Tuesday, October 16, 2012

Are You There RingMaster? It's Me Juniper. #WFD3 #Trapeze

DSC05680
Wireless Field Day #3 also visited Juniper to hear about their advancements since the Trapeze acquisition in 2010. The group of Juniper representatives were Tina Herrera, Bruce Alexander, Phal Nanda and Tim McCarthy.

Bruce Alexander has been in Wi-Fi since wireless began, and he gave us the overview on Juniper WLAN Architecture, describing the Local and Central Switching design of Juniper's wireless gear. He says that when you locally switch and have 802.11ac access points that you don't have to replace your controllers because the data doesn't hit the controller.



Juniper's wireless design uses virtualized controller clustering (resilient, non-stop enterprise connectivity). Their spectrum analysis is done with the standard access points and they can support scanning the spectrum and supporting clients through software licensing. The list price cost for an AP supporting spectrum analysis is $105 per access point, and you can move licenses in an ad-hoc fashion among the access points you've got deployed to support troubleshooting efforts.

Access point lineup WLA321 - single radio 802.11n 2X2
WLA322 - dual radio 802.11n 2X2
WLA522 - dual radio 2X2 MIMO 
WLA532 - dual radio 3X3 MIMO Maximum Performance
WLA621 - dual radio outdoors 3X3 heated NEMA enclosure

Controller lineup WLC2 - 4 (hardware licensed)
WLC8 - 12 (hardware licensed)
WLC800 - 16 - 128 (software licensed)
WLC880 - 16 - 256 (software licensed) remote AP with encryption to remote AP and IPV6
WLC2800 - 64 - 512 (software licensed) has 10GB interfaces


Juniper's Wireless LAN Management RingMaster Tool Suite (WLM-RMTS) is software if your'e managing up to 1000 access points and it is hardware if your'e managing 250 access points to 5,000 access points.

SmartPass allows for self provisioning of client devices, guest access and radius accounting. Juniper's centralized management allows for up to 32 controllers and 16,000 access points. It allows for continued service without rebooting the controller when the controller software is updated.


Jay Pochop (leads the hardware design team) did a fantastic job of taking us through the different Juniper access point and antenna designs, explaining they use Qualcomm chipsets and their goal is to be the best performing access point in that hardware category. Their two main points of focus are on the RF amplification and the antenna design.

Jay opened up the WLA532 and told us how the antennas are different from one another in the access point. The nulls in the antennas line up with the lobes from the other antennas in order to not have overlapping nulls. Juniper went one step further and tuned every antenna in the access point individually. If the two signals are polarized differently, 15-30db of isolation between two signals that are polarized differently. The horizontal polarity of the access points antenna is 66% and 33% are vertical in the six antenna layout. Juniper spent a long time to develop short vertically polarized antennas for their AP, then they optimized the 5GHz gain relative to the 2.4GHz antenna to be 7dBi on the 5GHz side and 3.5dBi on the 2.4GHz radio. 

Juniper deviated from the original reference design to get higher efficiency on the 2.4GHz radio. They use discreet power amplifiers to achieve higher receive gain on the antennas and have the same receive sensitivity. Juniper's hardware manufacturing return rate targets are .1 percent per year. They've shipped 10k APs out and haven't gotten any back yet due to hardware problems.
DSC05706
The installation brackets for Trapeze access points are easily moved and installed plastic brackets. Installation times are quoted as a 60 second install per AP once cabling is in and installed. The Trapeze plenum mount kit mounts access points directly above suspended ceiling metal (possibly not such a good idea due to the metal grid-work being directly under the access point).

The Trapeze access point naming convention is
300 performance level
500 performance level
600 outdoor

The 2nd number is the number of spatial streams, and the third number is the number of radios.

The Trapeze access points draw very little inline power, the overall power consumption for the 532 is less than 10w for a fully powered access point.



