Thursday, March 8, 2012

The Sony NEX-7 has finally arrived

After months and months of delays due to the horrible flooding in Thailand, Sony has started shipping the NEX-7 orders that were placed through the Sony website. My order arrived via FedEx this morning, a few hours after Stephen Foskett received his NEX-7.

Of course, I haven't read the manual (although I probably should - there are a billion new features I need to learn about) so the first pictures I took were with the stock lens, and everything set to auto, with the exception of the color setting set to Vivid.

I swung by the office to pick up the Cisco 3600 series AP that had been delivered (beta testing new Cisco features), and on the way back I stopped at the 360 boat ramp to take some test photos. It was very overcast, not the best day to be taking photos. Out of all the big differences between the NEX-5 and the NEX-7, I have to say that I love the view finder. The green grass I saw through the viewfinder looked a lot different than the green grass in the final pictures. The grass through the viewfinder was cartoonish electric green, and that's not what was in the photos. I'll have to read up more on what I should expect to see through the digital viewfinder before I use that for composing a shot with ISO/f stops.

The picture files are huge, obviously. They've ranged from 5 - 11Mb per picture, and storing upcoming digital photos is something I'm going to have to start dealing with sooner than I'd imagined.

DSC03921
When I got home, I adjusted the ISO and aperture on the tree in the front yard to see what the image would look like when it was overexposed. The tree images still have a lot of detail (IMO) considering how far I've pushed the exposure with the aperture almost wide open (5.6). Indoors I still had the aperture wide open (4.5) to pick up as much detail as possible from the ambient room light.
DSC03940

Clarity? Well, in the self portrait I took by the 360 bridge, I can tell I have an eyelash in my right eye. Mind you, I couldn't feel it, but the NEX-7 captured it in the photo. The indoor self portrait in the bathroom mirror was less detailed at full resolution, probably because I'd adjusted the exposure a bit by then, and maybe due to the camera trying to focus on the mirror itself, rather than my reflection.

DSC03898


DSC03944


Friday, March 2, 2012

How to get the Cisco MSE virtual machine up and running on an ESXi 5.x server

It took me a bit of time to get the new Cisco MSE VM up and running on my ESXi 5.0 box. I used the vSphere client from an XP64 vm to deploy the OVF template according to the video instructions posed by Cisco on YouTube.


But when the VM import was completed, I couldn't start the VM because the MSE OVA file is configured with 8 vCPUs. The error I received when trying to startup the MSE VM was indicating that I needed to run the command esxcfg-advcfg -s 1 /Cpu/AllowWideVsmp at the CLI of the ESXi server.

I had to do some searching to figure out how to get to the CLI of theESXi box. The
solution I found was written up ages ago by Rick Vanover.

I also found out the hard way that you can't have two vSphere clients managing the same ESXi box. If you find yourself facing the error message
Call "PropertyCollector.RetrieveContents" for object "ha-property-collector" on "[IP ADDRESS] ESXi failed. that's what's going on there.

Of course, I also forgot what the default username/password combination is for an MSE VM. For the record, th
e default user ID is root and the default password is password.

Thursday, February 9, 2012

Aerohive at Wireless Field Day 2

DSC04144

Aerohive was first to kick off 
Wireless Field Day 2, and we were first treated to a presentation by Matthew Gast Director of Product Management and author of 802.11: Networks the Definitive Guide and 802.11n: A Survival Guide.



Aerohive at WFD2 Part 1: Devin Akin, Matthew Gast, Founders from Stephen Foskett on Vimeo.

Matthew Gast did an incredible d
eep dive into the trouble with CCMP, Galois Counter Mode, 802.11w (CMAC/signing based on AES), 802.11ac draft 2.0, constellation diagrams and multi user beam forming in 802.11ac.

In order to get the speeds defined in 802.11ac the crypto method has to change in order to make that possible. Make sure the hardware you're buying is capable of supporting GCMP.

New Technology Aerohive is coming out with was presented by Abby Hassel Strong:
New 3x3:3 AP, outdoor AP and the BR-100 and their new Cloud VPN Gateway.

HiveOS 4.0 Networkbased MDM & private key self registration. The 
5.0 GUI complete redesign to accommodate wired and wireless policies.
Pseudomanager logging, integration with Pearson's PowerSchool solution more robust implementation of TeacherView.

As part of HiveOS 4.0 there is WIPS distributed with Automatic Mitigation - where the infrastructure can send deauth packets to rogue clients, and 
Spectrum Analysis on APs and viewable from an iPad.

Paul Levasseur presented the Aerohive solution for 
Secure Guest Access with Private PSK self registration (requires multiple SSIDs).

Mobile device management can be agent based or network based.
The first step is to connect to registration SSID, open the captive web portal, login or validate with Radius. You could also use permanent PSK for corporate SSID.

We all then had a hands on demonstration of the self registration component of the Aerohive BYOD solution.



Aerohive demos at Wireless Field Day 2 from Stephen Foskett on Vimeo.

