ● Frequency ● Amplitude ● Phase
3 4 4 4 4
Principles of Radio Frequency Antenna Concepts Types of Antennas Antenna Coverage Patterns Multiple-Input Multiple-Output (MIMO)
1.3.2. Explain the applications of physical RF antenna and antenna system types and identify their basic attributes, purpose, and function
● Omnidirectional / Dipole antennas ● Semidirectional antennas ● Highly-direction antennas ● Sectorized antennas ● MIMO antennas ● Antenna arrays
4 4
Antenna Concepts Types of Antennas
1.3.3. Describe the proper locations and methods for installing RF antennas
● Pole/mast mount ● Ceiling mount ● Wall mount ● Outdoor/Indoor mounting considerations
4 Antenna Installation
1.4.1. Identify the use of the following WLAN accessories and explain how to select and install them for optimal performance and regulatory domain compliance.
● Amplifiers ● Attenuators ● Lightning Arrestors ● Mounting Systems ● Grounding Rods/Wires ● Towers, Safety Equipment, and Concerns ● RF Cables ● RF Connectors ● RF Signal Splitters
4 Antenna Installation
496 Appendix A CWNA Certification Exam Objectives
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
A CWNA Exam Objective Domain Chapter Section
2.0: IEEE 802.11 Regulations and Standards
2.1.1. Identify some of the uses for spread-spectrum technologies
● Wireless LANs ● Wireless PANs ● Wireless MANs ● Wireless WANs
1 Types of Wireless Networks
2.1.2. Comprehend the differences between, and explain the different types of spread-spectrum technologies and how they relate to the IEEE 802.11-2007 standard’s (as amended and including 802.11n-draft2.0) PHY clauses
● DSSS ● HR-DSSS ● ERP ● OFDM ● HT (MIMO)
4 5
Multiple-Input Multiple-Output (MIMO)
Wireless Modulation Technologies
2.1.3. Identify the underlying concepts of how spread-spectrum technology works
● Modulation ● Coding
5 Wireless Modulation Technologies
2.1.4. Identify and apply the concepts which make up the functionality of spread-spectrum technology
● Colocation ● Channel Centers and Widths (all PHYs) ● Primary and Secondary Channels ● Adjacent Overlapping and Nonoverlapping Channels ● Carrier Frequencies ● Throughput vs. Data Rate ● Bandwidth ● Communication Resilience ● Physical Carrier Sense (CSMA/CA) ● Virtual Carrier Sense (NAV)
2 5 6
Types of Wireless LANs Physical Layer Standards MAC Operations
2.2.1. Identify, explain, and apply the frame types and frame exchange sequences covered by the IEEE 802.11-2007 standard
5 Physical Layer Standards
2.2.2. Identify and apply regulatory domain requirements ● Dynamic Frequency Selection (DFS) ● Transmit Power Control (TPC) ● Available Channels ● Output Power
5 Physical Layer Standards
2.2.3. OSI model layers affected by the 802.11-2007 standard and amendments
5 Physical Layer Standards
2.2.4. Use of ISM and UNII bands in Wi-Fi networks 5 Physical Layer Standards
Appendix A CWNA Certification Exam Objectives 497
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
CWNA Exam Objective Domain Chapter Section
2.2.5. Supported data rates for each IEEE 802.11-2007 PHY 2 Types of Wireless LANs
2.2.6. Understand the IEEE standard creation and ratification process and identify IEEE standard naming conventions
● Drafts ● Ratified Amendments ● Supplements ● Recommended Practices ● Standards
1 Wireless Standards Organizations and Regulatory Agencies
2.3.1. Define the roles of the following organizations in providing direction, cohesion, and accountability within the WLAN industry
● Regulatory Domain Governing Bodies ● IEEE ● Wi-Fi Alliance ● IETF
1
7
Wireless Standards Organizations and Regulatory Agencies
Controller-Based Architecture
3.0: IEEE 802.11 Protocols and Devices
3.1.1. Summarize the processes involved in authentication and association
● The IEEE 802.11 State Machine ● Open System Authentication, Shared Key
Authentication, and Deauthentication ● Association, Reassociation, and Disassociation
6 802.11 Medium Access Control (MAC) Layer Frame Formats and Types
3.1.2. Define, describe, and apply the following concepts associated with WLAN service sets
● Stations and BSSs ● Basic Service Area (BSA) ● Starting and Joining a BSS ● BSSID and SSID ● Ad Hoc Mode and IBSS ● Infrastructure Mode and ESS ● Distribution System (DS) ● Distribution System Media ● Layer 2 and Layer 3 Roaming
6 WLAN Service Sets
3.1.3. Explain and apply the following power management features of WLANs
● Active Mode ● Power Save Mode ● Unscheduled Automatic Power Save Delivery (U-APSD) ● WMM Power-Save (WMM-PS) ● Power Save Multi-Poll (PSMP) ● Spatial Multiplexing Power Save (SMPS) ● TIM/DTIM/ATIM
7 Power Management
498 Appendix A CWNA Certification Exam Objectives
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
A CWNA Exam Objective Domain Chapter Section
3.2.1. Describe and apply the following concepts surrounding WLAN frames
● IEEE 802.11 Frame Format vs. IEEE 802.3 Frame Format ● Layer 3 Protocol Support by IEEE 802.11 Frames ● Terminology Review: Frames, Packets, and Datagrams ● Terminology Review: Bits, Bytes, and Octets ● Terminology: MAC & PHY ● Jumbo frame support (Layer 2) ● MTU discovery and functionality (Layer 3)
5 6 6
Physical Layer Standards 802.11 Medium Access Control (MAC) Layer Frame Formats and Types
MAC Operations
3.2.2. Identify methods described in the IEEE 802.11-2007 standard for locating, joining, and maintaining connectivity with an IEEE 802.11 WLAN
● Active Scanning (Probes) ● Passive Scanning (Beacons) ● Dynamic Rate Switching
6 WLAN Service Sets
3.2.3. Define, describe, and apply IEEE 802.11 coordination functions and channel access methods and features available for optimizing data flow across the RF medium
● DCF and HCF coordination functions ● EDCA channel access method ● RTS/CTS and CTS-to-Self protocols ● HT Dual-CTS Protection ● HT L-SIG Protection ● HT Channel Width Operation (20 MHz, 20/40 MHz, PCO) ● HT Operation Modes (0, 1, 2, 3) ● Fragmentation ● AirTime Fairness ● Band Steering
6 7
MAC Operations Autonomous Access Point Architectures
3.3.1. Identify the purpose of the following WLAN infrastructure devices and describe how to install, configure, secure, and manage them
● Autonomous Access Points ● Controller-based Access Points ● Mesh Access Points / Routers ● Enterprise WLAN Controllers ● Remote Office WLAN Controllers ● PoE Injectors (single and multi-port) and PoE-enabled
Ethernet Switches ● WLAN Bridges ● Home WLAN Router
2 2 6
WLAN Infrastructure Devices WLAN Infrastructure Devices MAC Operations
3.3.2. Describe the purpose of the following WLAN client devices and explain how to install, configure, secure, and manage them
● PC Cards (ExpressCard, CardBus, and PCMCIA) ● USB2, CF, and SD Devices ● PCI, Mini-PCI, Mini-PCIe, and Half Mini PCIe Cards ● Workgroup Bridges
2 6
WLAN Client Hardware and Software
MAC Operations
Appendix A CWNA Certification Exam Objectives 499
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
CWNA Exam Objective Domain Chapter Section
4.0: IEEE 802.11 Network Implementation
4.1.1. Identify technology roles for which WLAN technology is appropriate and describe implementation of WLAN technology in those roles
● Corporate data access and end-user mobility ● Network extension to remote areas ● Building-to-building connectivity - Bridging ● Last-mile data delivery – Wireless ISP ● Small Office / Home Office (SOHO) use ● Mobile office networking ● Educational / Classroom use ● Industrial – Warehousing and Manufacturing ● Healthcare – Hospitals and Offices ● Hotspots – Public Network Access ● Municipal Networks ● Transportation Networks (trains, planes, automobiles) ● Law Enforcement Networks
1 Wireless Applications
4.2.1. Identify and explain how to solve the following WLAN implementation challenges using features available in enterprise class WLAN equipment.
● System throughput ● Cochannel and adjacent-channel interference ● RF Noise and noise floor ● Narrowband and wideband RF interference ● Multipath (in SISO and MIMO environments) ● Hidden nodes ● Near/Far ● Weather
4 12 12 12
Multiple-Input Multiple-Output (MIMO)
Troubleshooting a Wireless Network
WLAN Configuration Wireless Device Troubleshooting
4.3.1. IEEE 802.3-2005, Clause 33 (formerly IEEE 802.3af) 2 WLAN Infrastructure Devices
4.3.2. Powering HT (802.11n) devices ● Proprietary midspan & endpoint PSEs ● IEEE 802.3at draft midspan & endpoint PS
2 WLAN Infrastructure Devices
4.4.1. Define, describe, and implement autonomous APs ● Network connectivity ● Common feature sets ● Configuration, installation, and management ● Advantages and limitations ● QoS and VLANs
7 Autonomous Access Point Architectures
500 Appendix A CWNA Certification Exam Objectives
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
A CWNA Exam Objective Domain Chapter Section
4.4.2. Define, describe, and implement WLAN controllers that use centralized and/or distributed forwarding
● Network connectivity ● Core, Distribution, and Access layer forwarding ● Controller-based, mesh, and portal APs ● Scalability ● Intra- and Inter-controller station handoffs ● Configuration, installation, and management ● Advantages and limitations ● Tunneling, QoS, and VLANs
7 Controller-Based Architectures
4.4.3. Define, describe, and implement distributed WLAN architectures
● Network connectivity ● Common feature sets ● Configuration, installation, and management ● Scalability ● Inter-AP handoffs ● Advantages and limitations ● Tunneling, QoS, and VLANs
7 Autonomous Access Point Architectures
4.4.4. Define, describe, and implement a WNMS that manages autonomous APs, WLAN controllers, and mesh nodes
● Network connectivity ● Common feature sets ● Configuration, installation, and management ● Advantages and limitations
7 Wireless Network Management Systems (WNMS)
4.4.5. Define, describe, and implement a multiple channel architecture (MCA) network model
● BSSID / ESSID configuration ● Site surveying methodology ● Network throughput capacity ● Cochannel and adjacent channel interference ● Cell sizing (including micro-cell)
7 Multiple-Channel Architecture (MCA) vs. Single-Channel Architecture
4.4.6. Define, describe, and implement a single channel architecture (SCA) network model BSSID / ESSID configuration (including Virtual BSSIDs)
● Site surveying methodology ● Network throughput capacity ● Cochannel and adjacent channel interference ● Cell sizing ● Transmission coordination ● Channel stacking
7 Multiple-Channel Architecture (MCA) vs. Single-Channel Architecture
Appendix A CWNA Certification Exam Objectives 501
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
CWNA Exam Objective Domain Chapter Section
4.4.7. Define and describe alternative WLAN architectures ● WLAN Arrays ● Mesh Networks ● Cloud Management
7 Other Architectures
4.5.1. Understand WLAN design and deployment considerations for commonly supported WLAN applications and devices
● Data ● Voice ● Video ● Real-Time Location Services (RTLS) ● Mobile devices (tablets and smartphones) ● High density
7
13
Wireless Intrusion Detection and Prevention Systems
IEEE 802.11ac
5.0: IEEE 802.11 Network Security
5.1.1. Identify and describe the strengths, weaknesses, appropriate uses, and implementation of the following IEEE 802.11 security-related items:
● Legacy Security Mechanisms ● Modern Security Mechanisms ● Additional Mechanisms
9 9 10 10 10
Legacy IEEE 802.11 Security Protections
Vulnerabilities of IEEE 802.11 Security
Transitional Solutions IEEE 802.11i/WPA2 Security Other Wireless Security Tools
5.2.1. Describe, explain, and illustrate the appropriate applications for the following wireless security solutions
● Wireless Intrusion Protection System (WIPS) ● Protocol and Spectrum Analyzers
10 Wireless Intrusion Detection and Prevention Systems
5.3.1. Describe the following General Security Policy elements
● Applicable Audience ● Risk Assessment ● Impact Analysis ● Security Auditing ● Policy Enforcement ● Monitoring, Response, and Reporting ● Asset Management
11 Procedural Security Defenses
5.3.2. Describe the following Functional Security Policy elements
● Design and Implementation Best Practices ● Password Policy ● Acceptable Use & Abuse Policy ● Training Requirements ● Physical Security ● Social Engineering
11 Procedural Security Defenses
502 Appendix A CWNA Certification Exam Objectives
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
A CWNA Exam Objective Domain Chapter Section
6.0: IEEE 802.11 RF Site Surveying
6.1.1. Explain the importance of and the processes involved in information collection for manual and predictive RF site surveys. (These happen in preparation for an RF site survey)
● Gathering business requirements ● Interviewing managers and users ● Defining physical and data security requirements ● Gathering site-specific documentation ● Documenting existing network characteristics ● Gathering permits and zoning requirements ● Indoor- or Outdoor-specific information ● Identifying infrastructure connectivity and power
requirements ● Understanding RF coverage requirements ● Understanding data capacity and client density
requirements ● VoWiFi considerations for delay and jitter ● Client connectivity requirements ● Antenna use considerations ● Aesthetics requirements ● Tracking system considerations ● WIPS sensor considerations
8 8
Site Survey Tools Procedures for Performing a Site Survey
6.1.2. Explain the technical aspects involved in performing manual and predictive RF site surveys. (These happen as part of the RF site survey)
● Locating and identifying RF interference sources ● Defining AP and antenna types to be used ● Defining AP and antenna placement locations ● Defining AP output power and channel assignments ● Defining cochannel and adjacent-channel interference ● Testing applications for proper operation ● Measuring performance metrics according to design
requirements
8 Procedures for Performing a Site Survey
6.1.3. Describe site survey reporting and follow-up procedures for manual and predictive RF site surveys. (These happen after the RF site survey)
● Reporting methodology ● Customer reporting requirements ● Hardware recommendations and bills of material ● Application analysis for capacity and coverage verification
8 Creating the Site Survey Report
6.2.1. Identify the equipment, applications, and system features involved in performing predictive site surveys
● Predictive analysis / simulation applications (also called RF planning and management tools)
● Integrated predictive site survey features of WLAN controllers
● Site survey verification tools and/or applications ● Indoor site surveys versus outdoor site surveys
8 What is a site survey?
Appendix A CWNA Certification Exam Objectives 503
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
CWNA Exam Objective Domain Chapter Section
6.2.2. Identify the equipment, applications, and methodologies involved in performing manual site surveys
● Site survey hardware kits ● Spectrum analyzers ● Protocol analyzers ● Active site survey tools and/or applications ● Passive site survey tools and/or applications ● VoWiFi site survey best practices (dB boundaries,