Bruce Alexander then demonstrated the automatic client load balancing and band steering capable with the Juniper controllers. He described Primary Seed and Secondary Seed controllers (the connectivity is much like stacked switches). When joining access points to controllers, you can mix types of access points on controllers and you don't have to assign primary secondary or tertiary controllers. The primary/secondary assignment happens automatically and the access points don't have to be in the same subnet.

If your access points are configured for local switching, if controller fails - calls or videos will continue, if not locally switching the roam is 300ms or less.

High availability licensing for controllers, each can be licensed for 128 APs and the other controller in the cluster can take those APs providing there's enough overhead on the controller to take the APs. Only license what you need, but you'd still need to have extra licenses on each controller.

Code upgrade on controllers can be done without reloading the controllers. The code on the APs are done to ones that are not serving clients, the other APs will have their power turned down to force clients to roam then the AP code will be upgraded.
You can schedule the whole upgrade cycle from RingMaster for a given time, you can't piecemeal the upgrade to just do the controllers and then the APs later.

Each client maintains two connections to two controllers so when the controller drops a few video artifacts will be seen, but the video call does not drop.


TIm McCarthy demonstrated RingMaster (version 8.0) as an RF planning tool to do predictive site surveys. RingMaster can understand wall properties as defined within AutoCad, it can place the APs, set the channels in a multi-floor planning mode.

Some of the features of RingMaster are:

  • Push configurations to controllers
  • Monitoring/reporting of users by user, radio, AP, WLC, SSID
  • 30 day history
  • WIDS/WIPS integration
  • Location aware
  • Search by location
  • Roaming history
  • Geo Fencing

The list pricing for RingMaster starts at $895 and the licensing is variable per number of APs.
You can model sources of interference into your predictive planning, and it's a Java based application, no web UI at this time.


Tim McCarthy then demonstrated Guest access and BYOD with the Trapeze SmartPass (stand alone application) solution. Smart pass is capable of guest provisioning, BYOD, self registration, the end user's credentials are sent via SMS. SmartPass integrates with SMS providers like Clickatel. SmartPass comes licensed to support 50 user accounts for $1400 list price. If you have setup a policy to block YouTube, the video feed doesn't show, but you do see the "spinny circle of death". 

My takeaway from Juniper's presentation on where they are now with Trapeze: From what I can tell, they've done a lot of work with the antennas of their access point line, but the UI for the RingMaster is still Java based. Back in 2004 I did a bake-off between Cisco and Trapeze for the hospital where I was working. Even then I hated the Java interface for managing Trapeze access points. I avoid Java UIs at all costs because Java has wronged me far too many times to trust it again. I thought Jay Pochop did a great job explaining the hardware advancements Juniper has made since the Trapeze acquisition. He was very informative about all aspects of their antenna design and where Juniper tweaked the reference standard specifications. I have not personally run into a Trapeze deployment in recent years, so I cannot speak to the functionality of new Trapeze access points or the RingMaster management platform. It was interesting to get a refresher on the current state of Trapeze Networks now that they're part of Juniper.

Juniper was a sponsor of Wireless Field Day 3. As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 3. In addition, they provided me with a Juniper t-shirt. They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone.

Thursday, October 11, 2012

Meraki Dashboard, Now With Real Customer Data #WFD3

DSC05548
Sanjit Biswas CEO of Meraki began the presentation at Wireless Field Day 3. Since the last Wireless Field Day in January of 2012, the company has doubled their number of employees, and has added thousands of new customers. 




The Meraki MR product line features Meraki NAC (since 2011), has a 3x3 radio. Depending on the access point model, it is possible to have device based group policies for iPad and Android devices. PCI compliance reporting, SMS login for guest access and Air marshal WIPS enforcement is all possible.

The Meraki MX Cloud Management Security Appliance product line establishes an auto VPN, supports application control, link bonding failover, high performance multi-gigabit firewalls, content filtering anti malware, as well as WAN optimization.

The Meraki MS switch line supports virtual 1g/10g stacking, VoIP prioritization, 802.1x port security and Layer 7 visibility.

