24 November 2009

A Tale of Two Cities: Educause Denver and Interop New York


It was the best of Wi-Fi, it was the worst of Wi-Fi, it was the age of access, it was the age of stagnation, it was the epoch of mobility, it was the epoch isolation, it was the season of enlightenment, it was the season of bewilderment, it was the spring of tranquility, it was the winter of frustration, we had everything that was promised, we had nothing but words, we were all going direct to the Internet, we were all going nowhere (and slowly at that) — in short, the Aruba 802.11n wireless LAN at Educause Denver delivered the goods, the Xirrus arrays at Interop New York....well, read on.

The Educause 802.11n Wi-Fi network ran flawlessly and was smokin’ hot: 800 simultaneous users, 50% 802.11n clients, 50Mpbs delivered in client speed tests.


If you want to know what happened in New York see Jim Frey’s Network World posting, "Internet = InterNOT @ Interop."

If it looks like a skeet, and it flies like a skeet, and its connectivity is comparable to a skeet, then treat it like a skeet.

14 October 2009

The Shoe Drops: Brocade Dumps Single-Channel Architecture


Brocade yesterday announced that it will be reselling a new line of wireless LANs. Foundry (now part of Brocade) has been reselling wireless LANs for some time, so aside from a new OEM supplier where is the news?

Well, it turns out that Brocade didn't just select another vendor. It selected a completely different wireless LAN technology.


For roughly three years Foundry has been reselling Meru's proprietary single-channel / virtual-cell architecture. Meru has long made what we consider to be outrageous claims about its proprietary technology - airtime fairness, high throughput, fewer required access points, and so on. The Foundry team has had years of experience understanding the real strengths and weaknesses of Meru's single-channel networks, their 802.11n technology, their network management. They have deployed wireless LANs with virtual-cell technology across a range of customer types - education, healthcare, business. They, better than any single customer, knew the strengths and weaknesses of the vendor and the technology.


The upshot of yesterday’s news? Single-channel wireless LAN technology was rejected by the customer that knew it best.


Changing an OEM supplier is a decision that is never made lightly because it profoundly impacts the customer base and the company's reputation. Customers who invested in the single-channel / virtual-cell architecture are surely asking why Brocade abandoned a network that was supposed to be so innovative. What are the limitations and deficiencies that caused Brocade to change the underlying architecture as well as the vendor? The Brocade announcement is a watershed because it is a repudiation of the proprietary single-channel architecture. It also serves as a cautionary tale that vendor claims that sound too good to be true generally are.


The technology shift from single-channel to a new architecture will likely be very disruptive to Brocade’s customers. Brocade has already removed the Meru-based products from its Web site, and support-related issues will no doubt be unpleasant. But all is not lost.


Aruba wants Brocade’s wireless LAN customers as our customers, and we have a generous trade-in program to ease the pain of the transition to our award-winning adaptive 802.11n networks. Switching to Aruba will be a real step-up for those customers because we have field-proven adaptive wireless management, wireless infrastructure control, remote networking, wireless intrusion detection, policy-based firewalling, and client-to-core security that were never before available from Meru. Our AirWave Wireless Management Suite will manage their legacy Brocade/Meru network from the same console from which they will manage their brand spanking new Aruba wireless LAN.


The transition will be smooth and Brocade’s customers will be stepping up to a more secure, more stable platform from Aruba. And instead of a story line they'll be getting the real deal.

04 October 2009

Wired Bondage


The corded desk phone is becoming a rarity in most households, having long since been replaced by the more convenient wireless phone. Wireless phones offer untethered mobility, allowing us to make and receive calls wherever it's most convenient to do so. And we're not sacrificing features in the pursuit of mobility. Wireless phones today offer far more calling, conferencing, called ID, and answering options than corded phones ever did.

And then there's the office phone. Like a throwback in time, when we enter the typical place of work we enter a world of wired bondage. Why is the corded desk phone still so prominent in offices?

Single mode and dual-mode Wi-Fi enabled phones are available, but the small handheld devices don't offer the same user experience as a desk phone. There's something just right about a desk phone's handset that makes it ideal for hands-free talking when a speakerphone just won't do.

