Pages

Banner 468

Showing posts with label Cisco IOS Firewall Design. Show all posts
Showing posts with label Cisco IOS Firewall Design. Show all posts
Sunday, 2 February 2014

10 tips for boosting your wireless router signal

3 comments
 
10 tips for boosting your wireless router signal
When it comes to "boosting" wireless speeds, there are actually two enhancements users typically seek: Distance and speed. It's great having a speedy wireless network, but if you only get great speed when you use a wireless client right next to the router and get no signal if you are 15 feet away, then speed doesn't mean so much. You need to boost the signal's range. If your device can barely open friends' Facebook pictures when you're in the same room as the router, then we're talking about problems with speed.
In general, speed and range issues can all be lumped together as performance issues. You want both your speed and range to be as robust as possible. There are several factors that can impact both aspects of performance.
Distance can certainly impede performance. You may have a room in your home or office that is simply too far from your wireless router. Even the way your home or office is structured could be a culprit when it comes to poor wireless performance. If the signals have to bounce around too many corners to reach your wireless devices, that can cause problems (although a technology in newer premium routers called beamforming can help direct a router's signal to wireless clients).

Interference with the signal can be big factor in performance, too. If you live in an apartment building, your home might be inundated with signals from everyone else's routers. Maybe structural interference is the culprit. If your washing machine and dryer are between your router and your laptop, that doesn't help. Maybe it's the software you're using. Routers need software updates just like everything else – and sometimes the firmware they initially ship with is improved with a later-released update.
These are just a few of the possible reasons your connection might be poor (or non-existent). Fortunately, there are many ways to extend your wireless signal, and most of them simply involve a bit of tweaking to your wireless network or adding some affordable components. In this article, we’ll walk you through ten of the most useful fixes for your connectivity woes.
Some of these suggestions require no additional hardware or software to purchase, while others may require a small or larger investment, depending on the particular performance problem you're experiencing. We’ll start off with free solutions, then move through the cheap to more expensive improvements.

1. Change the channel (free)

Not the TV's channel, but your router's. Wi-Fi routers operate on specific channels. When you set up a typical router, it usually chooses a certain channel by default. Some routers choose the least-crowded channel, but yours may not have. Check for yourself which Wi-Fi channel is the least crowded to boost the router's performance, perhaps boosting signal range. A good free tool to use is inSSIDer. Don't be put off by the graphs and excess information. What you want to focus on is the column "Channel." See how many routers in this area are on channel 6 in the image above? If your router is on the same channel, you want to switch it to a less-crowded one, like 4 or 1. You can change the channel of your router by going into its interface. All routers have different ways to access the interface, so check with your manufacturer on this score.


2. Update router firmware (free)

Updating router firmware is often overlooked by home users. Business networking devices usually display some sort of notification when newer software for the device is available for download. Consumer products such as home wireless routers, especially older routers, don't always offer this notification. Check often for firmware updates for your router. There is typically a section in the router's interface for upgrading the firmware. However, you often have to go to the router manufacturer's website and search for the firmware (most vendors make searching for firmware pretty easy) and then upload it through the router's interface. There's often accompanying release notes that tell you what the firmware helps to fix – and often the fixes are for connectivity problems.


3. Update adapter firmware (free)

Just like routers, network adapters on PCs and laptops are also subject to firmware updates. Remember, good wireless range and performance is dictated not just by the router but by the network adapter on clients (as well as other factors, but these are the two biggies.) Most laptops have on-board adapters. Go into your Network settings to find the name of the adapter (via the Control Panel in Windows) and then to that adapter manufacturer's site to make sure you have the latest firmware.


4. Change position (free)

Do you have your wireless router nestled up against your broadband modem tucked away in your entertainment centre in your basement that's converted into the family den? Well, move it if you have range issues. It isn’t necessary to have the router in close proximity to your modem. Ideally, a Wi-Fi router should be in a central location. You can purchase custom length Ethernet Cat 5 cable from any computer store (although if you do that, technically this is no longer a free option) if you need more flexibility in centrally positioning the router.


5. DD-WRT (free)

This one is for the more adventurous: DD-WRT is open source software for routers. It's known to ramp up router performance and extend the feature set beyond what typically comes with most routers. Not every router supports it, but the number of routers that are supported keeps growing. A word of warning, though – installing DD-WRT could possibly invalidate your router's warranty. Many manufacturers will not help you troubleshoot router issues once you have DD-WRT on them. Hence, this is not a recommended option for routers under warranty or in a business network.
There are also no guarantees that DD-WRT upgrades won't negatively affect a router. However, many users are finding it a free way to trick-out their routers. So, if you have an older, spare router laying around, or want to take the plunge to see if DD-WRT firmware helps your range issues on a newer router, check if it's supported on the DD-WRT site. Also note that it's not easy to remove DD-WRT from some routers without doing a lot research.


6. Set up a second router as an access point or repeater (cheap)

You can set up just about any router as a wireless access point. To do so, you need to connect the second router's LAN port to the primary router's LAN port. On the second router, you will want to give it the same addressing information as the primary router. For example, if your primary router's IP address is 192.168.2.1 and its netmask is 255.255.255.0; then you could make the second router's IP 192.168.2.2 and use the same netmask. It's also important that you assign the same SSID and security on the second router, and turn DHCP off on the second one as well.
Newer routers make this process easier. If you have a second router that's only about a year old, most of them can be set to operate in "access point" or repeater mode. Configuring is as simple as clicking a button. Check with your router's manufacturer or documentation.


7. Antennas (cheap)

Newer routers are increasingly manufactured with internal antennas. There are some that still have or support external ones, and these antennas can often be upgraded. Consider a hi-gain antenna, which you can position so that the Wi-Fi signal goes in the direction you want. Hawking Technology offers the HAI15SC Hi-Gain Wireless Corner Antenna, which the company claims boosts wireless signal strength from a standard 2dBi to 15dBi. Antennas like these can attach to most routers that have external antenna connectors, and are relatively cheap upgrades.


8. Dedicated repeater/extender (more expensive)

Most major wireless networking vendors offer devices that act as repeaters or wireless extenders. While they can extend a Wi-Fi signal, they can be tricky to setup, and can cause interference with the signal. They can also be on the more expensive side. Note that if you choose this option the best bet is to use an access point made by the manufacturer of your router (see tip number 10 for further details).


9. New router/adapter (more expensive)

How about getting a new router and adapter(s) altogether? Upgrading your home network to one of the latest 802.11ac routers, or an 802.11n model using the 5GHz band should give a noticeable performance improvement. 2.4GHz is said to actually have greater range than the 5GHz band, but that only becomes apparent when supplying wireless coverage to large areas such as university campuses. In our testing, we’ve found that for smaller areas like a typical home network, 802.11n and the 5GHz band maintained better throughput than 2.4GHz with most routers, at greater distances. This is certainly a more expensive option, but if wireless connectivity is crucial for you, it's a plausible one. If you’re pondering an upgrade to an 802.11ac device, we’ve got a group test of seven such routers you might want to check out (our benchmarks here show the benefit of ac, and indeed the benefit of 5GHz over 2.4GHz). Bear in mind that if you get a new router, to take full advantage of the speeds possible you’ll need to update client adapters to the same standard as well.


10. Stick to a single vendor (more expensive)

Vendors are quick to point out that their devices will work with other vendor's products. But it just makes sense that Cisco network adapters will work better with Cisco routers; Belkin adapters work optimally with Belkin routers and so on. If possible, try to limit your network devices to one vendor – that means not only you


Readmore...
Friday, 9 August 2013

Cisco Network Troubleshooting

0 comments
 
As a Network Engineer, your primary goal is to make sure that your network equipment is operating properly at all times. But we all know that any equipment can break down. The reasons for this could be software inconsistencies, hardware malfunctions, maybe even environmental hazards.
Under such unpredictable conditions, your responsibility is to identify and isolate the cause of the malfunction and correct it as soon as you can. That’s why it is extremely helpful to know some specific techniques that have been proven to be crucial and essential in the networking world.
In today’s article I’ll present the most important commands that you will definitely find helpful and even mandatory throughout your networking career and specifically during network troubleshooting situations. The commands I am talking about, and which are truly invaluable, are:
  • Ping
  • Traceroute
  • Telnet
  • Show interfaces
  • Show ip interface
  • Show ip route
  • Show running-config
  • Show startup-config

The Ping Utility

The PING command operates on the Network layer and uses the services of the ICMP protocol. It is the first command that you should use at the beginning of your troubleshooting process.
With PING you can test whether a remote host is alive by transmitting echo request messages and receive echo replies from the specific host. Keep in mind that even if a host is alive, it does not mean that it is functioning properly, that is why PING is used at the beginning of your investigation and is the best command to start with.
I’ve covered PING extensively in one of my previous posts, so for more details on PING, check out: How to Troubleshoot Your Connections with Ping and Traceroute.
PING command has quite a lot of options from which you can greatly benefit. For example, you can choose to PING with different network protocols. Moreover, you are able to set the exact number of PING requests to be transmitted. You can also choose the length of data carried within the echo request packet (provided in bytes) and also specify whether fragmentation of this packet is allowed or not during transmission. The last two options in cooperation can be used to identify the lowest MTU value existing in the communication path.
On Cisco devices the simpler way to use the PING utility is to issue the command PING along with the IP address of the remote device:
Network Troubleshooting 1
For more advanced features, simply issue the PING command and follow the prompts from that point on:
Network Troubleshooting 2

The Traceroute Command

The TRACEROUTE command traces the end-to-end path a packet takes though an internetwork. Similarly with PING, it uses the ICMP protocol with TTL timeouts to perform its operation.
Again, for more details on this command see How to Troubleshoot Your Connections with Ping and Traceroute.
This command is very useful in identifying potential link bottlenecks throughout the transmission path. Here is a sample output of the TRACEROUTE command:
Network Troubleshooting 3


The Telnet Command

Use the telnet command to verify TCP stack and application layer software between source and destination stations. Of course, to be able to telnet on a Cisco device, the latter needs to be already configured to accept telnet connections. To use TELNET just issue the telnet command along with the IP address or hostname of the remote station:
Network Troubleshooting 4


The Show Interfaces Command

The show interfaces command presents all the available interfaces that can be configured on your Cisco device. You can explicitly use this command to show only details on a single interface by issuing the interfaces name after the show interfaces command. This command is very useful because it can reveal layer 1 and layer 2 problems. Moreover, this command provides details regarding the hardware address (MAC), IP address, encapsulation method and statistics concerning erroneous conditions on the specific interface. Examine the output of the show interface fastethernet 0:
Network Troubleshooting 5
The first line of the show interface command is the most important one. The first parameter refers to the physical layer, therefore
in this case FastEthernet 0 is up and operating. The second part of the line refers to the Data Link Layer; therefore here line protocol is up means that we have layer 2 connectivity as well. There are four possible outputs that you may come across:
  • FastEthernet0 is up, line protocol is up: Both the Physical and Data Link layers on the interface are functioning correctly.
  • FastEthernet0 is down, line protocol is down: This output indicates a physical interface problem. For example, the cable on this interface or on the remote interface is disconnected.
  • FastEthernet0 is up, line protocol is down: In this case, Physical layer is operational. The line protocol being down indicates a clocking or framing problem. Probable reasons for this are encapsulation and clock rate mismatches.
  • Ethernet0 is administratively down, line protocol is down: This output indicates that a local interface has been manually shut down using the shutdown command.

The Show IP Interface Command

The show ip interface command will provide details regarding layer 3 configuration on the interfaces. Using this command you can see the IP address and mask configured on a given interface, whether an access list is applied on the interface as well as basic
IP information.
Network Troubleshooting 6


The Show IP Route Command

Use the show ip route command to find detailed information regarding the routes configured on the router. Keep in mind that the router can only route packets to the networks listed in its routing table. It is possible that a router can not reach a network you manually configured therefore, that specific route is removed from its table and that is why you should use the show running configuration command in conjunction with show ip route to spot possible inconsistencies.
For more details on IP routing issues see my article on Default and Static Routing Basics.
Network Troubleshooting 7


Show Running-Config and Show Startup-Config Commands

Issue the show running configuration command to find out the whole configuration your Cisco devices use while operating. By looking at the details of your devices, configuration can help you identify the cause to your problem. Use the show startup configuration command to see the configuration commands that will be loaded to your device the next time it reboots and compare it with your running configuration in order to identify possible unconformities.
Network Troubleshooting 8


In the End … Follow Your Instincts

Isolating a network malfunction is not an easy task. In many cases you need to swim into really deep waters in order to identify the error. Meaning, that you will probably need to get into the bits and bytes in order to locate the error.
A lot of network monitor tools are available to help you during these difficult tasks. And although there’s a lot you can do, remember to never lose your courage; have patience and follow your gut.
Sometimes the problem that you’re searching for will be right in front of you and will slip out of your hands, just when you think you have it. So be persistent, be patient and remember: you will win the battle!
Be prepared; in order to fight well, you should be armed well. So get to know your device very well, know how it operates, and know how to use the basic troubleshooting commands – that you just learned – so that you can identify the problem, or at least estimate where the problem might be. Good luck!