The Meraki SM Systems Manager is their Mobile Device Management tool, which is available as a free download. It supports management of Macs, PCs and mobile devices via the cloud. In short, Meraki wants to have a single unified access layer to manage wired and wireless network components.

Meraki also now has a 2 day certification course covering wireless, switching, MDM and firewalls.


Ben Calderon VP of Hardware and Operations described Meraki's three phases of building and testing their products. Many technology partners are creating chipsets that Meraki uses:

  • Applied Micro
  • Skyworks
  • Qualcomm
  • Microsemi
  • Freescale
  • Broadcom
  • Bitesse
  • Integrated Device Technology
The radio design of a Meraki access points sometimes may include a filter for dual concurrent operation to negate spurious emissions. During early testing with the MR24 access point, it was discovered through testing that a firmware work-around was required to adjust settings to optimize band edge performance of the access point.


Per Ben, the MR24 PIFA antennas give you the best transmit efficiency. The form and function are determined through SLA models, machined models and hard tooling. The fit and finish includes a durable enclosure which goes through reliability testing. It is a UL2043 smoke tested, plenum rated enclosure (the plenum rated plastic is the most expensive piece in the AP construction!) The MR24 is drop and vibration tested to ensure reliability of the shipping units. The MR24 is IP67 certified (operates after 1m water submersion) and the aluminum housing is undercoated before it is painted.

Kiren Sekar VP of Marketing described how there have been 2 firmware upgrades since the last WFD (optimize for low-power clients, software controller RF enables ongoing tuning, scale capacity of new and early model 802.11n APs) One of Meraki's customers is Stanford, and they are seeing 9k clients a month, 65% YoY increase in wireless client counts. Meraki has built their own DHCP server on the AP itself (highly scalable) The Meraki MS product line has the highest growth of any new product in the company's history. Meraki is seeing customers adopting Meraki's switches as a result of wireless upgrade projects (deployed at the access layer).


Pablo Estrada and Todd Nightingale demoed a large customer deployment, showing actual customer data (with the permission of the customer) to give us a tour of the Meraki wired and wireless dashboard, the cloud DB search, client fingerprinting, L7 traffic analysis, multi-site cloud management, and real-time cloud tools

The internal operations group within Meraki are the only group of people who can access a customer's data. They have the ability to put an AP into Air Marshal mode, which would also be called 'sniffer mode'. You can set the scan schedule, and set off-channel scans. Rogues can be contained if they're detected on the LAN. There are a few concurrent algorithms running to determine on LAN rogues, not one single method in place. Policies can be set to contain an SSID that is not part of your WLAN deployment (SSID copying). Works across non Meraki switches as well.

Retail deployments are the biggest Air Marshal adopters. Nespresso stores (Nestle) wanted to provide mobile POS, give employees iPads to access inventory, ERP systems as well as guest access. The Nespresso stores deployed Meraki wireless along with switches and security appliances and WAN optimization. They were able to roll out the new hardware/infrastructure in a two month timeline.

All Meraki developers have Nexus 7 tablets to experience the wireless connectivity in the same way as the typical end users. Meraki has built in policies for whitelisted and blocked applications, there are group policies can be assigned per device type

Backpack is a Meraki app to add files to the end user devices as employees are on boarded. Employee handbooks etc are pushed to employees' (or students') devices. The data is stored in an app on the device. The Meraki app works on iOS and the Android platform.

Meraki has Applebee's (Apple American Group - the 2nd largest franchise operator of any restaurant model [20,000 employees]) 300 locations use Meraki gear for guest access. (Meraki had the customer's permission to show their data for WFD presentation). 

In the Meraki dashboard, when you hover over a group name, it shows the throughput graph for just that location without clicking anything. Most of this customer's restaurants have one access point, but you can quickly dive into AP data. It is possible to block the upgrading of iPhone software to save on bandwidth at customer sites.

