Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register
Page 2 of 3  «  Previous Page    Next Page » 

WLAN security shootout

 

When compared against the traditional, thick-AP methodology (configuring each manually and then managing them via dedicated third-party tools such as AirMagnet), the tools offered by both WLAN switch vendors are a quantum leap forward. These products finally make WLANs a truly enterprise-enabled infrastructure component, complete with structured deployment, ongoing monitoring, and true centralized management.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

DOWNLOAD PDF

Click here to download InfoWorld's special report Wi-Fi security


Still Not a Perfect World

That's the good news. The bad news was made crystal clear during our mobility test, in which each vendor behaved exactly the same as soon as we ran into problems.

At first, both vendors claimed the problems were due to us running the initial test in 802.11g mode rather than 802.11b. So we switched to 802.11b -- but the problems persisted. At this point, both vendors conceded that a production implementation of a true roaming session was still rarely encountered in the real world. Most WLAN implementations assumed roaming to mean an executive wandering from AP to AP, VLAN to VLAN, subnet to subnet with a closed notebook -- in other words, an inert session that simply re-established itself in a new stationary position. In our tests, we were carrying an active and transmitting session from one AP to another.

Had we been using actual wireless VoIP phones instead of simply establishing a streaming traffic session, things might have been slightly different. That's because VoIP phones, like cell phones, are designed to establish connectivity with new APs as they come into scanning range. This way the device can decide which is the strongest signal and roam to the new AP whenever it wants. Our cards held on to their existing AP sessions for dear life, only releasing when communication became almost impossible and then running through handshaking and reauthentication latency with the new AP while attempting to maintain session state.

Unfortunately, this problem isn't resident with the WLAN switch. It's resident in the client's WLAN NIC (network interface card) and associated driver. Both vendors conceded that their products each had a set of favorite WLAN NICs and drivers, and that the reason they encountered problems in our test was because in real life they wouldn't be constrained to a single NIC platform, such as a Proxim card -- they'd have used different cards optimized for different activities.

Although this somewhat colors their claim that WLAN switches can be seamlessly dropped onto any existing WLAN infrastructure, it also shows that even with a central back-end intelligence such as a WLAN switch, the client side of wireless is far from ubiquitous. Centrino may be in every notebook rolling off the production line, but that doesn't mean it's the best thing for your enterprise WLAN.

What this means to you is that althought WLAN switching is a huge step forward in manageability and security, it's not a silver bullet for every Wi-Fi woe. WLANs still have a long way to go in terms not only of updating their technology but integrating that technology into all the moving parts of a WLAN engine. Those of you considering a WLAN implementation will still need to closely test back-end security and management, client-side interoperability, and especially specific application performance.

Aruba 2400 Wireless LAN Switching System

The Aruba 2400 has been around as long as WLAN switching has been a product type, but it's hardly a dusty product. Since its inception, the Aruba 2400 has undergone a number of feature refinements and the version we tested was no exception, providing more support for advanced encryption standards and the silicon to back these new features up.

The core of the system is the back-end, datacenter-oriented 2400 WLAN switch. The 2400 we reviewed is based on three specialized CPUs: a PowerPC running embedded Linux as the switch OS, a Broadcom Sibyte to handle data-plane control, and a Nitrox Cavium, handling the proverbial kitchen sink of encryption protocols. Each 2400 can handle as many as 512 users and 48 managed APs -- while still processing at up to 2Gbps using IPSec traffic. Aruba also offers the 5000, which can handle as many as 4,096 attached users running over a maximum of 128 managed access points, as well as the 800, which holds as many as 256 users and a maximum of 16 managed APs.

For larger installations, these switches can be daisy-chained into larger logical units, but we found no need for this during our test. This 3U, rack-based device can attach up to 72 access points directly via 10/100 Ethernet wired connections. Port configurations are flexible, however, as the 2400 can just as easily connect to and manage access points using only level 2/level 3 logical connections, meaning the APs only need to be on the network and the 2400 will find them. For backbone performance, the 2400 can provide up to six GBIC (Gigabit Interface Converter)-based GbE uplinks, making this device quite easily the most flexible WLAN switch we've seen to date from a pure hardware perspective.

Click for larger view.

In fact, the 2400's resemblance to a standard Ethernet switch is one of the things we found most attractive about the device. Features, including port count and type, as well as redundant power supplies, can be implemented in the same modular fashion as any quality Ethernet switch. You'll even find some of the newer wired switch features supported, including power over Ethernet, the 802.3af Power via MDI standard, and serial over Ethernet, the Electronic Industries Alliance's recommended standard RS-232.

Aruba does include a management and deployment software suite, dubbed AirOS, that it positions against Trapeze's RingMaster. Although AirOS isn't quite as slick or feature-rich as RingMaster, it does handle all the basics of deployment and management, with a few goodies thrown in that you won't find in Trapeze's solution.

On the management side, Aruba has RF (radio-frequency) modeling based on basic environmental stats and can even extend these models into a three-dimensional space, though it does so by combining its data of multiple coverage areas (such as floors), not by treating the entire area as an actual three-dimensional space. It can make basic access point recommendations based on this data, but you'll almost certainly need to tweak this configuration once real life begins to creep in. While laying out its AP map for our test, AirOS could only input static values for things such as wall or floor construction, and its initial deployment plan was really just a good place to start. Designing a final coverage plan required us to input our own values into the plan and re-adjust AP placement and configuration accordingly.

After AP installation, Aruba's software handles all basic configuration and advanced tweaking, such as altering channel assignments, from a central location. Aruba also supports dynamic load balancing as well as ongoing device management. The latter feature spawned something of an argument among us testers. Unlike Trapeze, which monitors each device via software agents, Aruba designates a certain number of access points as Air Monitors.

An Air Monitor acts as a wireless management device that allows the Aruba system to gather device and traffic data for management purposes. This bothered us, as we considered it a waste of AP hardware, a source of unnecessary traffic, and a deployment complication. Each Air Monitor, however, can switch into AP mode should an AP in its coverage area fail, thus maintaining system integrity and even supplying a form of fail-over.

Although these additional APs do increase the overall solution cost somewhat, Aruba argues that the expense isn't that high and that the value gained is worthwhile. By placing its management overhead onto a separate hardware infrastructure, the company argues that it eliminates the possibility of overall system performance degradation often associated with active monitoring systems.

Where Aruba's software stands out, however, is in overall WLAN security. Next to all the 802.1x and AES buzzword features you'll find in most WLAN switching solutions, Aruba has done some careful planning not only to maximize its security offering but to tailor it to real-world WLAN difficulties and integrate it into an existing network security policy as well.

An important feature in this regard: The 2400 has what amounts to an embedded, stateful inspection firewall. That means not only is the box running all the WLAN encryption you'll need, it also can be used to identify noncrack WLAN hacks, such as ping of death or a DDoS (distributed denial of service) attack, and stop them simply by dumping that traffic. The system can also respond to man-in-the-middle attacks by identifying a valid user that's continually attempting to access the same AP (a precursor to a DDoS attack) and automatically force that user to roam. And, like Trapeze, the 2400 can detect rogue APs; but unlike Trapeze's solution, it can remove these boxes from the network as well as use a combination of deauthentication and a DoS attack against the rogue AP.

Our only disappointment with the 2400 came during performance testing. Our initial 802.1x cycle speed test was predicated on the assumption that the 2400 could do 802.1x on the wired side. This would have allowed us to generate the massive traffic we needed using a standard wired traffic generator from Spirent. Generating equivalent load from a purely wireless source was not feasible at test time. Consequently, we don't have exact numbers on how many 802.1x authentication cycles the 2400 can handle, but given its internal CPU muscle, the amount should be more than adequate for all but the highest performance requirements.


Continued
»  Previous Page | 1 | 2 | 3 | Next Page » 



Aruba 2400 Wireless LAN Switching System

Aruba Networks, arubanetworks.com

Very Good  8.2
criteria score weight
Security 9 25%
Management 8 20%
Configuration 8 15%
Implementation 7 15%
Integration 8 15%
Value 9 10%

Cost:
As tested price, $10,595

Bottom Line:
Aruba is a well-engineered and mature WLAN switching system. Although it lacks Trapeze’s management and configuration flexibility, Aruba is a step ahead in terms of rock-solid security. The 2400 not only manages authentication and encryption with aplomb, it does an excellent job of countering ongoing attacks as well as finding and neutralizing existing WLAN network threats.

About our Reviews and Scoring Methodology



Trapeze MX-20 Mobility System

Trapeze Networks, trapezenetworks.com

Excellent  8.7
criteria score weight
Security 8 25%
Management 9 20%
Configuration 9 15%
Implementation 9 15%
Integration 9 15%
Value 8 10%

Cost:
As tested price: MX-20, $9,495; dual radio access point, $549; RingMaster license, $1,995

Bottom Line:
Trapeze takes the gold in terms of polish and flexibility. Its bundled RingMaster management platform is easily the slickest and most flexible WLAN management application we've ever encountered. And although Aruba does beat it on security, Trapeze is no slouch in this department, being beaten only by Aruba’s advanced IDS functionality but giving no ground in terms of traffic or user protection. Its overall solution price places it higher than the Aruba, yet Trapeze is definitely worth the money for the majority of enterprise WLAN implementations.

About our Reviews and Scoring Methodology



 


 
Brian Chee is associate director and founder of the Advanced Network Computing Laboratory at the University of Hawaii's Department of Information and Computer Sciences. Oliver Rist is a senior contributing editor at InfoWorld.

  More of Oliver Rist's column
  Oliver Rist's Weblog

Newsletter Check out all of our free newsletters!
Enter e-mail address:




 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




Application Grid: Oracle's Vision for Next-Generation Application Servers and Infrastructure
View this live Webcast to hear senior Oracle executives Hasan Rizvi and Steve Harris discuss the application grid. Learn how Oracle is combining cutting-edge technologies from its recent acquisition of BEA with the Fusion Middleware portfolio. Discover a new level of reliability, performance, and "scale-agility" in your data center, with emphasis on efficiency for today's challenging economic environment. Sponsored by Oracle

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist