Mesh Networking: Building Infrastructure Support Services G E O R G E J. S ILO WA SH ( KC3AAD), MSIA, CISSP -ISSMP, G CFE



Similar documents
An in-depth look at mesh networking using repurposed WiFi equipment in FCC Part 97 Amateur Radio spectrum.

Introduction to Broadband- Hamnet TM Mesh Networks (HSMM-MESH TM ) Steve King KE6WEZ Joe Partlow W6JWP October 2014

HSMM-MESHTM / Broadband-HamnetTM. Presented by Don Hill, KE6BXT and Joe Ayers, AE6XE. The Orange County Mesh Organization

Mesh Networking and the Broadband-Hamnet

NEW AND IMPROVED! INSTALLING an IRC Server (Internet Relay Chat) on your WRT54G,GS,GL Version 1.02 April 2 nd, Rusty Haddock/AE5AE

*** Release Notes for Broadband-Hamnet *** (Please Read and Consider Updating Soon)

Amateur Radio Intranet When All Else Fails. FRRL Program March 2014 AH6EZ

Cisco Unified IP Conference Phone 8831 Installation

BBHN Mesh Network Client Handbook for Emergency Responders

Hands-on MESH Network Exercise Workbook

Powerful Dedicated Servers

DT01 WiFi/3G VoIP PBX / ATA User Manual

out of this world guide to: POWERFUL DEDICATED SERVERS

Business VoIP Solution Training 04/2009

Quick Installation Guide For Mac users

EZCast 5GHz. Rev ! Quick Start Guide. Introduction

Datasheet. Enterprise VoIP Phone with Touchscreen. Models: UVP, UVP-Pro, UVP-Executive. High-Definition, Multi-Touch Color Display

Linksys WAP300N. User Guide

CT LANforge WiFIRE Chromebook a/b/g/n WiFi Traffic Generator with 128 Virtual STA Interfaces

112 Linton House Union Street London SE1 0LH T: F:

Quick Installation Guide-For MAC users

UBIQUITI BRIDGE CONFIGURATION PROCEDURE (PowerStation & NanoStation Units ONLY)

Using a Wireless Bridge to Provide Remote Network Connectivity

Quick Installation Guide

Installation Guide. Wireless N Access Point EAP110/EAP120/EAP220

WINNEBAGO COUNTY INFORMATION TECHNOLOGY STANDARDS 2014/2015

Datasheet. Enterprise VoIP Phone with Touchscreen. Tel: +44 (0) Fax: +44 (0)

AP60. 9 Wireless. Wireless-b/g/n Long Range PoE Access Point. Wireless-b/g/n Long Range Radio. Passive PoE and 4-LAN Ports. IP Finder Management 4 LAN

Networking. Introduction. Types of Wireless Networks. A Build-It-Ourselves Guide to Wireless Mesh Networks

WISE-4000 Series. WISE IoT Wireless I/O Modules

are easy to use PAP/MSCHAP Hotspot areas Wi Fi combines: hotspot services. scalability. enhancement achieving 3703 access points.

What the student will need:

802.11n Wireless Router. Datasheet. Models: AR, AR-HP. Fast Wireless Speed Up to 150 Mbps. Long Range Up to 200+ Meters

Installing Virtual Coordinator (VC) in Linux Systems that use RPM (Red Hat, Fedora, CentOS) Document # 15807A1-103 Date: Aug 06, 2012

AirMax g High Powered Outdoor CPE. PoE. Simple All-In-One Solution. Long Distance Radio. Clear. 10dBi

+32 (491)

Delivering Voice, Video, Data & Mobility to SMBs

Quick Installation Guide

AC Wireless Dual Band Gigabit Router. Highlights

RSSI LED IP-67. Virtual. HTTPS WISP Bridge

CONNECTING THE RASPBERRY PI TO A NETWORK

USER MANUAL. PingBrother EPIW104 managed passive poe switch & IP watchdog

Wireless Internet. Is an system to provide connectivity to customers to the Internet. Service Provider (WISP) TECHNICAL INFO.

What is Bitdefender BOX?