antenna use, balanced links) ● Manufacturer’s client utilities
8 Site Survey Tools
6.2.3. Identify the equipment, applications, and methodologies involved in self-managing RF technologies
● Automated RF resource management
8 What is a site survey?
504 Appendix A CWNA Certification Exam Objectives
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
appendixB URLs for Hands-On Projects
Chapter 1
● Project 1-1: Locating Area Hotspots with Hotspot-Locations (www.hotspot-locations.com) ● Project 1-2: Locating Area Hotspots with Wi-Fi HotSpot List (www.hopspotr
.com/wifi) ● Project 1-3: Installing Network Meter Gadget (www.addgadget.com/network_meter)
Chapter 2
● Project 2-3: Installing and Using Virtual Router (virtualrouter.codeplex.com) ● Project 2-4: Installing and Using Connectify (www.connectify.me)
Chapter 3
● Project 3-2: Installing and Using Vistumbler (www.vistumbler.net) ● Project 3-4: Installing and Using inSSIDer (www.metageek.net/support/downloads)
Chapter 4
● Project 4-1: Using Online Calculators to Compute RF Behavior—Part I (www .swisswireless.org/wlan_calc_en.html)
● Project 4-2: Using Online Calculators to Compute RF Behavior—Part II (www .distributed-wireless.com/calculators/EIRP.html and www.afar.net/rf-link-budget- calculator)
● Project 4-3: Downloading and Installing a Wireless Monitor Gadget (www.xirrus .com/library/wifitools.php)
Chapter 5
● Project 5-1: Comparing WLAN Utilization Statistics Using a Wireless Network Simulator—Part 1 (www.pamvotis.org)
505 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
● Project 5-2: Comparing WLAN Utilization Statistics Using a Wireless Network Simulator—Part 2 (www.pamvotis.org)
● Project 5-3: Downloading and Installing Xirrus Wi-Fi Inspector Wireless Monitor (www.xirrus.com/library/wifitools.php)
Chapter 6
● Project 6-1: Creating a Bootable Linux USB Flash Drive with Network Protocol Analyzer Software (unetbootin.sourceforge.net and www.backtrack-linux.org)
Chapter 7
● Project 7-1: Configuring Access Points—Advanced Settings (www.dlink.com) ● Project 7-2: Configuring Access Points—QoS (www.dlink.com) ● Project 7-3: Configuring Access Points—Performance (www.dlink.com) ● Project 7-4: Configuring Access Points—VLAN (www.dlink.com)
Chapter 8
● Project 8-1: Using Vistumbler as a Site Survey Tool (www.vistumbler.net) ● Project 8-2: Online Site Survey Tool—WLAN Coverage Estimator (www.smartdraw
.com/examples/view/officeþlayoutþwithþmeetingþroom and www.airtightnetworks
.com/home/solutions/80211n/80211n-wlan-coverage-estimator.html) ● Project 8-3: Online Site Survey Tool—Wi-Fi Planning Tool (Part 1) (www.aerohive
.com/planner)
Chapter 9
● Project 9-1: Substitute a MAC Address Using SMAC (www.klcconsulting.net/smac) ● Project 9-2: Configuring Access Points—MAC Address Filtering (www.dlink.com) ● Project 9-3: Configuring Access Points—SSID and WEP Security (www.dlink.com) ● Project 9-4: Crack WEP Encryption (unetbootin.sourceforge.net and www.backtrack-linux.org)
Chapter 10
● Project 10-1: Viewing Security Information with Vistumbler (www.vistumbler.net) ● Project 10-2: Configuring Access Points—WPA2 and WPS (www.dlink.com) ● Project 10-3: Use SSH Application (www.putty.org) ● Project 10-4: Documenting BackTrack 5 Wireless Tools (unetbootin.sourceforge.net
and www.backtrack-linux.org)
Chapter 11
● Project 11-1: Viewing SNMP MIBs (www.mibdepot.com) ● Project 11-2: Configuring Access Points—Firmware Upgrade and WPS (www.dlink.com) ● Project 11-3: Configuring Access Points—Event Logs (www.dlink.com)
506 Appendix B URLs for Hands-On Projects
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
B
Chapter 12
● Project 12-2: Configuring Access Points—IP Address Distribution (www.dlink.com) ● Project 12-3: Configuring Access Points—Overlap, VLANs and Guest Networks
(www.dlink.com)
Chapter 13
● Project 13-1: Viewing Bluetooth Devices using BluetoothView (www.nirsoft.net/utils/ bluetooth_viewer.html)
● Project 13-2: Viewing Bluetooth Devices using Blueauditor (www.wifiauditor.com) ● Project 13-3: Configuring Access Points—Performance (www.dlink.com)
Appendix B URLs for Hands-On Projects 507
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
appendixC Wireless Web Sites
A wealth of wireless information is available on the Internet in a variety of forms. A sample listing of some of these sites is provided below.
It is not unusual for Web sites to change the location of where files are stored. If the URLs below no longer function, then open a search engine and search for the item(s) or Web site(s).
Wireless Standards Organizations and Regulatory Agencies
● Institute of Electrical and Electronics Engineers (IEEE). The IEEE Web site covers the current activities of working groups and task groups along with the technical IEEE 802 standards that can be freely downloaded. The Web address is www.ieee.org.
● Wi-Fi Alliance. The Wi-Fi Alliance organization has information on Wi-Fi standards, locating a hot spot, technical papers on wireless transmissions, and other material. The URL is www.wi-fi.org.
● Federal Communications Commission. Information regarding FCC proposed action, stra- tegic goals, and consumer issues that relate to wireless transmissions can be found at www.fcc.gov.
● International Telecommunication Union Radio Communication Sector (ITU-R). The ITU-R manages the international radio frequency spectrum and develops standards for wireless communications systems to ensure the most effective possible use of the spec- trum. Its URL is www.itu.int.
● International Organization for Standardization (ISO). The ISO is an international body that sets industrial and commercial standards and is known for its OSI networking model. The Web address is www.iso.org.
509 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Technical Support ● D-Link. Support for D-Link wireless products can be found at www.dlink.com/support/
products/. ● Netgear. The support site for Netgear wireless products is my.netgear.com/
myNETGEAR/support.asp. ● Cisco. The Web address of the Cisco technical support site is www.cisco.com/en/US/
support/index.html. ● Linksys. The Linksys support page is found at homesupport.cisco.com/en-us/support/
linksys. ● Microsoft. The Microsoft TechNet site contains information about wireless at the address
technet.microsoft.com/en-us/network/bb530679.
Wireless Security ● Wardrive. The Wardrive Web site (www.wardrive.net) contains technical papers,
tips, and techniques for securing a WLAN from wireless security threats. ● The Unofficial 802.11 Security Web Page. This site has numerous articles and links
regarding wireless security. The URL is www.drizzle.com/~aboba/IEEE.
Security Organizations ● Computer Emergency Response Team Coordination Center. The Computer Emergency
Response Team Coordination Center is part of a federally funded research and develop- ment center at Carnegie Mellon University’s Software Engineering Institute in Pittsburgh, Pennsylvania. It was created in 1988 to coordinate communication among experts during security emergencies and also to help provide information to prevent future attacks. In addition to responding to security incidents and analyzing vulnerabilities in applications, the Computer Emergency Response Team Coordination Center also develops and pro- motes secure systems, organizational security, coordinated response systems, and educa- tion and training. Their Web site is www.cert.org.
● Forum of Incident Response and Security Teams (FIRST). FIRST is an international security organization composed of over 170 incident response teams from educational institutions, governments, and business. FIRST’s goal is to both prevent and quickly respond to local and international security incidents as well as promote information sharing. Its Web site is www.first.org.
● InfraGard. The goal of InfraGard is to improve and extend information sharing between private industry and the FBI when dealing with critical national infrastructures. InfraGard provides both formal as well as information channels for exchanging information. Its URL is www.infragard.net.
● Information Systems Security Association (ISSA). ISSA is an international organization of security professionals and practitioners that provides research and education regarding
510 Appendix C Wireless Web Sites
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
C
computer security. The ISSA also sponsors advanced security certification programs. Its Web site is www.issa.org.
● National Security Institute (NSI). The NSI provides information about a variety of secu- rity vulnerabilities and threats. The Web site is www.nsi.org.
● Computer Security Resource Center (CSRC). The CSRC site is maintained by the National Institute of Standards and Technology and provides guidelines and assistance as security relates to the economic and national security interests of the U.S. The site is located at csrc.nist.gov.
Wireless Tools ● Kismet. Kismet is an 802.11 layer2 wireless network detector and intrusion detection
system. Kismet will work with many different types of wireless cards to detect wireless traffic. The Web site is www.kismetwireless.net.
● Fake AP. Black Alchemy’s Fake AP generates thousands of counterfeit 802.11b access points to confuse wireless sniffers. The address is www.blackalchemy.to/ project/fakeap.
● WildPackets. WildPackets offers several commercial products for analyzing and protecting WLANs. Its address is www.wildpackets.com.
● Aircrack-ng. Aircrack-ng is a tool to crack WEP and WPA-PSK and audit wireless networks. It is located at www.aircrack-ng.org.
Other ● Wireless Protocol Analyzer Comparisons. This site provides a comparison of free
and commercial wireless protocol analyzers and links to these resources. The URL is www.personaltelco.net/wiki/WirelessSniffer.
● CWNP Blog. The official blog of CWNP contains information about wireless technologies and the CWNA certification. It is found at www.cwnp.com/cwnp_wifi_blog.
● Wireless Networking Resources. This Web site contains information and links to a wide variety of wireless networking resources. The URL is www.bengross.com/wireless.
● Wireless Blog. This blog is designed for wireless engineers and contains technical wireless information. The blog is www.my80211.com/80211.
Other 511
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Glossary 10’s and 3’s Rules of RF Math A shortcut for calculating the increase or decrease of RF values.
16-level quadrature amplitude modulation (16-QAM) A modulation technique that sends 16 different signals simultaneously.
180 degrees out of phase Term used to describe two electromagnetic signals that are the complete opposite of each other.
2X mode A proprietary transmission scheme that doubles the effective rate of an 802.11a network.
4G (Fourth Generation) A cellular wireless data network with average download speeds of 4 Mbps.
64-level quadrature amplitude modulation (64-QAM) A modulation technique that can transmit 1.125 Mbps over each of 48 subchannels.
absorption The RF propagation behavior in which an RF signal is assimilated into a material.
acceptable use policy (AUP) A policy that defines the actions users may perform while accessing systems and networking equipment.
access category (AC) The classes of an EDCA.
access control Granting or denying approval to use specific resources.
access point (AP) A device that connects wireless devices to each other and to a wired network.
access point mode A mode of a wireless bridge that causes the bridge to function as a standard AP only. In access point mode, a wireless bridge does not communicate with other remote wireless bridges but only with wireless client devices.
active gain The gain in which additional power was sent to the antenna from the power source.
active mode A power management state in which the station is con- tinuously awake.
active RFID tag An RFID tag that must have its own power source.
active scanning A process in which a station first sends out a man- agement probe request frame on an available channel.
ad hoc mode A wireless network that does not use an AP.
ad hoc traffic indication message (ATIM) window A specific period of time that each station must be awake.
ad hoc wireless mesh network A network in which wireless client devices act as the relay station for signals to and from the AP.
adjacent channel interference Each cell is separated from other cells so that no two adjacent cells have the same channel number in order to reduce interference.
Advanced Encryption Standard (AES) The block cipher used in IEEE 802.11i/WPA2.
Aggregate MAC Protocol Data Unit (A-MPDU) A data unit that allows multiple MPDUs to be aggregated together.
Aggregate MAC Service Data Unit (A-MSDU) A data unit that allows multiple MSDUs to be combined together.
algorithm Procedures based on a mathematical formula; used to encrypt the data.
all-band interference RF interference that covers all bands of the RF spectrum.
amperes (amps) The measure of the flow of electrical current.
amplification An increase in a signal’s strength to achieve gain.
amplifier A device that amplifies or increases the amplitude of an RF signal.
amplitude The magnitude of the change of a wave; measured by how high or how deep the wave is.
amplitude modulation (AM) A modification of an analog electro- magnetic wave that changes the amplitude (height) of the wave.
amplitude shift keying (ASK) A modification of a digital electro- magnetic wave that changes the amplitude (height) of the wave.
analog signal A continuous signal with no “breaks” in it.
anomaly-based monitoring A method for auditing usage by detecting statistical anomalies.
antenna array Multiple antennas that can be customized to send an optimal signal.
antenna diversity The ability of an access point to examine multiple copies of a received transmission and then select the best signal.
antenna radiation chart A chart used to illustrate an antenna’s radiation pattern.
antenna A passive conductor used to transmit electromagnetic waves through space.
Arbitration IFS (AIFS) An interframe space that is used when setting priorities to different types of transmissions.
asset An item that has value.
asset management The task of identifying and categorizing assets.
association The final step in the process of a station being accepted into the wireless network.
attenuation Loss of signal strength that results in a decrease in the signal’s amplitude.
authentication The process of a station being accepted by the AP into the WLAN.
authentication request A data packet in an IEEE 802.1X network that contains the specific AP that is sending the authentication request and the user name and password.
authenticator A device in an IEEE 802.1X network that accepts or rejects a supplicant.
automated RF resource management A dynamic self-managing WLAN in which the wireless devices monitor the environment and then automatically adjust power levels or channels to compensate for changes.
Automatic Private IP Addressing (APIPA) An IP address that begins with the IP range 169.254.x.x and is assigned if a device cannot receive a valid IP.
autonomous access point A device that is separate from other network devices including other autonomous access points and that contains all the intelligence required for wireless authentication, encryption, and management.
autonomous body sensor network (ABSN) A network that introduces actuators in addition to sensors so that immediate effects can be made on the human body.
availability Security actions that ensure that data is accessible to authorized users.
Azimuth chart A chart that represents the horizontal coverage area of an antenna.
513 Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
backhaul connection An organization’s internal infrastructure connection between two or more remote locations.
backhaul wireless mesh network A wireless mesh network (WMN) that connects mesh access points for the purpose of sharing an Internet connection.
backoff interval A random amount of time that two sending devices pause after a collision.
bands The 450 different sections of the electromagnetic spectrum.
bandwidth The difference between the upper and lower frequencies.
Barker code The bit pattern used in direct sequence spread spectrum (DSSS) modulation.
Basic Service Area (BSA) The physical area of RF coverage provided by the AP of a BSS.
Basic Service Set (BSS) One or more stations that are served by a AP.
Basic Service Set Identifier (BSSID) The media access control (MAC) address of the AP.
beaconing The process by which the AP sends a beacon frame to both announce its presence and to provide the necessary information for wireless stations wanting to join the network.
beamwidth A measurement of a transmission’s width.
behavior-based monitoring A method for auditing usage by using the normal processes and actions as the standard.
bidirectional amplifier A device that increases the RF signal before it is injected into the device that contains or is directly connected to the antenna.
bill of materials (BOM) A list of itemized software and/or hardware components that are needed for a new WLAN.
block acknowledgment An IEEE 802.11n feature that supports multiple MPDUs in an A-MPDU.
block cipher An encryption cipher that manipulates an entire block of plaintext at one time.
bluejacking An attack that sends unsolicited messages to Bluetooth- enabled devices.
bluesnarfing An attack that accesses unauthorized information from a wireless device through a Bluetooth connection.
Bluetooth A WPAN technology that uses short-range transmissions.
Bluetooth piconet A Bluetooth network consisting of a master and at least one slave device.
Bluetooth scatternet A Bluetooth network consisting of a group of Bluetooth piconets, with connections between the different piconets.
body area networks (BAN) A network system of devices in close proximity to a person’s body that cooperate for the benefit of the user.
bridge A device that is used to connect two network segments together, even if those segments use different types of physical media.
Broadband Radio Service (BRS) A WMAN technology that uses microwave frequencies to transmit at distances of up to 35 miles (56 kilometers).
broadcast Network traffic sent to all users on the network.
broadcast probe A probe request frame sent by a station with a null value as the SSID so that all APs will respond.
bus On a computer, the subsystem for transferring data between the system’s components.
bus mastering A technology that allows a controller on the bus to talk to other devices or memory without going through the CPU.
cable lock A lock inserted into the security slot of a portable device and the cable connected to the lock that is secured to a desk or chair.
captive portal AP An AP that uses a standard Web browser to provide information, give the wireless user the opportunity to agree to a policy, or present valid login credentials.
CardBus A 32-bit bus in the PC Card form factor.
care-of address A new and temporary IP number assigned in Mobile IP.
carrier A modified electromagnetic wave that is used to transmit information. Also known as a carrier wave or a carrier signal.
Carrier Sense Multiple Access with Collision Avoidance (CSMA/CA) The IEEE 802.11 standard that is designed to handle collisions when they occur.
Carrier Sense Multiple Access with Collision Detection (CSMA/CD) A channel access method used by Ethernet.
carrier sensing The process in which a network device first listens on the wire to see if any other device is currently transmitting.
carrier signal See carrier.
carrier wave See carrier.
cell overlap The area between two APs in which a wireless device begins to search for a new AP with which to associate.
Certified Wireless Network Administrator (CWNA) A certification that is the foundation level wireless LAN certification for the CWNP program.
challenge text The text that is encrypted in shared key authentication.
channel A numeric value assigned to a frequency range.
channel access methods The different ways of sharing the network medium.
channel stacking A technology that allows for increased capacity by having more than one SCA operating in an area.
chipping code The bit pattern used in direct sequence spread spectrum (DSSS) modulation.
ciphertext Data that has been encrypted.
cleartext Unencrypted data.
client network adapter A device that connects a computer to a wired network.
closed circuit television (CCTV) Using video cameras to transmit a signal to a specific and limited set of receivers for security.
Cloud management Connecting wireless devices together using the Internet in order to remotely manage them.
cochannel interference Reduced throughput caused as a result of all of APs set to the same channel number.
colocation Sharing a frequency band between similar devices.
communication resilience Term used to describe transmissions that are less prone to interference.
CompactFlash (CF) A small form factor that is generally used as a mass storage device format for portable electronic devices.
complementary code keying (CCK) A coding technique used in 802.11b networks that consists of a set of 64 8-bit code words.
conductor A material that allows an electrical current to flow through it.
confidentiality Security actions that ensure only authorized parties can view the information.
514 Glossary514 Glossary
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
consortia Industry-sponsored organizations that want to promote a specific technology. Consortia often take on the task of creating standards for specific technologies.
contention A channel access method in which devices contend or compete with each other to use the network medium.
control frames Frames that provide assistance in delivering frames that contain the data by controlling access to the medium.
convolutional coding rate A type of error-correcting code.
cooperative control A proprietary product in which each AP contains the capabilities of a WLC.
corruption The loss in a signal that occurs when a delayed multipath signal is significantly out-of-phase with the primary signal.
Counter Mode with Cipher Block Chaining Message Authentication
Code Protocol (CCMP) The encryption protocol used for 802.11i/ WPA2.
cryptography The science of transforming information into a secure form while it is being transmitted or stored so that unauthorized persons cannot access it.
CTS-to-self A process used when 802.11g devices are mixed with 802.11b devices together.
current (I) The flow of electrical energy.
cycle The repetitive movement of an electromagnetic wave that returns back to its starting point.
cyclic redundancy check (CRC) A checksum value that is based on the contents of the text.
Cyclic Shift Diversity (CSD) A technique that sends a normal version of the signal along with a shifted version of the same signal.
data frame Frame that carries the information to be transmitted to the destination device.
data rate The theoretical maximum rated speed of a network.
deadbolt lock A door lock that extends a solid metal bar into the door frame for extra security.
decibel milliwatt (dBm) The power ratio in decibels (dB) of the measured power referenced to one milliwatt (mW).
decibels (dB) The measure used to determine RF power gain and loss on a relative scale.
decibels dipole (dBd) A measurement that compares the antenna gain against that of a dipole antenna.
decibels isotropic (dBi) The passive gain of power that is funneled from an antenna compared to that of an isotropic radiator sent in all directions.
decryption The process of changing ciphertext into plaintext.
de facto standards Standards that are common practices that the industry follows for various reasons such as ease of use or tradition.
de jure standards Standards that are official standards controlled by an organization or body that has been entrusted with that task.
delay The amount of acceptable time that a late packet can arrive and still be used.
delay spread The difference in time of multipath signals that reach the receiver.
delivery traffic indication message (DTIM) A special TIM sent by an AP that is used when a station in power save mode must receive a frame intended for all stations.
denial of service (DoS) An attack that attempts to prevent a device from performing its normal functions.
detector A device that receives a signal.
dictionary attack An attack that compares encrypted versions of common dictionary words against data captured through wireless transmissions.
differential binary phase shift keying (DBPSK) A two-level phase shift key used in 802.11b networks.
differential quadrature phase shift keying (DQPSK) A four-level phase change used in 802.11b networks.
diffraction The RF propagation behavior in which an RF signal bends in response to striking a rough surface.
diffused transmission An infrared wireless transmission that relies on reflected light.
digital signal A signal that consists of data that is discrete or separate.
dipole An antenna consisting of a single stretched wire with connection in the middle.
direct sequence spread spectrum (DSSS) A wireless modulation tech- nique that uses an expanded redundant code to transmit each data bit.
directed probe A probe request frame sent by a station that contains a specific SSID that the device is searching for.
directed transmission An infrared wireless transmission that requires that the emitter and detector be directly aimed at one another.
Distributed Coordination Function (DCF) The standard IEEE 802.11 contention method.
Distributed Coordination Function IFS (DIFS) An interframe space that is the standard interval between the transmission of data frames.
distributed WLAN architecture A wireless architecture configuration in which multiple APs form a non-centralized network through a wireless connection.
distribution system (DS) A system that is used by an AP to determine what communication needs to take place with other APs in the ESS or with the wired network.
distribution system media The media, either wired network, a wireless radio, or special purpose device, that interconnects APs.
downfade The signal loss that occurs when a delayed multipath signal is out-of-phase with the primary signal.
dwell time The amount of time that a transmission remains on a specific frequency in FHSS.
Dynamic Frequency Selection (DFS) A technology in which IEEE 802.11n WLANs using 40-MHz channels can automatically move to another channel or switch to 20-MHz operation to minimize interference.
dynamic rate switching A technology that allows a station farther away from an AP to still remain connected to the network but at a slower speed.
dynamic WEP An enhancement to WEP that uses rotating keys.
Electrically-Erasable Programmable Read-Only Memory (EEPROM)
The circuitry on which firmware resides.
electromagnetic interference (EMI) An undesirable electronic distur- bance, either manmade or natural, which causes an undesirable degrading in the performance of electrical equipment.
electromagnetic spectrum The range of all the different types of electromagnetic waves.
electromagnetic wave A special form of energy that transmits heat and light.
elevation chart A chart that represents the vertical coverage area of an antenna.
Glossary 515Glossary 515
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
emitter A device that transmits a signal and is used in an IEEE 802.11 infrared network.
encryption The process of changing plaintext into ciphertext.
endspan device A Power over Ethernet (PoE) device that injects power through a network device like a switch to provide power on each port.
Enhanced Distributed Channel Access (EDCA) An HCF that divides transmissions into four different classes.
Enterprise Encryption Gateway (EEG) A device that provides encryption and authentication services for a wireless network.
Equivalent (also called Effective) Isotropically Radiated Power (EIRP)
The amount of power that a theoretical isotropic radiator can generate.
event log A record of events.
evil twin An imposter AP that is set up by an attacker.
explicit feedback A TxBF technique in which the receiver makes a series of computations and sends them to the transmitter, which then uses them to configure how to make the best transmissions.
exploiting Taking advantage of a vulnerability.
ExpressCard A type of expansion card designed to deliver higher- performance modular expansion in a small size.
Extended IFS space (EIFS) An interframe space that is used when frames must be retransmitted.
extended rate PHYs (ERP) A mandatory mode for the faster 54 Mbps in IEEE 802.11g.
Extended Service Set (ESS) Two or more BSS networks that are interconnected.
Extensible Authentication Protocol (EAP) A framework for trans- porting the authentication protocols in an IEEE 802.1X network.
fade margin The difference between the received signal level and the signal level that is required by that radio to assure that the transmis- sion can be decoded without errors.
fat access points Devices that are separate from other network devices and even other (autonomous) access points that have all of the “intelligence” for wireless authentication, encryption, and management contained within the AP itself.
Federal Communications Commission (FCC) A body that serves as the primary regulatory agency for wireless communications in the United States and its territorial possessions.
fencing Securing a restricted area by erecting a barrier.
firmware Software that is embedded into hardware to control the device.
fixed-loss attenuator An RF attenuator that limits the RF power by a set amount.
Fixed WiMAX A WWAN based on IEEE 802.16-2004 that can serve as a substitute for fiber optic connections between buildings.
foreign agent A device that provides routing services to the mobile computer in Mobile IP.
foreign network A different network in Mobile IP.
form factor A term used to refer to the size and shape of a device.
Forward Error Correction (FEC) An IEEE 802.11a error correction technique that transmits a secondary copy along with the primary information.
frame acknowledgment An acknowledgment frame sent by the receiving device back to the sending device to confirm that the data frame arrived intact.
free space optics (FSO) An optical, wireless, point-to-point, line- of-sight wireless technology for outdoor transmissions.
free space path loss (FSPL) The “natural” loss of signal strength that occurs as a signal travels through space.
frequency The number of times that a wave completes a cycle within a given amount time.
frequency-hopping spread spectrum (FHSS) A modulation technique that uses a range of frequencies that change during the transmission.
frequency modulation (FM) A modification of an analog electro- magnetic wave that changes the frequency (number of waves).
frequency shift keying (FSK) A modification of a digital electro- magnetic wave that changes the frequency (number of waves).
Fresnel zone An elliptical area immediately surrounding the visual line of sight of an RF transmission.
full-channel FHSS A FHSS technology in which the devices use a minimum of 75 hop channels.
gain The positive difference in amplitude between two signals.
gateway A network device that acts as an entrance to another network.
global positioning system (GPS) A system of earth-orbiting satellites used as a navigation system.
Greenfield Mode A mode in which all of the stations in the BSS or ESS are 802.11n devices operating at the same HT speed with the same parameters.
ground rod A metal rod inserted in the earth to ground an antenna.
guard interval (GI) A delay built-in into the receiver to allow for late- arriving symbols.
Half Mini PCIe card A PCI-e card that is half the length of a Mini- PCI-e card.
handoff The process by which a station associates with a new AP.
HCF Controlled Channel Access (HCCA) The process of using polling along with centralized scheduling that is controlled by the AP.
hertz (Hz) The unit of measurement for electromagnetic frequencies.
heuristic monitoring A method for auditing usage by using an algo- rithm to determine if a threat exists.
hidden node problem A station that is within range of an AP but not another station.
high-density WLANs Wireless networks that are used in areas in which large numbers of devices are clustered close together.
high-gain antennas Antennas that have longer ranges and higher sig- nal quality than low-gain antennas yet must be aimed precisely in a particular direction.
highly-directional antenna An antenna that sends a narrowly focused signal beam long distances.
High-Rate DSSS (HR-DSSS) Transmission rates above 2 Mbps in IEEE 802.11b.
home agent A forwarding mechanism in Mobile IP that keeps track of where the mobile computer is located.
hopping code The sequence of changing frequencies in FHSS.
hop time The time it takes to change a frequency in FHSS.
hotspot A specific geographic location that is served by a wireless data system and provides network access to mobile users.
HT (MIMO) High Throughput Multiple-Input Multiple-Output for IEEE 802.11n WLANs that utilize a radio chain for each antenna.
516 Glossary516 Glossary
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
HT 20 MHz Protection Mode An HT Operation Mode in which a 20-MHz-only HT device associated with a 20/40-MHz AP cannot transmit simultaneously with a 40-MHz device.
HT Dual-CTS Protection A protection mechanism used with 802.11n devices in a mixed environment with 802.11a/b/g devices.
HT L-SIG Protection A protection mechanism used with 802.11n devices in a mixed environment with 802.11a/b/g devices.
HT Mixed Mode A mode in which both 802.11n and 802.11a/b/g devices can interoperate in the same BSA.
HT Nonmember Protection Mode A mode in which all stations use the non-HT 802.11a/b/g format to ensure backwards compatibility.
HT Operation Modes Different modes that allow faster HT devices to interoperate with slower devices.
hybrid coordination function (HCF) The IEEE 802.11 optional function that allows for different types of wireless traffic to be given different levels of priority.
Hypertext Transport Protocol over Secure Sockets Layer (HTTPS) A security protocol that uses HTTP sent over SSL/TLS.
IEEE 802.11 The first wireless LAN standard with a speed of 1 and 2 Mbps.
IEEE 802.11-2007 The official document of all of the IEEE 802.11 standards and amendments.
IEEE 802.11a A wireless LAN standard that specifies a speed of 54 Mbps and uses a different set of radio wave frequencies than 802.11b.
IEEE 802.11ac A proposed WLAN standard to support higher data rates in part to address the demand for wireless video delivery.
IEEE 802.11b A wireless LAN standard with a maximum speed of 11 Mbps.
IEEE 802.11e-2005 The IEEE QoS standards.
IEEE 802.11g A wireless LAN standard that supports a speed of 54 Mbps and uses the same set of radio wave frequencies as 802.11b.
IEEE 802.11i (also known as robust security network (RSN)) The current wireless security standard ratified by the IEEE in 2004.
IEEE 802.11n-2009 A wireless LAN standard that supports a speed of up to 600 Mbps while also increasing the area of coverage.
IEEE 802.1q An IEEE standard for marking VLAN packets.
IEEE 802.1X A standard originally developed for wired networks that blocks all traffic on a port-by-port basis until the client is authenticated.
impedance The total amount of resistance to the flow of electrical current.
implicit feedback Information that is computed by the receiver and sent back to the transmitter for use in antenna configuration.
Independent Basic Service Set (IBSS) A wireless network that does not use an AP.
Industrial, Scientific and Medical (ISM) An unlicensed band used for WLANs.
information security The tasks of securing information that is in a digital format.
Infrared Data Association (IrDA) A nonprofit consortium that developed standards for connecting different computer and tele- communications devices using infrared light.
infrared light An invisible light that can be used for wireless transmissions.
infrastructure mode A wireless network that uses an AP.
initialization vector (IV) A 24-bit WEP value that changes each time a packet is encrypted.
in phase Two electromagnetic signals that have the same peaks and valleys.
Institute of Electrical and Electronics Engineers (IEEE) An organiza- tion best known for its work in establishing standards for computer networks.
integrated sensor (also AP sensor or embedded sensor) A WIDS/ WIPS sensor that uses existing APs to monitor the RF.
integrity Security actions that ensure that the information is correct and no unauthorized person or malicious software has altered the data.
integrity check value (ICV) The checksum value generated by WEP.
intentional radiator (IR) A system used to create and transmit RF signals as defined by the Federal Communications Commission (FCC).
interframe spaces (IFS) The standard spacing intervals between the transmissions of the data frames.
International Organization for Standardization (ISO) An international body that sets industrial and commercial standards.
International Telecommunication Union Radio Communication
Sector (ITU-R) A division of the International Telecommunication Union (ITU) that is responsible for the global management of the radio frequency spectrum.
intersymbol interference (ISI) Signal interference as a result of multipath transmission.
intrusion system A security management system that compiles information from a computer network or individual computer and then analyzes it to identify security vulnerabilities and attacks.
isotropic radiator A source of RF waves that have the exact same magnitude or properties in all directions.
IV attack An attack that determines the keystream by analyzing two packets that were created from the same IV.
jitter The measure of delay between packets.
jumbo frame support The ability of network devices to accept frames that are between 1,500 and 9,000 bytes.
Kerberos An authentication system developed by the Massachusetts Institute of Technology (MIT) and used to verify the identity of networked users.
key A mathematical value entered into the algorithm to produce ciphertext.
keying See modulation.
keystream The output from a pseudo-random number generator (PRNG).
keystream attack An attack that determines the keystream by analyzing two packets that were created from the same IV.
last mile connection The connection that begins at a fast Internet service provider, goes through the local neighborhood, and ends at the home or office.
latency The time lapse between when a packet is sent on a network and when it is received.
layer 2 roaming A roaming process that occurs between APs on the same subnet.
layer 3 roaming A roaming process that occurs between APs on a different subnet.
license-exempt spectrum Parts of the radio spectrum that are available nationwide to all users without requiring a license.
Glossary 517Glossary 517
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
lightning arrestor A device that limits the amplitude and disturbing interference voltages by channeling them to the ground.
light spectrum All visible and invisible light.
lightweight access points An access point that does not contain the management and configuration functions that are found in autonomous access points.
lightweight mesh AP A mesh AP that is centrally configured and managed through a WLC.
Line of sight (LoS) Term used to refer to a setting in which an emitter is aimed directly at a transmitter with no intervening obstacles.
link budget A rough calculation of all known elements of a link to determine if a signal will have the proper strength when it reaches its destination.