More Related Posts

  1. Cisco ATA 180 Series Analog Phone Adapters
  2. IP Addressing and Routing Part 2: IP Routing Process
  3. Network+ Videos 8 and 9: Who Knew?
  4. How to Configure Routing Information Protocol: RIPv2
  5. How to Configure Interior Gateway Routing Protocol (IGRP)
Readmore...
Wednesday, 7 August 2013

types of computer network

0 comments
 

Ethernet Tutorial - Part I: Networking Basics

Computer networking has become an integral part of business today. Individuals, professionals and academics have also learned to rely on computer networks for capabilities such as electronic mail and access to remote databases for research and communication purposes. Networking has thus become an increasingly pervasive, worldwide reality because it is fast, efficient, reliable and effective. Just how all this information is transmitted, stored, categorized and accessed remains a mystery to the average computer user.
This tutorial will explain the basics of some of the most popular technologies used in networking, and will include the following:

Types of Networks

In describing the basics of networking technology, it will be helpful to explain the different types of networks in use.

Local Area Networks (LANs)

A network is any collection of independent computers that exchange information with each other over a shared communication medium. Local Area Networks or LANs are usually confined to a limited geographic area, such as a single building or a college campus. LANs can be small, linking as few as three computers, but can often link hundreds of computers used by thousands of people. The development of standard networking protocols and media has resulted in worldwide proliferation of LANs throughout business and educational organizations.

Wide Area Networks (WANs)

Often elements of a network are widely separated physically. Wide area networking combines multiple LANs that are geographically separate. This is accomplished by connecting the several LANs with dedicated leased lines such as a T1 or a T3, by dial-up phone lines (both synchronous and asynchronous), by satellite links and by data packet carrier services. WANs can be as simple as a modem and a remote access server for employees to dial into, or it can be as complex as hundreds of branch offices globally linked. Special routing protocols and filters minimize the expense of sending data over vast distances.

Wireless Local Area Networks (WLANs)

Wireless LANs, or WLANs, use radio frequency (RF) technology to transmit and receive data over the air. This minimizes the need for wired connections. WLANs give users mobility as they allow connection to a local area network without having to be physically connected by a cable. This freedom means users can access shared resources without looking for a place to plug in cables, provided that their terminals are mobile and within the designated network coverage area. With mobility, WLANs give flexibility and increased productivity, appealing to both entrepreneurs and to home users. WLANs may also enable network administrators to connect devices that may be physically difficult to reach with a cable.
The Institute for Electrical and Electronic Engineers (IEEE) developed the 802.11 specification for wireless LAN technology. 802.11 specifies over-the-air interface between a wireless client and a base station, or between two wireless clients. WLAN 802.11 standards also have security protocols that were developed to provide the same level of security as that of a wired LAN.
The first of these protocols is Wired Equivalent Privacy (WEP). WEP provides security by encrypting data sent over radio waves from end point to end point.
The second WLAN security protocol is Wi-Fi Protected Access (WPA). WPA was developed as an upgrade to the security features of WEP. It works with existing products that are WEP-enabled but provides two key improvements: improved data encryption through the temporal key integrity protocol (TKIP) which scrambles the keys using a hashing algorithm. It has means for integrity-checking to ensure that keys have not been tampered with. WPA also provides user authentication with the extensible authentication protocol (EAP).
Wireless Protocols
Specification Data Rate Modulation Scheme Security
802.11 1 or 2 Mbps in the 2.4 GHz band FHSS, DSSS WEP and WPA
802.11a 54 Mbps in the 5 GHz band OFDM WEP and WPA
802.11b/High Rate/Wi-Fi 11 Mbps (with a fallback to 5.5, 2, and 1 Mbps) in the 2.4 GHz band DSSS with CCK WEP and WPA
802.11g/Wi-Fi 54 Mbps in the 2.4 GHz band OFDM when above 20Mbps, DSSS with CCK when below 20Mbps WEP and WPA

The Internet and Beyond

More than just a technology, the Internet has become a way of life for many people, and it has spurred a revolution of sorts for both public and private sharing of information. The most popular source of information about almost anything, the Internet is used daily by technical and non-technical users alike.

The Internet:  The Largest Network of All

With the meteoric rise in demand for connectivity, the Internet has become a major communications highway for millions of users. It is a decentralized system of linked networks that are worldwide in scope. It facilitates data communication services such as remote log-in, file transfer, electronic mail, the World Wide Web and newsgroups. It consists of independent hosts of computers that can designate which Internet services to use and which of their local services to make available to the global community.
Initially restricted to military and academic institutions, the Internet now operates on a three-level hierarchy composed of backbone networks, mid-level networks and stub networks. It is a full-fledged conduit for any and all forms of information and commerce. Internet websites now provide personal, educational, political and economic resources to virtually any point on the planet.

Intranet:  A Secure Internet-like Network for Organizations

With advancements in browser-based software for the Internet, many private organizations have implemented intranets. An intranet is a private network utilizing Internet-type tools, but available only within that organization. For large organizations, an intranet provides easy access to corporate information for designated employees.

Extranet:  A Secure Means for Sharing Information with Partners

While an intranet is used to disseminate confidential information within a corporation, an extranet is commonly used by companies to share data in a secure fashion with their business partners. Internet-type tools are used by content providers to update the extranet. Encryption and user authentication means are provided to protect the information, and to ensure that designated people with the proper access privileges are allowed to view it.

Types of LAN Technology

Ethernet

Ethernet is the most popular physical layer LAN technology in use today. It defines the number of conductors that are required for a connection, the performance thresholds that can be expected, and provides the framework for data transmission. A standard Ethernet network can transmit data at a rate up to 10 Megabits per second (10 Mbps). Other LAN types include Token Ring, Fast Ethernet, Gigabit Ethernet, 10 Gigabit Ethernet, Fiber Distributed Data Interface (FDDI), Asynchronous Transfer Mode (ATM) and LocalTalk.
Ethernet is popular because it strikes a good balance between speed, cost and ease of installation. These benefits, combined with wide acceptance in the computer marketplace and the ability to support virtually all popular network protocols, make Ethernet an ideal networking technology for most computer users today.
The Institute for Electrical and Electronic Engineers developed an Ethernet standard known as IEEE Standard 802.3. This standard defines rules for configuring an Ethernet network and also specifies how the elements in an Ethernet network interact with one another. By adhering to the IEEE standard, network equipment and network protocols can communicate efficiently.