Staging your access points at Aerohive online if there's no local Hive Manager:
To find a local hive manager you can set a DNS entry for hivemanager.yourdomain.com, or a DHCP option 225 or 226 to find local Hive manager. Now Aerohive has a way to use port 80 to find a Hive Manager online if no local hive manager is found for staging the access points.
When you use the Aerohive redirector (staging@aerohive.com) can use serial numbers that are entered to redirect to your hive manager. Now you can deploy your devices to anywhere in the world and your access points will be primed and programmed to the right location over port 80 and 443. It is also possible to do automatic provision based on serial numbers, subnets or device types.

Color code meaning for Aerohive access points:
Blue light when booting/talking online 
White when it finds the hive manager
Yellow means the access point is meshing.

Out of the box, you can use the USB port to insert a cellular network connection card to initiate the connection to talk to the remote hive manager to redirect to the correct hive manager, and prime the access point for the appropriate location. The access points can use LTE as the main network connection or for backup connectivity.

The 
branch router (BR100) has integrated WiFi, 4 LAN Ethernet ports, 1 WAN Ethernet port, 1 usb port, Firewall/VPN/QoS/16 vlans/DHCP/RADIUS server/3g/4g LTE and it integrates with Websense and Barracuda via n-way proxy. The Aerohive Cloud VPN gateway is essentially virtualized HiveOS supports RIPv2 and OSPF. Routing and network decisions are made at the device itself. The Aerohive access point can operate as it's own standalone branch router, IPv6 support in the works.

They can whitelist based on user profiles or destination (Salesforce) to not send that traffic through a security profile. Guest networks can only get NATted out to the internet, and they can't VPN because it's a route based VPN and the routes won't work across the internet.

The BR100 has static routes (reverse link state routing updates) for connectivity for internet gateways. The Cloud VPN gateway can add routes to BR100s as scheduled. Convergence time is about a couple minutes when new changes are added. Timers can be tweaked, but the default is a minute. The BR100 supports 500 or 1000 tunnels on the Cloud VPN Gateway (virtual appliance on VMware ESX or ESXi).

The Aerohive hybrid xauth auto creates unique access accounts for the BR100s, and you can revoke that credential so that device can't ever re-connect to the hive/network.

I have not yet had a chance to plug in and test the BR100 or the AP350 unit that Aerohive presented to all the delegates. I'm working on setting up a home vm server, but it isn't ready yet. Expect more information to follow once I've started testing.

--------------

Full disclosure: Wireless Field Day 2 Disclaimer

Aerohive was a sponsor of Wireless Field Day 2.  As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 2. In addition, they presented each delegate with an Aerohive backpack, water bottle, pen and notepad set, an Aerohive BR100 evaluation unit, and an Aerohive AP 350 evaluation unit.  They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone. (disclosure verbiage snatched from 
http://networkingnerd.net/)

Wednesday, January 25, 2012

Wi-Fi Mobility Symposium - a recap


Andrew vonNagy and Marcus Burton
Today I attended the first Wi-Fi Mobility Symposium. The event was a gathering of panelists from key Wi-Fi companies and it was moderated by Andrew vonNagy (Revolution Wi-Fi), Marcus Burton (CWNP) and Stephen Foskett (Pack Rat). During this event, the attendees, panelists and moderators discussed the current state of Mobile Devices & BYOD, Hotspot 2.0 and the future of Gigabit Wi-Fi. It was very interesting to see the different opinions on how to handle the BYOD movement. I took a lot of notes on the opinions of the panelists, and I've paraphrased their presentations and discussions in the paragraphs below.

Devin Akin, Carlos Gomez, Paul Congdon

Carlos Gomez, Paul Gongdon, GT Hill


Carlos Gomez 
Product Manager for Network Services
Aruba networks

To recap the presentation by Carlos Gomez, in his opinion the education vertical has been doing BYOD for years. They have always had lots of devices to manage, diverse device set. Think college students and the types of wireless devices they bring to a campus scenario. End users demand simplicity and don't care how the connection is secured. Using a security method that involves certificates becomes problematic when you're revoking certificates on a per device basis. You can have issues because the certificate is often tied to a single user account. Device authentication/association can be done via an over the air profile delivery, based on the Apple style of device/user authentication without a client/agent on the device. (unique, per device credential, one for each type of device - can generate a unique per-device configuration file).

The challenges with Mobile Device Management (MDM) is that there are multiple devices, multiple operating systems, new/old software versions and remote wipe enforcement is difficult to carry out as a result. There are multiple points where the connectivity policy can be enforced,  indoor, outdoor etc.

Implementing BYOD is not just putting different users in different vlans, doing packet inspection and firewalling at the edge. BYOD is an evolution of Guest Access & the wireless vendors have led the push for security & role based access to WLANs. (802.1x example)
The BYOD portion of WLAN should still be seperate from the controller for a security perspective. The thought behind keeping them physically separate is for security reasons, but it does add another level of complexity to the association/authentication process.

