Saturday, November 14, 2009

Mobile IP RFC 3344

[notes]
Mobile IP RFC 3344



The Home Agent (HA) contains the location database unlike the CUWN, the HA does not maintain a distributed database between WLCs. It does not query other HA’s
 The mobile IP client joining the WLAN does not provide the HA with any information. There are two methods of client notification of a roam event:



  • Win OS L2 notification: Media Sense
  • Foreign Agent (FA) advertisements: the FAs are forwarded to the HA so the HA can build a new tunnel to the new FA and proceed to forward packets to the client.
Several types of tunnels are available: GRE UDP IP in IP


Behind a NAT gateway = UDP tunneling


Typically, the foreign WLC modifies the destination MAC address of any packet from the wireless client to be its gateway MAC before forwarding it on.


DHCP option 68 can be used to convey the HA to the MN (Mobile Node)

Mobile IP client software manipulate the host’s forwarding table so that the lower metric interface is the mobile IP client interface




VoWLAN

[notes]
VoWLAN



Recommendation to place all antennas 1 to 2 wavelengths from highly reflective surfaces.
2.4Ghz = 4.92 inches (12.5 cm)
  • 5GHz = 2.36 inches (6 cm)

The human head and body attenuates 5db of RF signal
If the antenna is in the body of the phone, the loss ~ 4db – 9db

Handsets do not have diversity antennas due to the length of the 2.4ghz wavelength distance (4.92in)


802.11A handsets do have a diversity antenna solution


DFS, 802.11h
When radar is detected:
  • stop packet transmission within 200ms
  • stop control transmission within 10 seconds
  • avoid transmitting on the channel for 30 minutes
  • scan a new channel for 60 seconds before transmitting

Cisco recommends that for voice apps, the cell edge be determined by using the actual phone at the desired data rate.


Voice packets sent between the AP and the phone are generally unicast RTP G711 packets with a typical size of 236 bytes.

Cisco recommends all APs have a maximum transmission power of 13dBm.


A call between two phones associated to the same AP counts as two active voice streams.

Guest anchor WLC – can support EoIP tunnels from 40 WLCs and supports 2500 simultaneous users and has forwarding capacity of 2gbps.

Multicast is not supported over guest tunnels.


One additional port number can be monitored for redirection: network web-auth-port


[notes]
MESH



By default, a RAP AP uses channel 161


Background scanning on 1510s operates on the 802.11a link, for 1505s it operates on the 802.11b/g link.
config mesh background-scanning enable/disable
show mesh background-scanning

Parent AP is chosen by using the adjusted ease. This is the ease of each neighbor divided by the number of hops to the RAP.
     Parents are given a 20% of bonus ease to reduce link flapping.

Routing Around an Interface (RAI)


config mesh secondary-backhaul enable


For this to work properly, all APs beyond the first hop to the one that is being used on the first hop must be on the same channel. RRM does not work with RAI


config mesh secondary-backhaul enable force same-secondary channel


This forces the whole subtree rooted at one hop MAPs to have the same secondary channel. Ignore RRM or manually assigned for MAPs at two hops and deeper.


Design constraints:

Recommended backhaul is 18Mbps
Number of backhaul hops – limit to 3 or 4
Number of MAPs/RAP – suggested limit of 20/1

Multiple RAPs for hardware diversity – deploy on same channel as primary RAP.
32 MAPs/RAP limit should be remembered.


Map density & distance
If building out a mesh to backhaul data - 1000 Ft RADIUS
Providing complete client coverage – 600 Ft RADIUS


Cisco Unified Wireless QoS

[notes]
Cisco Unified Wireless QoS


fixed network delay – encoding/decoding time
variable network delay – queuing/congestion

Radio downstream is most common deployment.
Radio client upstream QoS depends on client implementation.


When providing only radio downstream QoS from the AP, radio upstream client traffic is treated as best effort.


Data frames in 802.11 are sent using distributed coordination function (DCF)
     interframe spaces – (SIFS, PIFS, DIFS)
     random backoff (contention window) DCF is used in 802.11 networks to manage access to the medium.


Interframe spaces (base timing in 802.11b listed below – 802.11a/g are different)
     SIFS = 10us
     (PCF) PIFS = SIFS +1 x slot time = 30us
     (DCF) DIFS = 50us + 2 x slot time = 50us

Random backoff
When a data frame using DCF is ready to be sent it goes through the following steps:
     1. generates a random backoff number between 0 and a minimum contention window (CWmin)
     2. waits until the channel is free for a DIFS interval
     3. if the channel is still free, begins to decrement the random backoff number for every slot time (20us) that the channel remains free.
     4. if the channel becomes busy, the decrement stops & steps 2 – 4 are repeated
     5. if the channel remains free until the random backoff reaches zero, the frame can be sent.

Contention window is defined by aCWmin & aCWmax
The random number is between zero and aCWmin


If the initial random backoff expires without successfully sending the frame, the STA or AP increments the retry counter & doubles the value random backoff window size. The doubling continues in size until the size equals aCWmax. The retries continue until the max retries or TTL is reached.
      This process is referred to as binary exponential backoff


WMM is primarily the implementation of the EDCA component of 802.11e


WMM uses the 802.11p classification scheme developed by the IEEE (now part of the 802.11d spec)

U-APSD
A U-APSD client remains listening to the AP until it receives a frame from the AP with an end of service period (EOSP) bit set. This bit tells the client it can now go back into power save mode. The use of U-APSD allows the use of long DTIM intervals to maximize standby time without sacrificing call quality.

TSpec admission control – allows an 802.11e client to signal its traffic requirements to the AP. a TSpec request can be used to control the use of the various access categories in EDCA.
      - 7920 does not support TSpec
      - 7921G does support TSpec


Add Traffic Stream (ADDTS) – it’s how a WLAN client performs an admission request to an AP. Signaling it’s TSpec request, an admission request is in one of two forms:


ADDTS action frame – when a phone call is originated or terminated by a client associated to the AP


Association & Re-association message – the association message might contain one or more TSpecs & one TSRS (traffic stream rate set) IE if the STA wants to establish the traffic stream as part of the association.


WAN QoS & H-REAP – for locally switched WLANs with WMM traffic, the AP marks the dot1p value in the dot1q VLAN tag for upstream traffic. This occurs only on tagged VLANs; not on native VLANs.

With multicast enabled, any kind of multicast packet received on the VLAN from the first hop router is transmitted over the wireless including HSRP hellos, all router, EIGRP, and PIM multicast packets.

AP sends heartbeat messages to the WLC once every 30 seconds. If one response is missed, the AP sends 5 successive heartbeats (one per second) to determine whether connectivity still exists.

Up to 8 H-REAP APs needs at least 128kbps. PKC capable clients that roam between H-REAP APs undergo full 802.1x authentication.

If a WLAN is configured for IPSEC, CRANITE or FORTRESS, that WLAN cannot be configured for local switching on an H-REAP AP.

If dynamic DHCP is used, establish more aggressive NAT translation entry timeouts for ports 12222 & 12223 to 20-25 seconds.


ISRs CISF DSCP & dynamic ARP

[notes]

The only WLC that does not map WLAN traffic directly to a physical/logical interface at Layer 2 are ISR based WLC modules



ISRs do not have access to all the IOS & IPS features. IP traffic from the WLAN clients must be directed in and out of specific ISR service module interfaces using IOS VRF features on the router.

CISF is currently only available on the access switch – benefits obtained only if the traffic from the wireless attacker goes through the switch.


The primary difference between an LAP & a standard client is that the DSCP value of a LAP should be trusted.

Port security – if response is shutdown, port goes into err-disable. If response is restrict, traffic with unknown source MAC addresses is dropped
    - not recommended on H-REAP AP ports or WLC

Dynamic ARP inspection – DAI is enabled on the access switch on a per-VLAN basis. This prevents ARP poisoning that may lead to MIM attacks. When DAI is configured on a VLAN, and ARP rate limiter is configured globally to prevent flooding of ARP requests coming from a certain port. The default value is 15 packets/sec. When the limit is reached, the port is disabled.


Turn off ARP rate limiter on AP switchports
     IP ARP inspection limit none

IP source guard - when enabled on an interface of the access switch, IP source guard dynamically creates a per port access list (PACL) based on the contents of the DHCP snooping binding table. There is an option (port security) to filter the incoming address, also using the MAC address in the DHCP snooping binding table.


DHCP ARP Rogue Detection and MFPs

[notes]
DHCP & ARP protection

     When a WLC is a DHCP relay, it checks that the MAC included in the DHCP request matches the MAC of the WLAN client sending the request. The WLC does not forward DHCP requests back out the WLAN, this prevents a WLAN client from acting as a DHCP server.

WLCs do not allow direct ARP communication between WLAN clients.

AIR/RF detection
      When searching for a rogue AP, a LAP goes off channel for 50ms to listen for rogue clients and to monitor for noise & channel interference.


Rogue detector – radio is OFF, its role is to listen on the wired network for MAC addresses of clients associated to rogue APs. It listens for ARP packets that include these macs.
      -should be connected to all available broadcast domains using a switched port analyzer (SPAN)


MFP- the MIC used in MFP is not a simple crc hashing of the message – it also includes a digital signature component. This component is shared among mobility groups.

Encryption Types

[notes]
TKIP is the encryption method certified as WPA

     two primary functions of TKIP are the generation of a per packet key using RC4 encryption of the MAC service data unit (MSDU) & a MIC in the encrypted packet. The IV changes with each frame transmission, and is susceptible to an active attack.

AES counter mode/CBC MAC protocol (CCMP)
     Additional authentication data (AAD) is taken from the MAC header & included in the CCM encryption process.  To protect against replay attacks a sequenced (PN) packet number is included in the CCMP header.  The PN & portions of the MAC header are used to generate a nonce that is in turn used by the CCM encryption process.



PKC – proactive key caching & CCM
 - an 802.11i extension that allows for the proactive caching (before a roam event) of the PMK that is derived during a client 802.1x/EAP authentication at the AP.


CCKM – implementation is different than PKC, two mechanisms are incompatible.
              show pmk-cache all

802.11r workgroup is responsible for the standardization of an FSR mechanism for 802.11