* The Reviewmeister takes a tour of WLAN switches, starting with Airespace
endif; ?>The Reviewmeister is taking a tour of wireless LAN switches this week and next, so let’s start with the A’s, today we’ll look at Airespace. Next time, we’ll look at Aruba.
Airespace offers a well-designed Web management interface and good security features, and it has the fastest forwarding rates in our performance testing. While Aruba is big on automated site survey tools, Airespace says there’s no substitute for a physical site survey – that is, walking around the premises and gauging signal strength.
The Airespace Web interface was the most intuitive of ones we tested, with well-organized divisions of various WLAN and switch management functions. Airespace also is the only vendor to support SNMP Version 3, which offers much better security than its predecessors.
Our results suggest the Airespace system, which features dynamic radio frequency adaptation, does well when handling potential interference situations. In the forwarding rate tests using large (1,446-byte) frames, Airespace’s access points were the “hottest” of the group, posting the highest transfer rates across the board.
In the worst case, Airespace’s access point held up frames for an average of nearly 400 millisec. We also measured jitter (delay variation) of just 17 millisec, meaning most frames, not just a few outliers, experienced high delay.
Airespace did well in tests when three of their own access points had to contend with one rogue access point. And it demonstrated the ability to keep rogues from using any significant spectrum.
Airespace’s systems are very intelligent about rogue detection.When we used FakeAP to simulate rogue access points, Airespace simply treated the FakeAP traffic as noise.
Airespace also goes a step further with an option called rogue containment – essentially, kicking rogue access points off the air so clients can’t see them. In tests with actual rogue access points, both vendors’ rogue containment routines worked within 1 second of the rogue attempting to come up.
Support for 802.1x authentication carries another benefit by changing the keys used for Wired Equivalent Privacy (WEP) encryption at frequent intervals. That’s important because WEP design is inherently weak, and an attacker possessing a static key can decrypt traffic with relatively little effort. All vendors say they support emerging WEP replacement, Wi-Fi Protected Access with Temporal Key Integrity Protocol, but we did not verify this in testing.
All switches add various security measures above and beyond those furnished by the WLAN protocols, although the offerings are mixed. Airespace’s switches offer native IPSec capabilities to authenticate and encrypt traffic between clients and switches, and Airespace’s switch automatically sets up IPSec tunnels between switches.
For the full report, go to https://www.nwfusion.com/reviews/2003/0922rev.html