Cisco WAP200E Wireless-G Exterior Access Point: PoE Cisco Small Business Access Points

High Speed Multi Media Mesh Networking Using Commercial Off the Shelf Equipment. John Clements WB5SAL Corpus Christi

Remote Control Your HF Rig via the Internet. By Alfred T Yerger II WA2EHI

Frequently Asked Questions

P-2612HNU-Fx n ADSL2+ VoIP IAD DEFAULT LOGIN DETAILS. Firmware V3.00 Edition 1, 1/2010. Password: 1234 User Name: admin Password: 1234

vyacht Wifi Router vyacht yacht automation About this manual

WIRELESS INTERNET TROUBLESHOOTING GUIDE Help Desk

Cisco 7940 How To. (c) Bicom Systems

AC Touch Screen Wi-Fi Gigabit Router. Highlights

Configuring the Edgewater 4550 for use with the Bluestone Hosted PBX

AC Wi-Fi Range Extender RE580D. Highlights

8/26/2007. Network Monitor Analysis Preformed for Home National Bank. Paul F Bergetz

Setting Up the Cisco Unified IP Phone

Wireless Multi-Mode AP Router. AP Only. WDS Repeater. WDS Only. Adapter WAN. Port LAN LAN

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5

Machine-to-Machine Management System. Datasheet. Models: mport, mport-s, mpower, mpower Mini, mpower Pro, mfi-cs, mfi-ds, mfi-ths, mfi-msc, mfi-msw

Vertex VoIP Caller ID (Version 1.5)

300Mbps Wireless N VoIP VDSL/ADSL Modem Router

AC Wireless Tri-Band Gigabit Router. Highlights

WiFi Anywhere. Multi Carrier 3G/4G WiFi Router. IntraTec Solutions Ltd

WBS210/WBS510 Datasheet

Hardware Installation Guide HotPoint 5100 Access Point

WiFi hardware Vendors, Choices & Procurement Sebastian Büttrich, wire.less.dk edit: March

V660. Quick Start Guide. Dual-Mode Phone. Version /2007 Edition 1. Copyright All rights reserved

Securing your Linksys WRT54G

Connecting your Aiki phone to a network

Required Ports and Protocols. Communication Direction Protocol and Port Purpose Enterprise Controller Port 443, then Port Port 8005

5GHz 300Mbps 13dBi Outdoor CPE

Remote Monitoring Unit SC8100. Monitoring Unit SC8100

AC Wireless Dual Band Gigabit Router. Highlights

GETTING TO KNOW YOUR TELSTRA PRE-PAID 3G WI-FI

Cisco WIP310 Wireless-G IP Phone Cisco Small Business IP Phones

First of all Let's look at how you would connect your laptop via Ethernet, as it is the easier of the two methods.

CT LANforge-FIRE VoIP Call Generator

New DuraFon-SIP Long-Range Cordless Phone System. Presented by Walter Navarro

Linksys Voice over IP Products Guide: SIP CPE for Massive Scale Deployment

The 3CXIPPBX Tutorial

Nokia Call Connect v1.1 for Cisco User s Guide. Part Number: N Rev 003 Issue 1

1.1 Overview of the ChromeLab Components

AC 750. Wireless Dual Band Router. Highlights

Unified Office Gateway UMG-1000

IP Phone Configuration and Troubleshooting Guide

Front LEDs... 2 Rear Ports... 3 BASIC INSTALLATION... 4 Connecting Your Router... 5 Network Configuration... 6

VoIP 101: An introduction to the basics of Voice over Internet Protocol. How to guide

Implementing Cisco Collaboration Devices CICD v1.0; 5 Days; Instructor-led

Oracle Enterprise Manager Ops Center. Ports and Protocols. Ports and Protocols 12c Release 3 ( )

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-PRO, UAP-AC UAP-Outdoor, UAP-Outdoor5

VoIP Survivor s s Guide

Datasheet n Wireless Router Models: AR, AR-HP. Fast 150 Mbps Wireless Speed. Long Range Up to 200+ Meters

IP PBX. SD Card Slot. FXO Ports. PBX WAN port. FXO Ports LED, RED means online

Avaya IP Office 9.1. Set Up Guide for The IP Office Anywhere Demo Platform

How to setup a remote control of a radio across the mesh. Items needed:

WASP User Manual. Revision: 1.6. (c) 2012 North Pole Engineering, Inc.

How To Use 1Bay 1Bay From Awn.Net On A Pc Or Mac Or Ipad (For Pc Or Ipa) With A Network Box (For Mac) With An Ipad Or Ipod (For Ipad) With The

airmax Wireless Broadband CPE Datasheet Models: AG-HP-2G16, AG-HP-2G20, AG-HP-5G23, AG-HP-5G27 High Performance, Long Range Integrated InnerFeed CPE

GXP line SIP Enterprise Phone Quick Installation Guide

Transcription:

Mesh Networking: Building Infrastructure Support Services G E O R G E J. S ILO WA SH ( KC3AAD), MSIA, CISSP -ISSMP, G CFE J AY SCHALL (KB3NSJ)

Disclaimer I, George J. Silowash, am here today in my private capacity and not my official capacity. My statements express my personal views, observations, and not those of my employer. This presentation contains recommendations. The software and/or hardware presented is believed to be current as of November 2014. The presenter cannot be held liable for the performance of any product, service, or configuration mentioned in this presentation. You are encouraged to do research before implementing any solution. Your mileage may vary. Void where prohibited.

George J. Silowash, KC3AAD Father of two Master Of Science in Information Assurance / Security Certified Information Systems Security Professional (CISSP) Information Systems Security Management Professional (ISSMP) My security thinking gets in the way of some things, bare with me. GIAC Certified Forensic Examiner (GCFE) Think of CSI, but better Information Systems Consultant Adjunct Professor at Norwich University and Harrisburg University Ham radio enthusiast Big fan of open source solutions: If I can find a way to make it free or as cheap as possible, I will do it This seems to fit most ham radio junkies. I am not a network engineer, nor do I play one on TV. I try things, break things, and do my best to understand the technology

Jay Schall, KB3NSJ Blames broken things on George WEARS President Helps George spend money on toys

What is WEARS? Westmoreland Emergency Amateur Radio Service Part of Marguerite Volunteer Fire Department (Station 33) We are Command Post 600 (CP600) Provide Emergency Communications for Township / public service events

Agenda Building a Mesh Node CP600 Infrastructure Westmoreland County Airshow 2014 Lessons from the Battlefield Future Work Show & Tell, Demos CP600 Tour

Building a Mesh Node

What is a Mesh Node? Broadband-Hamnet, formerly HSMM-Mesh A high speed, self discovering, self configuring, fault tolerant, wireless computer network that can run for days from a fully charged car battery, or indefinitely with the addition of a modest solar array or other supplemental power source. The focus is on emergency communications. [1] [1] http://www.broadband-hamnet.org/

What Hardware Can Be Used? Linksys WRT54G Series Routers Version 4.0 or lower 5.0 or higher is not compatible WRT54G, WRT54GL, WRT54GS Read this document: http://www.broadband-hamnet.org/images/hsmm_docs/wrt54shop.pdf Great for localized networking and testing Ubiquity Rocket M2, Bullet M2 HP, AirGrid M2 HP, NanoStation Loco M2 (NSL-M2), NanoStation M2 (NS-M2) http://www.broadband-hamnet.org/section-blog/37-hardware-faqs/101-supportedhardware.html

Build Essentials Decide if you are going to use it outdoors, indoors, or both. Outdoors: Need weather resistant case Home Depot has a nice selection in electrical department Decide how you will power the equipment Battery / Solar Nuclear (aka the power grid) Decide what you want your node to do This drives what other stuff you may want to place with the node

Things You Should Have on Hand Power Injectors Several types Very useful Images from http://www.amazon.com

Things You Should Have on Hand (cont.) 12 Volt to 5 Volt Transformers (Great for Raspberry Pi Power) Images from http://www.amazon.com

Things You Should Have on Hand (cont.) 2.1mm x 5.5mm Male & Female power jacks (CCTV power) Assortment of 12volt and 5 volt power adapters with various ampere outputs USB Cables Assortment ( Micro, Regular, Mini, Male/Female extenders) Network Cables Fuses, switches, lights, PCB etching materials Patience and willingness to learn. Remember, I break things. Images from http://www.amazon.com

Building a Node- Lessons Learned Watch your voltage and polarity I fried a 12v to 5v transformer Silicone is your friend when weather proofing Minimize component exposure and water entry points Always think about how you will keep water out Keep in mind where you might place a node Remote power on/off Batteries are heavy PoE Injectors are awesome!

CP600 Infrastructure

CP600 Infrastructure Services Web Server Voice over Internet Protocol (VoIP) Chat FTP Web Cams General WiFi

Current State of the Network

What s Under the Hood?: Hardware Intel Atom Dual-Core D2500 1.86GHz processor 4GB RAM 120GB SSD Hard Drive Grandstream Phones (2 Line Phones) Various IP Camera Cisco Managed Switch TP-Link Dual WAN Router Rebadged Linksys Routers Ubiquity Bullets M2 HP TP-Link Antennas (Directional & Omni) Ubiquity AirGrid 2.4GHz & 5GHz (for Internet pilfering )

What s Under the Hood: Software PBX in a Flash (VoIP): http://pbxinaflash.net/ CentOS Rock Solid Linux Distribution Built for Enterprise use Apache Web Server Filezilla Server (FTP) Runs on Windows Laptop

How to Build It Some Linux knowledge is highly recommended Google is your friend Webmin (GUI) helps for most administrative tasks Recommend a minimum dual core Atom Processor system 4GB RAM 120GB SSD Burn ISO of PBX in a Flash, boot from it, and follow the install instructions Apache is installed by default

How to Build (cont.) Openfire Chat: XMPP (Jabber) protocol If you are using PBX in a Flash: www.pbxinaflash.org/piaf6/docs/install-openfire.pdf Can be configured to allow self registration Openfire was chosen due to logging capability Logs or it didn t happen. Emergency response should have all activities logged Clients: Any XMPP capable client HIGHLY recommend Spark: http://www.igniterealtime.org/downloads/index.jsp

How to Build it (cont.) Windows Workstation Really? Yes, really. Linux FTP server is a pain to get working (still haven t figured it out) Install Filezilla server DONE! Need to create a virtual web server in Apache to handle web requests to any other port that is not port 80. Recommend port 8080 Can do this in Webmin Point the following ports at your server: 21 TCP (FTP), 5060 UDP (VoIP), 8080 TCP (Web Done by placing link on your node s page)

Considerations Do I need all this power? How many VoIP calls could possibly be needed at any moment? Do I need a VoIP server? Maybe not. Do you need voicemail? Comes in handy if you are running emergency response / central command Could program phone with one VoIP provider to enable you to dial out. PBX in a Flash may be overkill for needs. Provides voicemail and many advanced features. Incredible PBX for Raspberry Pi may be for you Can dial by IP address Publish a directory of IP addresses (phonebook) in a text file on webserver

Considerations (continued) Can I use any VoIP phone? Yes, as long as it is SIP capable. May want to consider VoIP adapters to use POTS phones. POTS phone are likely to be more available during an emergency situation Some Cisco phones may not work without a special flavor of the firmware on the phone HIGHLY recommend Grandstream. Inexpensive, $60 for 5, 2 line phones on ebay Easy to program PoE Available on some models

General Considerations I am not an attorney Only licensed operators may use the equipment as you are likely exceeding FCC Part 15 You cannot use encryption Everything you do is in the clear text You can authenticate users though

Challenges & Solutions Network Access Control Problem: Wireless access points issue IPs to anyone. Mesh firmware has no provisions to limit this. Solution: Incompatible Access Points can be used. Set to Access Point only mode Disable DHCP Use wired connection to configure Lock wireless down to trusted devices by MAC address Follow a standard naming convention: eg: KC3AAD-100-AP

Challenges & Solutions (cont.) Centralized Services = Centralized Failure Single point of failure Distribute services across nodes One piece of equipment running multiple services can stress it Consider dedicating one or two services per server Have backup hardware & software configurations Hot-Hot Hardware Cold Spares Designate primary and secondary nodes for duplicate services One service goes down, can transfer to another node with services Configuration Management is going to be needed

Westmoreland County Airshow 2014 NOT E S FROM T HE BAT T LEFIELD

Latrobe Airport (LBE)

= Mesh Node = CP600 http://maps.bing.com

Lessons Learned Parabolic Dish Antennas are REALLY directional. Do not send a Linksys router to do a man s job. Ubiquity gear rocks! If you are using 2.4GHz back hauls in a crowd of 50,000+ people with Smartphones beaconing, you re going to have a bad time. Get your antennas up high Use parabolic antennas aimed at omni-directional antennas for better performance. Consider adding nodes in low coverage areas.

Pro Tip: Tether your gear! Tripod + High Gust Winds Tethers = Broken Gear

Lessons Learned (continued) Link quality is key when pushing video. You can never have enough 12 volt batteries. Have a Business Continuity Plan (BCP) / Disaster Recovery Plan (DR) If it can fail, it will. Diesel generator failure Have multiple methods of communication Dedicated Simplex frequencies and a repeater were great Instant messaging / chat / FTP can be a big help in an emergency

Future Work

What s Next? Redesign some components of CP600 Network Possibly move to a Windows System 3CX Free Edition VoIP System Filezilla FTP Server Westmoreland County Mesh Network Develop Standards, Policies, Documentation Create Go Box Self Contained Nodes Set and forget Give to anyone assisting in emergency

What s Next? (cont.) RF maps of public places to assist in emergency response Field testing on-site of nodes where we may be called to Lots to do!

Contact Information George J. Silowash KC3AAD kc3aad@wc3ps.org http://www.wc3ps.org

Contact Information Jay Schall KB3NSJ kb3nsj@comcast.net http://www.wc3ps.org