by Jim Geier

Wireless wake-up call

How-To
Mar 14, 20058 mins

Cisco/Airespace deal boosts thin access point/WLAN switch topology and makes enterprise WLANs more enticing.

Cisco’s recent purchase of Airespace could kick-start the wireless LAN market, creating new options for enterprise customers, particularly Cisco shops that were reluctant to pay a premium for Cisco gear, but which were also skittish about going with a WLAN switch start-up.

Cisco initially will offer Airespace WLAN switches and thin access points under the Cisco name alongside Cisco’s Aironet fat access points, which are part of its Structured Wireless-Aware Network (SWAN) product line.

The Airespace WLAN switch offers superb security and management features at a much lower total cost of ownership than an Aironet rollout. As a result, it’s likely that many customers that shied away from Cisco’s higher-priced offerings will move forward with the Cisco-Airespace product.

Cisco plans to integrate Airespace switches with SWAN, but there is no clear definition of how Cisco will make this integration work. It’s likely Cisco will interface Aironet access points to Airespace WLAN switches. This will let Cisco customers with Aironet access points migrate to a wireless switched network.

Cisco’s purchase of Airespace is seen as validation of the thin access point approach to WLANs, an approach taken by the start-ups such as Trapeze Networks, Aruba Wireless Networks and Airespace. Cisco followed the more traditional approach of deploying fat access points and connecting to current Ethernet switches. In Cisco’s case, the company created a WLAN blade for the Catalyst 6500 switch.

A switch in time

Cisco’s move also reflects an acknowledgement that the future belongs to the Airespace model. According to Infonetics, Cisco is No. 1 in WLAN revenue, with 17% market share, followed by Linksys (owned by Cisco), D-Link Systems and Netgear. But Infonetics reports that fierce price pressure is severely impacting revenue – in 2004 worldwide units sold increased 51% but revenue only increased 15%.

Synergy Research predicts that worldwide revenue from traditional access points will drop 2% in 2005, 35% in 2006 and 11% in 2007. On the other hand, sales of WLAN switches will grow 150% in 2005, 53% in 2006 and 59% in 2007, according to Synergy.

In the fat access point scenario, access points such as Cisco’s Aironet provide radio-based connections in addition to security, management and performance enhancements. The advantage is that you easily can make use of your Ethernet infrastructure, but the downsides are that the access points are relatively expensive and difficult to manage.

With the thin access point model, wireless switches provide those security, performance and management features. The thin access points then can concentrate on what they’re intended for – reliable, high-performance radio technology.

WLAN switches offer benefits

Beyond the cost savings, there are a number of technical reasons, including security, performance and ease of management, which make WLAN switching the way to go.

Security is a major concern for IT executives deploying WLANs. Unfortunately, WLAN standards cover encryption between user and access points, but not authentication, intrusion detection and rogue access point control.

For example, a hacker could try to compromise security by attaching a rogue access point to the wired network. Unless the company implements careful Ethernet switch port control, the rogue access point could gain access to the corporate network wirelessly from a nearby car.

Likewise, an employee might purchase an access point from an office supply store and connect it to the corporate network without setting acceptable security controls, which inadvertently leaves an opening for a mischievous person to exploit.

However, a wireless switch authenticates and configures each access point based on the company’s security policies. An employee or hacker might plug the access point into the network, but the wireless switch will disable the connection if the access point is not able to authenticate or configure correctly.

Additionally, a wireless switch ensures that all authorized access points comply with security policies. Access points can be configured to only allow policy changes from the wireless switch, which precludes a hacker from plugging a laptop into the access point via a console cable and change configurations that make the network unsecure.

The wireless switch can be kept inside a locked room and out of hackers’ reach. If a hacker attempts to disconnect a legitimate access point and plug in a rogue, the switch will notice what’s going on and physically disable the rogue’s access to the corporate network.

Higher performance

A fairly common issue with WLANs is that coverage holes – areas with low signal strength – often exist. This occurs because of poor placement of access points and the dynamics of the environment. After the initial installation of access points, for example, a company might add walls to create new offices or move large machinery. This affects the propagation of radio waves, which leads to lower and sometimes inadequate signal strength in parts of the building.

Some applications, such as e-mail and Web browsing, hold up pretty well as users roam through coverage holes. At least a user can read e-mails or view Web pages in cache on the mobile device while on route to a covered area.

However, a warehouse inventory management application commonly requires a constant connection between the terminal (mobile device) and the host (application server). If the wireless connection is temporarily lost, the user usually must log back on to the system. Sometimes this can even cause errors on the server if the loss of connection occurs in the middle of a transaction.

WLAN switches can compensate for the periodic disconnected state of mobile devices as users roam through coverage holes. The switch is smart enough to know that a mobile device no longer has a wireless connection to the access point. The switch continues to maintain the applicable connection with the application server. The worst case is users might experience application delays, but the application remains available and ready to start where it left off.

Another issue is that voice-over-WLAN (VoWLAN) phones will drop calls as users walk through areas where signal strength is too low. Cisco publishes stringent guidelines for deploying WLANs that enable effective VoWLAN operation, but most traditional thick access point WLAN installations don’t come close to offering the coverage and speedy handoffs between access points that VoWLAN applications require.

Wireless switches, though, are designed to provide adequate handoffs between access points and intelligent restarts to avoid dropped calls.

Improved management

Often, the costs associated with ongoing operational support of a WLAN becomes higher than the initial cost of hardware and software, unless you ensure that effective management tools and support methods are in place. WLAN switches are designed to offer effective, centralized support necessary to realize an expected ROI. Centralized management is possible with wireless switches, which can configure, monitor and upgrade multiple access points automatically.

For instance, a company can interface an access point into a WLAN switch, and the switch automatically configures the access point. This saves the time and potential human error of having an administrator perform the configuration. Also, the wireless switch immediately can detect a failed access point and alert appropriate staff.

Also, network managers might not have much experience with radio-based systems. An important aspect of wireless switches is that they offer a layer of management that reduces the need to understand radio waves. The automated switch functions, such as intelligently restarting applications when connections are lost and rogue access point control, compensate for lack of wireless network skills.

Because a wireless switch houses most of the intelligence of the WLAN, the access points can focus on radio connectivity, which usually keeps the prices of thin access points considerably lower than the thick access point counterparts. As a result, a company with thin access points can migrate to newer technologies at lower costs. The corresponding changes to the rest of the network can be done through software upgrades on the switches.

While it might be tempting to use the current wired Ethernet network to interconnect access points, the improvements in security, performance and management when deploying a wireless switch likely will make the ROI much better in the long run.

Just keep in mind that you probably won’t be able to use third-party access points and still realize all the benefits touted by the wireless switch maker.

That’s not too much of a problem for Cisco shops because they can choose Airespace and still be within the realm of Cisco for their entire network. But companies with non-Cisco infrastructures probably will need to use access points from the wireless switch vendor, which probably will be different from the vendor of the wired network.