Re: Cisco lightweight AP's / Airespace

Gary <[email protected]>
Newsgroups gmane.network.wireless.seattle.general
Message-ID <[email protected]>
We've installed a 12 port management switch, 10 local APs, and two 
remote or "edge" APs this month. So far here's what I've found -- and 
I've seen the options for IPsec but haven't had need to try them yet.

Enterprise WPA2 works great once you manage to figure it out. The 
documentation in general is rather sparse.

LWAPP lets you drop an AP on the LAN, the switch will flash the firmware 
to current, then load the config. The APs and switch use PKI to 
authenticate.

Web authorization similar to nocatauth works as advertised.

In layer 3 management mode, I was able to get an edge AP in our New York 
office configured once I updated IOS on the Cisco switch it was plugged 
in to. This was over a static IPsec tunnel between the firewalls at each 
office.

Rogue AP detection and containment is excellent. On the 2nd day of 
having a test environment online, some asshat in the building decided to 
set up an Evil Twin attack with his D-Link by using my SSID. I selected 
to APs to contain it then got a chance to see the end result. Through 
the Airespace switch, I could tell that someone with an Apple MAC 
address was trying to connect to it. It turns out that someone in my 
company had their PowerBook set to autoconnect to nearby networks. The 
constant flood of dissociate beacons would not let him stay associated 
for more than half a second. Once the rogue change his SSID, the switch 
listed it as 'containment pending' then jumped on it as soon as he 
changed his SSID back to mine.

Roaming between APs also works quite well. Our office building is shaped 
like a giant staggered letter H (http://snipurl.com/i8o1). We occupy all 
of the east half of the H of one floor, and half of the west side of the 
H minus the elevator lobby in between. The entire length of one wing is 
roughly 240ft long and the width of the H is approx 190ft. Testing with 
only one AP in each wing, I was able to stream NPR live on a laptop 
while walking from one far corner of the building to the other. With 
NetStumbler we could see a small dead spot at one corner of the elevator 
lobby but the overlap between the two was just enough to always stay 
connected -- of course, we placed the APs so they were pointing 
east/west since there's a patch panel on both sides of the AP. The H 
points north/south so the APs point toward the center of the H and out 
from the middle. 
http://www.cisco.com/en/US/products/ps6306/prod_view_selector.html

FYI, the remodeled downtown Seattle library that opened a year and a 
half ago uses Airespace gear.

-Gary




Tyler van Houwelingen wrote:

> do they do IPSec all the way to the client or just to the AP?  
> Centralized controllers are nice (we use Meru), but need redundancy 
> for redundancy which can be pricey.
>
> tyler
>
>
> ----- Original Message ----- From: "Casey Halverson" 
> <[email protected]>
> To: "SeattleWireless Talk List" <[email protected]>; 
> "SeattleWireless Development List" <[email protected]>
> Sent: Friday, October 07, 2005 9:34 AM
> Subject: Cisco lightweight AP's / Airespace
>
>
> Has anyone played with Cisco's Lightweight AP hardware?  They bought
> Airespace a while back, and the product looks very interesting.
>
> The idea is to have a series of lightweight AP, forwarding to a
> centralized controller, and optionally managed by a management server.
> The system supports IPSec, various WiFi security bandaids, etc.


_______________________________________________
Talk mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.