Cisco to unveil Apple Bonjour gateway for enterprise WiFi networks

Cisco joins rivals in giving Apple’s discovery protocol enterprise behaviors

Cisco plans to add code to its wireless LAN controllers to make Apple’s Bonjour-based technologies like AirPlay and AirPrint better behaved on enterprise networks.

BACKGROUND: IT groups petition Apple to ‘fix’ Bonjour protocol

The code will turn the controller into a Bonjour gateway, and couple this with policy-based end user privileges. For users, this will mean that Apple clients will be able to find and access network-attached AirPrint printers, Apple TVs and the like on different subnets, so everything will “just work” as it does on their own home networks.

A second expected result will be a big decrease in the amount of Bonjour-based discovery traffic that today is putting a heavy load on enterprise nets teeming with Apple’s MacBook laptops, iPhones, iPads and more.

Cisco is hosting a Webcast seminar and demonstration of its still-in-development Bonjour Gateway Tuesday, July 24, at 10 a.m. Pacific (1 p.m. Eastern).

The webcast will also present Cisco’s plan to extend one of its existing technologies, called Network Based Application Recognition, to its wireless LAN firmware. For the first time, Cisco WLAN controllers will be able to dissect packets and compare them to a database of about 1,500 application “signatures” to identify a specific application -- such as a video conference versus a Netflix video, or a Skype voice call -- to be prioritized, blocked, or given bandwidth limits, for example.

Bonjour, originally called Rendezvous when introduced in the early 2000’s, is Apple’s latest implementation of “zero configuration networking” or Zeroconf, which is a group of open Layer 2 protocols to automatically and quickly set up an IP network, without having to set up services such as Dynamic Host Configuration Protocol, DNS, and DNS Service Directory. (More background is online at a page maintained by Stuart Cheshire, Zeroconf’s pioneer, who was later hired by Apple.)

And in simple home Wi-Fi networks, that’s just what happens: Apple clients broadcast for services, the services identify themselves, and client and service simply connect, paving the way for specific Apple protocols like AirPrint for printers and AirPlay for sharing multimedia among Apple clients via an intervening Apple TV box

But the strengths of Bonjour become problematic in more complex networks, which now can have hundreds, thousands or tens of thousands of iPhones and iPads advertising for services, but unable to connect if they’re on separate subnets. And the discovery traffic can, according to some colleges and universities, sometimes hit 90% of the network load. The problems are pressing enough that last week a group of higher education IT managers finalized a petition to Apple, asking for a range of Bonjour, and related, changes to make the protocols better citizens on enterprise networks. [See "IT groups petition Apple to ‘fix’ Bonjour protocol"]

Cisco is the third WLAN vendor to address these issues with a Bonjour gateway. Aerohive this week announced the release of HiveOS 5.1 and HiveManager 5.1, which now include its Bonjour gateway, first announced in March. Rival Aruba Networks announced a similar capability, also in March, and is expected to release it before the end of 2012.

On a Cisco WLAN, Apple clients will advertise for Bonjour services, just as they do now, says Chris Spain, vice president of product marketing for Cisco’s wireless business unit. The Cisco access point then will tunnel those requests back to the WLAN controller, and match them with an inventory of available AirPrint printers, Apple TVs, iTunes libraries and the like on any subnet in the enterprise network. The controller identifies the user, matches the authenticated user with his or her access privileges and grants access to the requested Bonjour service or not, based on group policies. 

So faculty but not students might have access to Apple TVs in specific rooms, or to certain AirPrint printers.

Cisco’s Webcast promotional page puts it this way: “With the Cisco Bonjour Gateway, available in a future software update, the wireless controller will answer device service queries in proxy of the server. Once the client gets a response it can connect via layer 3. Now file servers, printers, video devices, or any Bonjour server device can be accessed across subnets—making it easy for users to access the services they need.”

Spain says Cisco is currently testing the gateway to find out how and to what degree it can reduce Bonjour discovery traffic. In effect, with the intervening controller, every Bonjour request-response appears to the client device as a local, single-network transaction. Because the controller acts as a proxy for other Bonjour services on other subnets, it can minimize broadcasts, at least in theory.

“We think the gateway will reduce the total amount of Bonjour traffic over the network,” says Spain.

The Tuesday webcast will also demonstrate Cisco’s “application visibility and control” (AVC) over wireless LANs. This software, which identifies specific applications based on deep packet inspection compared to a catalog of application signatures, has been around for years as part of Cisco’s popular ISR routers and other products, especially to optimize relatively slower, shared resources like WAN links. This code is now being embedded on the Cisco WLAN controllers and given yet another Cisco acronym, NBAR, for Network Based Application Recognition.

By being able to “see” specific applications on the Wi-Fi links, the controller can then apply pre-determined policies to manage and optimize them. Voice or video applications, which are sensitive to jitter and latency, might be given priority treatment by the WLAN, for example. Or some applications, such as bandwidth hungry Netflix streaming video might be blocked; other applications might be given a specific bandwidth allocation.

Previously, Cisco’s WLAN firmware had some limited ability to identify applications. But the inclusion of AVC will now make this broader, deeper, and more specific, and allow IT to associate more granular controls on specific applications, according to Spain.

John Cox covers wireless networking and mobile computing for “Network World.”

Twitter: http://twitter.com/johnwcoxnww

Email: john_cox@nww.com

Blog RSS feed: http://www.networkworld.com/community/blog/2989/feed

Editors' Picks
Join the discussion
Be the first to comment on this article. Our Commenting Policies