Fast Ethernet

The Fast Ethernet standard (IEEE 802.3u) has been established for Ethernet networks that need higher transmission speeds. This standard raises the Ethernet speed limit from 10 Mbps to 100 Mbps with only minimal changes to the existing cable structure. Fast Ethernet provides faster throughput for video, multimedia, graphics, Internet surfing and stronger error detection and correction.
There are three types of Fast Ethernet: 100BASE-TX for use with level 5 UTP cable; 100BASE-FX for use with fiber-optic cable; and 100BASE-T4 which utilizes an extra two wires for use with level 3 UTP cable. The 100BASE-TX standard has become the most popular due to its close compatibility with the 10BASE-T Ethernet standard.
Network managers who want to incorporate Fast Ethernet into an existing configuration are required to make many decisions. The number of users in each site on the network that need the higher throughput must be determined; which segments of the backbone need to be reconfigured specifically for 100BASE-T; plus what hardware is necessary in order to connect the 100BASE-T segments with existing 10BASE-T segments. Gigabit Ethernet is a future technology that promises a migration path beyond Fast Ethernet so the next generation of networks will support even higher data transfer speeds.

Gigabit Ethernet

Gigabit Ethernet was developed to meet the need for faster communication networks with applications such as multimedia and Voice over IP (VoIP). Also known as "gigabit-Ethernet-over-copper" or 1000Base-T, GigE is a version of Ethernet that runs at speeds 10 times faster than 100Base-T. It is defined in the IEEE 802.3 standard and is currently used as an enterprise backbone. Existing Ethernet LANs with 10 and 100 Mbps cards can feed into a Gigabit Ethernet backbone to interconnect high performance switches, routers and servers.
From the data link layer of the OSI model upward, the look and implementation of Gigabit Ethernet is identical to that of Ethernet. The most important differences between Gigabit Ethernet and Fast Ethernet include the additional support of full duplex operation in the MAC layer and the data rates.

10 Gigabit Ethernet

10 Gigabit Ethernet is the fastest and most recent of the Ethernet standards. IEEE 802.3ae defines a version of Ethernet with a nominal rate of 10Gbits/s that makes it 10 times faster than Gigabit Ethernet.
Unlike other Ethernet systems, 10 Gigabit Ethernet is based entirely on the use of optical fiber connections. This developing standard is moving away from a LAN design that broadcasts to all nodes, toward a system which includes some elements of wide area routing. As it is still very new, which of the standards will gain commercial acceptance has yet to be determined.

Asynchronous Transfer Mode (ATM)

ATM is a cell-based fast-packet communication technique that can support data-transfer rates from sub-T1 speeds to 10 Gbps. ATM achieves its high speeds in part by transmitting data in fixed-size cells and dispensing with error-correction protocols. It relies on the inherent integrity of digital lines to ensure data integrity.
ATM can be integrated into an existing network as needed without having to update the entire network. Its fixed-length cell-relay operation is the signaling technology of the future and offers more predictable performance than variable length frames. Networks are extremely versatile and an ATM network can connect points in a building, or across the country, and still be treated as a single network.

Power over Ethernet (PoE)

PoE is a solution in which an electrical current is run to networking hardware over the Ethernet Category 5 cable or higher. This solution does not require an extra AC power cord at the product location. This minimizes the amount of cable needed as well as eliminates the difficulties and cost of installing extra outlets.
LAN Technology Specifications
Name IEEE Standard Data Rate Media Type Maximum Distance
Ethernet 802.3 10 Mbps 10Base-T 100 meters
Fast Ethernet/
100Base-T
802.3u 100 Mbps 100Base-TX
100Base-FX
100 meters
2000 meters
Gigabit Ethernet/
GigE
802.3z 1000 Mbps 1000Base-T
1000Base-SX
1000Base-LX
100 meters
275/550 meters
550/5000 meters
10 Gigabit Ethernet IEEE 802.3ae 10 Gbps 10GBase-SR
10GBase-LX4
10GBase-LR/ER
10GBase-SW/LW/EW
300 meters
300m MMF/ 10km SMF
10km/40km
300m/10km/40km

Token Ring

Token Ring is another form of network configuration. It differs from Ethernet in that all messages are transferred in one direction along the ring at all times. Token Ring networks sequentially pass a “token” to each connected device. When the token arrives at a particular computer (or device), the recipient is allowed to transmit data onto the network. Since only one device may be transmitting at any given time, no data collisions occur. Access to the network is guaranteed, and time-sensitive applications can be supported. However, these benefits come at a price. Component costs are usually higher, and the networks themselves are considered to be more complex and difficult to implement. Various PC vendors have been proponents of Token Ring networks.

Networking and Ethernet Basics

Protocols

After a physical connection has been established, network protocols define the standards that allow computers to communicate. A protocol establishes the rules and encoding specifications for sending data. This defines how computers identify one another on a network, the form that the data should take in transit, and how this information is processed once it reaches its final destination. Protocols also define procedures for determining the type of error checking that will be used, the data compression method, if one is needed, how the sending device will indicate that it has finished sending a message, how the receiving device will indicate that it has received a message, and the handling of lost or damaged transmissions or "packets".
The main types of network protocols in use today are: TCP/IP (for UNIX, Windows NT, Windows 95 and other platforms); IPX (for Novell NetWare); DECnet (for networking Digital Equipment Corp. computers); AppleTalk (for Macintosh computers), and NetBIOS/NetBEUI (for LAN Manager and Windows NT networks).
Although each network protocol is different, they all share the same physical cabling. This common method of accessing the physical network allows multiple protocols to peacefully coexist over the network media, and allows the builder of a network to use common hardware for a variety of protocols. This concept is known as "protocol independence," which means that devices which are compatible at the physical and data link layers allow the user to run many different protocols over the same medium.