Problem is that the desk phone just hasn't made the same strides as the wireless handset. Sure, we've added IP connectivity, fancy displays for Caller ID, phone books that simplify dialing, and even wireless headsets to bring us a small measure of mobility. But the modern desk phone still requires a wired Ethernet port, and typically a Power over Ethernet power source, too.

This megalith with a direct lineage extending back to the telegraph is the last hurdle to the introduction of a wireless network edge. Replace the wired desk phone with an enterprise-class Wi-Fi desk phone and you can eliminate a big chuck of the wiring and edge switching infrastructure, lowering costs and saving electricity to boot. You also gain the freedom to locate the phone where you want it, and to make adds, moves, and changes at minimal expense.

134 years after the creation of the phone gave us the freedom to speak with the world, it today shackles us in wired bondage. It tethers us to Ethernet ports, to expensive infrastructure, to yesterday's way of working. Let's look forward to the day when Wi-Fi desk phones set us free at last.

02 August 2009

Who Moved My Packets, Or How I Learned To Stop Worrying And Cut The Cord


With the ratification of 802.11n just around the corner, it’s a good time to reexamine the fundamentals of Wi-Fi design and determine how this blazingly fast new technology will affect you. Who Moved My Packets is about the design considerations associated with 802.11n data, voice, and video applications.

Let’s start with a discussion about designing for coverage or capacity. For some wireless applications simple connectivity is the biggest issue with which users have to contend. Designing a network for coverage ensures that a Wi-Fi signal can be received at any location in which a Wi-Fi device is likely to be used. Connectivity is the primary objective - bit rate, packet throughout, multi-media support, quality of service, and even redundancy of coverage are secondary considerations.

Consider an indoor application in which Wi-Fi is used to communicate with a pool of bar code scanners for inventory management. The users are few in number, the amount of data transmitted is relatively small. Since the bit rate of an in-building Wi-Fi connection typically falls with distance and in the presence of interference sources, what started as a high speed connection near an access point could drop to 1Mpbs or less just a short distance away. However, even at that low throughput, a network designed for coverage should be sufficient for the application.

Any Wi-Fi network can be designed for coverage, and as a rule, designing for coverage requires far fewer access points. Just crank up the access point power to full, space the access points so that their coverage patterns overlap slightly, and the design part is done. Interference compensation, fair airtime availability, security, and network management are another matter entirely, but they’re outside the scope of this discussion.

A handful of Wi-Fi vendors have made an art of promoting their products as requiring fewer access points. Some Wi-Fi array (multiple access points in one box) and single channel vendors go so far as to tout their “unique” ability to deliver what no other Wi-Fi vendors can accomplish.


It’s all smoke and mirrors. Wi-Fi vendors all use Wi-Fi chip sets from a small pool of IC suppliers, and by regulation the power output of the radios is tightly controller by the government. The distance over which they can transmit, using comparable antennas, is the same. If you pull back the curtain, the secret of their claims is simply that they’re designing for coverage. Nothing more.


In fact, it’s really something less. Why? Because many users need a system that is designed for capacity. In a network designed for capacity, coverage is a given but bit rate, packet throughout, multi-media support, quality of service, and often fault-tolerance are primary considerations.


A capacity-based network requires that the vendor pay keen attention to internal architecture, algorithmic processing, and packet handling necessary to service deployments with a high capacity requirement: (1) large number of users; (2) users that are densely congregated; or (3) applications using voice or streaming video or business-critical telemetry data. Coverage alone is not sufficient for these scenarios – they require guaranteed bit rate, high packet throughout, and quality of service.


These scenarios are already the norm in education, healthcare, and government applications, and are fast becoming typical in enterprise, retail, and industrial deployments. With the migration of data, voice, and video applications to 802.11n from wired LANs, the need for capacity-based Wi-Fi will skyrocket. Users will expect wire-like performance with virtually unconstrained capacity on their shiny new 802.11n networks.


So the next time you’re given a pitch for a wireless LAN with one half, one quarter, one eighth the number of access points of an Aruba network, ask the vendor if they’re designing for coverage or capacity. And ask for test data to back it up. Doing so will avoid following Maj. T.J. 'King' Kong on a ride that is a mistake from the outset.