-------------------------------------------
Paul Congdon
Fellow
HP Research Labs

HP describes the holy grail of wireless connectivity as a single computing device always connected... They see cloud services as what supports all the diverse mobility devices.
The problem is with how to identify the traffic coming from the device towards work or personal, and direct the traffic to the correct network destination. Using Wi-Fi from cell operators is easier via HotSpot 2.0 and it may be possible to bring hotspot 2.0 into the enterprise, and outsource the enterprise WLAN to the cell providers.

High speed wireless moving us closer to an all wireless edge where we can achieve a mobile personal grid in lieu of the holy grail. The idea is to create a digital avatar to know about your mobile devices and connect them to one another in order to create sharing among your mobile devices without the need for you to configure the interconnectivity.  The idea is that a persistent digital presence that preserves your privacy, but you need basic network connectivity to create useful and effortless connectivity.

-----------------------------------------
GT Hill
Technical Marketing Director
Ruckus

In the BYOD scenario, the problem is the device. Can you support 2-3 devices per person per room? Readying the physical RF layer to support BYOD is the first step in the process. Per GT, offloading cellular data to wifi networks is the answer. Predicts 80% of the population will use wifi as the first access, not cellular. There's not enough spectrum to serve everyone.

-----------------------------------------

Devin Akin
Chief Wi-Fi Architect

AeroHive

Aerohive has moved routers into the access point at  the remote edge. They use one OS on the ap and the router, and the same OS is running in the cloud at VPN gateway. AeroHive uses standard protocols, and per Devin, "Protocols are what's going to take over." His take is that the future of wifi lives in protocols & the architecture must become internet-like.

The biggest thing of today's BYOD discussion that struck me was the concept of a Personal Connectivity Assistant (PCA), and creating a persistent digital presence to preserve your privacy. I'm not comfortable with the idea of letting someone or something in the "cloud" have access to all my digital information, location data, email, internet history, phone call history and that this PCA could have read/write access to all the devices I've allowed the PCA to manage. I selectively allow location data to applications on the iPhone that require location data to be enabled in order for the application to function. I deny all other apps to this data of mine. I would be more likely to accept a PCA that allowed me to manage and host this virtual assistant on a computer system that I managed and controlled. I can only hope that the PCA scenario is a blue sky "what if" system and that it will be a long time before this idea becomes a reality.

Thursday, January 5, 2012

Wi-Fi Mobility Symposium – Live January 25th 2012!

anticipation
'anticipation' - photo by SFoskett

Coming very soon is an event unlike any other webinar, presentation or end-user conference you've ever attended. The first ever Wi-Fi Symposium will be held January 25th in San Jose, CA.

This event will bring together the industry leaders of wireless innovation to discuss the current state of 
Mobile Devices & BYOD, Hotspot 2.0 and the future of Gigabit Wi-Fi. It will be streamed online at TechFieldDay.com

Andrew vonNagy has written an
in depth post about the Symposium event, and he and Marcus Burton will be the Symposium hosts. Check out Andrew's post for all the nitty gritty event details. If you're going to be in San Jose on January 25th, you can get tickets to attend the event in person from the Wi-Fi Mobility Symposium Eventbrite website.

I strongly encourage you to tune in when the streaming goes live, and it would be great to see you there if you're in the neighborhood!

For a little background on what the Symposium event will be like, check out the archived video from the
OpenFlow Symposium.

Tuesday, January 3, 2012

Vintage Terrwave Battery With A Bad Fuse

If you find yourself surveying with a very old version of this Terrawave battery pack and it is suddenly not charging, or only works when it is connected to the wall charger, the fuse in it may have gone bad.


Remove the main unit cover, and you will see a plastic housing with a glass fuse in it.  The glass fuse was broken, so I replaced it with a fuse I purchased from RadioShack (4/$2.00).  After replacing the fuse, the battery took a charge, and worked properly after obtaining a full charge overnight.


The symptoms I had were that the battery did not take a charge from the wall wart, and the wall wart did not show that there was a load on it.  The light stayed green - indicating the battery pack was not charging.


The battery pack would not power on an attached access point unless the battery pack was connected to wall power.

Friday, December 23, 2011

White Spaces - new wireless space launched



Remember the death of analog TV? Those unused analog TV channels are now approved for use as wireless White Spaces. White spaces operate at lower frequencies, and are able to travel great distances just as analog TV signals did when they were in use. Supporters of white spaces say that use of these regions of  licensed spectrum offer the same benefits of WiFi spectrum with the added advantages of the signals traveling greater distances, and the ability to assign spectrum to avoid wireless interference.


Spectrum Bridge has been been given the green light to become the database administrator for all allocated white spaces.




KTS Wireless is the first manufacturer of a wireless device to take advantage of the white spaces spectrum re-allocation for wireless communications. They have participated in city wide trials of white space usage in Claudeville, VA and Wilmington, NC.






It will be interesting to see how usage of the white space advances. Currently, the FCC is working through how to address the issues of wireless microphones using the same frequencies as white spaces. Once those issues are resolved, the nationwide roll out of white space usage will be possible.