The Open System Interconnection Model

The Open System Interconnection (OSI) model specifies how dissimilar computing devices such as Network Interface Cards (NICs), bridges and routers exchange data over a network by offering a networking framework for implementing protocols in seven layers. Beginning at the application layer, control is passed from one layer to the next. The following describes the seven layers as defined by the OSI model, shown in the order they occur whenever a user transmits information.
Layer 7: Application
This layer supports the application and end-user processes. Within this layer, user privacy is considered and communication partners, service and constraints are all identified. File transfers, email, Telnet and FTP applications are all provided within this layer.
Layer 6: Presentation (Syntax)
Within this layer, information is translated back and forth between application and network formats.  This translation transforms the information into data the application layer and network recognize regardless of encryption and formatting.
Layer 5: Session
Within this layer, connections between applications are made, managed and terminated as needed to allow for data exchanges between applications at each end of a dialogue.
Layer 4: Transport
Complete data transfer is ensured as information is transferred transparently between systems in this layer. The transport layer also assures appropriate flow control and end-to-end error recovery.
Layer 3: Network
Using switching and routing technologies, this layer is responsible for creating virtual circuits to transmit information from node to node. Other functions include routing, forwarding, addressing, internetworking, error and congestion control, and packet sequencing.
Layer 2: Data Link
Information in data packets are encoded and decoded into bits within this layer. Errors from the physical layer flow control and frame synchronization are corrected here utilizing transmission protocol knowledge and management. This layer consists of two sub layers: the Media Access Control (MAC) layer, which controls the way networked computers gain access to data and transmit it, and the Logical Link Control (LLC) layer, which controls frame synchronization, flow control and error checking.
Layer 1: Physical
This layer enables hardware to send and receive data over a carrier such as cabling, a card or other physical means. It conveys the bitstream through the network at the electrical and mechanical level. Fast Ethernet, RS232, and ATM are all protocols with physical layer components.
This order is then reversed as information is received, so that the physical layer is the first and application layer is the final layer that information passes through.

Standard Ethernet Code

In order to understand standard Ethernet code, one must understand what each digit means. Following is a guide:
Guide to Ethernet Coding
10 at the beginning means the network operates at 10Mbps.
BASE means the type of signaling used is baseband.
2 or 5 at the end indicates the maximum cable length in meters.
T the end stands for twisted-pair cable.
X at the end stands for full duplex-capable cable.
FL at the end stands for fiber optic cable.
For example: 100BASE-TX indicates a Fast Ethernet connection (100 Mbps) that uses a
twisted pair cable capable of full-duplex transmissions.

Media

An important part of designing and installing an Ethernet is selecting the appropriate Ethernet medium. There are four major types of media in use today: Thickwire for 10BASE5 networks; thin coax for 10BASE2 networks; unshielded twisted pair (UTP) for 10BASE-T networks; and fiber optic for 10BASE-FL or Fiber-Optic Inter-Repeater Link (FOIRL) networks. This wide variety of media reflects the evolution of Ethernet and also points to the technology's flexibility. Thickwire was one of the first cabling systems used in Ethernet, but it was expensive and difficult to use. This evolved to thin coax, which is easier to work with and less expensive. It is important to note that each type of Ethernet, Fast Ethernet, Gigabit Ethernet, 10 Gigabit Ethernet, has its own preferred media types.
The most popular wiring schemes are 10BASE-T and 100BASE-TX, which use unshielded twisted pair (UTP) cable. This is similar to telephone cable and comes in a variety of grades, with each higher grade offering better performance. Level 5 cable is the highest, most expensive grade, offering support for transmission rates of up to 100 Mbps. Level 4 and level 3 cable are less expensive, but cannot support the same data throughput speeds; level 4 cable can support speeds of up to 20 Mbps; level 3 up to 16 Mbps. The 100BASE-T4 standard allows for support of 100 Mbps Ethernet over level 3 cables, but at the expense of adding another pair of wires (4 pair instead of the 2 pair used for 10BASE-T). For most users, this is an awkward scheme and therefore 100BASE-T4 has seen little popularity. Level 2 and level 1 cables are not used in the design of 10BASE-T networks.
For specialized applications, fiber-optic, or 10BASE-FL, Ethernet segments are popular. Fiber-optic cable is more expensive, but it is invaluable in situations where electronic emissions and environmental hazards are a concern. Fiber-optic cable is often used in inter-building applications to insulate networking equipment from electrical damage caused by lightning. Because it does not conduct electricity, fiber-optic cable can also be useful in areas where heavy electromagnetic interference is present, such as on a factory floor. The Ethernet standard allows for fiber-optic cable segments up to two kilometers long, making fiber-optic Ethernet perfect for connecting nodes and buildings that are otherwise not reachable with copper media.
Cable Grade Capabilities
Cable Name Makeup Frequency Support Data Rate Network Compatibility
Cat-5 4 twisted pairs of copper wire -- terminated by RJ45 connectors 100 MHz Up to 1000Mbps ATM, Token Ring,1000Base-T, 100Base-TX, 10Base-T
Cat-5e 4 twisted pairs of copper wire -- terminated by RJ45 connectors 100 MHz Up to 1000Mbps 10Base-T, 100Base-TX, 1000Base-T
Cat-6 4 twisted pairs of copper wire -- terminated by RJ45 connectors 250 MHz 1000Mbps 10Base-T, 100Base-TX, 1000Base-T

Topologies

Network topology is the geometric arrangement of nodes and cable links in a LAN. Two general configurations are used, bus and star. These two topologies define how nodes are connected to one another in a communication network. A node is an active device connected to the network, such as a computer or a printer. A node can also be a piece of networking equipment such as a hub, switch or a router.
A bus topology consists of nodes linked together in a series with each node connected to a long cable or bus. Many nodes can tap into the bus and begin communication with all other nodes on that cable segment. A break anywhere in the cable will usually cause the entire segment to be inoperable until the break is repaired. Examples of bus topology include 10BASE2 and 10BASE5.

Topology ExamplesGeneral Topology Configurations

10BASE-T Ethernet and Fast Ethernet use a star topology where access is controlled by a central computer. Generally a computer is located at one end of the segment, and the other end is terminated in central location with a hub or a switch. Because UTP is often run in conjunction with telephone cabling, this central location can be a telephone closet or other area where it is convenient to connect the UTP segment to a backbone. The primary advantage of this type of network is reliability, for if one of these 'point-to-point' segments has a break; it will only affect the two nodes on that link. Other computer users on the network continue to operate as if that segment were non-existent.

Collisions

Ethernet is a shared medium, so there are rules for sending packets of data to avoid conflicts and to protect data integrity. Nodes determine when the network is available for sending packets. It is possible that two or more nodes at different locations will attempt to send data at the same time. When this happens, a packet collision occurs.
Minimizing collisions is a crucial element in the design and operation of networks. Increased collisions are often the result of too many users on the network. This leads to competition for network bandwidth and can slow the performance of the network from the user's point of view. Segmenting the network is one way of reducing an overcrowded network, i.e., by dividing it into different pieces logically joined together with a bridge or switch.

CSMA/CD

In order to manage collisions Ethernet uses a protocol called Carrier Sense Multiple Access/Collision Detection (CSMA/CD). CSMA/CD is a type of contention protocol that defines how to respond when a collision is detected, or when two devices attempt to transmit packages simultaneously. Ethernet allows each device to send messages at any time without having to wait for network permission; thus, there is a high possibility that devices may try to send messages at the same time.
After detecting a collision, each device that was transmitting a packet delays a random amount of time before re-transmitting the packet. If another collision occurs, the device waits twice as long before trying to re-transmit.

Ethernet Products

The standards and technology just discussed will help define the specific products that network managers use to build Ethernet networks. The following presents the key products needed to build an Ethernet LAN.

Transceivers

Transceivers are also referred to as Medium Access Units (MAUs). They are used to connect nodes to the various Ethernet media. Most computers and network interface cards contain a built-in 10BASE-T or 10BASE2 transceiver which allows them to be connected directly to Ethernet without the need for an external transceiver.
Many Ethernet devices provide an attachment unit interface (AUI) connector to allow the user to connect to any type of medium via an external transceiver. The AUI connector consists of a 15-pin D-shell type connector, female on the computer side, male on the transceiver side.
For Fast Ethernet networks, a new interface called the MII (Media Independent Interface) was developed to offer a flexible way to support 100 Mbps connections. The MII is a popular way to connect 100BASE-FX links to copper-based Fast Ethernet devices.

Network Interface Cards

Network Interface Cards, commonly referred to as NICs, are used to connect a PC to a network. The NIC provides a physical connection between the networking cable and the computer's internal bus. Different computers have different bus architectures. PCI bus slots are most commonly found on 486/Pentium PCs and ISA expansion slots are commonly found on 386 and older PCs. NICs come in three basic varieties: 8-bit, 16-bit, and 32-bit. The larger the number of bits that can be transferred to the NIC, the faster the NIC can transfer data to the network cable. Most NICs are designed for a particular type of network, protocol, and medium, though some can serve multiple networks.
Many NIC adapters comply with plug-and-play specifications. On these systems, NICs are automatically configured without user intervention, while on non-plug-and-play systems, configuration is done manually through a set-up program and/or DIP switches.
Cards are available to support almost all networking standards. Fast Ethernet NICs are often 10/100 capable, and will automatically set to the appropriate speed. Gigabit Ethernet NICs are 10/100/1000 capable with auto negotiation depending on the user’s Ethernet speed. Full duplex networking is another option where a dedicated connection to a switch allows a NIC to operate at twice the speed.

Hubs/Repeaters

Hubs/repeaters are used to connect together two or more Ethernet segments of any type of medium. In larger designs, signal quality begins to deteriorate as segments exceed their maximum length. Hubs provide the signal amplification required to allow a segment to be extended a greater distance. A hub repeats any incoming signal to all ports.
Ethernet hubs are necessary in star topologies such as 10BASE-T. A multi-port twisted pair hub allows several point-to-point segments to be joined into one network. One end of the point-to-point link is attached to the hub and the other is attached to the computer. If the hub is attached to a backbone, then all computers at the end of the twisted pair segments can communicate with all the hosts on the backbone. The number and type of hubs in any one-collision domain is limited by the Ethernet rules. These repeater rules are discussed in more detail later.
A very important fact to note about hubs is that they only allow users to share Ethernet. A network of hubs/repeaters is termed a "shared Ethernet," meaning that all members of the network are contending for transmission of data onto a single network (collision domain). A hub/repeater propagates all electrical signals including the invalid ones. Therefore, if a collision or electrical interference occurs on one segment, repeaters make it appear on all others as well. This means that individual members of a shared network will only get a percentage of the available network bandwidth.
Basically, the number and type of hubs in any one collision domain for 10Mbps Ethernet is limited by the following rules:
Readmore...

Computer Networking Tutorial

0 comments
 

A Simple Network Structure




Above figure shows a simple network with three computers and a Printer. You can see that all devices are connected with network cables to a central network device called a Network Router. The printer in this network can be used by all the PCs. Also the figure show you how the Wireless network Works, the Notebook and the Computer connected with the wireless router by wireless adapters which equipped with them.
Network Stations: May be terminal, computers, telephones or other communication devices. They are also called HOST\END SYSTEMS. The hosts are connected to communication subnet or subnet. They carry messages from host and consist of switching elements and transmission lines. Transmission lines are also called CIRCUITS, CHANNELS, TRUNKS, move bits between the machines.
The switching elements are specialized computers used to connect two or more transmission lines. The purpose of the switching element is to choose outgoing line and forward the data arriving on an incoming line. All traffic to/from the host has to go via its IMP. They are also known as PACKET SWITCHING NODES, INTERMEDIATE SYSTEM OR DATA SWITCHING EXCHANGES.
Subnet is the collection of the communication lines and routers but not the host. The set of nods to which stations attached is the boundary of the communication network. The collection of routers and communication lines moves packets from source host to the destination host.
Network structure can be thought with
   - Data terminal equipment (DTE).
   - Data circuit terminating Equipment (DCE) concept.

Most digital data processing device have limited data transmission capacity and limited distance of data transmission. DTE is the end user machine, generally refers to (Devices) terminals and computers.
Example: Email terminal, workstation, ATM in a bank, sales terminal in a departmental store. They are not commonly connected directly to transmission medium.
DCE is used to connect the communication channel.
Example: modem. It interacts with DTE and provides an interface of DTE to communication network transmits and receive bits one at a time over the communication channel.
To specify the exact nature of interface between DTE and DCE various standards and protocols have been developed. DCEs and DTEs are connected in two ways. A high degree of cooperation is essential in DTE-DCE combination, as data and control information is to be exchanged. They can be connected in two ways
   - Point to point configuration: Here only two DTE devices are in the channel

   - Multidrop configuration: Here more than two devices are connected to the same communication channel.

 
This will provide the basic technology concepts required for understanding networking. The following are the lessons how we categorized Computer Network.
Browse Topics
 
Networking Basics
OSI Reference Model
Introduction to TCP/IP
LAN Basics
Understanding Switching
WAN Basics
Understanding Routing
What Is Layer 3 Switching?
Understanding Virtual LANs
Understanding Quality of Service
Security Basics
Understanding Virtual Private Networks
Voice Technology Basics
Network Management Basics The Internet
Readmore...

Using VLANs with Cisco Aironet Wireless Equipment

0 comments
 

Introduction

This document provides a sample configuration to use virtual LANs (VLANs) with Cisco Aironet wireless equipment.

Prerequisites

Requirements

Ensure that you meet these requirements before you attempt this configuration:
  • Familiarity with Cisco Aironet wireless equipment
  • Familiarity with LAN switching concepts of VLANs and VLAN trunking

Components Used

The information in this document is based on these software and hardware versions:
  • Cisco Aironet Access Points and Wireless Bridges
  • Cisco Catalyst Switches
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command.

Related Products

You can use the switch side of this configuration with any of these hardware or software:
  • Catalyst 6x00/5x00/4x00 that runs CatOS or IOS
  • Catalyst 35x0/37x0/29xx that runs IOS
  • Catalyst 2900XL/3500XL that runs IOS

Conventions

Refer to Cisco Technical Tips Conventions for more information on document conventions.

VLANs

A VLAN is a switched network that is logically segmented by functions, project teams, or applications rather than on a physical or geographical basis. For example, all workstations and servers used by a particular workgroup team can be connected to the same VLAN, regardless of their physical connections to the network or the fact that they can be intermingled with other teams. Use VLANs to reconfigure the network through software rather than physically unplug or move the devices or wires.
A VLAN can be thought of as a broadcast domain that exists within a defined set of switches. A VLAN consists of a number of end systems, either hosts or network equipment (such as bridges and routers), connected by a single bridging domain. The bridging domain is supported on various pieces of network equipment, such as LAN switches, that operate bridging protocols between them with a separate group for each VLAN.
When you connect a device to a Cisco Catalyst switch, the port where the device is connected is a member of VLAN 1. The MAC address of that device is a part of VLAN 1. You can define multiple VLANs on a single switch, and you can configure a switch port on most Catalyst models as a member of multiple VLANs.
/image/gif/paws/46141/16751.gif
When the number of ports in a network exceeds the port capacity of the switch, you must cross-connect multiple switch chassis, which defines a trunk. The trunk is not a member of any VLAN, but a conduit over which traffic passes for one or more VLANs.
In fundamental terms, the key in the configuration of an access point to connect to a specific VLAN is to configure its SSID to recognize that VLAN. Because VLANs are identified by a VLAN ID or name, it follows that, if the SSID on an access point is configured to recognize a specific VLAN ID or name, a connection to the VLAN is established. When this connection is made, associated wireless client devices that have the same SSID can access the VLAN through the access point. The VLAN processes data to and from the clients the same way that it processes data to and from wired connections. You can configure up to 16 SSIDs on your access point, so you can support up to 16 VLANs. You can assign only one SSID to a VLAN.
You extend VLANs into a wireless LAN when you add IEEE 802.11Q tag awareness to the access point. Frames destined for different VLANs are transmitted by the access point wirelessly on different SSIDs with different WEP keys. Only the clients associated with that VLAN receive those packets. Conversely, packets that come from a client associated with a certain VLAN are 802.11Q tagged before they are forwarded onto the wired network.
For example, employees and guests can access the wireless network of a company at the same time and be administratively separate. A VLAN maps to an SSID, and the wireless client attaches to the appropriate SSID. In networks with wireless bridges, you can pass multiple VLANs across the wireless link in order to provide connectivity to a VLAN from separate locations.
If 802.1q is configured on the FastEthernet interface of an access point, the access point always sends keepalives on VLAN1 even if VLAN 1 is not defined on the access point. As a result, the Ethernet switch connects to the access point and generates a warning message. There is no loss of function on either the access point or the switch, but the switch log contains meaningless messages that can cause more important messages to be wrapped and not seen.
This behavior creates a problem when all SSIDs on an access point are associated to mobility networks. If all SSIDs are associated to mobility networks, the Ethernet switch port to which the access point is connected can be configured as an access port. The access port is normally assigned to the native VLAN of the access point, which is not necessarily VLAN1. This causes the Ethernet switch to generate warning messages noting that traffic with an 802.1q tag is sent from the access point.
You can eliminate the excessive messages on the switch if you disable the keepalive function.
If you ignore minor points in these concepts when you deploy VLANs with Cisco Aironet wireless equipment, you can experience unexpected performance, for example:
  • The failure to limit allowed VLANs on the trunk to those defined on the wireless device
    If VLANs 1, 10, 20, 30 and 40 are defined on the switch, but only VLANs 1, 10 and 30 are defined on the wireless equipment, you must remove the others from the trunk switchport.
  • Misuse of the designation of infrastructure SSID
    When you install access points, only assign the infrastructure SSID when you use an SSID on:
    • workgroup bridge devices
    • repeater access points
    • non-root bridges
    It is a misconfiguration to designate the infrastructure SSID for an SSID with only wireless laptop computers for clients, and causes unpredictable results.
    In bridge installations, you can only have one infrastructure SSID. The infrastructure SSID must be the SSID that correlates to the Native VLAN.
  • Misuse or incorrect design of guest mode SSID designation
    When you define multiple SSIDs/VLANs on Cisco Aironet wireless equipment, one (1) SSID can be assigned as guest mode SSID with the SSID broadcast in 802.11 radio beacons. The other SSIDs are not broadcast. The client devices must indicate which SSID to connect.
  • Failure to recognize that multiple VLANs and SSIDs indicate multiple OSI Model Layer 3 subnets
    Deprecated versions of Cisco Aironet software permit binding multiple SSIDs to one VLAN. Current versions do not.
  • OSI Model Layer 3 routing failures or incorrect designs
    Each SSID and its linked VLAN must have a routing device and some source to address clients, for example a DHCP server or the scope on a DHCP server.
  • Misunderstand or incorrectly configure Native VLAN
    The routers and switches that make up the physical infrastructure of a network are managed in a different method than the client PCs that attach to that physical infrastructure. The VLAN these router and switch interfaces are members of is called the Native VLAN (by default, VLAN 1). Client PCs are members of a different VLAN, just as IP telephones are members of yet another VLAN. The administrative interface of the access point or bridge (interface BVI1) are considered and numbered a part of the Native VLAN regardless of what VLANs or SSIDs pass through that wireless device.

