Wireless switching is changing the way wireless networks work. Sifting through the complex and often hype-intense offerings can be difficult. To help get you started, here are seven areas to include in any analysis of this technology.
Wireless switching is changing the way wireless networks work. Instead of access points (APs) bridging traffic directly onto a wired network, wireless switching creates a virtual overlay network on top of an existing wired infrastructure. In wireless switching, wireless clients talk to APs, and the APs tunnel that traffic to control appliances – the wireless switches. This hierarchy of APs, tunnels, and switches offers benefits such as simplified network deployment, integrated security, increased scalability, and eased management. In spite of its advantages, though, wireless switching is still a developing technology. Sifting through the complex and often hype-intense offerings can be difficult. To help get you started, here are seven areas to include in any analysis of this technology.
Planning tools
Deploying a wireless LAN can be time consuming and expensive. In addition to selecting the right number of APs to use, each radio in a deployment requires an optimized location, a non-conflicting channel, and a proper power setting. The old way of doing this was to temporarily deploy APs, take measurements, move the APs, and start over. To simplify WLAN deployments, most wireless switching products offer automated site survey tools that can simulate your environment to predict the best locations for APs. After deployment, many wireless switching systems can also establish the best channel and power settings for your initial network. If your vendor supports automated site surveys, gauge whether the plans can be built based on coverage, capacity, or both. Next, judge accuracy by determining whether building materials can be factored into the plan. Be sure to balance accuracy with the time it will take to develop the survey. Other items that deserve consideration are tools that permit you to plan areas where you don’t want coverage, or where you do want wireless-LAN access, but can’t place APs.
RF management
Because noise and interference can play havoc with performance, even a well-planned wireless network must adapt to changes in the RF environment. In order to facilitate this, some wireless switching systems can continuously change AP channel and power settings to avoid frequencies that become overused while ensuring seamless WLAN coverage. In the area of RF management, first get an understanding how and when APs sense trouble in the environment. After that, establish whether APs are capable of simultaneously serving clients and monitoring the network. Your next step should be to determine what metrics will trigger changes and where (in the network) RF adjustment decisions will be made. Examine any tools put in place limit the scope and frequency of RF changes, and then consider features that permit client-AP load balancing when the network is over utilized. Keep in mind, though, that load balancing may be dependant on client support.
SSIDs and networks
In wired networks, clients connect to ports, ports belong to IP subnets, and subnets can be constrained by policy. In wireless, though, there are no client ports, and wireless networks (called SSIDs) don’t necessarily relate to subnets. To understand your options for SSID and subnet design in wireless switching, determine whether you’ll be able to map multiple SSIDs to a single subnet, or a single SSID to multiple subnets on one, or more switches. If using a single SSID will ease management, consider mechanisms for mapping clients to IP networks based not on SSID, but on identity or location. Some of the choices here can include mapping clients using RADIUS, MAC address, AP, authentication type¾or a combination of these options.
Access control
While most wireless switching products support 802.1x authentication, that’s where the similarities end. You’ll want to know whether the vendor can offload 802.1x processes or cache keys from RADIUS, because that can decrease the time it takes for clients to move around the network while lessoning the load on your servers. Next, inquire about access control tools that permit you to determine not only when, but also where clients can get into the network. Currently, most vendors permit you to build lists of clients and the APs they can attach to. Some vendors make this easier by grouping APs in categories such as “floor” or “building”. In the future though, vendors will use RF to determine where clients are, permitting easier and more granular access control.
Firewalls
Many enterprises separate their wireless LAN and intranet using standalone firewalls. To streamline and enhance this, some wireless switches include integrated firewalls that can be beneficial in environments that require identity-based filtering policy, security for mixed WPA and WEP clients, or architectural simplification. If you need an integrated firewall, first determine whether extra hardware is required to enable that functionality. Find out if the firewall operates in a stateful fashion, or whether it’s just a packet filter. If ICSA certification is important to your security staff, ask about it. Lastly, gauge the firewall’s capability to map policies to individuals on the same wireless network.
Scalability
Wireless switching networks can grow larger than legacy wireless LANs primarily because you manage the switches, and not each AP. To understand how complex a large wireless switching network will be, determine how many clients and APs each switch can support, taking into account the fact that 802.11 considerably reduces advertised wireless throughput numbers. Then, examine the number of switches and APs the vendor’s management system can handle to get an overall picture of how your wireless switching network will scale.
Guest access
Although a big benefit of wireless LANs is providing access to guests, many companies don’t want to rely on traffic filtering to control what those guests can do while on site. One trend is to get guests on the WLAN¾and then force their data out of the enterprise as quickly as possible. To do this, many vendors are integrating features that will map guest traffic to tunnels that connect them directly to a DMZ. In the guest access arena, you should gauge the ease with which guest tunnels can be built and enforced. Since your guests may not support 802.1x authentication, be sure to also ask about integrated captive web portal authentication.
Remote site support
Until recently, wireless switching was aimed at campuses, not remote sites. Now, vendors are offering small remote site switches or solutions that offload functionality to a wireless switch at a hub site. If remote site switches are a choice, focus on scalability and cost. If remote WLAN traffic is forced to a hub site, consider any performance or redundancy implications that might exist. Next, investigate plans to add control functionality to the APs themselves, which will eliminate the need for both small switches and centralized functionality. Finally, if you use 802.1x and need survivability, consider RADIUS support at your remote site. While some vendors offer limited authentication database support in their products, others offer full RADIUS functionality.
Spencer Giacalone is a VP at a major international financial firm, and holds a CCIE, CISSP, and CWNA. He can be reached at giacalones@yahoo.com




