Why Packets Matter. Capturing Packets and Solving WLAN Issues (Why, How, Where, When)



Similar documents
Site Survey and RF Design Validation

Wi-Fi / WLAN Performance Management and Optimization

7 Key Requirements for Distributed Network Monitoring

CWNA Instructor Led Course Outline

WHITE PAPER. WEP Cloaking for Legacy Encryption Protection

Express Forwarding : A Distributed QoS MAC Protocol for Wireless Mesh

CS6956: Wireless and Mobile Networks Lecture Notes: 2/11/2015. IEEE Wireless Local Area Networks (WLANs)

CT LANforge WiFIRE Chromebook a/b/g/n WiFi Traffic Generator with 128 Virtual STA Interfaces

What s Really Happening on Your Wireless Network Multi-Channel Analysis for WLAN Mobility

Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 6. Wireless Network Security

Welch Allyn Acuity Network installation. Best practices

Designing and Deploying. High Capacity ac Wi-Fi

CT LANforge-FIRE VoIP Call Generator

A Closer Look at Wireless Intrusion Detection: How to Benefit from a Hybrid Deployment Model

Real-Time Communication in IEEE Wireless Mesh Networks: A Prospective Study

Beyond Monitoring Root-Cause Analysis

Welch Allyn Connex, VitalsLink by Cerner, and Connex CSK Network installation. Best practices overview

Clearing the Way for VoIP

Meru MobileFLEX Architecture

CSE331: Introduction to Networks and Security. Lecture 6 Fall 2006

WildPackets engaged Miercom to conduct comprehensive,

Meru MobileFLEX Architecture

Troubleshooting VoIP & VoFi Call Quality Issues

Centralized WLAN Troubleshooting

Radio Resource Management in HiveOS. solution brief

Analysis of QoS parameters of VOIP calls over Wireless Local Area Networks

Dedicated Air Monitors? You Decide.

Meraki Wireless Solution Comparison

Design Guide for Pervasive Wireless Networks

Enterprise A Closer Look at Wireless Intrusion Detection:

Question: 3 When using Application Intelligence, Server Time may be defined as.

Solving the Sticky Client Problem in Wireless LANs SOLVING THE STICKY CLIENT PROBLEM IN WIRELESS LANS. Aruba Networks AP-135 and Cisco AP3602i

White paper. Cisco Compatible Extensions: Client Benefits on a Cisco WLAN

Wireless Security Overview. Ann Geyer Partner, Tunitas Group Chair, Mobile Healthcare Alliance

Lecture 17: Wireless Networking"

Nokia Siemens Networks. CPEi-lte User Manual

WIRELESS SECURITY. Information Security in Systems & Networks Public Development Program. Sanjay Goel University at Albany, SUNY Fall 2006

Optimizing Wireless Networks.

Wi-Fi Capacity Analysis for ac and n: Theory & Practice

How To Unify Your Wireless Architecture Without Limiting Performance or Flexibility

Troubleshooting Common Issues in VoIP

Attenuation (amplitude of the wave loses strength thereby the signal power) Refraction Reflection Shadowing Scattering Diffraction

Voice over WiFi Deployment recommendations and best practices

NX 9500 INTEGRATED SERVICES PLATFORM FOR THE PRIVATE CLOUD

24x7 Monitoring and Troubleshooting Distributed Application Performance

Introduction VOIP in an Network VOIP 3

White Paper. D-Link International Tel: (65) , Fax: (65) Web:

Motorola AirDefense Network Assurance Solution. Improve WLAN reliability and reduce management cost

Configuration Notes Trapeze Networks Infrastructure in Ascom VoWiFi System

Wireless LAN Services for Hot-Spot

Course Content for Managing Cisco Wireless LANs (WMNGI 1.2) Duration : 4 Days

EETS 8316 Wireless Networks Fall 2013

Wi-Fish Finder: Who will bite the bait?

Encapsulating Voice in IP Packets

Recommended Wireless Local Area Network Architecture

Software-Defined Networking for Wi-Fi White Paper

Wireless Network Analysis. Complete Network Monitoring and Analysis for a/b/g/n

Network Master Gigabit Ethernet Tester. Network Master Gigabit Ethernet Tester. Introduction. By Ole Sørensen Product manager.

