skip to main |
skip to sidebar
Following a rise in the theft of payment card data, the Payment Card Industry (PCI) standards council was created by the top card brands to combat such crime. The resulting PCI Data Security Standard (DSS) defines mandatory security guidelines for use by all merchants and service providers that store, process and transmit cardholder data.
Wireless LAN security is a core component of these requirements. DSS v1.1 permitted the use of WEP encryption. Indeed, many retailers wanted to continue using the WEP devices they had already purchased, not because of the encryption scheme but to avoid the capital outlays required to replace WEP devices with higher security equivalents.
While WEP encryption is easily cracked, and was subsequently banned under DSS v1.2, an ingenious method was used to protect WEP devices so they could continue in service until DSS v1.2 was implemented. This solution protected the network without requiring any changes or clients added to the WEP devices. This solution holds great promise for the protection of SCADA, smart grid, and energy control systems.
Consider the humble bar code scanner. A workhorse of both point-of-sale (POS) and logistics systems, many scanners in use today rely on 802.11b/g Wi-Fi and WEP. Data from the scanners are passed via Wi-Fi to the enterprise network. If you crack WEP you therefore potentially open a back door into that network.
Integrating a stateful, role-based policy enforcement firewall into the wireless network slams shut this back door. By blacklisting unauthorized devices – not based on the port through which they entered the network but rather by the user and/or type of device - unauthorized users can be denied access to the rest of the network.
The firewall can distinguish between multiple classes of users, allowing one common network infrastructure to function as independent networks whose isolation is ensured by policy enforcement. Guest access is separate from POS which is separate from logistics, etc.
The elegance of this approach is that it can be retrofitted to existing networks – wired and wireless using a true overlay model - without any software clients or other changes to the devices being protected. It protects any devices from any manufacturers.
This same segmentation and policy enforcement scheme can be applied to wired and wireless sensors as soon as their data hit the IT infrastructure. Access rights, quality-of-service, bandwidth, VLANs – almost any parameter can be controlled and actively managed by the stateful, role-based policy enforcement firewall. It is to the benefits of this approach, used in conjunction with additional security enhancements, that we’ll turn in the next posting.
You've invested thousands - tens of thousands - in new educational software, a fleet of new Wi-Fi enabled laptops, and even computer carts to chauffeur computers between classrooms. But when the students fire up the machines and try to access the shiny new instructional video you're trying to stream wirelessly, they get nothing. Nothing but static. Or jitter. Or dropouts. What went wrong?
Those who forget the lessons of Wi-Fi are doomed to repeat them. Lesson #1: not all Wi-Fi networks are created equal. They all have access points, and they may even be Wi-Fi Alliance certified. But the similarity ends there.
Streaming real-time video is a demanding Wi-Fi application that requires additional processing above and beyond the Wi-Fi standard. The main technology enablers for video over Wi-Fi are adequate bandwidth, quality of service (QoS), and multicast support.
While 802.11n - the newest high-speed Wi-Fi technology - provides a significant bandwidth boost, RF management algorithms are important to ensure continuous, high-rate coverage. These algorithms must include control of the access points and the laptops (clients) - a feature provided by Aruba's Adaptive Radio Management technology - to automatically calculate the optimum channel and transmit power assignments, move clients to the most appropriate access point, and optimize the network’s use of available radio spectrum. This function is especially important for mobile clients - like iPhones - and in the presence of densely deployed clients such as you would find in classrooms and lecture halls.
QoS for video uses the same mechanisms as for voice, however, the bandwidth requirements of video applications vary widely. It is therefore important that any content that requires special handling be correctly flagged. Aruba's integrated stateful firewall does just that.
Since video can account for a large percentage of network bandwidth, determining when to broadcast to multiple clients - multicast streaming - is essential. Here again, Aruba incorporates technology to monitor multicast group members, and only delivers multicast streams to access points whose clients require it.
If you'd like to get the whole picture on video over Wi-Fi you've only to download our free white paper, I Can See Clearly Now. And leave it to someone else to relearn the lessons of Wi-Fi.
With the ratification of 802.11n just around the corner, it’s a good time to reexamine the fundamentals of Wi-Fi design and determine how this blazingly fast new technology will affect you. Who Moved My Packets is about the design considerations associated with 802.11n data, voice, and video applications.
Let’s start with a discussion about designing for coverage or capacity. For some wireless applications simple connectivity is the biggest issue with which users have to contend. Designing a network for coverage ensures that a Wi-Fi signal can be received at any location in which a Wi-Fi device is likely to be used. Connectivity is the primary objective - bit rate, packet throughout, multi-media support, quality of service, and even redundancy of coverage are secondary considerations.
Consider an indoor application in which Wi-Fi is used to communicate with a pool of bar code scanners for inventory management. The users are few in number, the amount of data transmitted is relatively small. Since the bit rate of an in-building Wi-Fi connection typically falls with distance and in the presence of interference sources, what started as a high speed connection near an access point could drop to 1Mpbs or less just a short distance away. However, even at that low throughput, a network designed for coverage should be sufficient for the application.
Any Wi-Fi network can be designed for coverage, and as a rule, designing for coverage requires far fewer access points. Just crank up the access point power to full, space the access points so that their coverage patterns overlap slightly, and the design part is done. Interference compensation, fair airtime availability, security, and network management are another matter entirely, but they’re outside the scope of this discussion.
A handful of Wi-Fi vendors have made an art of promoting their products as requiring fewer access points. Some Wi-Fi array (multiple access points in one box) and single channel vendors go so far as to tout their “unique” ability to deliver what no other Wi-Fi vendors can accomplish.
It’s all smoke and mirrors. Wi-Fi vendors all use Wi-Fi chip sets from a small pool of IC suppliers, and by regulation the power output of the radios is tightly controller by the government. The distance over which they can transmit, using comparable antennas, is the same. If you pull back the curtain, the secret of their claims is simply that they’re designing for coverage. Nothing more.
In fact, it’s really something less. Why? Because many users need a system that is designed for capacity. In a network designed for capacity, coverage is a given but bit rate, packet throughout, multi-media support, quality of service, and often fault-tolerance are primary considerations.
A capacity-based network requires that the vendor pay keen attention to internal architecture, algorithmic processing, and packet handling necessary to service deployments with a high capacity requirement: (1) large number of users; (2) users that are densely congregated; or (3) applications using voice or streaming video or business-critical telemetry data. Coverage alone is not sufficient for these scenarios – they require guaranteed bit rate, high packet throughout, and quality of service.
These scenarios are already the norm in education, healthcare, and government applications, and are fast becoming typical in enterprise, retail, and industrial deployments. With the migration of data, voice, and video applications to 802.11n from wired LANs, the need for capacity-based Wi-Fi will skyrocket. Users will expect wire-like performance with virtually unconstrained capacity on their shiny new 802.11n networks.
So the next time you’re given a pitch for a wireless LAN with one half, one quarter, one eighth the number of access points of an Aruba network, ask the vendor if they’re designing for coverage or capacity. And ask for test data to back it up. Doing so will avoid following Maj. T.J. 'King' Kong on a ride that is a mistake from the outset.