Peer-to-peer, dropbox, other online backup services are blocked by a L7 firewall built into the AP at Applebee's restaurants. Wifi is used as a local advertising splash screen to provide discounts, coupons or information about special events. Configuration settings from source networks can be pushed out to selective other customer networks. The Meraki management can turn off/on Wi-Fi to match restaurant open/close times.

Next (High-end clothing retailer in the UK) is currently deploying Meraki to 500 + locations.

I saw Meraki present at Wireless Field Day 2, and then I was impressed by their dashboard interface. This time they presented, I was impressed by the level of information that could be easily obtained about the current user traffic. It was very interesting seeing them drill down into a live network - with the customer's permission - to show off what managing a diverse deployment of Meraki access points looks like from the customer's point of view. I still think that the Meraki dashboard is a very slick interface which shows a lot of useful content without requiring a lot of training to figure out which menu tab the information is hiding under.

Meraki was a sponsor of Wireless Field Day 3. As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 3. In addition, they provided me with a gift bag containing a t-shirt, pen, water bottle and a Meraki MR16 access point. They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone.


Monday, October 8, 2012

Tanaza Cloud Management of Diverse Wireless Hardware Platforms #WFD3

DSC05520
Kelley Seaman introduced Tanaza at Wireless Field Day 3, then the founder of Tanaza Sebastiano Bertani explained his software solution to the problem of having to manage multiple consumer grade access points in either a centralized or distributed deployment. Tanaza is a vendor agnostic cloud management for 'good enough' wireless. They will soon be growing from supporting mid-tier to enterprise class access points. In Q4 2014 Tanaza will begin supporting switching hardware.

 


There are options for managing access points with Tanaza. Some access points can use their original firmware, others will run Tanaza firmware instead. The access point/software connects to the Tanaza engine (engine.tanaza.com), and from here will have a configuration pushed or it, or configuration information from the AP can be retrieved.

The Tanaza backend UI (
https://ajax.tanaza.com) sends information through ajax requests to the Tanaza web interface (https://cloud.tanaza.com). The user front-end accesses static resources (css, javascript, images, html).


Tanaza requires a Tanaza host per subnet. The Tanaza agent is available for Windows and Mac and there is no need for VPNs, public IPs or DynDNS. 
The Tanaza agent is written in C and is based on the OpenWrt code. I'm most familiar with using dd-wrt (a variant of OpenWrt) to tweak the Linksys WRT54G access point to perform better than the code it shipped with.



I was not familiar with Tanaza prior to attending Wireless Field Day 3. It was very interesting to hear their solution presented, since it is something I wouldn't otherwise have encountered. I can see where Tanaza could be used to manage a diverse deployment of off the shelf access points and do so by using a single web interface. Tanaza is a slick solution to overcome the problem of how to manage the different wireless hardware you'd find in small shops (restaurants, laundromats, schools).


Tanaza was a sponsor of Wireless Field Day 3. As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 3. They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone.



Monday, September 17, 2012

Ruckus at Wireless Field Day 3

Ruckus Wireless newly designed stadium antenna
Ruckus was a presenter at Wireless Field Day 3. In Steve Martin's presentation he explained how Ruckus puts their effort into redesigning the entire RF integrated circuitry of reference designed wireless silicon chips/antennas to get the lowest noise floor and have the best receive sensitivity of any access points in the wireless business. 


He says that through this redesign process, Ruckus access points/antennas will have a 3 to 6 dB better difference than their competitors. Most of this antenna redesign is done by their 25 person design team in house, most of whom reside in the US.

They take and adapt reference design, create their own versions, get the new designs fabricated then they go through extensive testing. Typically new antenna designs go through this re-design/testing process at least three times (six month + process).

Ruckus has more low level source code control access to the Atheros chip set, and as a result Ruckus has a preference in modifying Atheros reference wireless chipsets.

Manufacturing for the Ruckus product line is done in Malaysia and China, and stringent quality control is ensured by building their own manufacturing test setups. The final product testing before its shipped to the end user is done as a separate step to ensure repeatable quality of their products. Periodically they sample 10 or 20 of a given model out of finished goods, bring them back to engineering & re-run them through the engineering verification testing.