Long Term Evolution (LTE) A wireless metropolitan area network technology that can provide access from up to 10 miles (15 km) in distance.
low-gain antennas Antennas with a shorter range than high-gain antennas that do not have to be precisely aimed at the receiver.
MAC Protocol Data Unit (MPDU) A data unit that is simply an IEEE 802.11 frame.
MAC Service Data Unit (MSDU) A data unit that contains data from Layers 3-7 along with LLC data.
managed body sensor network (MBSN) A network that utilizes sensors placed on the human body to monitor human biological functions that are transmitted to a third party physician.
management frames Frames that are used to set up the initial com- munications between a device and the access point (for infrastructure mode) or between stations (for ad hoc mode), and then maintain the connection.
management information base (MIB) The storage area in which SNMP software agents store their data.
man-in-the-middle An attack that makes it appear that the wireless device and the network computers are communicating with each other, when actually they are sending and receiving data with an evil twin AP between them.
manual site survey A site survey that requires walking through the area of the WLAN while carrying a wireless client like a laptop or tablet computer.
maximal ratio combining (MRC) The algorithm a MIMO AP uses when it receives multiple copies of a signal from a non-MIMO device.
maximum transmission unit (MTU) The frame size in an IEEE 802.11 network.
Media Access Control (MAC) address filtering Restricting admission to a WLAN based on the client device’s MAC address.
mesh access point An access point that communicates wirelessly with the next closest mesh access point.
Message Integrity Check (MIC) Part of the WPA standard designed to prevent an attacker from conducting active or passive man- in-the-middle attacks.
micro-cell architecture A wireless architecture that creates small areas of coverage.
microseconds (μs) One millionth of a second.
midspan device A Power over Ethernet (PoE) device that is connected in-line to each end device and adds power to the line.
milliseconds (ms) One thousandth of a second.
milliwatt (mW) One thousandth of a watt of power.
MIMO diversity A MIMO technique of sending the same transmission out on different paths from different antennas.
Mini-PCI A connector in a laptop computer used to expand the laptop’s capabilities.
Mini-PCI-e A smaller version of a Mini-PCI connector.
Mobile IP A mechanism within the TCP/IP protocol to better support mobile computing.
mobile telecommunications switching office (MTSO) The link between the cellular network and the wired telephone world that controls all of transmitters and base stations in the cellular network.
Mobile WiMAX A WWAN based on IEEE 802.16e-2005 that can connect mobile devices over a wide area.
modulation The modification of an electromagnetic wave to transmit information; also called keying.
Modulation and Coding Scheme (MCS) A system that assigns a numeric value to each of the 77 possible transmission combinations IEEE 802.11n.
multipath The phenomena in which multiple copies of a signal reach the receiver at different times.
multiple-channel architecture (MCA) A wireless architecture in which more than one channel is used in the wireless network.
Multiple-Input Multiple-Output (MIMO) A system that uses one radio chain for each antenna so that each antenna can simultaneously transmit and receive signals.
multiplexing The process of sending multiple signals simultaneously.
multiport PoE injectors A PoE injector that can provide power to multiple cables simultaneously.
Multi-User MIMO (MU MIMO) An IEEE 802.11ac technology that enables the simultaneous transmission of different data frames to different clients.
municipal network A hotspot funded by city, county, or other local governments.
nanosecond One billionth of a second.
narrowband interference RF interference that is usually generated by television, radio, and satellite transmitters and that impacts a narrow portion of the spectrum, without affecting the rest of the band.
narrowband transmission Radio signals that are sent on only one radio frequency or a very narrow portion of the frequencies.
near/far A transmission problem involving two wireless devices, in which the wireless device closest to the AP transmits at a higher power than the other, more distant device, thereby overwhelming the weaker signal from the distant device.
near field communication (NFC) A set of standards primarily for smartphones and smart cards that is used to establish communication between devices.
net allocation vector (NAV) The field in which the time reserved for the medium in RTS/CTS is stored.
network interface card (NIC) A device used to connect a computer to a network.
noise Unwanted interference that impacts an RF signal.
noise floor A measure of the total of all the noise from different systems.
nonroot mode A mode of a wireless bridge in which the bridge can transmit only to a wireless bridge that is in root mode.
nulling The cancellation of a signal that occurs when a delayed multipath signal is 180 degrees out of phase with the primary signal.
518 Glossary518 Glossary
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
ohms The measure of the restriction of the flow of current.
omnidirectional antenna An antenna that radiates its signal out horizontally in all directions equally.
open system authentication The process of a client connecting to a WLAN by sending a request to the AP with the SSID of the network it wants to join.
open system authentication The process of a station sending an association request frame to an AP to be accepted into the WLAN.
Open Systems Interconnection (OSI) reference model A seven-layer model that conceptually illustrates the steps of networking.
orthogonal frequency division multiplexing (OFDM) A modulation technique that splits a single high-speed digital signal into several slower signals running in parallel.
oscillating signal The visual representation of up-and-down electrical waves.
out of phase Term used to describe two electromagnetic signals with peaks and valleys that do not match.
overlay sensor A WIDS/WIPS sensor that uses separate dedicated sensors for scanning the RF for attacks.
passive gain The gain in which no additional power is added.
passive RFID tag An RFID tag that does not have its own power supply but uses the tiny electrical current induced in the antenna by the incoming signal.
passive scanning A process in which a station changes to the different channels that it supports and listens for a beacon frame for a set period of time.
password policy A policy that address how passwords are created and managed.
PBCC-22 (Packet Binary Convolutional Coding) An optional 802.11g technique for transmitting at 22 Mbps.
PC Card A type of expansion card used in a laptop computer, also known as a PCMCIA card.
PCI Express (PCI-e) An expansion slot that contains a high-speed point-to-point serial bus. This technology has replaced the older shared parallel PCI bus architecture.
PCMCIA (Personal Computer Memory Card International Associa-
tion) cards A type of expansion card used in a laptop computer.
peer-to-peer A wireless network that does not use an AP.
Peripheral Component Interconnect (PCI) Expansion slots inside the computer that allow devices to be added to the system.
per-packet key Dynamically generating a new key for each packet to preventing collisions.
Per-User Preshared Keys (PPSK) A technology that combines many of the advantages of 802.1X with the ease of use of PSK.
phase The relationship between at least two signals that share the same frequency yet have different starting points.
phase modulation (PM) A modification of an analog electromagnetic wave that changes the starting point of the wave.
phase shift keying (PSK) A modification of a digital electromagnetic wave that changes the starting point of the wave.
Phased Coexistence Operation (PCO) An optional IEEE 802.11n technology that alternates between using 20-MHz and 40-MHz channels.
phishing Sending an e-mail or displaying a Web announcement that falsely claims to be from a legitimate sender in an attempt to trick the user into surrendering private information.
Physical Layer Convergence Procedure (PLCP) A Physical layer sub- layer that reformats the data received from the MAC layer (when transmitting) into a frame that the PMD sublayer can transmit and “listens” to the medium to determine when the data can be sent.
Physical Medium Dependent (PMD) A Physical layer sublayer that defines the standards for both the characteristics of the wireless medium and the method for transmitting and receiving data through that medium.
picocell A WLAN that uses a reduced power output from the AP; results in a smaller coverage area but can allow for increased performance due to channel reuse.
plaintext Data input into an encryption algorithm.
PLCP Protocol Data Unit (PPDU) A data unit that is created by adding a header and other information to it.
PLCP Service Data Unit (PSDU) The result of the PMDU sent to the PLCP sublayer.
plenum The air-handling space above drop ceilings that is used to circulate and handle air in a building.
PoE-enabled Ethernet switch A device that can contain embedded PoE technology that provides both electrical power and data.
PoE injector A small and inexpensive device that can inject power into an Ethernet cable.
Point Coordination Function (PCF) The IEEE 802.11 optional polling function.
Point Coordination Function IFS (PIFS) An interframe space used by a device to access the medium after it has been asked and then given approval to transmit.
point-to-multipoint (PtMP) A remote wireless bridge configuration in which multiple buildings are connected.
point-to-point (PtP) A remote wireless bridge configuration in which two buildings are connected.
polarization The orientation of radio waves as they leave an antenna.
polling A channel access method in which each device is polled or asked in sequence if it wants to transmit.
power management A technology that allows a WLAN to conserve power.
Power over Ethernet (PoE) A technology that sends direct current (DC) power to an AP through the unused wires in a standard unshielded twisted pair (UTP) Ethernet cable.
power save mode A power management state in which the station turns off the wireless network interface card adapter to conserve battery life.
Power Save Multi-Poll (PSMP) An enhanced power management technology that can have either a scheduled or an unscheduled component.
power sourcing equipment (PSE) A PoE device that provides data and electrical power via embedded PoE technology.
predictive analysis simulation application Site survey software used in a predictive site survey that allows for building floor plans to be loaded and analyzed.
predictive site survey A site survey that is a virtual survey of the area that uses modeling techniques to design the wireless network.
preshared key (PSK) A secret value that is manually entered on both the AP and each wireless device.
primary channel The first channel of two bonded IEEE 802.11n channels.
Glossary 519Glossary 519
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
protocol analyzer Hardware or software that captures packets to decode and analyze its contents.
Protocol Data Unit (PDU) A unit of data that will be sent to the peer protocol layer at the receiving device instead of that being sent to a lower layer level.
pseudo-random number generator (PRNG) A WEP mechanism for creating a random number.
quadrature phase shift keying (QPSK) An IEEE 802.11a modulation technique that increases the amount of data encoded to 250 Kbps per channel.
Quality of Service (QoS) Prioritizing different types of frames over a network.
radio chain A radio with supporting infrastructure such as devices to amplify the signal or convert an analog signal into a digital signal.
radio frequency identification (RFID) A wireless technology that emits a wireless data signal over a short range.
radio frequency interference (RFI) Any undesirable electrical energy emitted within the frequency range dedicated to RF transmissions.
Real-Time Location Services (RTLS) Using wireless technologies for asset tracking of wireless equipment.
Receive Signal Strength Indicator (RSSI) A value intended for internal use by the wireless NIC.
reduced-channel FHSS A FHSS technology in which the devices use fewer than 75 hop channels.
Reduced IFS (RIFS) An interframe space that is used by 802.11n devices to reduce the amount of “dead space” required between OFDM transmissions.
reflection The RF propagation behavior in which an RF signal bounces back after striking a material.
refraction The RF propagation behavior in which an RF signal bends due to a change in atmospheric condition.
Remote Authentication Dial In User Service (RADIUS) The industry standard with widespread support suitable for high-volume service control applications.
Remote Network Monitoring (RMON) An SNMP-based tool that monitors networks using dedicated hardware devices.
remote office WLAN controller A device used to remotely manage multiple enterprise WLAN controllers from a central location.
remote wireless bridge A device that connects two or more networks that are separated by a longer distance.
repeater mode A mode of a wireless bridge that allows the bridge to extend the distance between buildings.
Request to Send/Clear to Send (RTS/CTS) An optional IEEE 802.11 channel access method that reserves the medium for a period of time.
residential WLAN gateway A single wireless hardware network device for SOHO or home use that typically combines multiple features into a single hardware device.
resistance (R) Measure of the restriction of the flow of electrical current.
return loss The VSWR as measured in dB.
RF attenuator A device that decreases the RF signal and is used when the gain of an antenna did not match the power output of an AP.
RF jamming A DoS attack that floods the RF spectrum with extrane- ous RF signal “noise” that prevents communications from occurring.
RF line of sight A theoretical straight line between a transmitter and the receiver.
RF planning and management tools See predictive analysis simula- tion application.
RF signal splitter A device that divides the power in the input signal to multiple outputs.
RF site tuning Adjustments to a WLAN performed as part of routine maintenance.
risk The likelihood that a threat agent will exploit a vulnerability.
RJ-45 connection A connector on a network interface card used to connect the card to a wired network using a cable.
roaming The movement between cells.
rogue AP An unauthorized AP.
Role-Based Access Control (RBAC) Providing access based on a user’s job function within an organization.
root bridge Term used to refer to a wireless bridge operating in root mode. A root bridge can communicate only with other wireless bridges that are not in root mode.
root mode A mode of a remote wireless bridge in which the bridge can communicate only with other bridges that are not in root mode.
rounds An iteration used in AES encryption.
RTS threshold Transmitted short data packets without RTS/CTS.
scattering The RF propagation behavior in which an RF signal bounces off small objects, such as raindrops.
Scheduled PSMP (S-PSMP) An enhanced power management technol- ogy in which the AP sends a transmission schedule to one or more stations in a WLAN.
secondary channel The second channel of two bonded IEEE 802.11n channels.
sectorized antenna An antenna that divides the coverage area into different sectors and gives each sector its own antenna.
Secure Digital (SD) A small form factor that was originally used as a format for portable storage devices for digital cameras and PDAs.
Secure Digital Input Output (SDIO) A combination of an SD card and an input/output (I/O) device such as a wireless NIC.
Secure Shell (SSH) An encrypted alternative to the Telnet protocol that is used to access remote computers.
Secure Shell 2 (SSH2) The current version of the Secure Shell (SSH) protocol.
Secure Sockets Layer (SSL) A protocol developed by Netscape for securely transmitting documents over the Internet.
security policy A written document that states how an organization plans to protect the company’s information technology assets.
semidirectional antenna An antenna that focuses energy in one direction.
sensitivity The signal strength needed for a good reception.
Service Data Unit (SDU) A specific unit of data that has been passed down from a higher OSI layer to a lower layer but has not yet been encapsulated by that lower layer.
Service Set Identifier (SSID) A logical network name that is a unique identifier to differentiate WLANs.
shared key authentication The process of a station encrypting text in order to be accepted into the WLAN.
520 Glossary520 Glossary
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Short IFS (SIFS) An interframe space used for immediate response actions such as ACK and has the highest level of priority.
signal-to-noise ratio (SNR) A ratio of the desired signal to undesired signal in the average power level of a transmission.
signature-based monitoring A method for auditing usage by exam- ining network traffic, activity, transactions, or behavior to compare against well-known patterns.
sine wave See oscillating signal.
single-channel architecture (SCA) An architecture in which all of the APs use the same channel.
single-input single-output (SISO) A wireless communication system that uses one radio chain.
single port PoE injectors A PoE injector that can provide power to a single cable.
site survey An in-depth examination and analysis of a WLAN site.
slot time The amount of time that a station must wait after the medium is clear.
small office/home office (SOHO) A business setting that typically has ten or fewer employees.
SNMP (Simple Network Management Protocol) A management pro- tocol that provides information such as the number of bytes transmitted and received, the number of frames transmitted and received, the num- ber of errors, and port status.
SNMP management station A computer running SNMP management software.
SNMP trap An alert message generated on a network using SNMP.
social engineering A means of launching an attack or gathering information for an attack by relying on the weaknesses of individuals.
SoftAP A software-based wireless access point that uses a designated virtual wireless NIC.
software agent Software used in SNMP to monitor network traffic.
Space Time Block Coding (STBC) An 802.11n option that sends a redundant copy of part or all of the transmited signal on an unused antenna.
spatial diversity A MIMO technique of sending the same transmis- sion out from different antennas that will take different paths.
spatial multiplexing A MIMO technique of sending independent streams of information at the same time over the same frequencies.
Spatial Multiplexing Power Save (SMPS) An enhanced power man- agement technology that turns off MIMO radios.
spectral efficiency The efficiency of the radio measured in the num- ber of bits per hertz.
spectrum analyzer A device that scans the RF spectrum to locate potential sources of interference.
split MAC A division in which lightweight APs only handle the real- time layer functions while MAC functionality is processed by the WLC.
spread-spectrum transmission A technique that takes a narrow, weaker signal and spreads it over a broader portion of the radio frequency band.
