RE: Cisco lightweight AP's / Airespace
"Casey Halverson" <[email protected]>
| Newsgroups | gmane.network.wireless.seattle.general |
|---|---|
| Message-ID | <[email protected]> |
Thanks for the in-depth response, this really helps me. One thing I really would like to do is integrate authentication into our Active Directory architecture (LDAP). But I only see support for RADIUS, is this true? Yeah, I know there is CiscoACS (pile of crap), I could ask one of the systems guys to start running RADIUS on our domain controller, or perhaps deploy some nasty Unix RADIUS/LDAP hack, but all of these options are undesirable. I am looking at this access point hardware, and it looks like it is sitting on a little stand --something id deploy into my home office and sit on the desk. I currently like the wall mount configuration of my Cisco 1200's and I would like to do the same with these 1000 series AP's. How did wall mounting work out for you? - Casey > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Gary > Sent: Friday, October 07, 2005 11:49 AM > To: SeattleWireless Talk List > Subject: Re: Cisco lightweight AP's / Airespace > > We've installed a 12 port management switch, 10 local APs, > and two remote or "edge" APs this month. So far here's what > I've found -- and I've seen the options for IPsec but haven't > had need to try them yet. > > Enterprise WPA2 works great once you manage to figure it out. > The documentation in general is rather sparse. > > LWAPP lets you drop an AP on the LAN, the switch will flash > the firmware to current, then load the config. The APs and > switch use PKI to authenticate. > > Web authorization similar to nocatauth works as advertised. > > In layer 3 management mode, I was able to get an edge AP in > our New York office configured once I updated IOS on the > Cisco switch it was plugged in to. This was over a static > IPsec tunnel between the firewalls at each office. > > Rogue AP detection and containment is excellent. On the 2nd > day of having a test environment online, some asshat in the > building decided to set up an Evil Twin attack with his > D-Link by using my SSID. I selected to APs to contain it then > got a chance to see the end result. Through the Airespace > switch, I could tell that someone with an Apple MAC address > was trying to connect to it. It turns out that someone in my > company had their PowerBook set to autoconnect to nearby > networks. The constant flood of dissociate beacons would not > let him stay associated for more than half a second. Once the > rogue change his SSID, the switch listed it as 'containment > pending' then jumped on it as soon as he changed his SSID > back to mine. > > Roaming between APs also works quite well. Our office > building is shaped like a giant staggered letter H > (http://snipurl.com/i8o1). We occupy all of the east half of > the H of one floor, and half of the west side of the H minus > the elevator lobby in between. The entire length of one wing > is roughly 240ft long and the width of the H is approx 190ft. > Testing with only one AP in each wing, I was able to stream > NPR live on a laptop while walking from one far corner of the > building to the other. With NetStumbler we could see a small > dead spot at one corner of the elevator lobby but the overlap > between the two was just enough to always stay connected -- > of course, we placed the APs so they were pointing east/west > since there's a patch panel on both sides of the AP. The H > points north/south so the APs point toward the center of the > H and out from the middle. > http://www.cisco.com/en/US/products/ps6306/prod_view_selector.html > > FYI, the remodeled downtown Seattle library that opened a > year and a half ago uses Airespace gear. > > -Gary > > > > > Tyler van Houwelingen wrote: > > > do they do IPSec all the way to the client or just to the AP? > > Centralized controllers are nice (we use Meru), but need redundancy > > for redundancy which can be pricey. > > > > tyler > > > > > > ----- Original Message ----- From: "Casey Halverson" > > <[email protected]> > > To: "SeattleWireless Talk List" <[email protected]>; > > "SeattleWireless Development List" <[email protected]> > > Sent: Friday, October 07, 2005 9:34 AM > > Subject: Cisco lightweight AP's / Airespace > > > > > > Has anyone played with Cisco's Lightweight AP hardware? > They bought > > Airespace a while back, and the product looks very interesting. > > > > The idea is to have a series of lightweight AP, forwarding to a > > centralized controller, and optionally managed by a > management server. > > The system supports IPSec, various WiFi security bandaids, etc. > > > _______________________________________________ > Talk mailing list > [email protected] > http://seattlewireless.net/mailman/listinfo/talk > _______________________________________________ Talk mailing list [email protected] http://seattlewireless.net/mailman/listinfo/talk