Home > Networking Tips > Network Management > Choosing a wireless architecture: Authentication, VLANs and installation
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK MANAGEMENT

Choosing a wireless architecture: Authentication, VLANs and installation


David Jacobs
01.05.2005
Rating: -4.08- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The first article in this series discussed types of wireless Access Points (APs) and how AP design affects network function and cost. This article examines vendor design approaches to authentication, VLANs, and network installation issues. These issues impact how your users connect to the network, their access to network resources and the overall cost of adding WLANs to your network.

Authentication

WLAN users must enter authentication credentials, usually a username and password to gain access to the WLAN. Authentication facilities are usually designed so that the same credentials provide admittance to the network and to resources such as e-mail and shared drives. The 802.1x protocol, supported by all of the major vendors, defines the authentication interchange between the user's laptop and the network. Thin APs pass the authentication packets to the switch without examining them. More powerful APs handle the protocol interchange, but in either case the user's credentials must be sent through the wired network to a RADIUS server for verification. Most vendors do not require use of a specific vendor's RADIUS server, but verify that this is true of your chosen vendor since a switch of RADIUS products could be a major task.

As users move through the area served by the WLAN, they travel from the area served by one AP and into the area served by another AP. The process of severing a connection to one AP and establishing a connection to another is called roaming. It is crucial that roaming take place as quickly as possible, especially where voice over wireless is supported. A delay that isn't a problem for a user reading e-mail will cause a dropped phone call. The process of re-authenticating to the new AP would cause an unacceptable delay.

The wireless vendors all address this problem by maintaining information on authenticated users in a central location, but they differ on the location. Thin AP vendors Symbol and Aruba use their switches to maintain the information. Cisco maintains authentication information in a facility built into Cisco's IOS software called Wireless Domain Services (WDS). WDS usually executes in a card installed in a Catalyst switch, but in a small network that doesn't include a Catalyst switch, WDS can execute in one of the APs.

Chantry Networks maintains authentication information in its BeaconMaster router. Colubris Networks uses its access controller, which in contrast with the other products, is a software product running on a rackmount Linux system while the switches and routers are all specially designed hardware.

VLANs

Virtual LANS (VLANs) are an essential facility on many corporate networks. Products vary in the number of VLANs supported and how users connect to a specific VLAN. In many architectures, each VLAN is assigned to a specific Service Set Identifier (SSID). A user connects to a VLAN by connecting to the corresponding SSID. In other cases, users do not need to be aware of how to select and connect to an SSID because a single SSID supports multiple VLANs. In these cases, the authentication process automatically assigns users to the proper VLAN.

VLANs can also be used to prioritize traffic from different applications. For example, voice data requires minimal network latency. A VLAN for voice should be given higher priority than other VLANs. Thin APs prioritize traffic at the switch. More powerful APs prioritize in the AP so high priority packets won't be backed up behind low priority data waiting to be sent over the link from the AP to the network backbone. You need to verify that your chosen vendor can support the latency requirements of voice given the level of lower priority traffic projected in your network.

Installation

Installation costs can be a significant factor. Most APs are designed to install in the ceiling. Power over ethernet eliminates the need to provide a power connection in the ceiling, but it is still necessary to run an ethernet cable into the ceiling. Aruba Networks Grid Point APs are designed to be installed on cubicle walls, reducing installation labor by eliminating the need for a ceiling network connection. With APs within an easy reach, employees may be tempted to remove one for home use, but Aruba's APs are useless when separated from Aruba's switch.

Environments other than office areas require specialized products. Vivato's products are designed for use in large open spaces such as warehouses and outdoor areas. Vivato's APs detect the location of users and direct narrow beams of radio energy directly to the users instead of spreading the energy evenly over an entire area. The same total amount of transmitted energy is able to cover a much larger area.

Each of the issues discussed in these articles is addressed by all of the vendors and each will provide reasons why its solution is best. No one solution is best for every network, so you must carefully review how each fits with your current and future requirements, the cost of each including equipment, training and ongoing support, and the difficulty of integration with your existing network.


David B. Jacobs has more than twenty years of networking industry experience. He has managed leading-edge software development projects and consulted to Fortune 500 companies as well as software start-ups.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
LANs (Local Area Networks)
3Com acquisition confirms HP-Cisco battle for China
Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
Enterprise passive optical networks: a spanning-tree LAN alternative
10 Gigabit Ethernet tutorial: Connecting data centers, storage, LAN and beyond
Intelligent edge switches: Complexity is driving a smarter LAN
Q&A: Jim Metzler previews the networking track at Interop
Extreme's port extender can replace consumer devices at network edge
VLANs versus IP subnets: Why use a VLAN over IP subnetting?
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Top 10 networking advice of 2008

Wireless LAN Implementation
University tackles large-scale 802.11n wireless network management
Why is my network adapter not working after a Vista Business upgrade?
How many wireless base stations can connect to 802.11g access points?
802.11n wireless APs bring IP video to sprawling Illinois high school
No data cable? Wireless mesh networking the answer for Wi-Fi backhaul
Integrated wireless and wired LAN: Brocade-Motorola deal ups the ante
802.11n WLAN architecture strategies: The 2.4 vs. 5 GHz band debate
802.11n upgrade: College ditches legacy network for new vendor
802.11n ratification will drive down wireless LAN prices
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?

Network Performance Management
Web gateway helps Texas manufacturer develop network user management
Desktop virtualization network challenges: A primer
Green enterprise: Three networking investments that make a difference
Storage area networks change management primer
CA-NetQoS deal: Network management = application performance
Virtualization change and configuration management primer
Network change and configuration management primer
Distributed network management means no more hard NOCs
WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
Network management from a service-based perspective

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
32-bit IP addressing  (SearchNetworking.com)
ARCNET  (SearchNetworking.com)
master  (SearchNetworking.com)
master/slave  (SearchNetworking.com)
Port Address Translation (PAT)  (SearchNetworking.com)
subnet  (SearchNetworking.com)
subnet mask  (SearchNetworking.com)
system administrator  (SearchNetworking.com)
Technical Office Protocol  (SearchNetworking.com)
virtual systems management  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts