Rolf Leutert. Network Expert & Trainer Leutert NetServices Switzerland. Analyzing WLAN Roaming Problems. 1 2012 Leutert NetServices



Similar documents
IEEE 802 Protocol Layers. IEEE Wireless LAN Standard. Protocol Architecture. Protocol Architecture. Separation of LLC and MAC.

Lab Exercise Objective. Requirements. Step 1: Fetch a Trace

Wireless LAN Protocol CS 571 Fall Kenneth L. Calvert All rights reserved

Wireless LAN Pen-Testing. Part I

IEEE Technical Tutorial. Introduction. IEEE Architecture

Section 1 Wireless Packet Captures & Connection Analysis- A Review

Basic processes in IEEE networks

Optimizing Wireless Networks.

visual packet analysis

Protection Ripple in ERP WLANs White Paper

The Wireless Network Road Trip

Avaya WLAN Orchestration System

A Technical Tutorial on the IEEE Protocol

Wireless LAN g USB Adapter

AirPcap User s Guide. May 2013

IEEE WIRELESS LAN STANDARD

Wireless Tools. Training materials for wireless trainers

How To Understand The Power Of A Network On A Microsoft Ipa 2.5 (Ipa) (Ipam) (Networking) 2 (Ipom) 2(2

Markku Renfors. Partly based on student presentation by: Lukasz Kondrad Tomasz Augustynowicz Jaroslaw Lacki Jakub Jakubiak

Avaya WLAN Orchestration System

How To Manage A Wireless Network With Avaya Wlan 9100 Series (Wlan) System (Wos)

visual packet analysis

Universiti Teknologi MARA MAC Layer Sniffer Using Spoof Detection Algorithm

Wireless Local Area Networks (WLANs)

WUA Mbps Wireless USB Network Adapter

CS 356 Lecture 29 Wireless Security. Spring 2013

AirWave Help Desk Guide. Help Desk Guide: Troubleshooting WLAN Issues with AirWave. 2006, AirWave Wireless, Inc. All rights reserved.

Monitoring and ensuring WLAN performance

IEEE Wireless LAN Standard. Updated: 5/10/2011

Wireshark Lab: v6.0

A6210 WiFi USB Adapter ac USB 3.0 Dual Band User Manual

A Short Look on Power Saving Mechanisms in the Wireless LAN Standard Draft IEEE

Configuration Notes Trapeze Networks Infrastructure in Ascom VoWiFi System

Wireless Network Analysis. Complete Network Monitoring and Analysis for a/b/g/n

Wiereless LAN

Access Point Configuration

Enterprise IT Solutions (Hardware, Software, Services) Shared Services and Outsourcing Technology Products Distribution and Trading

LevelOne User Manual WPC-0600 N_One Wireless CardBus Adapter

Troubleshooting WLAN Issues

Wireshark Lab:

CSMA/CA. Information Networks p. 1

Wireshark Hands-On Exercises

Observer Analyzer Provides In-Depth Management

Getting Started with HP Wireless Networks. Version 10.41

Tutorial on Network Management and Measurements. Tasos Alexandridis

Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 6. Wireless Network Security

Chapter 7 Low-Speed Wireless Local Area Networks

White paper. Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points.

Recommended Wireless Local Area Network Architecture

WLAN w Technology

Wireless g CF Card User Manual

12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust

Setting up of a Wireless Distribution System (WDS)

N600 WiFi USB Adapter

WI-FI TECHNOLOGY: SECURITY ISSUES

Discovering IPv6 with Wireshark. presented by Rolf Leutert

Site Survey and RF Design Validation

Troubleshooting Wireless Clients Version 1.1

Help Desk Guide. Enterprise Troubleshooting WLAN Issues with AirWave Wireless Management Suite

Wireless LAN advantages. Wireless LAN. Wireless LAN disadvantages. Wireless LAN disadvantages WLAN:

Department of Computer Science Columbia University

Top 10 Security Checklist for SOHO Wireless LANs

IEEE a/ac/n/b/g Enterprise Access Points ECW5320 ECWO5320. Management Guide. Software Release v

Document ID: Contents. Introduction. Prerequisites. Requirements. Components Used. Related Products. Conventions. 802.