Optimizing Network and Client Performance Through Dynamic Airtime Scheduling. white paper

Avaya WLAN Orchestration System

Top Six Considerations

QUALITY OF SERVICE FOR CLOUD-BASED MOBILE APPS: Aruba Networks AP-135 and Cisco AP3602i

Network Simulation Traffic, Paths and Impairment

INTERNATIONAL JOURNAL OF PURE AND APPLIED RESEARCH IN ENGINEERING AND TECHNOLOGY

Monitoring and ensuring WLAN performance

Observer Analysis Advantages

A Research Study on Packet Sniffing Tool TCPDUMP

Troubleshooting Guide Ascom i62 VoWiFi Handset

AT&T activearc unified IP data solution

Beyond Monitoring Root-Cause Analysis

Agilent Technologies Performing Pre-VoIP Network Assessments. Application Note 1402

EAGLE EYE Wi-Fi. 1. Introduction

Analysis and Simulation of VoIP LAN vs. WAN WLAN vs. WWAN

White paper. Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points.

Eliminating the cost and complexity of hardware controllers with cloud-based centralized management

This document describes how the Meraki Cloud Controller system enables the construction of large-scale, cost-effective wireless networks.

ICTTEN5168A Design and implement an enterprise voice over internet protocol and a unified communications network

Comparing Mobile VPN Technologies WHITE PAPER

Observer Analyzer Provides In-Depth Management

How To Manage A Wireless Network With Avaya Wlan 9100 Series (Wlan) System (Wos)

Configuring QoS in a Wireless Environment

TamoSoft Throughput Test

Evaluating Wireless Broadband Gateways for Deployment by Service Provider Customers

The Wireless Network Road Trip

Measuring the Performance of VoIP over Wireless LAN

White Paper: Troubleshooting Remote Site Networks Best Practices

Detecting Threats in Network Security by Analyzing Network Packets using Wireshark

Multichannel Virtual Access Points for Seamless Handoffs in IEEE Wireless Networks

Cost-effective Wireless Alternatives to Corporate Leased-line Connectivity. White Paper

Overview to the Cisco Mobility Services Architecture

Monitoring and Managing Voice over Internet Protocol (VoIP)

Cisco CCNP Optimizing Converged Cisco Networks (ONT)

Modeling and Simulation of Quality of Service in VoIP Wireless LAN

Transcription:

Why Packets Matter Capturing Packets and Solving WLAN Issues (Why, How, Where, When) Jay Botelho Director of Product Management, Savvius jbotelho@savvius.com Follow me @jaybotelho IT Professional Wi-Fi Trek 2015

Synopsis Packet analysis shouldn t be a last resort. It should be an integral part of any WLAN analysis procedure.

IT Professional Wi-Fi Trek 2015 Why?

Why a Packet Analyzer? 802.11 is the language of Wi-Fi 802.11 is a complex protocol strong foundation but many, many layers Unlike wired networks, an inefficient physical layer (Layer 1) leads to protocol issues that require packet analysis Interpreting 802.11 packets captures requires experience and a good understanding of the 802.11 protocol

But Don t Just Take It From Me What s in Your Wi-Fi Tool Box? Spectrum Analyzer Protocol Analyzer (packet analyzer or sniffer) Site Survey George Stefanick In Wi-Fi since early 2000s Numerous certifications Wireless Architect for a large healthcare system managing 25,000+ Wi-Fi Clients Consultant Cisco VIP 2012, 2013, 2014 Aruba MVP 2014 Blog www.my80211.com http://www.informationweek.com/interop/whats-in-your-wi-fi-tool-box/d/d-id/1113592

What Can You Address with a Protocol Analyzer? Wi-Fi is not authenticating. Wi-Fi is slow. Wi-Fi is dropping connections. Wi-Fi doesn t work Wi-Fi is unreliable.

Critical Elements of a Protocol Analyzer High fidelity, high-speed packet capture Multi-channel analysis Long-term packet storage Visualization Analysis modules High-quality decodes

IT Professional Wi-Fi Trek 2015 How? Where?