SSID hiding Configuring an AP to prevent the beacon frame from including the SSID.
standard A model that is used for comparison.
station (STA) A wireless device.
stream cipher An encryption cipher that takes one character and replaces it with another character.
supplicant A device in an IEEE 802.1X network that makes an appeal for access.
switching The process of choosing which antenna reception to accept.
symbols Radio frequency signals.
system operating margin (SOM) The difference between the received signal level and the signal level that is required by that radio to assure that the transmission can be decoded without errors.
task group (TG) An IEEE subgroup that is responsible for fulfilling a charter that results in an amendment or a recommendation, or that disbands if no solution can be identified.
temporal key A 128-bit encryption key used in TKIP.
Temporal Key Integrity Protocol (TKIP) Part of the WPA standard that adds an additional layer of security while still preserving WEP’s basic functionality.
thin access points An access point that does not contain the manage- ment and configuration functions that are found in autonomous access points.
threat A type of action that has the potential to cause harm.
threat agent A person or element that has the power to carry out a threat.
throughput The measure of how much actual data can be sent per unit of time across a network.
total cost of ownership (TCO) The total cost of owning a product, including acquisition, setup, support, ongoing maintenance, service, and all operating expenses.
traffic indication map (TIM) A list of stations that have buffered uni- cast frames waiting at the AP.
transmission opportunities (TXOP) The process of scheduling access to the channel by allocating to the stations.
transmit beam forming (TxBF) An option for reducing outside signal interference by using complex antenna systems to allow for different directions and beamwidths.
transmit diversity The ability of an access point to transmit on the antenna that most recently received the strongest incoming signal.
transmit power control (TPC) An IEEE 802.11a technology to reduce interference.
Transport Layer Security (TLS) A protocol that guarantees privacy and data integrity.
trunk-based leased lines Special high-speed circuits leased from a local carrier that can be used to connect remote sites of a business.
trunking A single cable is used to support multiple virtual LANs.
turbo mode A proprietary transmission scheme used to double the effective rate of an 802.11a network.
ultra-wideband (UWB) An IEEE 802.15.3c-2009 standard of a high- rate WPAN with speeds over 2 Gbps.
unidirectional amplifier A device that increases the RF signal level before it is injected into the transmitting antenna.
unlicensed bands Parts of the radio spectrum that are available nationwide to all users without a license.
Glossary 521Glossary 521
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Unlicensed National Information Infrastructure (UNII or U-NII) An unlicensed band used for WLANs.
Unscheduled Automatic Power Save Delivery (U-APSD) A technology in which whenever the AP sees a frame coming from the station it will immediately release any frames it has been holding for the station.
upfade The gain in a signal that occurs when the delayed multipath signal arrives at the same time as and is in phase with the primary signal.
variable guard interval (VGI) An IEEE 802.11n technology that uses a reduced guard interval of 400 nanoseconds.
variable-loss attenuator An RF attenuator that allows the user to set the amount of loss.
virtual carrier sensing An optional polling IEEE 802.11 channel access method.
virtual local area network (VLAN) A logical grouping of network devices within a larger physical network.
virtual private network (VPN) A technology that uses an unsecured public network as if it were a secure private network.
Virtual WiFi Term used to refer to the virtualization of the physical wireless NIC into multiple virtual wireless NICs.
visible light communications (VLC) An IEEE 802.15.7 standard that transmits data by the intensity of the modulating optical source.
visual line of sight An unobstructed straight line between objects.
Voice over IP (VoIP) A telephony system that uses Internet Protocol (IP-based) data packet switching networks to transmit voice communications.
voltage (V) Electrical pressure on a wire.
Voltage Standing Wave Ratio (VSWR) A measure of how well an electrical load is impedance-matched to its source.
volts The measure of electrical pressure on a wire.
VPN concentrator A device that aggregates VPN connections.
vulnerability A flaw or weakness that allows a threat agent to bypass security.
vulnerability assessment (impact analysis) A systematic and methodical evaluation of the exposure of assets to attackers, forces of nature, or any other entity that is a potential harm.
war driving The process of searching for wireless signals from an automobile or on foot using a portable computing device.
warehouse management system (WMS) Software that can manage all activities in a warehouse, from receiving through shipping.
watts (W) A basic unit of power of 1 amp of current that flows at 1 volt.
wavelength The distance between peaks in an electromagnetic wave.
wave propagation The way in which an electromagnetic signal travels.
weak keys Cryptographic keys that create a repeating pattern.
WEP2 (WEP Version 2) An enhancement to WEP that attempted to overcome WEP’s limitations by adding a longer key value and a dif- ferent authentication system.
wideband interference RF interference that affects the entire fre- quency band, such as the entire 2.4-GHz band.
Wi-Fi (Wireless Fidelity) Alliance An organization that verifies that a product follows IEEE standards.
Wi-Fi Multimedia (WMM) A QoS specification created in 2004 by the Wi-Fi Alliance modeled after a wired network QoS prioritization scheme.
Wi-Fi Protected Access (WPA) A temporary security solution devel- oped by the Wi-Fi Alliance in 2003.
Wi-Fi Protected Access 2 (WPA2) The Wi-Fi Alliance’s security stan- dard based on IEEE 802.11i.
Wi-Fi Protected Setup (WPS) An optional means of configuring secu- rity on wireless local area networks designed to help users who have little or no knowledge of security.
Windows Connect Now (WCN) A feature of Microsoft Windows 7 for connecting wireless devices for home networking and SOHOs.
wired equivalent privacy (WEP) A wireless security mechanism that is intended to guard the confidentiality of information as it is transmitted.
wireless client network interface card adapter A device that con- nects a wireless device to a wireless network.
wireless distribution system (WDS) A distribution system that pro- vides services through a wireless infrastructure.
wireless intrusion detection system (WIDS) A security management system that constantly monitors the RF for attacks and sounds an alert if one is detected.
wireless intrusion prevention system (WIPS) A security management system that monitors network traffic to immediately react to block a malicious attack.
wireless ISP An Internet Service Provider that makes wireless data access available directly to the home or office.
Wireless LAN controller (WLC) A device that can be configured with a wireless network’s settings, after which the settings are automatically distributed to all lightweight access points on the network.
wireless local area network (WLAN) A wireless network designed to replace or supplement a wired local area network.
wireless mesh network (WMN) A network of wireless mesh access points that communicate between themselves.
wireless mesh routers A mesh access point that functions similar to routers in directing traffic along the best traffic path.
wireless metropolitan area network (WMAN) A wireless network that is designed for devices in a broader area of coverage than a WLAN or at higher speeds.
wireless network management system (WNMS) A set of hardware and/or software that can be used to provide unified management of a wireless network.
wireless personal area network (WPAN) A wireless network designed for hand-held and portable devices at slow transmission speeds and in close proximity.
wireless policy A policy that specifies the conditions that wireless devices must satisfy in order to connect to the organization’s network.
wireless switch A device that contains the management and configu- ration functions for a lightweight access point.
wireless switch Another name for a WLAN controller.
wireless VLANs A wireless virtual LAN typically used to segment traffic.
wireless wide area network (WWAN) A wireless data network that can encompass multiple states, regions, or countries.
522 Glossary522 Glossary
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
wireless workgroup bridge A device used to connect a wired network segment to a wireless network segment.
Wireless Zero Configuration (WZC) A wireless connection manage- ment utility that operates as a Windows service and interacts with the client hardware NIC drivers.
WLAN array A proprietary product marketed that contains a WLC that can be directly connected to as many as 16 integrated APs.
WLAN Autoconfig A Microsoft Windows 7 and Vista wireless connection management utility that operates as a Windows service and interacts with the client hardware NIC drivers default settings.
WLAN profile A set of specific configurations that can be applied to different wireless stations.
WMM Power-Save (WMM-PS) A technology that is similar to Unscheduled Automatic Power Save Delivery (U-APSD).
working group (WG) An IEEE committee that is responsible for cre- ating and overseeing a specific standard.
Worldwide Interoperability for Microwave Access (WiMAX) A WWAN based on the IEEE 802.16 standards.
WPA Enterprise A temporary security solution intended for large enterprises, schools, and government agencies.
WPA2 Enterprise The current Wi-Fi Alliance standard designed for large enterprises, schools, and government agencies.
WPA Personal A temporary security solution designed for individuals or small office/home office settings.
WPA2 Personal The current Wi-Fi Alliance standard designed for individuals or small office/home offices.
ZigBee A low-power, short-range, and low-data rate specification that is based on 802.15.4 but that includes standards for network config- uration, security and other higher-level features.
Glossary 523Glossary 523
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Index 10’s and 3’s Rules of RF Math, 98, 99
16-level quadrature amplitude modulation (16-QAM), 177, 178
180 degrees out of phase, 88
2X mode, 177
3rd Generation Partnership Project Long Term Evolution (3GPP LTE), 480
40-MHz channels, 182–183
4G (Fourth Generation), 19, 479–480
64-level quadrature amplitude modulation (64-QAM), 177, 178
A absorption, 101–102
acceptable use policy (AUP), 250, 251, 400–401
access categories (AC), 225
access control, 331–332
access layer, 252
access points (APs). See also D-Link
association and, 215–216
authorized, 371–372
autonomous, 53, 243–248
bridges and, 57
BSS and, 199–200
captive portal, 250–252
categorization of, 371–372
Cisco AP, 409, 411
configuring, 70–72, 269–274, 299, 346–348, 385–386, 422–423, 436–437, 491–492
controller-based architectures and, 249
EEPROM and, 413
enterprise-level, 413–414
ESS and, 201–203
event logs for, 423
fat, 53, 243
functions of, 51–52
identification of, 371–372
known, 371–372
LED status lights and, 436
lightweight, 53–54, 249–250
lightweight mesh, 250
location of, 299
MAC layer and, 213–216
mesh, 54–56, 250
mobile IPs and, 202–203
mode, 59
near/far transmission problems and, 437–438
open (misconfigured), 325
optimization of, 447–448
overview, 51–53
PoE and, 61–63
power level adjustment and, 285
probes, 377
receiving, 414
rogue, 325–326, 371–372, 377–378
sensors, 370–371
site surveying and, 285–286
SSIDs and, 436
thin, 53–54, 249–250
troubleshooting configuration settings, 436–437
utilities, 407, 409–410
virtual, 73–77
wireless devices and, 445
wireless distribution systems and, 203
wireless NICs and, 61
acknowledgment frame (ACK), 219, 287
active gain, 124
active manual site survey, 282
active mode, 259
Active Mode test, 287
active RFID tags, 470
active scanning, 213
active slaves, 465–467
ad hoc mode, 203
ad hoc networks, 212
ad hoc traffic indication message (ATIM) window, 260
ad hoc wireless mesh network, 54
adapters, wireless, 439, 444
address filtering, 331, 337
Address Resolution Protocol (ARP), 339
adjacent channel interference, 256, 433–434
Advanced Encryption Standard (AES), 362
Aerohive, 254, 311–313, 506
AES (Advanced Encryption Standard), 362
Aggregate MAC Protocol Data Unit (A-MPDU), 206
Aggregate MAC Service Data Unit (A-MSDU), 206
AirConnect, 408
Aircrack-ng, 511
airline industry, 2, 9–10
AirTight, 309–310, 506
AirTran Airways, 2
algorithm(s)
decryption, 333
encryption, 332–333
maximal ratio combining, 140
RC4 cipher, 334
routing, 56
WEP, 333–334, 349–351
all-band interference, 430
alternating current (AC), 83
America’s Cup, 80–81
amperes (amps), 96
amplification, 105. See also amplifiers
amplifiers, 142. See also amplification
amplitude, 86–87
amplitude modulation (AM), 92
amplitude shift keying (ASK), 94
amps (amperes), 96
analog modulation, 91–93
analog signals, 91–93
anomaly-based monitoring, 369
antenna(s). See also specific antennas
accessories, 141–142
array, 130
coverage patterns, 131–136
defined, 121
diversity, 129
fade margin, 144, 432
gain, 105, 124–125
installation of, 140–145
intersymbol interference and, 433
link budgets and, 143–144
location, 131
measurements, 123–126
MIMO systems and, 136–140
overview, 121–122
radiation chart, 131–132
RF interference and, 432
SISO systems and, 137, 432–433
site surveys and, 293–294
system operating margin and, 144
types of, 126–131
VoWiFi and, 293–294
VSWR and, 144–145 525
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Antheil, George, 162
anti-virus scanning, 368
anticlimb collar, 406
anticlimb paint, 406
APIPA (Automatic Private IP Addressing), 439–440
AppleTalk, 199
Application layer, 160
APs (access points). See access points (APs)
Arbitration IFS (AIFS), 222
architectures
autonomous access point, 243–248
cloud management, 255
controller-based, 248–254
cooperative control, 254
multiple-channel, 255–256
single-channel, 256–257
wireless mesh networks, 255
WLAN array, 254
assets, 394, 399, 471
association request frame, 209, 214, 215–216
association response frame, 209, 216
associations, 209, 214, 215–216
attack vectors, 324–326
attack(s). See also security
defenses against, 321–324, 398–407
denial of service, 328–329, 357
dictionary, 356–357
distributed, 323
enterprise, 324–329
hijacking wireless connections, 328
home, 330
initialization vector, 338–339
man-in-the-middle, 328, 357
mobile user, 329
network traffic, 328
sophistication of, 321
speed of, 321
tools, 322–323, 388–389
wireless, 324–329
attenuation, 104
attenuators, 142
audio distribution, 468
AUP (acceptable use policy), 250, 251, 400–401
authentication
defined, 214
Kerberos, 356–357