30 July 2009

The Decline And Fall Of Ethernet (At The Edge)



The first quarter of 2009 witnessed the first ever decline in wired switch port sales, accompanied by sales of laptops exceeding those of desktop PCs. These events herald the advent of the always-connected mobile workforce. A workforce that expects network access to be available everywhere works transpires. An untethered workforce.

According to the PEW Internet & American Life Project, it is not unusual for Americans to use the Internet “constantly” at work. To do so effectively, Americans either need to be equipped with Ethernet extension cords or cut the cord entirely. Why? Because where once we worked at desks all day long, today roughly half of us spend at least 20 percent of our work time away from our primary workplace. That from Yankee Group's Anywhere Enterprise—Large: 2009 U.S. Transforming Infrastructure and Transforming Applications Survey.


We are transitioning into an increasingly mobile workforce. And to stay connected we are turning our backs on traditional wired Ethernet networks and looking to Wi-Fi. According to another Yankee Group report, Make Wireless the Burger of Enterprise LAN Access, Not the Fries, in 2006 about 43 percent of enterprises did not even offer Wi-Fi access. In 2009 that number dropped to just 11 percent. More telling, 45 percent of enterprises expect that by 2012 more than 50% of their work forces will be connected to an office Wi-Fi network.


The transition from wired to Wi-Fi did not come quickly or easily. Many generations of wireless pretenders have attempted to steal the edge access throne from Ethernet – starting with proprietary frequency hoppers and moving through three versions of 802.11 standards-based wireless.

In ascendance now is the real king – 802.11n. The first standards-based wireless to offer performance, security, and value that rivals or bests Ethernet. In difficult economic times, it’s value that sells, and for network access 802.11n wins hands down over wired networks except for a very limited number of power users.

The good news is that selecting an access method is not a binary choice. Users can mix Ethernet and 802.11n access, using the former only where necessary and the latter everywhere else. Indeed, Wave 1 of the Yankee Group survey revealed that forty percent of enterprises have no plans to deploy gigabit Ethernet to the desktop, preferring instead to move to 802.11n Wi-Fi. Following such a
“rightsizing” process promises to deliver the greatest value and the lowest access cost per user, while offering a level of mobility a wired network can simply never match.

Just as the Roman Empire succumbed to invasions due to the loss of its greatness, so too is Ethernet edge access fading in the face of a more virtuous technology. So if you’re considering an office network refresh, or have a green field deployment, follow the tide. As Gibbons wrote, “the wind and the waves are always on the side of the ablest navigators.”

24 July 2009

The End Of The Beginning: The Final Ratification Of The 802.11n Standard


The long-awaited ratification of the high-speed 802.11n standard is slated to happen in mid-September. And the ramifications are both large and small.


Large in the sense that many enterprises have held back from deploying 802.11n until the standard is formally ratified. The reason? Fear of incompatibility between products compliant with the Draft 2.0 pre-standard and those built to meet the final standard.


Small because Draft 2.0 802.11n was already the de facto standard. In order to ameliorate concerns about potential incompatibilities, the Wi-Fi Alliance last year stated that interoperability was a given between products adhering to the draft and final versions of the standard. The September 2009 ratification will simply render that pronouncement prescient, with the draft morphing into the de jure standard with no significant changes to mandatory specifications.


When implemented "correctly," 802.11n is the first wireless technology that not only gives Ethernet a run for its money, it wins the skirmish, battle, and war. I say correctly because there are wide variations among vendors in how 802.11n channels and bands are managed, the impact of legacy 802.11a/b/g clients, the performance of densely deployed clients, and how secure 802.11n networks can be made against attack.


Wire-like reliability, harmonious client interoperability, exceptional throughput, and military-grade security are all possible – but none is assured. Not without additional engineering built on top of the 802.11n standard.


So to paraphrase Churchill, with the ratification of the 802.11n standard we’ve at last reached the end of the beginning. With the standard in place the impetus will now be on end users to validate vendors’ claims about reliability, interoperability, performance, and security. Conduct bake-offs, put equipment through its paces, ensure the veracity of claimed features and benefits. The results will open your eyes to the realization that the ratification of a standard is just the beginning of the real work.

If you’re interested in learning more about how Aruba is making 802.1n realize its full potential, please see the white paper
ARM Yourself to Increase Enterprise WLAN Data Capacity (http://bit.ly/wFj9n) and the technical brief 802.11n Client Throughput Performance (http://bit.ly/bMvT).