Niv Hanigal presented after Steve Martin, and he explained that Ruckus also has a large presence with Carrier/Service Providers to offload cellular connectivity to Wi-Fi. Today's fixed line carrier cable operators don't have licensed spectrum, they only have Wi-Fi as an offload option. The carriers have been  losing subscribers, experiencing more customer churn, and they needed to invest in an option to enable more features for their customers. This is how Ruckus came to provide the ability to do 802.11u offloading from a carrier to local Wi-Fi. There are two phones already certified for 802.11u but the make and model are currently unknown. The only thing we know is that it is not an iPhone. Reasons for difficulty in getting 802.11u client devices to test with are mostly around the adoption cycle of replacing devices. The lifecycle of a typical cellphone is just over two years. As part of the testbed for 802.11u, Passpoint 2.0 is trying to address online signup process difficulty and enable the operator control side for the Wi-Fi devices.

The SmartCell gateway takes the Wi-Fi connection and makes it look like any other cellular connection. The northbound connections most common are GDP ? It acts as if it is part of the cellular network.

Bill Kish CTO Ruckus Wireless then went over how Ruckus makes advancements in antenna design by adapting the degrees of freedom that the chipsets provide for them. Their antenna testing uses throughput based metrics. This is traffic that is normally generated by the access point is used for throughput modeling, the access point does not need to go off channel during this procedure. They use the 802.11h channel change notification to announce to clients that the channel has changed on the access point. Keep in mind that client devices that support/understand channel change announcements are Broadcom and Atheros chipsets.

If ChannelFly is running on multiple Ruckus access points at the same time, d
istributed optimization technique (simulated annealing) is how the group of APs do not disrupt each others' ChannelFly algorithm. There is a period of 'burn-in' where the access points may interfere with one another while the proper operating channels are being determined by the ChannelFly algorithm.

Victor Shtrom told us more about the multiple spatial stream access points Ruckus has in their porfolio. Ruckus has 3x3 and 4x4 spatial stream capable antennas for outdoor point to point links, but without multi-path you won't get multiple spatial streams out of the access points. Multi-path is almost required to actually get multiple streams. The antennas' signals must look very different from one another if you're using more than 2x2 antennas. The antennas chosen to use with an outdoor 3x3 spatial stream access point would  need to have different multi-path profiles to make full use of the spatial stream capabilities of the access point.

Ruckus was a sponsor of Wireless Field Day 3. As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 3. In addition, they provided me with a desk name plate made from antenna sector chips (silk screened with my name), a  ZoneDirector 1100 controller and a 7321 access point (I think that's the right model of AP - they're shipping it so I don't have it just yet). They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone.

Sunday, September 16, 2012

Metageek at Wireless Field Day 3

DSC05484
Metageek was back at Wireless Field Day 3 to tell us about the updates they've made to their product line since the last Wireless Field Day in January 2012.

Ryan Woodings gave us the background on the Metageek story, how they got started as a company. He explained that the company used agile software and they keep track of all of the projects they're working on via their "Wall of Agility". Metageek employees have 20% of their working time allocated to working on pet projects they find personally motivating. Out of this 20% time slice, the Eye P.A. application was born. Metageek is headquartered in Boise, Idaho and they've won many awards for being an innovative company and for encouraging alternative transportation methods to work (biking/carpooling). 




inSSIDer Updates:
At the bottom of main inSSIDer page, they've put links to training and education for the people who have downloaded inSSIDer. The information shown on the main application launch screen is specifically targeted at the end user who is trying to fix their problematic wireless network. inSSIDer is available for Windows, Mac and Android. The Android phone version of inSSIDer can offer recommendations to change the channel of your access point if you use it to optimize your wireless network. inSSIDER on Android handhelds is designed to encourage the end user to use the app on the phone to calibrate/site survey the areas surrounding where the wireless issues are happening.