MAC layer and, 209, 214–215
open system, 214, 215, 335, 336
security and, 335
shared key, 214–215, 335, 337, 360
vulnerabilities of, 336–337
wireless device connections and, 443
WPA2 and, 364–367
authentication frame, 209
authentication request, 364
authenticator, 364
authorized APs, 371–372
AutoCAD drawing (.dwg) files, 284
automated RF resource management, 282
Automatic Private IP Addressing (APIPA), 439–440
automobile industry, 10, 120, 470
autonomous APs, 53, 243–248
autonomous body sensor network (ABSN), 473
availability, 321
awareness, 403–404
Azimuth
chart, 131–133, 134
plane pattern, 134
B backhaul connection, 14
backhaul wireless mesh network, 54
backoff interval, 216–217
BackTrack, 349–350, 388–389, 506
band steering, 440
bands, 88–91
bandwidth
business requirements for, 295
defined, 162–163
IEEE 802.11ac and, 481
requirements for online tasks, 447
shared frequency, 166
site surveys and, 283
Barker code, 173, 181
base key, 358
baseline, 369
Basic Service Area (BSA), 200
Basic Service Set (BSS), 199–200, 204, 243
Basic Service Set Identifier (BSSID), 199, 253
battery life, 482
beacon frame(s). See also beaconing
defined, 210
interval field, 212
passive scanning and, 211–213
PCF and, 224
security vulnerabilities and, 336
beaconing, 211, 336. See also beacon frame(s)
beam forming, 482
beamwidth, 133, 134–135
behavior-based monitoring, 369
behaviors, RF, 100–105, 152–155
Bell, Alexander Graham, 474
bidirectional amplifier, 142
bill of materials (BOM), 301
Bitmap Image File (.bmp), 284
block acknowledgment, 219–220
block cipher, 362
BlueAuditor, 490–491, 507
bluejacking, 468
blueprints, 296–297
bluesnarfing, 468
Bluetooth
in retail, 462
overview, 18–19, 464–468
piconet, 465–467, 468
scatternet, 466–467
v4.0, 465
viewing, 489–491
Bluetooth Low Energy, 465
BluetoothView, 489–490, 507
body area networks (BANs), 472–473
Boeing, 2
Brandeis University, 198
bridges, 56–59, 127
Broadband Radio Service (BRS), 477–478
broadcast frame, 260
broadcast probe, 213
broadcast topology, 475
broadcast traffic, 357
BSA (Basic Service Area), 200
BSS (Basic Service Set), 199–200, 204, 243
BSSID (Basic Service Set Identifier), 199, 253
bus, 45
bus mastering, 49
business(es)
applications, 5
site survey requirements, 295–296
wireless attacks on, 324–329
526 Index526 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
C cable locks, 406–407
Caesar, Julius, 332
calculators, online, 152–155, 505
capability information field, 212
captive portal APs, 250–252
CardBus, 49
care-of-addresses, 202
Carnegie Mellon University, 198
carrier (carrier signal/carrier wave), 91
Carrier Sense Multiple Access with Collision Avoidance (CSMA/CA), 216–220, 223, 430, 438
Carrier Sense Multiple Access with Collision Detection (CSMA/CD), 216–218, 438
carrier sensing, 216
categorization, AP, 371–372
CCK (complimentary code keying) mode, 181
CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol), 362–364
cell overlap, 446
cellular telephones, 18–19, 464–468, 479–480
CERT/CC (Computer Emergency Response Team Coordination Center), 510
certifications
CWNA, 25, 495–503
Wi-Fi, 25, 45, 198
Certified Wireless Network Administrator (CWNA), 25, 495–503
challenge text, 215, 335
channel(s)
40-MHz, 182–183
access methods, 216
allocation, 179–181, 256
bonding, 182–183
defined, 164
FHSS and, 164–165
frequency usage, 180
interference, 256, 433–434
ISM, 90, 172
multiple-channel architecture, 255–256
nonoverlapping, 173
optimization, 445–447
single-channel architecture, 256–257
stacking, 257
chipping code, 165–166
Cipher Block Chaining Message Authentication Code (CBC-MAC), 362
cipher, block, 362
ciphertext, 332–333
Cisco
Cisco AP, 409, 411
Web site, 510
WLAN study, 5
Cisco Hot Standby Router Protocol (HSRP), 328
cleartext, 332, 333
client hardware/software, 45–51
client network adapters, 45–50, 61, 286
closed circuit television, 406
cloud management, 255
CMOS (complementary metal oxide semiconductor), 43
cochannel interference, 256, 433
coexistence, 469
colleges, 198
collisions
CSMA/CA, 216–220
CSMA/CD, 216–218
defined, 338
RTS/CTS, 220–223
WEP and, 338
colocation, 166
communication resilience, 168
community strings, 375
CompactFlash (CF) cards, 49
complementary code keying (CCK), 173
complementary metal oxide semiconductor (CMOS), 43
compliance monitoring/evaluation, 399
Computer Security Resource Center (CSRC), 511
conductors, 121
confidentiality, 321
configuring
AP settings, 269–274, 346–347, 385–386, 422–423, 436–437, 456–458, 491–492
wireless device connections, 444
WLAN AutoConfig, 51, 70–72
WLANs, 433–437
connected mode, 466
Connectify, 75–77, 505
connectivity
autonomous access point architecture, 243–244
information security and, 321
Windows 8, 443
wireless device troubleshooting, 438, 443–445
wireless LAN controllers and, 252–253
WLANs and, 14–15
Connexion, 2
consortia, 38–39
constantly awake mode, 259
construction industry, 6
contention, 216
continuous aware mode (CAM), 259
Continuous Link Test settings, 287
control, 402
control frames, 210
controller-based architectures, 248–254
convolutional coding rate, 183
cooperative control, 254
core layer, 252
corruption, 105
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP), 362–364
coverage, 127–128
coverage patterns, 131–136
CRC (cyclic redundancy check), 334–335, 359
cryptography, 332–335
CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance), 216–220, 223, 430, 438
CSMA/CD (Carrier Sense Multiple Access with Collision Detection), 216–218, 438
CTS-to-self, 221
current
alternating, 83
defined, 96
direct, 83
PoE and, 61–62
CWNA (Certified Wireless Network Administrator), 25, 495–503
CWNP Blog, 511
cycles, 82–83
cyclic redundancy check (CRC), 334–335, 359
Cyclic Shift Diversity (CSD), 138
D D-Link. See also access points (APs)
configuring APs, 346–348, 385–386
distributing IP address through APs, 456–458
setting performance parameters for APs, 491–492
upgrading AP’s firmware, 422–423
Web site, 506, 507, 510
Index 527Index 527
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
data
collection, 410
frames, 210–211
gathering, 294–295
high speed transfer, 468
medical data collection, 470
reading, 326, 328
retention, 410
scrambling, 332–333
units, 204–206
Data field, 171, 175–176
Data Link layer, 160, 169
data rates, 43, 301–302, 469
Data Rates setting, 288
Data Retries setting, 287
datagrams, 171
dBm levels/watts, 97
DBPSK (differential binary phase shift keying), 173, 181
DCF (Distributed Coordination Function), 216–223, 244
de facto standards, 38
de jure standards, 38
dead space, 279
deadbolt locks, 404–405
deauthentication frame, 210
decibel milliwatt (dBm), 96–98
decibels (dB), 97
decibels dipole (dBd), 125–126
decibels isotropic (dBi), 124–125
decryption, 332–333. See also encryption
dedicated applications, 287–288, 289
dedicated probe, 377–378
delay, 293
Delay Between Packets setting, 288
delay spread, 105, 432
delivery traffic indication message (DTIM), 260
denial of service (DoS) attacks, 328–329, 357
deployment, 15–16, 281, 357
desktop computers, 45, 46–48
desktop probe, 377
Destination MAC settings, 287
detectors, 41
devices. See wireless device(s)
dictionary attacks, 356–357
differential binary phase shift keying (DBPSK), 173, 181
differential quadrature phase shift keying (DQPSK), 173, 181
diffraction, 104
diffused transmissions, 41
DIFS (Distributed Coordination Function IFS), 222
digital modulation, 93–95. See also modulation
digital monitoring, 11–12
digital signals, 93–95
dipole antenna, 125–126, 127–129
direct current (DC), 83
direct sequence spread spectrum (DSSS)
Barker code and, 173
interframe spacing and, 222–223
modulation technologies comparison, 168
overview, 165–166
physical layer and, 181
directed probe, 213
directed transmissions, 41
disassociation frame, 210
disruptive technology, 2–3
distributed attacks, 323
Distributed Coordination Function (DCF), 216–223, 244
Distributed Coordination Function IFS (DIFS), 222
distributed WLAN architecture, 243–244
distribution centers (DCs), 278–279
distribution layer, 252
distribution system (DS), 203
distribution system media, 203
documentation
of existing network characteristics, 297–298
site survey and, 292–293
site-specific, 296–297
door locks, 404–405
DoS (denial of service) attacks, 328–329, 357
downfade, 105
DQPSK (differential quadrature phase shift keying), 173, 181
DSSS (direct sequence spread spectrum). See direct sequence spread spectrum (DSSS)
dual band wireless adapters, 439
dwell time, 163
Dynamic Frequency Selection (DFS), 183
Dynamic Host Configuration Protocol (DHCP), 439
Dynamic MIMO Power Save, 262
dynamic WEP, 357, 358
E EAP (Extensible Authentication Protocol),
366
EAP-AKA protocol, 366
EAP-FAST protocol, 366
EAP-SIM protocol, 366
EAP-SIM/AKA/AKA Prime, 443
EAP-TLS protocol, 366
EAP-TTLS, 443
EAP-TTLS/MSCHAPv2 protocol, 366
education, 3–5, 198, 403–404
EEG (Enterprise Encryption Gateway), 59, 60
EEPROM (Electrically-Erasable Programmable Read-Only Memory), 412–413
EIRP (Equivalent Isotropically Radiated Power), 123–124, 126, 154
electrical current. See current
electrical power, 96. See also power
electrically-erasable Programmable Read- Only Memory (EEPROM), 412–413
electromagnetic interference (EMI), 428
electromagnetic spectrum, 88–91
electromagnetic wave(s)
amplitude of, 86–87
cycles, 82–83
electromagnetic spectrum, 88–91
frequency of, 85–86
overview, 82
phase, 87–88
wavelengths, 83–85
electronic cash cards, 471
elevation charts, 131–133, 134
elevation plane pattern, 134
embedded sensors, 370–371
emitters, 40–41
encryption. See also decryption; keys
algorithms, 332–333
defined, 332
dynamic WEP, 357
packet, 334, 337
TKIP and, 358–359, 363
WEP and, 334–335, 349–351
WPA Enterprise and, 358
WPA2 and, 362–364
encryption keys. See keys
endpoints, 373
endspan devices, 63
Enhanced Distributed Channel Access (EDCA), 225
528 Index528 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
enterprise attacks, 324–329
Enterprise Encryption Gateway (EEG), 59
enterprise-level APs, 413–414
Equivalent (Effective) Isotropically Radiated Power (EIRP), 123–124, 126, 154
error correction, 166, 175, 482. See also troubleshooting
ESS (Extended Service Set), 201–203, 204, 243
Ethernet
CSMA/CD and, 218
frame format, 207
naming of, 82
ports, 198
standards, 216
event actions/notifications, 372–373
event logs, 409, 423
Event Viewer, 443, 454–456
evil twins, 326
exabyte (EB), 481
explicit feedback, 140
exploiting, 395
ExpressCard, 49
Extended IFS space (EIFS), 222
extended rate PHYs (ERP), 181
Extended Service Set (ESS), 201–203, 204, 243
Extensible Authentication Protocol (EAP), 366
external interference, 428–432
Extremely High Frequency (EHF), 90
F facial-recognition software, 463
facilitated sessions, 296
fade margin, 144, 432
Fake AP, 511
false positives, 369, 370
fat APs, 53, 243
FBI (Federal Bureau of Investigation), 318
FCC (Federal Communications Commission). See Federal Communications Commis- sion (FCC)
Federal Aviation Association (FAA), 468
Federal Bureau of Investigation (FBI), 318
Federal Communications Commission (FCC)
amplifiers and, 142
antennas and, 141
Broadband Radio Service and, 477–478
DSSS restrictions and, 166
intentional radiators and, 123
ISM band and, 90
licensing and, 89
medical micropower networks and, 473
overview, 22
UNII frequency band and, 174
unlicensed bands and, 89
Web site, 509
feedback, 140
fencing, 406
FHHS (frequency hopping spread spectrum). See frequency hopping spread spectrum (FHSS)
finite-state machine (FSM), 214
firewalls, 324, 367
firmware, 258, 412–415, 422–423
fixed WiMAX, 479
fixed-loss attenuators, 142
football, 158–159
foreign agents, 202
foreign networks, 202
form factors, 48–50
Forum of Incident Response and Security Teams (FIRST), 510
Forward Error Correction (FEC), 175
Fourth Generation (4G), 19, 479–480
fragmentation, 207, 221
frame(s). See also beacon frame(s); specific types
acknowledgment, 219
analyzing, 237
capturing, 235–237
fragmentation, 221
MAC formats, 204–208
MAC types, 208–211
free space optics (FSO), 476–477
free space path loss (FSPL), 104
frequency, 85–86. See also frequency hopping spread spectrum (FHSS); frequency modulation (FM); frequency shift keying (FSK); radio frequency (RF)
frequency hopping spread spectrum (FHSS)
all-band interference and, 430
Bluetooth technology and, 467
communication resilience of, 168
DSSS and, 168
FCC restrictions, 165
HIT system and, 158–159
overview, 162–165
frequency modulation (FM), 92–93
frequency shift keying (FSK), 94, 95
Fresnel zone, 135–136
FSO (free space optics), 476–477
full-channel FHSS, 165
G GaAs (gallium arsenide), 43
Gadd Severity Index (GSI), 159
gain, 105, 124–125
gamma rays, 89
garden hose waves, 82
gateways, 59–61
gigabyte (GB), 481
gigahertz (GHz), 86
global positioning system (GPS), 6, 7, 462
Gormsson, Harald "Bluetooth," 18
GPS (global positioning system), 6, 7, 462
Graphics Interchange Format (.gif), 284
Greenfield Mode, 208
ground plane, 122
ground rods, 143
group interviews, 295–296
guard interval (GI), 167
guidelines, 398
H Half Mini PCIe cards, 50
handoffs, 201, 257
hard edges, 324–325
hardware, client, 45–50
HCF Controlled Channel Access (HCCA), 225
Head Impact Telemetry (HIT) System, 158–159
Header Error Check field, 171
health care industry, 11–12, 36, 463, 472
health risks, of WLANs, 17
hertz (Hz), 85–86
heuristic monitoring, 370
hidden node problem, 217–218, 438
High Frequency (HF), 90
High Frequency tag, 471
high-density WLANs, 446–447
high-gain antennas, 125
High-Rate (HR) DSSS, 173
highly-directional antennas, 130–131
HIPERMAN, 478
HIT (Head Impact Telemetry) System, 158–159
HiveAP (Aerohive), 254
Index 529Index 529
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
home agents, 202
home attacks, 330
home entertainment systems, 468
hop time, 163
hopping code, 163–164
hopping sequence, 467
horizontal polarization, 128
hospitals, 463
Hosted Network, 60–61
Hot Standby Router Protocol (HSRP), 328
hotspots, 13–14, 31–33
HT (MIMO), 138
HT 20 MHz Protection Mode, 208
HT Dual-CTS Protection, 221
HT L-SIG Protection, 221
HT Mixed Mode, 208
HT Nonmember Protection Mode, 208
HT Operation Modes, 208
HTTPS (Hypertext Transport Protocol over Secure Sockets Layer), 374, 375
Hybrid Coordination Function (HCF), 225
Hypertext Transport Protocol over Secure Sockets Layer (HTTPS), 374, 375
I IBSS (Independent Basic Service Set),
203–204, 243
identification, AP, 371–372
IEEE (Institute for Electrical and Electronics Engineers). See also specific standards
overview, 22–24
Project 802, 23
ratification process, 23–24
task groups (TGs), 23–24
Web site, 509
working groups (WGs), 23–24
IEEE 802.11 standard. See also specific versions
amplifiers and, 142
cryptography and, 333–335
frames and, 207
MAC layer standards, 204–225
overview, 23, 40–42
Physical layer standards, 168–184
RSSI and, 99
security and, 331–339, 355–367, 373–378
troubleshooting and, 431, 443
IEEE 802.11-2007 standard, 39–40. See also IEEE 802.11 standard
IEEE 802.11a standard
EIRP for, 124
IEEE 80211n HT and, 208
overview, 43
Physical layer standards, 173–181
troubleshooting and, 431
IEEE 802.11ac standard, 480–482
IEEE 802.11b standard
EIRP and, 123
free space path loss and, 104