WAP3205 v2. User s Guide. Quick Start Guide. Wireless N300 Access Point. Default Login Details. Version 1.00 Edition 2, 10/2015

NWA1120 Series. User s Guide. Quick Start Guide. Wireless LAN Ceiling Mountable PoE Access Point. Default Login Details

WRE2205. User s Guide. Quick Start Guide. Wireless N300 Range Extender. Default Login Details. Version 1.00 Edition 1, 06/2012

Lab - Using Wireshark to View Network Traffic

Useful CLI Commands. Contents. Enable Logging

Microsoft Lync Certification Configuration Guide for WiNG 5.5

What s Really Happening on Your Wireless Network Multi-Channel Analysis for WLAN Mobility

Wireless Ethernet LAN (WLAN) General a/802.11b/802.11g FAQ

Networking: Certified Wireless Network Administrator Wi Fi Engineering CWNA

WRE6505. User s Guide. Quick Start Guide. Wireless AC750 Range Extender. Default Login Details. Version 1.00 Edition 1,

Attenuation (amplitude of the wave loses strength thereby the signal power) Refraction Reflection Shadowing Scattering Diffraction

Wireless-N Range Extender. User Manual

Welch Allyn Connex, VitalsLink by Cerner, and Connex CSK Network installation. Best practices overview

Top 10 Security Checklist for SOHO Wireless LANs

Enhancing the Security of Corporate Wi-Fi Networks Using DAIR. Example : Rogue AP. Challenges in Building an Enterprise-scale WiFi Monitoring System

WL-5460AP. User s Manual. 54Mbps Multi-Function Wireless AP. AirLive WL-5460AP v2 User Manual

HP ac Wireless Client Bridge Configuration and Administration Guide

ADDENDUM 12 TO APPENDIX 8 TO SCHEDULE 3.3

How To Do a Successful RF Site Survey. Overview

Overview of Networks and Standards

Table of Contents. Product Overview...5

White Paper. Wireless Network Considerations for Mobile Collaboration

WLAN Positioning Technology White Paper

NXC5500/2500. Application Note w Management Frame Protection. ZyXEL NXC Application Notes. Version 4.20 Edition 2, 02/2015

N300 Wireless Router WNR2000v4 User Manual

Troubleshooting Problems Affecting Radio Frequency Communication

Virtual Access Points

Enterprise A Closer Look at Wireless Intrusion Detection:

Wireless Security. New Standards for Encryption and Authentication. Ann Geyer

How To Secure Wireless Networks

EETS 8316 Wireless Networks Fall 2013

WildPackets Guide to Wireless LAN Analysis

Transcription:

Rolf Leutert Network Expert & Trainer Leutert NetServices Switzerland Analyzing WLAN Roaming Problems 1 2012 Leutert NetServices

Case Study Customer is a large retail store chain in Switzerland Sales areas are covered with WLANs for inventory management Customer reported sporadic hang ups of bar code scanners Scanner recovers after delays up to minutes back to normal Application is mission critical for logistic purposes Finger pointing between scanner vendor and WLAN deployer Customer is stuck between a rock and a hard place, since month! Task: Analyze WLAN and investigate the source(s) of problems 2 2012 Leutert NetServices

Case Study Situation facts: WLANs working in A-Band (5 GHz) WLANs encrypted with WPA2 enterprise WPA2 decryption keys are not available Tools used: Wireshark with three AirPcap Nx Adapters WiSpy DBx for frequency analysis Three AirPcap Nx combined Case demonstrates WLAN troubleshooting with even encrypted data 3 2012 Leutert NetServices

Possible causes for the hung up problem: Radio gaps in WLAN covering Radio interferences from other devices Overloaded WLAN cells Roaming problem Settings / defects on Access Points Settings / defects on Mobile Clients Application or handling problems Frequency analysis with WiSpy (MetaGeek) 4 2012 Leutert NetServices

Setup your Wireshark with: Choose 802.11+ Radio for 802.11 A/B/G Choose 802.11+ PPI for 802.11 N (Per-Packet Information) This will add a Radio Tap Header to each frame with radio values Add columns to display values Colors will improve orientation 5 2012 Leutert NetServices

Management Frames: Beacon Probe request and response Authentication Deauthentication Association request and response Reassociation request and response Disassociation Ad-hoc-Networks only: Announcement Traffic Indication Message (ATIM) 6 2012 Leutert NetServices

Control Frames: Request to Send (RTS) Clear to Send (CTS) Acknowledge Power Save Poll Only for PCF-Mode: Contention Free End (CF-End) Contention Free End + Acknowledge (CF-End+CF-ACK) 7 2012 Leutert NetServices

Data Frames: Data Null Function Only for PCF-Mode: Data + CF-Ack Data + CF-Poll Data + CF-Ack + CF-Poll CF-Ack (no data) CF-Poll (no data) CF-Ack + CF-Poll (no data) 8 2012 Leutert NetServices

Sta2 AP FC Dur. BSS ID SA DA MAC AP MAC Sta1 MAC Sta2 Seq. PDU Sta1 To Distribution System DA SA Type MAC Sta2 MAC Sta1 PDU Ethernet Frame Ethernet Frame DA SA Type MAC Sta1 MAC Sta2 PDU DA BSS ID SA FC Dur. MAC Sta1 MAC AP MAC Sta2 Seq. PDU Sta1 From Distribution System AP Sta2 9 2012 Leutert NetServices

Sta2 AP FC Dur. BSS ID SA DA MAC AP MAC Sta1 MAC Sta2 Seq. PDU Sta1 Data Frame RA FC Dur. MAC Sta1 FCS AP Sta1 Acknowledgement 10 2012 Leutert NetServices

11 2012 Leutert NetServices

The position of your Wireshark analyzer is relevant for analysis! Where should you capture? If you suspect a single cell problem, stay near the Access Point If you suspect a roaming problem, move with the Mobile Client Use Beacon S/N ratio to define your position in relation to APs Signal to Noise (S/N) ratio should be 20 db Sometimes, a graphic tells us more than a thousand frames 12 2012 Leutert NetServices

AP a9:37:80 Channel A48 AP a9:3b:c0 Channel A40 AP a9:3c:60 Channel A36 AP a9:38:40 Channel A36 S/N ratio of four Access Points 13 2012 Leutert NetServices

Lets check to which Access Points our Mobile Client is associated at the beginning of the trace file at the end of the trace file 14 2012 Leutert NetServices

AP a9:37:80 Channel A48 1. Client associated AP a9:3b:c0 Channel A40 Wireshark with three AirPcaps Mobile Client fb:c4:57 2. Client roaming AP a9:3c:60 Channel A36 AP a9:38:40 Channel A36 + 15 2012 Leutert NetServices

Mobile Client fb:c4:57 Click on graph to jump to frame AP a9:3b:c0 Channel A40 AP a9:3c:60 Channel A36 S/N ratio of two Access Points and mobile client 16 2012 Leutert NetServices

17 2012 Leutert NetServices

Findings: Last frame seen before hang up: Request ID No reaction from the client at this point After 30 sec the client is deauthenticated by AP Important question: Did the frame arrive at client? If YES Client should reply with: Response ID If NO AP should retransmit the Request ID Can we tell if the Request ID has arrived at the client? Yes we can! Have a closer look at the trace file and you will find the answer! (Hint be careful with display filter) 18 2012 Leutert NetServices

: The Solution In WLAN, all frames correctly received are acknowledged! The client does acknowledge the reception of Request ID in frame 5651 The client should now process the request and reply with a Response ID A bug in the client firmware caused this sporadic misbehavior The client vendor provided an upgrade and the problem was solved! 19 2012 Leutert NetServices

Thanks for visiting SeaPics.com Hope you learned something useful Rolf Leutert, Leutert NetServices, www.wireshark.ch 20 2012 Leutert NetServices