Metageek uses a unique method for focusing their goal directed application designs. The have created eight Personas. This is their attempt at tailoring their solutions to each customer by creating individual use case Personas. Each fictional character is an end customer of their products, and each Persona has a unique need to use a Metageek tool to solve a wireless problem. This type of focused thinking about what you're trying to accomplish as a company, and putting yourself in the head of your customers is a powerful way of staying connected to the people that want/need the tools Metageek creates.

 

Chanalyzer updates
You can now name sessions by rooms or floors to help you remember where you were and what you saw when you were testing. You can filter by band to just show the 2.4GHz or 5GHz networks, or you can filter by vendor name/identifier. The vendor OUI lookup table is not editable by end user, but it can be updated by contacting Ryan or Trent and sending them the new vendor OUI information. You can double click at any point in the Chanalyzer Pro stream to zoom into that segment/capture. This is called Amplitude History Navigation. The r
eport creation in Chanalyzer uses the filters you've set on your capture view when you're adding information blocks into the final report. Filters can be ANDed to show multiple SSIDs, but can't be ORed at this time. The Pro features of Chanalyzer Pro are sometimes difficult to find. For example, the save button has arrow to do non-save options to append other blocks. You can add 'devices that interfere' blocks for customer education to show the customer the RF patterns of  typical sources of interference. You can also add images to blocks to add the details about a particular access point model and you can add custom text blocks to include recommendations on how to mitigate the adverse effects of sources of interference. Report blocks also respect the segment of the timespan you have selected. Meaning, you can zoom into the problem  area in the timeline and add a specific point in the capture to the report. Reports can be exported to RTF or HTML. One caveat to Chanalyzer Pro is that concurrent scanning isn't possible just yet. Using two Wi-Spy dBx adapters is the way to gather both spectrums. The cost of purchasing two Wi-Spy dBx adapters is less expensive than a dual band Wi-Spy dBx USB adapter would ultimately cost to design and manufacture.


Eye P. A.
Eye P.A. now has filters to edit out beacons or whatever you don't want to see to tweak the visuals to focus on the data in the packet capture that you want to analyze. Eye P.A. now has a few training slides that are shown when the app is first launched. You can't use Eye P.A. to open wired captures because there aren't any control frames or management information in a wired capture. That wireless specific information in the capture is required to use Eye P.A. as a wireless protocol visualization tool. You can export Eye P.A. information to a CSV to take that data and put it into a report block in Chanalyzer Pro or you can do a screen capture to put it into a final report. Currently it isn't possible to do a remote capture to any vendor's APs, the only direct capture is to AirPcap (2x2 spatial stream card).

What's coming up
Ruthless Rye (Chandroid) 
Metageek is working on a Chanalyzer Pro application to work on Android tablets. They demonstrated the application on a Toshiba Thrive. The Toshiba Thrive has regular USB ports, whereas most lighter tablets have micro USB reports. Many times micro USB ports do not transmit enough power to the connected devices and an inline power source would be required to power the Wi-Spy dBx Pro USB tool.

inSSIDer 3 codename Strongbow
You can now identify your own network in the networks list displayed within inSSIDer. This allows you to get focused recommendations on what you should do to improve your local wireless issues. Room Level Channel Organization - this piece of inSSIDer 3 is attempting to encourage the end user to walk around to check the channels in the vicinity of the main problem area. If there is a Wi-Spy connected, it will be used in the channel quality check measurements that are calculated. Soon, there will be a report tab to receive a written recommendation report on what steps to take next. For example "Your Xbox will not function properly in this room until you move your access point to location X or you configure your access point to operate on channel Y.

It is now possible to use the Tamograph site survey tool with Wi-Spy integration. This new cross-platform interoperability allows you to perform a site survey in much the same way you would with AirMagnet Survey Pro with AirMagnet Spectrum XT integration. You can collect information on RSSI, SNR at the same time as you're collecting RF spectrum data with the Wi-Spy tool. The final survey data points will include pop-up images which display the spectrum data collected at that survey point location.

Metageek was a sponsor of Wireless Field Day 3. As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 3. In addition, they provided me with a USB tool bag containing copies of Chanalyzer Pro and a WiSpy dBx usb spectrum analyzer and the directional antenna used with the WiSpy dBx tool. They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone.

WildPackets at Wireless Field Day #3


WildPackets presentation

Jay Botelho Director of Product Management at WildPackets presented at Wireless Field Day 3. He started out by giving us all a short history of WildPackets. They've been providing tools for protocol analysis since 1990 and began wireless analysis in 2001. They were first to market with a visual network analyzer, and were involved with the Wi-Fi alliance before there were many test labs to officially certify wireless hardware.

As of 2012, Wildpackets is the first wireless network analyzer to support 802.11ac, k r, u, v, and w. Many of the chipset vendors (Atheros, Qualcomm, Broadcom, Intel) use WildPackets during testing and WildPackets has the source code for some vendors' chipsets (Atheros for example) in order to tightly integrate the protocol analysis software with the functioning of the wireless silicon.

OmniPeek Remote Assistant (ORA) is a tool plug-in which allows non technical users to perform packet captures. ORA was developed originally for Cisco to enable field engineers to gather data without sending a highly technical resource to a remote site.

The background analysis modules of the OmniPeek application are called Experts. The Experts tools are designed to flag for signs of interference, rogues or wireless attacks that may be detected. Any of the Experts metrics have adjustable thresholds that can be tweaked to adjust when/how triggers are hit.

OmniPeek is designed for network and application analysis, multi channel analysis, remote analysis (OmniPeek Remote Assistant). There is not a Mac version yet, but OmniPeek version 7 is due to be released at the end of September 2012.

In OmniPeek, if 
access points are not broadcasting their SSIDs, the SSID information for those access points are listed with numerical names (since no SSID information is available). 

Users of OmniPeek can enable aggregators to use multiple adapters to capture simultaneously. Mixing vendor cards is possible due to their relationships/drivers with wireless card manufacturers.

Signal strength ranges reported for wireless clients to Omnipeek are the RSSI measurements gotten from the wireless clients, not from the access points.

I'm not sure if everyone is aware that VoIP calls can be captured and played back - therefore it is vital to put them in a separate vlan to keep that traffic secure and encrypted (via AES/TKIP for example). There are also registry settings in the OmniPeek application that can disable the playback of calls captured, if the person capturing the wireless traffic should not have the ability to playback and listen to VoWiFi audio.

Roaming Analysis Module: Roaming analysis is done in the background along with the regular packet capturing. Roam times look for data being sent to the last access point then to the next access point to identify roams. These times may end up being longer as a result.

Remote Analysis: remote adapters can be used with Aruba, Meru, Xirrus and Cisco currently. Remote analysis relies on the central controller or the individual ability to put an access point into sniffer mode. The packets are sent back over the local network for analysis. 

OmniPeek Remote Analysis (ORA) group creation makes a zip file for saving that has the ORA executable (250kb) with a quickstart guide (if the end user needs assistance with what to do next). Today the user needs to install the proper driver, on the roadmap is the installation of the driver with the exe. The application is a standalone executable, which doesn't install on the remote system. The specific driver for the wireless card used at the remote location will need administrator rights to install on the remote machine. The ORA executable creates a .pke file. The .pke file can then be opened in OmniPeek. ORA groups that are created can have their own public private key pair assigned, in order to have a different encryption key for sending the ORA software/hardware to different end devices/groups/users.

The MyPeek community is a robust information sharing portal for end users of the WildPackets suite of software tools. Information found on the site includes developer documentation (requires a maintenance contract), video how-tos and user forums.

OmniPeek can be used to compare traffic flows of wired and wireless captures by using the IP ids that are tagged from wireless to wired transmissions. Evaluation licensing is tied to the machine it's installed on, not the MAC address. This results in a lack of portability of the toolset since it is not licensed to the wireless USB adapter card, but instead the physical laptop the software is installed on. Moving/installing the software to other computers/laptops is limited to two occurrences.  Site licensing options are available to allow 25 copies of OmniPeek to be installed up to 100 times. If larger quantities of OmniPeek are purchased, the limits for install/moves can be customized to the organizations installation needs.