IEEE 802.11n HT and, 208
multiple-channel architecture and, 255
narrowband interference and, 429
overview, 42–43
Physical layer standards, 170–173
IEEE 802.11e-2005 standard, 245
IEEE 802.11g standard
EIRP and, 124
free space path loss and, 104
IEEE 802.11n HT and, 208
overview, 43–44
Physical layer standards, 181–182
throughput and, 181
IEEE 802.11i standard, 361–367
IEEE 802.11n standard
block acknowledgment and, 219
devices, 198
HT, 208
interference and, 431
MAC layers and, 206
MIMO and, 137–140
Physical layer standard, 182–184
IEEE 802.11n-2009 standard, 44–45. See also IEEE 802.11n standard
IEEE 802.11r-2008, 449
IEEE 802.11w standard, 329
IEEE 802.11X standard, 449
IEEE 802.15 standard. See also specific versions
Bluetooth and, 464–468
body area networks and, 472–473
low rate technologies and, 469–471
ultra-wideband and, 468–469
visible light communications and, 473–476
IEEE 802.15.1-2005 standard, 464–468
IEEE 802.15.3c-2009 standard, 468–469
IEEE 802.15.7 standard, 473–476
IEEE 802.16 standard, 478–479
IEEE 802.16-2004 standard, 479
IEEE 802.16e-2005 standard, 479
IEEE 802.1q standard, 246
IEEE 802.1X standard, 364–367, 445
IEEE 802.3 standard, 207
impact analysis, 399
impedance, 96
impersonation, 396
implicit feedback, 140
in phase, 87–88
Independent Basic Service Set (IBSS), 203–204, 243
Industrial, Scientific and Medical (ISM) bands, 90, 172
industry, 5–9
information security. See also security
challenges of, 321–324
components of, 322
defined, 320
overview, 320–321, 322
principles of, 319–320
Information Systems Security Association (ISSA), 511
InfraGard, 510
infrared
light, 40–41
light emitting diodes (LEDs), 473–474
rays, 89
transmissions, 40–42, 476
wireless systems, 41–42
Infrared Data Association (IrDA), 473
infrastructure mode, 203
initialization vector (IV), 334, 338–339, 360
inSSIDer, 115–116, 505
Institute of Electrical and Electronics Engineers (IEEE). See IEEE (Institute for Electrical and Electronics Engineers)
integrated sensors, 370
integrity, 321
integrity check value (ICV), 334
intentional radiator (IR), 123
interference
adjacent channel, 256, 433–434
all-band, 430
cochannel, 256, 433
electromagnetic, 428
external, 428–432
identifying, 299–300
intersymbol, 167, 432–433
530 Index530 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
narrowband, 429
nontraditional device, 445
radio frequency, 428, 431
weather, 430–431
wideband, 429
interframe spaces (IFS), 221–223
Interior Gateway Routing Protocol (IGRP), 328
internal cards, 50
International Organization for Standardization (ISO), 22, 159–160, 509
International Telecommunication Union Radio Communication Sector (ITU-R), 21–22, 509
Internet, 477–478, 481
Internet Engineering Task Force (IETF) Control and Provisioning of Wireless Access Points (CAPWAP) Working Group, 254
Internet Group Management Protocol (IGMP), 328
interoperability, 207–208
intersymbol interference (ISI), 167, 432–433
interviews, 295–296
intruder detection, 470
intrusion systems, 367
inventory control, 471
ISM (Industrial, Scientific and Medical) bands, 90, 172
ISO (International Organization for Standardization), 22, 159–160, 509
isotropic radiator, 123
ISPs, wireless, 14
ITU-R (International Telecommunication Union Radio Communication Sector), 21–22, 509
IV (initialization vector), 334, 338–339, 360
J jamming, 328
jitter, 293
Joint Photographic Experts Group (.jng), 284
jumbo frame support, 207
K Kerberos, 356–357
key fobs, 46–47, 332
key(s)
base, 358
defined, 332
hashing, 361
length of, 334, 358
mixing, 360
per-packet, 358
preshared, 360, 444
temporal, 359
weak, 333
keyed entry locks, 404, 405
keying, 91–95
keystream, 334
keystream attack, 338–339
kilohertz (KHz), 86
Kismet, 511
Kiva Systems, 278–279
known APs, 371–372
L Lamarr, Hedy, 162
laptop computers
antennas and, 128
cards for, 48–50
Hosted Network and, 61
NICs for, 45
power management of, 258–259
large form factor cards, 48–49
last mile connection, 14
latency, 17
Layer 2 roaming, 201, 248
Layer 3 roaming, 202, 248
learning styles, 403–404
learning traits, 403
LEDs (light emitting diodes), 436, 473
legacy wireless NIC drivers, 444
Length field, 175–176
license-exempt spectrum, 89–91
light, 470, 473–476
light emitting diodes (LEDs), 436, 473
light spectrum, 40
lightning arrestors, 143
lightweight APs, 53–54, 249–250
lightweight mesh APs, 250
line-of-sight (LoS), 41, 42, 59, 135
link budget, 143–144
Linksys, 510
Linux, 234–238
load balancing, 248
location, device, 437––438
locks, 404–407
Logical Link Control (LLC) sublayer, 169
logs, 443
Long Term Evolution (LTE), 19–20, 479–480
LoS (line-of-sight), 41, 42, 59, 135
loss, of RF signals, 97–98, 104–105
Low Frequency (LF), 90
Low Frequency tag, 471
low rate technologies, 469–471
low-gain antennas, 125
LTE (Long Term Evolution), 19–20, 479–480
M MAC (Media Access Control) sublayer
address filtering, 331
all-band interference and, 430
authentication and, 209, 214–215
discovering WLANs, 211–213
fragmentation and, 221
frame formats, 204–208
frame types, 208–211
joining WLANs, 213–216
overview, 169–170
service sets, 199–204
standards, 204–225
transmitting on, 216–225
WiMAX and, 478
MAC address(es)
BSSID and, 199
filtering, 332–333, 337, 346–347
site surveys and, 287
spoofing, 337
substituting, 345–346
troubleshooting, 444
wireless device connections, 444
MAC Protocol Data Unit (MPDU), 205
MAC Service Data Unit (MSDU), 205
maintenance, WLAN, 412–415
man-in-the-middle attacks, 328, 356
managed body sensor network (MBSN), 472
managed switch, 252
management frames, 209–210
management information base (MIB), 410
manual site surveys, 282, 284–285
manufacturing, 9
Marconi, Guglielmo, 122
Marshalls, 354
Massachusetts Bay Transportation Authority (MPTA), 9
master devices, 465–467
Index 531Index 531
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
maximal ratio combining (MRC), 140
maximum transmission unit (MTU), 207
measurement(s)
antenna, 123–126, 143–145
RF signal strength, 95–100
tools, 299
Media Access Control (MAC) sublayer. See MAC (Media Access Control) sublayer
medical data collection, 470
medical micropower networks (MMNs), 473
Medium Frequency (MF), 90
megahertz (MHz), 86
mesh access routers, 54
mesh APs, 54–56, 250
Message Integrity Check (MIC), 359
message integrity code (MIC), 359, 360
mibDepot, 421–422, 506
micro-cell architecture, 256
microseconds (µs), 163
Microsoft NetBEUI, 199
Microsoft TechNet Web site, 510
Microsoft Vista, 51
Microsoft Windows 7
Event Viewer, 443, 454–456
Hosted Network, 60–61
Netsh utility, 112–114
Windows 8 operating system vs, 443
wireless connection tools, 440–443
wireless device connection process, 438–440
WLAN AutoConfig., 51, 70–72
Microsoft Windows 8, 443
Microsoft Windows XP, 51, 336
Microwave tag, 471
microwaves, 89
midspan devices, 63
milliseconds (ms), 163
milliwatts (mW), 96
MIMO (Multiple-Input Multiple-Output). See Multiple-Input Multiple-Output (MIMO)
Mini-PCI slots, 50
Mini-PCI-e slots, 50
misconfigured APs, 325
mobile device utilities, 407, 408
Mobile IP, 202–203
mobile telecommunications switching office (MTSO), 479
mobile user attacks, 329
mobile WiMAX, 479
mobility, 12–13, 295
modem, LTE, 20
modulation
16-level quadrature amplitude, 177, 178
64-level quadrature amplitude, 177, 178
amplitude, 92
analog, 91–93
digital, 93–95
frequency, 92–93
narrowband transmission, 160–161
overview, 91–95
phase, 93
radio frequency, 91–95
spread spectrum transmissions, 161–168
techniques, 176–178
technology comparison, 168
Modulation and Coding Scheme (MCS), 183–184
monitoring
anomaly-based, 369
APs, 371–372
behavior-based, 369
compliance, 399
devices, 258
digital, 11–12
heuristic, 370
signature-based, 368
sports/fitness, 472
standard network tools, 410–412
wireless network tools, 407–410
motion sensors, 463
Multi-User MIMO (MU MIMO), 481
multicast frame, 260
Multichannel Multipoint Distribution Service (MMDS), 477
multipath, 101, 432
multipath distortion, 162
multiple-channel (multichannel) technology, 477
multiple-channel architecture (MCA), 255–256
Multiple-Input Multiple-Output (MIMO)
diversity, 138
intersymbol interference and, 432–433
Long Term Evolution and, 480
overview, 136–140
Spatial Multiplexing Power Save and, 262
multiplexing, 139–140, 166–167
multiport PoE injectors, 63
municipal networks, 13–14
N nanoseconds, 105
narrowband interference, 429
narrowband transmission, 160–162, 168
National Football League (NFL), 158
National Security Institute (NSI), 511
near field communication (NFC), 471
near-LoS paths, 59
near/far transmissions, 437–438
net allocation vector (NAV), 220
NetBEUI, 199
NetBios traffic, 328
Netgear, 510
Netsh utility, 112–114
Network Connection Details dialog box, 441, 442
network interface cards (NICs), 45–50, 61, 286
Network layer, 160
Network Meter gadget, 32–33, 505
Network Sharing Center, 440
network(s). See also specific networks
hard edge, 324, 325
placement, wireless LAN controllers, 252
NFC (near field communication), 471
NFL (National Football League), 158
NICs (network interface cards), 45–50, 61, 286
noise, 100, 428, 431
noise floor, 428
non-line-of-sight (non-LoS) paths, 59
nonroot mode, 58
notebook computers. See laptop computers
Novell IPX/SPX, 199
nulling, 105
Number of Packets setting, 287
O OFDM (orthogonal frequency division
multiplexing), 166–168, 174, 181, 480
Ohm’s Law, 96
Ohm, George, 96
ohms, 96
omnidirectional (dipole) antenna, 126–129, 133
on-board diagnostic port (ODB), 242
532 Index532 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
one-on-one interviews, 295
open APs, 325
Open Shortest Path First (OSPF), 328
open system authentication, 214, 215, 335, 336
Open Systems Interconnection (OSI) reference model, 159–160
open-source packet sniffers, 431
optimization
access point, 447–448
channel, 445–447
wireless device, 448–449
orthogonal frequency division multiplexing (OFDM), 166–168, 174, 181, 480. See also specific layers
oscillating signals, 83
OSI (Open Systems Interconnection) reference model, 159–160
out of phase, 87
outdoor site surveys, 283–284, 300–301
overlay sensors, 371
P Packet Size setting, 287
Packet Tx Type setting, 288
packet(s)
capturing, 339
defined, 171
EAP, 366
encrypting of, 334, 337
loss, 293
site surveys and, 282, 287–288
VLAN, 245–248
WEP and, 291, 334, 337
Pad field, 175–176
page mode, 466
Pamvotis, 191–193, 505, 506
parameter sets field, 212
Parity field, 175–176
park/hold mode, 466
parked slaves, 465–467
passive gain, 124–125
passive manual site survey, 282
passive RFID tags, 470
passive scanning, 211–213
passphrase, 361
passwords, 356–357, 401
patching, 323
PBCC-22 (Packet Binary Convolutional Coding), 181
PC Cards, 48–49
PCF (Point Coordination Function), 223–224
PCI (Peripheral Component Interconnect), 50
PCI Express (PCI-e) slots, 50
PCMCIA (Personal Computer Memory Card International Association) cards, 48–49
PDU (Protocol Data Unit), 171, 204–205
PEAPv0/EAP-MSCHAPv2 protocol, 366
PEAPv1/EAP-GTC protocol, 366
peer-to-peer (ad hoc) mode, 203
peer-to-peer topology, 474
per-packet key, 358
Per-User Preshared Keys (PPSK), 366
Percent Success Threshold setting, 288
percentage, RSSI, 99–100
performance, configuring APs for, 491–492
periodic site surveys, 281
Peripheral Component Interconnect (PCI), 50
Personal Computer Memory Card International Association (PCMCIA) cards, 48–49
personal identification number (PIN), 60, 61, 376
petabyte (PB), 481
phase, 87–88
phase modulation (PM), 93
phase shift keying (PSK), 94, 95
Phased Coexistence Operation (PCO), 183
phishing, 396–398
Physical (PHY) layer
all-band interference and, 430
DSSS and, 181
narrowband transmission, 160–161, 168
overview, 159–160
spread spectrum transmission, 161–168
standards, 168–184
Physical Layer Convergence Procedure (PLCP) sublayer, 169–172, 175–176
Physical Medium Dependent (PMD) sublayer, 169–170, 172–173
physical requirements, site surveys, 296
picocells, 448
piconet, Bluetooth, 465–467, 468
PIFS (Point Coordination Function IFS), 222
PIN (personal identification number), 60, 61, 376
plaintext, 332, 333
planning. See site survey(s)
PLCP (Physical Layer Convergence Procedure) sublayer, 169–172, 175–176
PLCP Protocol Data Unit (PPDU), 205
PLCP Service Data Unit (PSDU), 205
plenums, 141
PMD (Physical Medium Dependent) sublayer, 169–170, 172–173
pocketknives, 467
PoE (Power over Ethernet), 61–63
Point Coordination Function (PCF), 223–224
Point Coordination Function IFS (PIFS), 222
point-to-multipoint (PtMP), 57–58
point-to-point (PtP), 57–58
polarization, 128–129
policies, security, 398–402
polling, 223–224
Portable Network Graphics (.png), 284
portable wireless inventory devices, 6, 7
postdeployment site surveys, 281
power
consumption, 469
electrical, 96
levels, 285, 430, 435
maintenance, 432
management, 258–262
troubleshooting settings, 434–435
Power over Ethernet (PoE), 61–63
power save mode, 259
Power Save Multi-Poll (PSMP), 261–262
power sourcing equipment (PSE), 62
Pre-n devices, 44–45
predeployment site surveys, 281
predictive analysis simulation application, 282–283
predictive site surveys, 282–283, 284
Presentation layer, 160
preshared key (PSK), 360, 444
primary channel, 182
PRNG (pseudo-random number generator), 334, 356
probe request frame, 210
probe response frame, 210
profiles, 253, 444
Progressive Insurance, 242
Project 802, 23
propagation behaviors, 100–101
protection mechanisms, RTS/CTS, 221
protection, information. See information security; security
protocol analyzers, 291–292, 372–373, 377
Protocol Data Unit (PDU), 171, 204–205
Index 533Index 533
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
pseudo-random number generator (PRNG), 334, 356
PSMP (Power Save Multi-Poll), 261–262
public safety organizations, 10, 14
Push-Button method, 376
PuTTY, 387–388, 506
Q QoS (Quality of Service), 244–245, 469
quadrature amplitude modulation (QAM), 177, 178
quadrature phase shift keying (QPSK), 177
Quality of Service (Qos), 244–245, 469
quarter wavelength, 122
questionnaires, 296
R radio chain, 137
radio frequency (RF)
amplifier, 142
antennas and, 143–145
attenuators, 142
behavior of, 100–105, 152–155
cables, 142–143
connectors, 142–143
electromagnetic waves, 82–91
interference, 17, 428–433, 431
jamming, 328
line-of-sight, 135
loss, 97–98, 104–105
Math, 98, 99
measurement, 95–100
modulation, 91–95
planning and management tools, 282–283
scanning, 372–373
signal splitters, 142–143
site tuning, 414–415
troubleshooting, 430
radio frequency identification (RFID) tags
active, 470
defined, 7
health care industry and, 11
manufacturing and, 9
overview, 470–471
passive, 470
retail and, 463
warehouse management and, 7–9
radio frequency interference (RFI), 428
radio waves, 42, 89, 128
RADIUS (Remote Authentication Dial in User Service), 364–365
Rate field, 175–176
RC4 cipher algorithm, 334
Real-Time Location Services (RTLS), 372
Realtime View charts, 290
reassociation request frame, 210
reassociation response frame, 210
Receive Signal Strength Indicator (RSSI), 98–99, 286
Reduced IFS (RIFS), 222
reduced-channel FHSS, 165
reflection, 102
refraction, 102, 103, 430
regulatory agencies, 20–25
Remote Authentication Dial In User Service (RADIUS), 364–365