24 May 2009

Companies That Can't Innovate Replicate...Or Just Whine

A funny thing happened while Aruba was on the way to market with its innovative Virtual Branch Network (VBN) solution and "network rightsizing" initiative - Cisco got hot and bothered.

Just after the VBN solution received the 2009 Best of Interop Las Vegas Award in the Wireless & Mobility category (http://bit.ly/aUocV), Joel Conover, senior manager, network systems at Cisco called the new 600 Series Branch Office Controller "a travesty" (http://bit.ly/KOmNv). He then claimed that Cisco offered the same capabilities with a new product...but only when used behind an expensive Cisco 800 Series ISR Router. Why does Cisco need an expensive WAN router when Aruba VBN does not, even for the entry level $99 list RAP-2?

Aruba's rightsizing initiative promotes the use of Wi-Fi everywhere it can be used, wired networks only where they must be used. Rightsizing is a three step process whereby users assess current wired LAN utilization using a tool like StatSeeker (on average 30-40% of wired ports aren't used at all), consolidate switches and scale service plans/cooling/power consumption to match, and then invest the savings in upgrading the Wi-Fi network to 802.11n. Simple and logical, right? If you can save money you should. If your network is already rightsizied then the most you've invested is some time verifying that's the case.

Customer reaction to rightsizing has been nothing short of amazing. The California State University System identified $30M of savings by shifting from wired networks to Wi-Fi (http://bit.ly/uvjbu).

Cisco, however, had a different reaction.When John Cox published an article in Network World titled "Is it time to cut the Ethernet access cable?" (http://bit.ly/3cG4t) in which he noted that pervasive WLANs leave costly wired ports idle, Cisco flipped. Chris Kozup, ironically titled senior manager for mobility solutions at Cisco, maintained that an Ethernet cable is exactly what everyone needs. Aruba's right-sizing is a "shortsighted message from a wireless-only provider. It's penny-wise and pound-foolish." Using Wi-Fi as the primary form of network access is inflexible and the benefits exaggerated, he said.

And yet....Cisco itself released a report stating that its own employees average 90 minutes per day of additional productive time using Wi-Fi (http://bit.ly/UNHQd). So why is Cisco so aggressively pushing wired LANs on customers?

The answer to both questions can be found in Cisco's business model, which depends on profits generated from selling overpriced wired routers and wired ports. The big R&D bucks go to the wired side of the house, which is perhaps one reason why Cisco's lackluster wireless LANs are missing innovative features like application awareness and adaptive response to changes in local RF conditions.

Cisco's focus on wired LANs and lack of wireless innovation has resulted in two consistent forms of behavior: attempts to replicate features found in Aruba's innovative products (Cisco's new band steering feature and the changes in their newest network management console appear to be almost exact replicas of Aruba features); and whining, as exemplified in the articles above.

If you want real innovation, look to companies that identify problems and deliver creative solutions. Replicators and whiners need not apply.

21 April 2009

802.11n Performance: Radios vs. Streams

Many organizations pride themselves on being at the cutting edge of technological innovation, the first to deploy a vendors newest innovation. Indeed, >50% of organizations surveyed will evaluate other wireless vendors’ products within the next 12-18 months. Being the first to catch the hottest new innovation carries with it the risk of being burned, and a little due diligence can go a long way in making sure that a buying decision is prudent.

Take for example the matter of 802.11n performance. 802.11n performance is based in part on both the number of radio chains and the number of spatial streams. The two are often confused...at the buyers peril. The number of radio chains corresponds with the number of transmitters or receivers, and is typically denoted as “m x n” where m is the number of transmitters, and n the number of receivers. m x n need not necessarily be symmetrical, and some 802.11n access point can dynamically adjust the numbers, e.g., a 3x3 radio can operate in 3x3, 2x3 or 1x3 mode depending on configuration, mode and power profile.

While multiple transmitter and receiver chains can be used to improve the signal quality, the big increases in data rates associated with multiple input-multiple output (MIMO) access points are more dependent on the number of spatial streams. Using 1 stream, the maximum 802.11n data rate per radio, assuming 40MHz bandwidth, is 150Mbps. Using 2 streams that number doubles to 300Mbps, and so on. The number of spatial streams is typically denoted by S in “n x m : S.” There are as yet no 3 stream access points on the market, though several access points have 3 receiver and/or transmitter chains.

By way of example, Aruba's AP-124 and AP-125 Access Points are 3x3:2 devices. In contrast, Cisco's 1140 and 1250 series access points have a dual transmitter, triple receiver design and are 2x3:2 devices. If you're looking for the best performance, Aruba's 3x3:2 access points are your best bet.

18 April 2009

Saving Energy and Money By Extending the Battery Life of Mobile Devices

The battery life of Wi-Fi capable mobile devices can be extended by enabling the Wi-Fi radio to enter a low-power “sleep” mode during period when the device neither needs to transmit or receive data. The longer the sleep time, the lower the battery drain. The difficulty is ensuring that sleep mode does not interfere with network performance, i.e., the device can wake-up in a timely manner.

Mobile device drivers and radio firmware employ a variety of pre-set times and trigger events to optimize entry into, and termination of, sleep time. The techniques employed typically vary by device and applications. For example, scanners typically have longer pre-set sleep times than laptops because the latter is assumed to have greater access to a recharger. The IEEE 802.11 standard includes a mandatory power save polling (PSP) feature whereby the Wi-Fi access point with which the device is associated must buffer data for that device while it is sleeping. Once the device awakens, the buffered data are delivered.

Following the transaction the device can return to the sleep mode if no additional data are to be sent or received. The PSP mechanism includes additional provisions that enable the access point to override sleep times and force the device to wake up at shorter intervals (called DTIM interval) even if there is no traffic to send or receive.

Battery life can be compromised as a result of two primary issues. Network performance problems, such as the failure to respond to ARP requests within the allocated time, or insufficient buffer storage within an access point, can reduce the DTIM interval and cause a mobile device to wake-up more often than necessary.

Additionally, broadcast and multicast Wi-Fi traffic chatter can prevent a mobile device from entering sleep mode, keeping it awake to check lest any of the chatter include packets intended for the device. In both scenarios battery life is compromised because the sleep mode cannot be utilized as intended.

To address these issues some vendors have implemented proprietary power-saving solutions that require software clients (Cisco CCX) or firmware hooks (Symbol). There are two fundamental issues with these approaches: they limit the range of available devices by locking customers into using only devices embedded with the proprietary technology; they require that the customer implement strict revision control over the client software and firmware to avoid incompatibilities or performance differences that exist between revisions.

Aruba has taken a standards-based approach to extending battery life by using infrastructure controls to manage off-the-shelf mobile devices without recourse to proprietary software or firmware. Three standards-based infrastructure controls are leveraged to equal or exceed the battery life achievable with proprietary solutions:

• Proxy-ARP: Mobility Controllers answer all ARP requests for devices with their radios in sleep mode, permitting longer DTIM intervals than could be supported if access points alone managed these requests;

• Long DTIMs: Long DTIM intervals are enabled by a battery boost feature, set by SSID, that permits the conversion of multicast / broadcast frames to unicast frames without having to buffer every DTIM period. Client devices can define their own DTIM periods thereby extending battery life without negatively affecting network performance;

• Multicast suppression: Mobility Controllers employ real-time packet inspection to identify and block network chatter (multicast traffic) that would negatively affect mobile devices. As a result, mobile devices able to remain in sleep mode longer and conserve additional power.

This three-pronged approach to power saving allows for longer sleep times on mobile devices such as scanners and voice handsets. Longer operating service from a single charge can have significant logistics and cost benefits, requiring fewer mobile devices, battery packs, and /or charging stations. Additionally, battery service life will be extended since service time is inversely related to the number of charge cycles.

Aruba’s standards-based approach also frees customers to use any Wi-Fi certified mobile device on the market, with the assurance that its battery life will be maximized regardless of make, model, form-factor or application. Eliminating sole-sourced products in favor of a procurement process based on price and/or performance can yield significant cost savings.

09 April 2009

You Get What You Pay For: Meru Pays Novarum For Performance Not Seen By Customers

Novarum recently published a test report claiming that Meru Networks’ 802.11n wireless LAN delivers higher throughput, better power efficiency, and superior airtime fairness than either Aruba or Cisco. The report is available from Novarum's Web site.