WildPackets recommends 
Atheros or Ralink chipsets in the USB adapters used to perform wireless protocol analysis.

Unfortunately there is no way to run AirMagnet tools and the OmniPeek software at the same time, due to the different wireless card drivers required by each application. There is a 'software shim' available to use the AirPcap card with OmniPeek.

I learned a lot from the WildPackets presentation at Wireless Field Day 3. I'm looking forward to using the evaluation copy of OmniPeek given to us. It has been many years since I've used their wireless protocol analysis tools.

WildPackets was a sponsor of Wireless Field Day 3.  As such, they were responsible for covering a portion of my travel and lodging expenses while attending Wireless Field Day 3. In addition, they provided me with a gift bag containing a t-shirt and a USB drive containing evaluation copies of their software. They did not ask for, nor where they promised any kind of consideration in the writing of this review/analysis.  The opinions and analysis provided within are my own and any errors or omissions are mine and mine alone.


Friday, August 31, 2012

Wireless Field Day 3


The kick off date for Wireless Field Day 3 has really snuck up on me! I kept telling myself I'd have gobs of time to write my inaugural post about the event, but it's right around the corner - September 12 through 14, 2012 in good old SJC!

Would you believe that this is the THIRD Wireless Field Day! There's simply nothing like this event anywhere else in the IT conference/seminar space. WFD3 brings together independent minded wireless IT professionals and their technical counterparts at leading RF companies. The sponsors of the event all operate within the wireless technology space, and this year's event is jam packed with visits to nine vendors. Some were present at one or more Wireless Field Days but Wildpackets and Tanaza are new to the event and I'm very interested to hear what they'll be presenting. I also hear that Juniper is supposed to have some awesome super quick failover capabilities that I've never seen before...

The delegates are chosen based on their independence, contribution, and willingness to ask the difficult questions about PHY specs or QAM modulation schemes (not really!). Basically, if you'd like to throw your name into the hat of potential delegate candidates use this link to do so! If you're interested in finding out more about what delegates should know, then head over here to read about it.

The full schedule is complete and looks something like this list here:
Wed, Sep 12 18:00-21:00 Dinner with Aerohive
Thu, Sep 13 08:00-10:00 MetaGeek 
Thu, Sep 13 10:30-12:30 Ruckus 
Thu, Sep 13 13:30-14:30 Tanaza 
Thu, Sep 13 16:00-18:00 Meraki 
Fri, Sep 14 08:00-12:00 Aruba 
Fri, Sep 14 13:30-15:30 Cisco 
Fri, Sep 14 16:00-18:00 Juniper 

As always, the entire Wireless Field Day event will be streamed live and recorded for posterity, so even if you can't attend in person or virtually, you'll be able to hook up with the goodness after the fact.

The party limo bus-thing will be occupied by the following miscreants (and I say that lovingly!). Some I've met, some I haven't - and I've already warned the new people about how to behave (or not!). I'm hoping there will be a repeat  serenade of a rap song I've never heard in my life, but other delegates know by heart (you know who you are!).

Blake Krone @BlakeKrone
Chris Lyttle @WiFiKiwi
Daniel Cybulskie @SimplyWiFi
George Stefanick @WirelesssGuru
Gregor Vučajnk @GregorVucajnk
Keith R. Parsons @KeithRParsons
Rocky Gregory @BionicRocky
Ryan Adzima @RAdzima
Sam Clements @Samuel_Clements
Scott Stapleton @ScottpStapleton
Sean Rynearson @SRynearson
Tom Carpenter @CarpenterTom

As always, whenever Dan Cybulskie is in the house there will be much polar bear. I love an event with a mascot and I can only hope someone would show up wearing this. 

Look forward to much more information pouring out of Wireless Field Day, it's fun for all!