Subscribe to our RSS Feeds
Hello, this is a sample text to show how you can display a short information about you and or your blog. You can use this space to display text or image introduction or to display 468 x 60 ads and to maximize your earnings.
Showing posts with label Wireless network interface. Show all posts
Showing posts with label Wireless network interface. Show all posts

Tuesday, September 14, 2010

Top 10 basic wireless security practices

Wireless security is a hot topic these days, and different advice abounds. Here's a short checklist to make sure you have the basics covered:

  1. Use vendor-supplied security -- Since the capabilities of each wireless router/access point/bridge differ from brand to brand, it's best to get the vendor's recommendation on the best security options for their devices


  2. Change the default admin password of your wireless router/access point/bridge -- Once a potential attacker detects a wireless network, this is one of the easiest ways to further compromise it.


  3. Turn down the power -- Some vendor's wireless router/access point/bridge's offer the option of changing the power settings so that your wireless network is not broadcasting its signal farther than you really need it to.


  4. Use Media Access Control (MAC) address filtering and Wired Equivalent Privacy (WEP) -- MAC address filtering will help restrict access to your home wireless network to only those users you authorize. If WEP is the only security option available on your wireless router/access point/bridge, use a key that is hard to guess and change it periodically.


  5. Consult the vendor about antenna positioning -- Different antennas radiate signal in different patterns. Check your vendor's documentation to verify optimal antenna positioning for your wireless network.

And Protection Firewall or Viruses

  1. Change SSID and, if possible, disable SSID broadcast -- Your wireless router/access point/bridge may come with a default SSID already configured. Change it as soon as you set up your wireless network. Also, some vendor's may offer the option of not broadcasting this network identifier.

  2. Keep your wireless router/access point/bridge firmware up to date -- New firmware can help resolve compatibility problems, plug security holes and provide other important fixes. Check the vendor's Web site for these updates.


  3. Use a VPN for working at home -- For enterprise users working at home, always check with your enterprise IT department or help desk for best practices regarding accessing the company network over your wireless home network. Often, virtual private network (VPN) software is required for this purpose.


  4. Keep your antivirus software up to date -- Viruses, worms and Trojans are a continuous threat. Make sure your wireless network is not a haven for these problems.


  5. Use a firewall -- Either a hardware or software firewall can help protect your computer and the rest of your network from attack.

Monday, September 13, 2010

Design Structured Cabling Systems and IT wireless Network Infrastructures

Introduction

Designing a Structured Cabling System - a ten step HOWTO guide

Steps

Below we have provided a ten step introductory guide for the Design of Structured Cabling Systems and IT Network Infrastructures. (see structured cabling schematic)

Step 1: Which group of standards will you conform to?

European Union CENELEC EN standards America ANSI/TIA/EIA standards Canada CSA standards Australia/New Zealand AS/NZ standards Rest of the World ISO/IEC standards

The three principle design standards give the details of how to design and specify a structured cabling standard, they are;

ISO 11801
EN 50173
TIA/EIA 568-A or 568-B

BICSI


These standards in turn however refer to hundreds of other standards relating to component specifications, fire performance, testing methods, containment systems etc.

Step 2: Horizontal cabling - Basic rules

Four-pair cables are run from user positions to a patch panel. At the patch panel, patchcords link into the active LAN equipment or into backbone cabling. The user position has a wall outlet or floor outlet, and this links into the PC on your desk via another patchcord. The outlet is a called a TO (Telecommunications Outlet) and contains an eight way plug meeting IEC 60603-7, more commonly referred to as an RJ-45.

  • Two outlets per work area
  • Two outlets per 10 square metres of useable floor space
  • Outlets to be within 3 metres of the user station
  • Both outlets to be RJ 45
  • Max cable run to be 90 m
  • Max total length of patchcords at both ends of the link to be 10 m
  • Cable and RJ45 to be Cat5e grade

Options

Cat 3 or optical fibre can be used

If optical fibre, select 50/125 or 62.5/125 multimode

If using fibre select SC or ST connectors

Cat 6/Class E can be specified

Cat 5e Cable can be unscreened, UTP, Foil screened, FTP, or Foil and Braid screened S-FTP.

Cable fire performance can be:

  1. IEC 332-1
  2. IEC 332-1, IEC 754, IEC 1034
  3. IEC 332-3-c. IEC 754, IEC 1034
  4. UL 910 plenum

Each grade, in ascending order, has a better performance in fire situations but at a correspondingly higher price.

