by Tom Henderson, Network World Global Test Alliance

Newbury Location Appliance is adept at tracking Wi-Fi gear

Reviews
Apr 2, 20076 mins

With an invisible fence, a barking dog runs right up to an unseen barrier and stops cold. Underground is a ropelike antenna that defines a perimeter and shocks the pet if it attempts the cross the boundary. Our Clear Choice Test of Newbury Networks’ Newbury Location Appliance found it has a similar effect on wireless traffic.


How we tested Newbury Location Appliance

Archive of Network World tests

Subscribe to the Network Product Test Results newsletter


With a little bit of setup and training (called fingerprinting), we achieved a clear boundary using the appliance and were able to track Wi-Fi gear traveling across a digital map of the office area. Overall, it’s a fascinating combination, although it takes a bit of work to integrate.

For an extra cost, you can add Newbury’s WiFi Watchdog software to disable objects when they move out of defined boundaries, called locales. The device also provides a locations API for feeding data to a wireless location-tracking platform from Newbury or other third-party applications.

Inside the rack-mounted box is an Intel Xeon twin-CPU system running the Linux 2.6.16 kernel. Initial setup had us dragging out a serial cable to get a terminal connection to the unit, but the rest of the setup comes from either a Web browser or a Java Run-time Environment application connection over Ethernet that runs on Windows XP (we had trouble with Vista), MacOS (10.4.9) or Linux.

WIRELESS NEWBURY LOCATION APPLIANCE

Newbury Networks

4.0
Price:$1,500
Pros:Highly effective Wi-Fi perimeter fence; easy to use once set up.
Cons:May require temporary installation Wi-Fi site downtime; lacked some documentation.
The breakdown
Security 20%3.5Scoring Key: 5: Exceptional4: Very good3: Average2: Below average1: Subpar or not available
Administration 20%3.5

Management functionality 40%

4.5
Setup/integration 20%4.0
TOTAL SCORE4.0

Check out our Wireless Buyer’s Guide

After a 30-second setup via the serial cable, life got easier, and we were able to use HTTPS, LocalePoint Manager application or a Secure Shell session back to the original terminal interface.

Newbury started several years ago to calculate the three-dimensional location of Wi-Fi gear by using the observations of its own patented and proprietary Wi-Fi access points. The slight latencies between signals allow Wi-Fi devices to be triangulated; therefore, items heard by the access points via a time vs. math relationship allows them to be pinpointed physically among the access-point receptors.

The vendor then graduated to using Cisco access points, and now several leading brands of access points can be used. We tested Newbury’s scheme before and found its accuracy to be reasonably good within the three dimensions.

What’s changed is that there’s no longer a requirement to run what was essentially a parallel network using Newbury’s proprietary passive access points.

Newbury appliance tracks wireless signals.

We tested the appliance using six Trapeze Networks MP-372 access points connected to a Trapeze MX-8 switch. We connected the NLA to our test site organization’s switched Ethernet infrastructure, along with the Trapeze switch. A quick perimeter walk-around of the floor of the office building revealed 22 foreign access points and dozens of clients from local hotels and businesses.

We also discovered two open access points touted as free Wi-Fi services for a coffee shop on the first floor of the building as well as a fake access point (the infamous “Free WiFi NOW” phish). The energy of the foreign access points could be very high, with strong signals despite our eighth-floor office location. The NLA appliance would need to learn to ignore many things in this highly active RF environment.

We set the Trapeze Networks MX-8 switch to snoop (actually forward packets chopped off to 82 bytes) by shipping packets to the NLA, which learned the relationship between them. We also set up the Trapeze network to use WPA2 preshared keys for authentication, to prevent interim unauthenticated logons to the network we built.

Then we used the Newbury Networks’ software to establish a perimeter (a Wi-Fi fenced area called a locale) using an HP notebook to walk around the office, noting the notebook’s location periodically on a small map we drew. In short order, we established the node points for boundaries of the geography that we wanted to cover.

Devices found were subsequently tagged using the NLA software. Their location then can be tracked as they rest, or move within defined locales or out of locale areas.

Another feature of the NLA lets one learn/find the location of a device in less than 30 seconds. Only by running at top speed across the office were we able to cause the updates to change, rendering tracking of the device under test difficult.

Newbury supplies small candy-box-sized $70 Wi-Fi transceivers, which can be attached to high-cost or high-need devices that are mobile. We could track any device simply and easily through the locales map that we drew, bounded by the perimeters we established.

It’s possible to set up tracked devices within the NLA software to spawn alarms when the devices are tracked outside of specific predefined boundaries.

What we didn’t like

This Version 1 of the appliance lacked several key security access items, as strong passwords are neither encouraged, mandated nor enforced, and the documentation for integration with the fresh variety of new access points that are compatible with NLA wasn’t on the supplied CDs or printed documentation.

Newbury says most rollouts will involve an installer, but those seeking a do-it-yourself installation are advised to obtain integration information from the vendor before embarking on the deployment. A Newbury spokesperson says the CDs will be corrected to include all needed documents, as well as access point-vendor-specific detailed instructions.

Newbury is opening the APIs in the NLA for third-party customizers. While the vendor may not be interested in getting into the security alarm business, we feel that many Wi-Fi devices and location-based information couplings make sense for organizations. Having an instant alarm when a $100,000 spectrometer decides to get legs could be very handy, for example.

