Re: Cisco lightweight AP's / Airespace
Gary <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.general |
|---|---|
| Message-ID | <[email protected]> |
We've installed a 12 port management switch, 10 local APs, and two remote or "edge" APs this month. So far here's what I've found -- and I've seen the options for IPsec but haven't had need to try them yet. Enterprise WPA2 works great once you manage to figure it out. The documentation in general is rather sparse. LWAPP lets you drop an AP on the LAN, the switch will flash the firmware to current, then load the config. The APs and switch use PKI to authenticate. Web authorization similar to nocatauth works as advertised. In layer 3 management mode, I was able to get an edge AP in our New York office configured once I updated IOS on the Cisco switch it was plugged in to. This was over a static IPsec tunnel between the firewalls at each office. Rogue AP detection and containment is excellent. On the 2nd day of having a test environment online, some asshat in the building decided to set up an Evil Twin attack with his D-Link by using my SSID. I selected to APs to contain it then got a chance to see the end result. Through the Airespace switch, I could tell that someone with an Apple MAC address was trying to connect to it. It turns out that someone in my company had their PowerBook set to autoconnect to nearby networks. The constant flood of dissociate beacons would not let him stay associated for more than half a second. Once the rogue change his SSID, the switch listed it as 'containment pending' then jumped on it as soon as he changed his SSID back to mine. Roaming between APs also works quite well. Our office building is shaped like a giant staggered letter H (http://snipurl.com/i8o1). We occupy all of the east half of the H of one floor, and half of the west side of the H minus the elevator lobby in between. The entire length of one wing is roughly 240ft long and the width of the H is approx 190ft. Testing with only one AP in each wing, I was able to stream NPR live on a laptop while walking from one far corner of the building to the other. With NetStumbler we could see a small dead spot at one corner of the elevator lobby but the overlap between the two was just enough to always stay connected -- of course, we placed the APs so they were pointing east/west since there's a patch panel on both sides of the AP. The H points north/south so the APs point toward the center of the H and out from the middle. http://www.cisco.com/en/US/products/ps6306/prod_view_selector.html FYI, the remodeled downtown Seattle library that opened a year and a half ago uses Airespace gear. -Gary Tyler van Houwelingen wrote: > do they do IPSec all the way to the client or just to the AP? > Centralized controllers are nice (we use Meru), but need redundancy > for redundancy which can be pricey. > > tyler > > > ----- Original Message ----- From: "Casey Halverson" > <[email protected]> > To: "SeattleWireless Talk List" <[email protected]>; > "SeattleWireless Development List" <[email protected]> > Sent: Friday, October 07, 2005 9:34 AM > Subject: Cisco lightweight AP's / Airespace > > > Has anyone played with Cisco's Lightweight AP hardware? They bought > Airespace a while back, and the product looks very interesting. > > The idea is to have a series of lightweight AP, forwarding to a > centralized controller, and optionally managed by a management server. > The system supports IPSec, various WiFi security bandaids, etc. _______________________________________________ Talk mailing list [email protected] http://seattlewireless.net/mailman/listinfo/talk