The exact density of cables, number of outlets and their position is up to the end user, or else at the proposal of the installer/designer

Step 3: Backbone Cabling

All of the horizontal cables are star-wired back to Telecommunications Closets or Floor Distributors where they are terminated in patch panels. These patch panels are connected together via the building backbone cabling which can be up to 500 metres long. It can be copper cable but is more likely to be optical fibre, either multimode or singlemode. The kind of cables and the number of cores needs to be decided.If fibre is chosen, a loss budget should help you make your decision

Step 4: Campus Cabling

The campus cabling links different buildings together. It can be up to 1500 m long. It can be copper cable but is more likely to be optical fibre, either multimode or singlemode. The kind of cables and the number of cores needs to be decided.

Step 5: Positioning and design of Telecommunications Closets to link horizontal and backbone cabling.

Positioning and design of the equipment room as a central focus for the main computing, LAN and PABX equipment.

Positioning and design of the Service Entrance facility whereby outdoor cables are terminated and the point of demarcation between customer owned equipment and the PTT cables is defined.

Step 6: Cable containment system

How will the cables be protected? Within buildings the choices are:

  • Cable trays
  • wire basket/raceway
  • cable ladders
  • J hooks
  • conduit
  • dado rails
  • PVC trunking
  • built-in underfloor duct
  • raised floors
  • suspended ceilings

The following must be taken into account:

  • the density and volume of cables to be organised
  • the aesthetic appearance of the cabling within offices and other visible areas
  • economics of different schemes
  • proximity to power cables and other potential sources of interference
  • firestopping

Useful standards are:

  • TIA/EIA 569 Commercial building standard for telecommunications pathways and spaces
  • EN 50174 Information technology – cabling installation

For external applications the choices are:

  • underground cable ducts
  • direct buried cable trench
  • concrete cable trough
  • self supporting aerial cable
  • supported aerial cable, i.e. catenary or messenger wire
  • fixed to building exteriors

In all cases the designer must ensure that all civils work has been carried out, rights of way established and availability of cable ducts and manholes established. Aerial cable routes must keep a minimum distance away from power cables and all external cables must be selected for the environment and temperature ranges in which they are expected to survive. External copper cables usually need to be protected by overvoltage and fault current devices where they enter a building.

Step 7: Cable Administration system

The cabling and its containment system need to be clearly identified and their locations, routes and capabilities recorded in a cable administration system. This usually involves a logical numbering scheme that can be applied to all cables, outlets, patch panels and even containment systems. Various colour schemes are also available.

These schemes can be paper based but for the larger installations then a computer based system is advisable. There are several proprietary solutions on the market which offer various database and graphical methods for keeping track of cabling assets. Some systems are also active in that they can detect moves and changes and automatically update the database.

Useful standards are:

  • TIA/EIA-606 Administration standard for the telecommunications infrastructure of commercial buildings
  • EN 50174 Information technology – cabling installation

Step 8: Earthing Scheme

All exposed metallic elements of the cable system and cable containment system need to be earthed (grounded) for safety and also electromagnetic compatibility requirements. If screened cables are used then special attention must be given to effective bonding of the screening elements. Poorly earthed screened cabling may behave worse than unscreened cabling.

An electrically ‘clean’ earth must be available at all points where the cabling is terminated, but especially within telecommunication closets, equipment rooms and service entrances. A clean earth is usually defined as a conductive element with not more than 1 volt rms potential difference between it and the real earth down below. Copper cabling linking two different buildings can suffer from earth loops if the ground potential is different. Non-metallic optical cabling is usually picked for problem areas such as these.

Some useful standards are:

  • PrEN50303 Application of equipotential bonding and earthing at premises with information technology equipment
  • PrEN50174-2 Information Technology, Cabling installation, part 2, Installation, planning and practices inside buildings
  • TIA/EIA-607 Commercial Building Grounding and Bonding Requirements for Telecommunications

Step 9: Testing regime

All cables must be tested to demonstrate compliance with the standards and specification to which they were bought. Testing can be split into copper cable testing and optical fibre testing. Ideally all cables should be 100% tested.

Copper cables.

There are five manufacturers of hand held copper cable testers that will automatically test the installed cable plant for all the expected parameters. By the use of a remote injector, the cabling is tested from both ends, which is a condition of the standards. The cabling has to pass all of the suite of tests to be awarded and overall pass. Points to remember are;

What is being tested? the channel (i.e. end-to-end including all the patchcords) or the basic link (i.e. the permanently installed cable from outlet to patchpanel). The test figures are different for each setting. It is usually more practical to test the basic link (also referred to as the permanent link).