Our other complaints focused on the appliance requiring installations of fewer than eight access points to be set up using a highly constrained operating environment during the training phase of the NLA. This required using one channel (we used 11) and disabling the tuning features of Trapeze’s infrastructure. We were also encouraged to use 802.11b during tuning (802.11b/g/a could be used later) during this phase.

Retrofits will therefore require a network in a smaller installation to be modified this way until the NLA is trained in locales. It also means a very large single-channel footprint for the wireless network during this phase.

The boundary and fence of the Newbury NLA required us to jump through a few hoops, but the installation time took just a few hours. The payoff is that once installed, the appliance put an effective boundary in three dimensions around a Wi-Fi network, augmenting other security components that should be in place, such as strong authentication.

Henderson is principal of ExtremeLabs in Indianapolis. He can be reached at thenderson@extremelabs.com

4.0

Price:$1,500
Pros:Highly effective Wi-Fi perimeter fence; easy to use once set up.
Cons:May require temporary installation Wi-Fi site downtime; lacked some documentation.
The breakdown
Security 20%3.5Scoring Key: 5: Exceptional4: Very good3: Average2: Below average1: Subpar or not available
Administration 20%3.5

Management functionality 40%

4.5
Setup/integration 20%4.0
TOTAL SCORE4.0

Check out our Wireless Buyer’s Guide

After a 30-second setup via the serial cable, life got easier, and we were able to use HTTPS, LocalePoint Manager application or a Secure Shell session back to the original terminal interface.

Newbury started several years ago to calculate the three-dimensional location of Wi-Fi gear by using the observations of its own patented and proprietary Wi-Fi access points. The slight latencies between signals allow Wi-Fi devices to be triangulated; therefore, items heard by the access points via a time vs. math relationship allows them to be pinpointed physically among the access-point receptors.

The vendor then graduated to using Cisco access points, and now several leading brands of access points can be used. We tested Newbury’s scheme before and found its accuracy to be reasonably good within the three dimensions.

What’s changed is that there’s no longer a requirement to run what was essentially a parallel network using Newbury’s proprietary passive access points.

Newbury appliance tracks wireless signals.

We tested the appliance using six Trapeze Networks MP-372 access points connected to a Trapeze MX-8 switch. We connected the NLA to our test site organization’s switched Ethernet infrastructure, along with the Trapeze switch. A quick perimeter walk-around of the floor of the office building revealed 22 foreign access points and dozens of clients from local hotels and businesses.

We also discovered two open access points touted as free Wi-Fi services for a coffee shop on the first floor of the building as well as a fake access point (the infamous “Free WiFi NOW” phish). The energy of the foreign access points could be very high, with strong signals despite our eighth-floor office location. The NLA appliance would need to learn to ignore many things in this highly active RF environment.

We set the Trapeze Networks MX-8 switch to snoop (actually forward packets chopped off to 82 bytes) by shipping packets to the NLA, which learned the relationship between them. We also set up the Trapeze network to use WPA2 preshared keys for authentication, to prevent interim unauthenticated logons to the network we built.

Then we used the Newbury Networks’ software to establish a perimeter (a Wi-Fi fenced area called a locale) using an HP notebook to walk around the office, noting the notebook’s location periodically on a small map we drew. In short order, we established the node points for boundaries of the geography that we wanted to cover.

Devices found were subsequently tagged using the NLA software. Their location then can be tracked as they rest, or move within defined locales or out of locale areas.

Another feature of the NLA lets one learn/find the location of a device in less than 30 seconds. Only by running at top speed across the office were we able to cause the updates to change, rendering tracking of the device under test difficult.

Newbury supplies small candy-box-sized $70 Wi-Fi transceivers, which can be attached to high-cost or high-need devices that are mobile. We could track any device simply and easily through the locales map that we drew, bounded by the perimeters we established.

It’s possible to set up tracked devices within the NLA software to spawn alarms when the devices are tracked outside of specific predefined boundaries.

What we didn’t like

This Version 1 of the appliance lacked several key security access items, as strong passwords are neither encouraged, mandated nor enforced, and the documentation for integration with the fresh variety of new access points that are compatible with NLA wasn’t on the supplied CDs or printed documentation.

Newbury says most rollouts will involve an installer, but those seeking a do-it-yourself installation are advised to obtain integration information from the vendor before embarking on the deployment. A Newbury spokesperson says the CDs will be corrected to include all needed documents, as well as access point-vendor-specific detailed instructions.

Newbury is opening the APIs in the NLA for third-party customizers. While the vendor may not be interested in getting into the security alarm business, we feel that many Wi-Fi devices and location-based information couplings make sense for organizations. Having an instant alarm when a $100,000 spectrometer decides to get legs could be very handy, for example.

Our other complaints focused on the appliance requiring installations of fewer than eight access points to be set up using a highly constrained operating environment during the training phase of the NLA. This required using one channel (we used 11) and disabling the tuning features of Trapeze’s infrastructure. We were also encouraged to use 802.11b during tuning (802.11b/g/a could be used later) during this phase.

Retrofits will therefore require a network in a smaller installation to be modified this way until the NLA is trained in locales. It also means a very large single-channel footprint for the wireless network during this phase.

The boundary and fence of the Newbury NLA required us to jump through a few hoops, but the installation time took just a few hours. The payoff is that once installed, the appliance put an effective boundary in three dimensions around a Wi-Fi network, augmenting other security components that should be in place, such as strong authentication.

Henderson is principal of ExtremeLabs in Indianapolis. He can be reached at thenderson@extremelabs.com.

Henderson is also a member of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.