Packet Capture Requires a Point-of-Presence

But Don t Confuse Portable with Point-of-Presence Portable, but not the only way, and maybe not the best way, to be present

802.11ac vs. Portable Packet Capture 1,733Mbps vs. 433Mbps 866Mbps vs. What happened to my ping data?

Remote Point-of-Presence As wireless approaches wired speeds, it s time to start relying on the wire Distributed analysis using deployed assets typically APs is the only effective solution as wireless capabilities and speeds grow The choices: Custom Remote Adapters Remote PCAP Remote sensors

Custom Remote Adapters Specific to Savvius and OmniPeek Allow an AP to be put into promiscuous mode and act like a direct-connected sniffing device APs are reconfigured via the AP controller software Depending on the manufacturer and the model, APs may or may not be able to continue sending traffic

Remote Pcap A WinPcap feature that allows interaction with a remote machine to capture packets Simply start a capture on the analyzer and point it to the available RPCAP interfaces Typically not a marketed feature Devices we have worked with include: Aerohive: Model HiveAP 120 Ruckus: ZoneFlex 7363 (requires ZoneDirector Controller)

Example Mission-Critical Financial Trading All users on Wi-Fi; BYOD 100 s of simultaneous users 100 s of trades per second Deliver, verify that each individual gets the same QOS to guarantee fair trading Single appliance solution 24x7 forensics data capture with additional real-time captures to handle spot problems

150 feet High Density/Small Physical Footprint Deployment Dense deployment 28 APs per trading floor Sensor APs 2 groups of 3 Provides dedicated, 24x7 monitoring 300 feet

150 feet Highly Distributed, Multi-Campus Deployment Dense deployment ~ 28 APs per building floor 100 s of building floors Reactive capture and analysis 300 feet

IT Professional Wi-Fi Trek 2015 When?

Solving Problems with Packets Verifying device capabilities Network capabilities look at beacons Client capabilities look at probe requests Verifying device configuration QoS enabled/disabled Beacon intervals too long/short CTS frames that look like duration attacks (10,000ms duration field) Troubleshooting connection/authentication issues Identifying sources of poor VoFi quality Identifying network bottlenecks Chatty clients Probe requests Inefficient network utilization Wireless is slow Analyzing roaming issues Sticky clients Roaming latency

When? Examples IT Professional Wi-Fi Trek 2015

Verifying Device Capabilities Network Capabilities - Beacons

Verifying Device Capabilities Client Capabilities Probe Requests

Verifying Device Configuration QoS

Verifying Device Configuration Beacon Intervals

Verifying Device Configuration CTS Excessive Duration

Troubleshooting Connection/Authentication Issues Authentication EAPOL Key Exchange The AP sends a nonce key to the STA The STA sends its own nonce key to the AP with a Key MIC The AP sends the key data with another MIC The STA sends a confirmation to the AP

Identifying Sources of Poor VoFi Quality RTP packets (G.711) Overall VoIP analysis Jitter, packet loss, latency

Identifying Network Bottlenecks Chatty/probing clients, i.e. phones Inefficient network utilization Wireless is slow

Chatty Clients Device On Unassociated Larger frames, low data rate, fewer packets ~250msec/frame Associated Smaller frames, higher data rate, more packets ~1msec/frame http://www.sniffwifi.com/2012/04/phones-on-wlan.html

Inefficient Network Utilization Probe response Pure HT mode No protection should be used (no RTS/CTS) http://www.sniffwifi.com/2014/05/why-are-you-slowing-down-my-wifi-apple.html Data transmission Some HT clients still using protection Unnecessary mgmt packets @ 24Mbps diminish WLAN efficiency

Wireless Is Slow - Retransmissions

Analyzing Roaming Issues Sticky clients Clients make poor roaming decisions Look for: signal strength and lower-than-expected data rates Roaming latency Criteria for determining latency depends on your perspective

Summary Packet analysis is an essential part of any wireless engineer s toolkit In many cases packets are the ONLY way to determine the root cause of an issue Packet analysis doesn t always involve just looking at the packets themselves Don t assume portable, in-person analysis is your only choice

Thank You! Savvius, Inc. 1340 Treat Boulevard, Suite 500 Walnut Creek, CA 94597 (925) 937-3200 IT Professional Wi-Fi Trek 2015