What level is being tested? The tester should normally be set to Cat5e link or Class E link if Category 6 cable is being used.

The results are stored electronically and must be in a format recognisable by the cable management software that comes with the tester. There are now numerous test standards and draft standards. The most influential is likely to be;

IEC 61935 Generic specification for the testing of balanced generic cabling in accordance with ISO/IEC 11801

The tests required are; IEC 61935 Wire Map X Attenuation X; NEXT pair to pair X; NEXT Powersum X; ELFEXT air to pair X; ELFEXT Powersum X; Return Loss X; Propagation Delay X; Delay Skew X;DC Loop Resistance X. Cable length and ACR are also useful additions to this set of tests.

Optical cables

All that needs to be tested with short distance multimode optical cables is attenuation. This can be achieved by a device called a light source and power meter. This device will simply measure the absolute loss across the optical link. This then has to be compared with the design value of attenuation. If the tested value is less than the design value then the link can be seen to be acceptable.

Optical Time Domain Reflectometers can give a great deal of information about optical fibres, but for short haul multimode fibre they are an expensive overkill that gives results that need expert interpretation. An OTDR remains an essential tool for fault finding.

Step 10: Final thoughts

Is the design of the cabling system in-step with the LAN aspirations of the end user? For example, Cat5e is the minimum performance grade suitable for gigabit Ethernet. Standard Cat5 cable may not have sufficient delay skew performance for RGB video systems however. Cat 6 cabling will give a longer service life due to its higher performance, but at an initial higher cost.

Some optical fibre LANs, e.g. gigabit Ethernet cannot transmit over the full distance allowed in standards based optical structured cabling. These LAN limitations have to be taken into account. The next generation of 10 gigabit Ethernet will need a new generation of optical fibre to make it work.

The best way to ensure success in a structured cabling installation is to use properly trained people to design, implement and test the system. The RCDD qualification from BICSI is the only qualification which covers all aspects of structured cabling design and implementation.

The above information is offered as a summary of ISO 11801 and related standards. It is not a definitive design guide and does not replace study and implementation of the Standards themselves. The publisher accepts no responsibility for inaccuracies or omissions. To purchase the full Standards go to your national standards body, e.g. British Standards Institution, Nederlands Normalisatie Instituut etc. or ISO.



Wireless Network Management

Wireless Network Management refers to use of software tools designed to enhance performance, reliability and security of wireless networks particularly by diagnosing, detecting and reducing sources of radio frequency interference. Unlike in case of wired networks, where the redundancy of the equipment can be applied to mitigate the impact of performance problems and network failures to some extent, the wireless networking have a very limited options owing to availability of very limited wireless spectrum and the effects of wireless interference.

The factors that can have impact on the wireless network performance include traffic flows, working of the network topologies and network protocols, hardware, software and also, the environmental conditions. Therefore, often the Wireless users can be subjected to problems such as lack of coverage, intermittent discontinuity and difficult to monitor security aspects.

Wireless Network Management systems help to ensure network availability, as well as to provide other maintenance tasks, such as performance monitoring, testing, and fault management.

Some of the tools for Wireless Network management are Colubris MultiService Access Points (Maps), Airwave Management Platform (AMP) and Wireless Management Suite, wireless network management spectrum analysis software from Cognio Inc., Radio IP MTG, Cisco’s suite of Wireless Network management products etc.

Friday, September 10, 2010

Wireless Network and Router Security Tips

Reminded by the latest Cisco security alert, many network managers do not realize that their routers can be the jump point to attack. Router operating systems are just as vulnerable to hacker mischief as network operating systems. Most medium to small sized companies do not employ router engineers, or outsource this function on a need to do basic. And because of this, network administrators, and managers, either do not know enough to secure the router or do not have time. Listed below are the 10 basic router security tips.

1. Update your router's OS. Just like network operating systems, router operating systems need to be updated to correct programming oversights, flaws, and buffer overflow issues. Always check with your router manufacture for current updates and OS versions.

2. Change the default password. As much as 80 % of security incidents are caused by weak or default passwords, (This is according to CERT at Carnegie Mellon University) Avoid using common passwords and use mixed case letters as a stronger password policy .

3. Disable HTTP configuration and SNMP. The HTTP configuration part of your router may be easier to configure for a busy network admin, but it is also a security problem for routers. If your router has a command line configuration, disable the HTTP config mode and use it. If you are not using SNMP on your router, then there is no need to have it enabled. Cisco has a SNMP vulnerability with GRE tunnel attacks.

4. Block ICMP ping requests. Ping and other ICMP functions are useful tools for both the network admin and the hacker. ICMP enabled on your router can be used by hacker to identify information to target your network for attack.

5. Disable Telnet use from the Internet. In most cases you do not need an active telnet session from an Internet interface. Access to your router's configuration is more secure if accessed internally.

6. Disable IP directed broadcast. IP directed broadcast can allow Denial of Service (DOS) attacks on your equipment. A router's memory and CPU can be maxed out from too many requests, which can result in a buffer overflow entry.

7. Disable IP source routing and IP redirects. Redirects allow packets to come in from one interface and leave by another. You don't want engineered packets to redirect to a private internal network.

8. Packet filtering. Packet filtering routes only the types of packet you want to enter your network. Many companies only allow 80 (http) and 110/25 (email). Additionally you can block and allow IP Addresses and Ranges.

9. Review Security Logs. By simply taking the time to review your log files you will see obvious patterns of attack, and or even vulnerabilities. You will be surprised to how much activity your router is subject to.

10. Unnecessary Services. Unnecessary services should always be disable, whether they are on a router, server, or workstation. By default, Cisco devices up through IOS version 11.3 offer the "small services": echo, chargen, and discard. These services, especially their UDP versions, are infrequently used for legitimate purposes, but can be used to launch denial of service and other attacks that would otherwise be prevented by packet filtering.

Top 10 things to know about network administration

If you're just getting started in the networking field, you've got a lot to learn, and with the rate of changes in networking technology, you can expect to always have a lot to learn, but here are ten essential topics that you should concentrate on (and if you are not just getting started, here are some things to review):

  1. The OSI model: Memorize it. It's almost a cliché, but understanding it is critical.
  2. TCP/IP concepts: Learn to think in binary and get a firm grasp on bitmasks, subnetting, gateways (like the "default gateway") and how addresses are constructed (the network portion, the host portion, etc).
  3. Stacks: Read about how the network stack is implemented on hosts. Get a good feel for what each component (the NIC, firmware, device drivers, the OS, etc) is responsible for. Once you understand this, troubleshooting is easy.
  4. Layer 2: Learn how switches operate and how they're different from hubs and routers. Understand bridging, and get a general idea of what Spanning Tree Protocol does. Learn the difference between a collision domain and a broadcast domain, and then study VLANs.
  5. Routing: Learn a routing protocol. Start with RIP, because it's easy. You don't need to be a guru, just get a general idea about how routers can exchange information about the network.
  6. Services: Understand the role of DNS and DHCP and WINS and know their alternatives, like the host and lmhost files and static addressing.
  7. Find yourself some good networking reference material. Whatis.com is a great for deciphering arcane acronyms.
  8. Security: Read a little about how firewalls operate and other security technologies like VPNs. Understand the difference between authentication, authorization and accounting.
  9. Output: Learn how to get status and information out of your networking devices. A good place to start is with the "show" commands (which will be featured in next week's tip).
  10. Finally, do a walkthrough: follow data as it goes from one application to another. How does it get from the application, to being segmented, packetized, framed, and routed? How does your computer know what IP address to send the packet to? (DNS) How does it know what MAC address to send it to? (ARP) How does it know how big to make the frame? (MTU) How does a switch know which port to forward your packet out on? (FDB) How does a router know which interface to use? (routing table) If you can answer these questions, you're well on your way to being competent and productive.

WLAN Modes of Operation

The Anritsu MT8860C is the only WLAN Test Set with Network and Direct modes for testing WLAN devices conforming to IEEE 802.11 standards.

The MT8860C is an integrated one-box test set dedicated to testing 802.11 WLAN devices. It provides a high-speed measurement solution that is suitable for both production testing and design proving.

The MT8860C replaces existing test systems that typically require power meters, spectrum analyzers, and Gold Radios with external attenuators. The result is a test instrument with faster integration into production, offers a universal solution for all WLAN chip sets, and is simpler to maintain and calibrate. The MT8860C also reduces test system costs, increases production throughput, and delivers the most flexible WLAN testing available.

The MT8860C has two modes of operation: Network and Direct. The "Network" mode uses standard WLAN signaling and can be used for testing both the transmitter and receiver of DUTs. In "Direct" mode, the MT8860C tests DUT receivers by generating and transmitting WLAN packets, and tests DUT transmitters with its built-in transmitter analyzer. In Direct mode, the DUT must be controlled by the test mode software utility from the chipset vendor. The user interface is implemented through the supplied LANLook software package. LANLook runs on a standard PC and uses a conventional Windows®, based interface for both instrument configuration and results displays in clear numerical and graphical formats. LANLook communicates with the MT8860C using remote commands that are sent via a GPIB or Ethernet interface.

Features
  • Integrated test set for validating the RF performance of WLAN devices operating in the 2.4 GHz and 5 GHz frequency bands
  • 'Network' mode – tests devices in a connection using standard WLAN signalling.
  • 'Direct' mode – tests WLAN devices with the support of control software from the chipset vendor
  • Built-in reference radio for calibrated Packet Error Rate (PER) measurements
  • Automatic assignment of DUT IP address using built-in DHCP server
  • Built-in TX Analyzer
  • Shorter test system design times
  • High-speed transmitter measurements including power bust, spectral mask and modulation accuracy (EVM)
  • Dedicated WLAN signal generator for 802.11b/g/a
  • Supports GPIB and Ethernet remote interfaces
  • LANLook software for instrument configuration and results display
  • CombiTest software for automated production test requirements


Advantages and Disadvantages of WLANs ( Wireless / Wifi )

WLANs have advantages and disadvantages when compared with wired LANs. A WLAN will make it simple to add or move workstations and to install access points to provide connectivity in areas where it is difficult to lay cable. Temporary or semipermanent buildings that are in range of an access point can be wirelessly connected to a LAN to give these buildings connectivity. Where computer labs are used in schools, the computers (laptops) could be put on a mobile cart and wheeled from classroom to classroom, provided they are in range of access points. Wired network points would be needed for each of the access points. A WLAN has some specific advantages:

  • It is easier to add or move workstations.

  • It is easier to provide connectivity in areas where it is difficult to lay cable.

  • Installation is fast and easy, and it can eliminate the need to pull cable through walls and ceilings.

  • Access to the network can be from anywhere within range of an access point.

  • Portable or semipermanent buildings can be connected using a WLAN.

  • Although the initial investment required for WLAN hardware can be similar to the cost of wired LAN hardware, installation expenses can be significantly lower.

  • When a facility is located on more than one site (such as on two sides of a road), a directional antenna can be used to avoid digging trenches under roads to connect the sites.

  • In historic buildings where traditional cabling would compromise the façade, a WLAN can avoid the need to drill holes in walls.

  • Long-term cost benefits can be found in dynamic environments requiring frequent moves and changes.


WLANs also have some disadvantages:



Thursday, August 19, 2010

Wireless Routers

A wireless Glossary Link router is simply a router with a wireless interface and incorporates the utilities of a wireless access point. It is generally used to permit access to the Internet or a local computer network without the necessity for a wired connection. It can work in a cabled Glossary Link LAN (local area network), only wireless network, or a combination of both.

Characteristics of Wireless Router

  1. LAN ports - They work exactly similar to the ports on a network switch
  2. WAN port - It connects to WAN (wider area network)
  3. Wireless antennae – The antennae allows the router to link up with other wireless devices for communication
A wireless router could be a regular Glossary Link IP router with an 802.11 interface card and antenna added, or it could be a router specifically designed for wireless use. Most wireless routers also act as firewalls, switches, and provide Network Address Translation (NAT).

If network speed is important to you, be sure to purchase an 802.11a or 802.11g wireless router. If you are comfortable with 11Mbps then save money by purchasing an older 802.11b wireless router. If you need to increase the range of your wireless router, consider upgrading it with a better wireless antenna.

In the 802.11 Wi-Fi era, most people refer to wireless routers as "Access Points". Few foremost wireless router manufacturers are Buffalo Technology, D-Link, Linksys, Netgear, 3Com, TP-Link and Belkin.

Saturday, August 14, 2010

Wireless Interference

Interference is an issue with any form of radio communication, and a wireless network is no exception. The potential for interference is especially great indoors, where different types of building materials (concrete, wood, drywall, metal, glass and so on) can absorb or reflect radio waves, affecting the strength and consistency of a wireless network's signal. Similarly, devices like microwave ovens and some cordless phones can cause interference because they operate in the same 2.4 frequency range as 802.11b/g/n networks. You can't avoid interference entirely, but in most cases it's not significant enough to affect the usability of the network. When it does, you can usually minimize the interference by relocating wireless networking hardware or using specialized antennas.next..