At a high level – setting aside all technical details – the report’s findings are at odds with the experience of many prospects and installed-base customers. Meru deployments have been removed from, or Meru lost head-to-head technical evaluations (“bake-offs”) at, the following schools among many others:

• University of Tennessee – replacement and bakeoff
• C-2 Raytown School District - replacement
• Norwood School - replacement
• Francis Xavier Warde School - replacement
• Drexel - bakeoff

The EDUCAUSE Board (http://ised-l.blogspot.com/2009_01_01_archive.html) has been rife with postings about issues with Meru’s 802.11n network. See for example the posting from Jomar McDonald, Director of Technology, The Frances Xavier Warde School.

Recent press articles have explored the reasons why customers are replacing Meru networks with Aruba adaptive 802.11n networks. One such case is Mike Morisy’s Search Networking article, “From Cisco to Meru to Aruba, school finally finds right WLAN” (http://searchnetworking.techtarget.com/news/article/0,289142,sid7_gci1352631,00.html#).

No one can dispute that performance differences exist between different wireless LANs, however, the dichotomy between the findings of the Novarum report and what customer’s experience in the real world is startling. A little digging into the research methodology employed in the Novarum report highlights casts a bright light on the reasons for this schism. Novarum is a paid consulting firm – a writer for hire, as it were – and given the fact that their findings are completely at odds with what we (along with other vendors) see in actual deployments in the industry, one has to believe that the results they publish are heavily influenced by the source of the funding. For example, a 2007 Novarum report – also commissioned by Meru – saw Aruba’s AP-70 Access Points tested with their antennas closed and in the wrong planar orientation relative to the clients. Novarum claimed that the network was set-up in accordance with Aruba’s guidelines, however, that proved not to be the case with the antenna position and a host of other critical parameters.

Fast forward to the newest Novarum report. The methodology issues are different from the 2007 report but just as significant with respect to their denigration of performance:

• The tests used just one single access point from each vendor - hardly an environment conducive to measuring wireless LAN capacity – and Meru access points were operated at full power but the other access points were not;

• Commercially available software releases were used for the Aruba and Cisco devices (Aruba 3.3.2.10 and Cisco 5.2.178) but Meru used a special test code that is not available to its customers. This inobtainium code was no doubt crafted to perform special tasks, just for the test, that would otherwise be unnatural acts in a commercial deployment;

• Encryption was disabled, despite a mandate by most customers to cipher communications. Encryption has been demonstrated to degrade the performance of Meru wireless LANs;

• Only two client types were used, one being a plug-in adapter, this despite the plethora of clients in real world deployments. The performance of Meru wireless LANs has been previously demonstrated to degrade in the presence of commonly used clients that were excluded from this test;

• Screen shots show major misconfigurations of Aruba’s controller. Aruba utilizes a technology called Adaptive Radio Management (ARM) to optimize wireless LAN performance, and in the test the ARM traffic management profile for fairness was created but not assigned to the Aruba access point under test. The voice traffic DSCP (ToS) tag was also incorrectly set to a value of 56. Other errors abound;

• Meru’s own installation guide states that 3X3 MIMO operation cannot be supported over 802.3af power over Ethernet, and that both radios have to back down to 2X2 MIMO. Therefore it is possible that a single radio was used during power measurements of the Meru access point, and the same was done for the Cisco 1250 access point – providing nothing more than that one radio consumes less power than two.

Occam’s razor - entia non sunt multiplicanda praeter necessitatem – states that the explanation of any phenomenon should be parsimonious with respect to assumptions about observable predictions. The Novarum report is nearly forty pages long, but the most fundamental underlying assumption – that the competing equipment was set-up properly, fairly, and in accordance with the manufacturers’ guidelines – was violated. The results – all of the results – were thereby nullified, the paper wasted.

One assumes one gets what one pays for: Meru got a test report in exchange for paying Novarum. Readers, however, got nothing of value. Caveat emptor.

At Aruba we appreciate and encourage head-to-head testing by our customers before they choose a WLAN. It is only in these real-world scenarios, running the applications and equipment that are intended to be used, that one can best evaluate the performance of a network. We also appreciate the value of thorough testing done by industry experts. However, when you can’t replicate a test in the real world - as is the case with the Novarum report – then the testing procedure is flawed and/or skewed.