Remote Network Monitoring (RMON), 411–412
remote office WLAN controllers, 53
remote wireless bridges, 57–59
remote-access VPNs, 373
repeater mode, 59
reports, site survey, 301–303
Request to Send/Clear to Send (RTS/CTS), 220–223
residential WLAN gateway, 59–61
resistance, 96
retail sales, 354–355, 392–393, 463
Retail Transaction Switch (RTS) servers, 354
return loss, 144
RFID (radio frequency identification) tags. See radio frequency identification (RFID) tags
RFID pad reader, 7–9
risk, 394–398, 399
RJ-45 connections, 45–46
RMON (Remote Network Monitoring), 411–412
roaming
channel optimization and, 445–446
client, 254
ESS and, 201–203
Layer 2, 201, 248
Layer 3, 202, 248
MAC layer and, 212
optimization and, 445–446, 448–449
overview, 201–202
SSID hiding and, 336
wireless device optimization and, 448–449
robotic drive units, 278
robust security network (RSN), 361–367
rogue APs
defined, 371–372
discovery tools, 377–378
overview, 325–326
Role-Based Access Control (RBAC), 376–377
roller barrier, 406
root bridge, 58
root mode, 58
rotating spikes, 406
rounds, 362
routing algorithms, 56
RSSI (Receive Signal Strength Indicator), 98–99, 286
RTS threshold, 220
RTS/CTS (Request to Send/Clear to Send), 220–223
S San Francisco Bay Area Rapid Transit
(BART), 9
San Francisco parking, 120
scalability, 253
scaling, 256
scanning, 211–213, 368, 372–373
scattering, 102, 103
scatternet, 466–467
Scheduled PSMP (S-PSMP), 261
scrambling, data, 332–333
secondary channel, 182
Secret Communication System, 162
sectorized antennas, 129–130
secure device management protocols, 374–375
Secure Digital (SD) cards, 49–50
Secure Digital Input Output (SDIO) devices, 49–50
Secure Shell (SSH), 374, 387–388
Secure Shell 2 (SSH2), 374
Secure Sockets Layer (SSL), 374
security. See also encryption
authentication and, 335
awareness and training, 403–404
DSSS and, 166
firewalls, 324, 367
implementation of, 361–367
legacy protections, 331–335
overview, 16–17
passwords, 356–357, 401
534 Index534 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
physical, 404–407
policies, 398–402
principles of information, 319–324
requirements, 296
retail, 354–355
risk management, 394–398
rogue AP discovery tools, 377–378
Role-Based Access Control, 376–377
secure device management protocols, 374–375
settings, 437
spread spectrum transmissions and, 162
SSIDs and, 348
transitional solutions, 355–361
UWB and, 469
virtual private networks, 373–374
vulnerabilities, 335–339
WEP and, 348
Wi-Fi Protected Setup, 375–376
wireless attacks, 318–319, 324–331
Wireless Intrusion Protection System, 367–373
WPA2 models, 366–367
semidirectional antennas, 129–130, 134
sensitivity, 144
sensors, 370–371
Service Data Unit (SDU), 171, 204
Service field, 175–176
Service Set Identifiers (SSIDs). See SSIDs (Service Set Identifiers)
service sets, 199–204, 243
Session layer, 160
shadowing, 296
shared key authentication, 214–215, 335, 337, 360
shared secrets, 360
SHF (Super High Frequency), 90
Short IFS (SIFS), 222
shoulder surfing, 337
SiGe (silicon germanium), 43
Signal Data Rate field, 171
signal strength, 95–100, 114–116, 286
signal-to-noise ratio, 100
signature-based monitoring, 368
signatures, 370
Simbex, 158
Simple Network Management Protocol (SNMP)
defined, 252
management stations, 410
overview, 374–375, 410–411
traps, 410–411
sine waves, 83
single port PoE injectors, 63
single-channel architecture (SCA), 256–257
single-input single-output (SISO), 137, 432–433
site survey(s)
analyzers, 287–288
dedicated applications, 287–288, 289
defined, 280
manual, 282, 284–285
overview, 279–280
performing, 281–282, 294–298, 299–303
predictive, 282–283, 284
protocol analyzer, 291–292
purpose of, 280–281
reports, 301–303
spectrum analyzer, 288–291
tools, 292–293, 309–313
troubleshooting, 281
types of, 282–284
voice over WiFi tools/surveys, 293–294
wireless device tools, 285–286
site-to-site VPN, 373
slaves, 465–467
slot time, 219
SMAC, 345–346, 506
small form factor cards, 49–50
small office/home office (SOHO), 5, 29, 59–60, 361
Smart Keys, 471
smart slippers, 12
smoke detection, 470
Snapshot® discount program, 242
Sniffer Network Analyzer, 291
sniffers, 291, 431
SNIP MIBs, 421–422
SNMP (Simple Network Management Protocol). See Simple Network Management Protocol (SNMP)
social engineering, 395–398
SoftAP, 61
software
client, 51
vulnerabilities in, 323
software agent, 410
SOHO (small office/home office), 5, 29, 59–60, 361
SOM (system operating margin), 144, 432
Space Time Block Coding (STBC), 140
spacial multiplexing, 139–140
Spanning Tree Protocol (STP), 328
spatial diversity, 138–139
Spatial Multiplexing Power Save (SMPS), 262
spectral efficiency, 182
spectrum
analyzers, 288–291, 429, 431, 435
IEEE 802.11ac and, 481
utilization, 469
speed
Bluetooth technology and, 467
of attacks, 321
of data transfer, 468
transmission, 42–44, 435–436
WLANs and, 17
split MAC architecture, 249
spoofing addresses, 337
spread spectrum transmissions
advantages over narrowband transmission, 161–162
direct sequence, 165–166
frequency-hopping, 162–165
orthogonal frequency division multiplexing, 166–168
SSIDs (Service Set Identifiers)
AP configuration settings, 436
association and, 215–216
authentication, 214–215, 336–337
BSS and, 199
defined, 199
duplicate, 445
field, 212
hiding, 336–337
security, 348
troubleshooting, 436, 439
WEP security and, 348
standards. See also specific standards
advantages of, 37–38
consortia-created, 38–39
de facto, 38
de jure, 38
defined, 37, 398
MAC layer, 204–225
need for, 37–38
organizations, 20–25
Physical layer, 168–184
star topology, 475
Index 535Index 535
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Start Frame Delimiter field, 171
state machine, 214
stations (STAs), 42
stream cipher, 362
streaming, 481
Streetline Networks, 120
Super High Frequency (SHF), 90
supplicant, 364
supported rates, 212
surveillance, video, 406
surveys. See site survey(s)
Swiss Army pocketknives, 467
Swiss Wireless, 505
switching, 129, 200
switching software, 430
symbols, 167
Synchronization field, 171, 175–176
system operating margin (SOM), 144, 432
system throughput, 435–436
T tablet computers, 258–259, 286
Tail field, 175–176
Task Group n (TGn), 44
task groups (TGs), 23–24
TCP/IP, 202, 410, 412
telegraphy, wireless, 122
telephones, cellular, 18–19, 464–468, 479–480
temperature control, 470
temporal key, 359
Temporal Key Integrity Protocol (TKIP). See TKIP (Temporal Key Integrity Protocol)
terabyte (TB), 481
thin APs, 53–54, 249–250
threat agents, 395, 399
threats, 394–395
throughput
BSA and, 200
channel allocation, 256
defined, 43
firmware and, 415
HT (MIMO), 138
IEEE 802.11g and, 181
IEEE 802.11n and, 206
IEEE 802.11n HT and, 208
OFDM and, 168
standards to maximize, 447
system, 435–436
timestamp field, 212
tire-tracking, 471
TJX, 354–355
TKIP (Temporal Key Integrity Protocol)
CCMP and, 363
encryption, 358–359, 363
key mixing, 360
overview, 358–359
security and, 360
WPA2 and, 361
toll booths, 470
total cost of ownership (TCO), 249–250
traffic indication map (TIM), 259
training, 403–404
transmission opportunities (TXOP), 225
transmissions, wireless
options, 40–42
speed of, 42–44, 435–436
transmit beam forming (TxBF), 140
transmit diversity, 129
transmit power control (TPC), 175
Transport layer, 160
Transport Layer Security (TLS), 374
travel industry, 9–10
TREAD (U.S. Transportation, Recall, Enhancement, Accountability and Documentation) Act, 471
troubleshooting. See also error correction
overview, 427
RF interference, 428–433, 431
site surveys, 281
SSIDs, 436, 439
wireless devices, 437–445
WLAN configurations, 433–437
trunk-based leased lines, 15
trunking, 246
trust, 402
tunneling protocols, 373–374
turbo mode (2X mode), 177
U U.S. Department of Commerce, 333
U.S. Federal Communications Commission (FCC). See Federal Communications Commission (FCC)
U.S. passports, 471
U.S. Transportation, Recall, Enhancement, Accountability and Documentation Act (TREAD Act), 471
Ultra High Frequency (UHF), 90
ultra-wideband (UWB), 468–469
Ultrahigh Frequency tag, 471
unicast
frames, 259
traffic, 357–358
transmissions, 288
unidirectional amplifier, 142
UNII (Unlicensed National Information Infrastructure), 90–91, 174–175
universities, 198
unlicensed bands, 89–91
Unlicensed National Information Infrastructure (UNI or UNII), 90–91, 174–175
unmanaged switch, 252
Unofficial 802.11 Security Web site, 510
Unscheduled Automatic Power Save Delivery (U-APSD), 261
upfade, 105
USA-17, 80–81
USB flash drives, 234–235
USB NICs, 46–48
user profiles, 365
UWB (ultra-wideband), 468–469
V Variable Guard Interval (VGI), 183
variable-loss attenuators, 142
vehicle-to-vehicle (V2V) communications, 10
vertical polarization, 128–129
Very High Frequency (VHF), 90
Very Low Frequency (VLF), 90
video distribution, 468
video pills, 11, 12
video surveillance, 406
virtual APs, 73–77
virtual carrier sensing, 220–223
virtual local area network (VLAN), 245–248
virtual private dial-up network (VPDN), 373
virtual private network (VPN), 373–374
Virtual Router, 73–75, 505
Virtual Router Redundancy (VRRP), 328
Virtual WiFi, 61
visible light communications (VLC), 473–476
visible waves, 89
Vista, 51
Vistumbler
displaying RF signal strength, 114–115
gathering RF information, 309
536 Index536 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
identifying WLANs, 433
viewing security information with, 384–385
Web site, 505, 506
visual line of sight, 135
VLAN (virtual local area network), 245–248
VLAN (wireless virtual LAN), 245–248
VLC (visible light communications), 473–476
VLF (Very Low Frequency), 90
Voice over IP (VoIP), 245, 262
Voice over Wi-Fi (VoWiFi) tools/surveys, 293–294
VoIP (Voice over IP), 245, 262
voltage, 96
Voltage Standing Wave Ratio (VSWR), 144–145
volts, 96
VPDN (virtual private dial-up network), 373
VPN (virtual private network), 373–374
VPN concentrator, 373
VSWR (Voltage Standing Wave Ratio), 144–145
vulnerability, 336–337, 395, 398–399
W war driving, 330–331
Wardrive Web site, 510
warehouse management, 6–9
warehouse management system (WMS), 6–7
Washington State Ferry, 9
Waterfall View charts, 290
watts, 96
wave propagation, 101
Waveform View charts, 290
wavelengths, 83–85
weak keys, 333
weather interference, 430–431
Web sites
hands-on projects, 505–507
security organizations, 510–511
technical support, 510
wireless security, 510
wireless standards organizations and regulatory agencies, 509
wireless tools, 511
WEP. See wired equivalent privacy (WEP)
WEP2 (WEP Version 2), 356–357
whip antennas, 122
white space spectrum, 478
Wi-Fi (Wireless Fidelity) Alliance
certification, 45, 198
overview, 24–25
QoS specification, 245
Web site, 509
WPA and, 357
WPA2 and, 361, 367
WPS, 375–376
Wi-Fi Multimedia (WMM), 245
Wi-Fi Planning Tool (Aerohive), 311–313
Wi-Fi Protected Access (WPA), 357–361
Wi-Fi Protected Access 2 (WPA2), 361–367, 385–386
Wi-Fi Protected Setup (WPS), 385–386, 422–423
WiBro, 478
wideband interference, 429
WIDS (wireless intrusion detection systems), 368–373
WildPackets, 511
WiMAX (Worldwide Interoperability for Microwave Access), 137, 478–479, 480
Windows 7. See Microsoft Windows 7
Windows 8, 443
Windows Connect Now (WCN), 60
Windows XP, 51, 336
WIPS (wireless intrusion prevention systems), 370–373
wired equivalent privacy (WEP)
cryptography, 332–333
encryption, 334–335, 349–351
implementation, 333–335
initialization vector and, 356, 358
overview, 332
packets and, 291, 334, 337
security, 348
vulnerabilities of, 337–339, 355–356
weakness of, 318, 354
wireless adapters, 439, 444
Wireless Blog, 511
wireless client network interface card adapters, 46–50, 61, 286
wireless device(s)
monitoring, 258
optimization, 448–449
power levels, 435
probe, 377
tools, 285–286
tracking, 372
troubleshooting, 437–445, 438, 443–445
Wireless Display (WiDi), 468
wireless distribution system (WDS), 203
Wireless Ethernet Compatibility Alliance (WECA), 24–25
wireless indoor location tracking, 462–463
Wireless Internet Service Provider roaming (WISPr), 443
wireless intrusion detection systems (WIDS), 368–373
wireless intrusion prevention systems (WIPS), 370–373
wireless ISPs, 14
wireless LAN controllers (WLCs), 53, 252–254
wireless local area networks (WLANs). See WLANs (wireless local area networks)
wireless mesh networks (WMNs), 54–56, 250, 255
wireless mesh routers, 54
wireless metropolitan area networks (WMANs)
Broadband Radio Service, 477–478
distance range of, 464
free space optics, 476–477
overview, 19, 476
Wireless Network Connection Properties dialog box, 441–443
Wireless Network Connection Status dialog box, 441
wireless network management system (WNMS), 258–262
Wireless Networking Resources, 511
wireless networks. See also specific networks
characteristics of, 21
comparison of, 20
geographical distance and, 463–464
standards organizations and regulatory agencies, 20–25
wireless NICs (network interface cards), 45–50, 61, 286
wireless personal area networks (WPANs)
Bluetooth technology, 464–468
body area networks, 472–473
distance range of, 463, 464
low rate technologies, 469–471
overview, 18–19
ultra-wideband, 468–469
visible light communication, 473–476
wireless policies, 401–402
wireless probes, 377–378
Index 537Index 537
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
Wireless Protocol Analyzer Comparisons, 511
wireless switches, 53, 252–254
wireless telegraphy, 122
wireless virtual LANs (VLANs), 245–248
wireless wide area networks (WWANs)
distance range of, 464
IEEE 802.11ac, 480–482
Long Term Evolution, 479–480
overview, 19–20, 478
WiMAX, 478–479
wireless workgroup bridges, 56–59
Wireless Zero Configuration (WZC), 51
Wireshark network protocol analyzer, 234–238, 506
WISPr (Wireless Internet Service Provider roaming), 443
WLAN array (Xirrus), 254
WLAN AutoConfig, 51, 70–72
WLANs (wireless local area networks)
advantages of, 12–16
applications of, 5–12
client hardware/software, 45–51
configuring, 433–437
disadvantages of, 16–18
discovering, 211–213
joining, 213–216
maintaining, 412–415
monitoring, 407–412
overview, 3, 19
profile, 253
standards, 37–45
transmitting on, 216–225
types of, 18–20, 39–45
utilization statistics of, 191–193
WLCs (wireless LAN controllers), 53, 252–254
WMANs (wireless metropolitan area networks). See wireless metropolitan area networks (WMANs)
WMM (Wi-Fi Multimedia), 245
WMM Power-Save (WMM-PS), 261
WMNs (wireless mesh networks), 54–56, 250, 255
WNMS (wireless network management system), 258–262
working groups (WGs), 23–24
World War II, 162
Worldwide Interoperability for Microwave Access (WiMAX), 137, 478–479, 480
WPA (Wi-Fi Protected Access), 357–361
WPA Enterprise, 358
WPA Personal, 357–358
WPA2 (Wi-Fi Protected Access 2), 361–367, 385–386
WPA2 Enterprise, 361
WPA2 Personal, 361
WPANs (wireless personal area networks). See wireless personal area networks (WPANs)
WPS (Wi-Fi Protected Setup), 375–377, 385–386, 422–423
WWANs (wireless wide area networks). See wireless wide area networks (WWANs)
X x-rays, 89
X2Impact, 158
Xirrus Wi-Fi Inspector gadget, 194, 506
Xirrus Wi-Fi Monitor gadget, 155, 505
Xirrus WLAN array, 254
Z zettabyte (ZB), 481
ZigBee, 470
538 Index538 Index
Copyright 2012 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.