RE: Cisco lightweight AP's / Airespace

"Casey Halverson" <[email protected]>
Newsgroups gmane.network.wireless.seattle.general
Message-ID <[email protected]>
Thanks for the in-depth response, this really helps me.

One thing I really would like to do is integrate authentication into our
Active Directory architecture (LDAP).  But I only see support for
RADIUS, is this true?  

Yeah, I know there is CiscoACS (pile of crap), I could ask one of the
systems guys to start running RADIUS on our domain controller, or
perhaps deploy some nasty Unix RADIUS/LDAP hack, but all of these
options are undesirable.

I am looking at this access point hardware, and it looks like it is
sitting on a little stand --something id deploy into my home office and
sit on the desk.  I currently like the wall mount configuration of my
Cisco 1200's and I would like to do the same with these 1000 series
AP's.  How did wall mounting work out for you?

- Casey

 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Gary
> Sent: Friday, October 07, 2005 11:49 AM
> To: SeattleWireless Talk List
> Subject: Re: Cisco lightweight AP's / Airespace
> 
> We've installed a 12 port management switch, 10 local APs, 
> and two remote or "edge" APs this month. So far here's what 
> I've found -- and I've seen the options for IPsec but haven't 
> had need to try them yet.
> 
> Enterprise WPA2 works great once you manage to figure it out. 
> The documentation in general is rather sparse.
> 
> LWAPP lets you drop an AP on the LAN, the switch will flash 
> the firmware to current, then load the config. The APs and 
> switch use PKI to authenticate.
> 
> Web authorization similar to nocatauth works as advertised.
> 
> In layer 3 management mode, I was able to get an edge AP in 
> our New York office configured once I updated IOS on the 
> Cisco switch it was plugged in to. This was over a static 
> IPsec tunnel between the firewalls at each office.
> 
> Rogue AP detection and containment is excellent. On the 2nd 
> day of having a test environment online, some asshat in the 
> building decided to set up an Evil Twin attack with his 
> D-Link by using my SSID. I selected to APs to contain it then 
> got a chance to see the end result. Through the Airespace 
> switch, I could tell that someone with an Apple MAC address 
> was trying to connect to it. It turns out that someone in my 
> company had their PowerBook set to autoconnect to nearby 
> networks. The constant flood of dissociate beacons would not 
> let him stay associated for more than half a second. Once the 
> rogue change his SSID, the switch listed it as 'containment 
> pending' then jumped on it as soon as he changed his SSID 
> back to mine.
> 
> Roaming between APs also works quite well. Our office 
> building is shaped like a giant staggered letter H 
> (http://snipurl.com/i8o1). We occupy all of the east half of 
> the H of one floor, and half of the west side of the H minus 
> the elevator lobby in between. The entire length of one wing 
> is roughly 240ft long and the width of the H is approx 190ft. 
> Testing with only one AP in each wing, I was able to stream 
> NPR live on a laptop while walking from one far corner of the 
> building to the other. With NetStumbler we could see a small 
> dead spot at one corner of the elevator lobby but the overlap 
> between the two was just enough to always stay connected -- 
> of course, we placed the APs so they were pointing east/west 
> since there's a patch panel on both sides of the AP. The H 
> points north/south so the APs point toward the center of the 
> H and out from the middle. 
> http://www.cisco.com/en/US/products/ps6306/prod_view_selector.html
> 
> FYI, the remodeled downtown Seattle library that opened a 
> year and a half ago uses Airespace gear.
> 
> -Gary
> 
> 
> 
> 
> Tyler van Houwelingen wrote:
> 
> > do they do IPSec all the way to the client or just to the AP?  
> > Centralized controllers are nice (we use Meru), but need redundancy 
> > for redundancy which can be pricey.
> >
> > tyler
> >
> >
> > ----- Original Message ----- From: "Casey Halverson" 
> > <[email protected]>
> > To: "SeattleWireless Talk List" <[email protected]>; 
> > "SeattleWireless Development List" <[email protected]>
> > Sent: Friday, October 07, 2005 9:34 AM
> > Subject: Cisco lightweight AP's / Airespace
> >
> >
> > Has anyone played with Cisco's Lightweight AP hardware?  
> They bought 
> > Airespace a while back, and the product looks very interesting.
> >
> > The idea is to have a series of lightweight AP, forwarding to a 
> > centralized controller, and optionally managed by a 
> management server.
> > The system supports IPSec, various WiFi security bandaids, etc.
> 
> 
> _______________________________________________
> Talk mailing list
> [email protected]
> http://seattlewireless.net/mailman/listinfo/talk
> 
_______________________________________________
Talk mailing list
[email protected]
http://seattlewireless.net/mailman/listinfo/talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.