Significance of Native VLAN

When you use an IEEE 802.1Q trunk port, all frames are tagged except those on the VLAN configured as the "native VLAN" for the port. Frames on the native VLAN are always transmitted untagged and are normally received untagged. Therefore, when an AP is connected to the switchport, the native VLAN configured on the AP must match the native VLAN configured on the switchport.
Note:  If there is a mismatch in the native VLANs, the frames are dropped.
This scenario is better explained with an example. If the native VLAN on the switchport is configured as VLAN 12 and on the AP, the native VLAN is configured as VLAN 1, then when the AP sends a frame on its native VLAN to the switch, the switch considers the frame as belonging to VLAN 12 since the frames from the native VLAN of the AP are untagged. This causes confusion in the network and results in connectivity problems. The same happens when the switchport forwards a frame from its native VLAN to the AP.
The configuration of native VLAN becomes even more important when you have a Repeater AP setup in your wireless network. You cannot configure multiple VLANs on the Repeater APs. Repeater APs support only the native VLAN. Therefore, the native VLAN configuration on the root AP, the switch port to which the AP is connected, and the Repeater AP, must be the same. Otherwise traffic through the switch does not pass to and from the Repeater AP.
An example for the scenario where the mismatch in the Repeater AP's native VLAN configuration can create problems is when there is a DHCP server behind the switch to which the root AP is connected. In this case the clients associated with the Repeater AP do not receive an IP address from the DHCP server because the frames (DHCP requests in our case) from the Repeater AP's native VLAN (which is not the same as root AP and the switch) are dropped.
Also, when you configure the switch port, ensure that all the VLANs that are configured on the APs are allowed on the switchport. For example, if VLANs 6, 7, and 8 exist on the AP (Wireless Network) the VLANs have to be allowed on the switchport. This can be done using this command in the switch:
switchport trunk allowed vlan add 6,7,8
By default, a switchport configured as a trunk allows all VLANs to pass through the trunk port. Refer to Interaction with Related Switches for more information on how to configure the switchport.
Note: Allowing all VLANs on the AP can also become a problem in some cases, specifically if it is a large network. This can result in high CPU utilization on the APs. Prune the VLANs at the switch so that only the VLAN traffic that the AP is interested in passes through the AP to avoid high CPU.

VLANs on Access Points

In this section, you are presented with the information to configure the features described in this document.
Note: In order to find additional information on the commands used in this document, use the Command Lookup Tool (registered customers only) .

Concepts with Access Points

This section discusses concepts about how to deploy VLANs on access points and refers to this network diagram.
In this sample network, VLAN 1 is the Native VLAN, and VLANs 10, 20, 30 and 40 exist, and are trunked to another switch chassis. Only VLANs 10 and 30 are extended into the wireless domain. The Native VLAN is required to provide management capability and client authentications.
overview.gif

Access Point Configuration

In order to configure the access point for VLANs, complete these steps:
  1. From the AP GUI, click Services > VLAN to navigate to the Services: VLAN page .
    1. The first step is to configure the native VLAN. From the Current VLAN List, select New.
    2. Enter the VLAN number of the Native VLAN in the VLAN ID box. The VLAN number must match the Native VLAN configured on the switch.
    3. Because interface BVI 1 is associated to the subinterface of the Native VLAN, the IP address assigned to interface BVI 1 must be in the same IP subnet as other infrastructure devices on the network (that is, the interface SC0 on a Catalyst switch that runs CatOS.)
    4. Select the checkbox for the Native VLAN.
    5. Select check boxes for the radio interface or interfaces where this VLAN applies.
    6. Click Apply.
      vlan1.gif
      Or, from the CLI, issue these commands:
      AP# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      AP(config)# interface Dot11Radio0.1
      AP(config-subif)# encapsulation dot1Q 1 native
      AP(config-subif)# interface FastEthernet0.1
      AP(config-subif)# encapsulation dot1Q 1 native
      AP(config-subif)# end
      AP# write memory
      
  2. In order to configure other VLANs, follow these steps:
    1. From the Current VLAN List, select New.
    2. Enter the VLAN number of the desired VLAN in the VLAN ID box. The VLAN number must match a VLAN configured on the switch.
    3. Select check boxes for the radio interface or interfaces where this VLAN applies.
    4. Click Apply.
      vlan10.gif
      Or, from the CLI, issue these commands:
      AP# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      AP(config)# interface Dot11Radio0.10
      AP(config-subif)# encapsulation dot1Q 10
      AP(config-subif)# interface FastEthernet0.10
      AP(config-subif)# encapsulation dot1Q 10
      AP(config-subif)# end
      AP# write memory
      
    5. Repeat steps 2a through 2d for each VLAN desired or enter these commands from the CLI with appropriate changes to the subinterface and VLAN numbers:
      AP# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      AP(config)# interface Dot11Radio0.30
      
      AP(config-subif)# encapsulation dot1Q 30
      
      AP(config-subif)# interface FastEthernet0.30
      
      AP(config-subif)# encapsulation dot1Q 30
      
      AP(config-subif)# end
      AP# write memory
      
  3. The next step is to associate the configured VLANs to the SSIDs. In order to do this, click Security > SSID Manager.
    Note: You do not need to associate every VLAN defined on the access point with an SSID. For example, for security reasons, most access point installations do not associate an SSID with the Native VLAN.
    1. In order to create a new SSID, choose New.
    2. Enter the desired SSID (case-sensitive) in the SSID box.
    3. Select the desired VLAN number to associate this SSID with from the dropdown list.
      Note: In order to keep this document within its intended scope, security for an SSID is not addressed.
    4. Click Apply-RadioX to create the SSID on the selected radio, or Apply-all to create it on all radios.
      /image/gif/paws/46141/ssidred.gif
      Or from the CLI, issue these commands:
      AP# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      AP(config)# interface Dot11Radio0
      AP(config-if)# ssid Red
      AP(config-if-ssid)# vlan 10
      AP(config-if-ssid)# end
      AP# write memory
      
  4. Repeat steps 3a through 3d for each SSID desired or enter these commands from the CLI with appropriate changes to the SSID.
    AP# configure terminal
    Enter configuration commands, one per line.  End with CNTL/Z.
    AP(config)# interface Dot11Radio0
    AP(config-if)# ssid Green
    AP(config-if-ssid)# vlan 30
    AP(config-if-ssid)# end
    AP# write memory
    
    Note: These examples do not include authentication. Some form of authentication (Open, Network-EAP) is required for clients to associate.

VLANs on Bridges

Concepts on Bridges

This section discusses concepts related to how to deploy VLANs on bridges and refers to this network diagram.
In this sample network, VLAN 1 is the Native VLAN, and VLANs 10, 20, 30 and 40 exist. Only VLANs 10 and 30 are extended to the other side of the link. The wireless link is encrypted.
bridge-vlan-diagram.gif
In order to encrypt data that passes over the radio link, apply encryption to only the SSID of the Native VLAN. That encryption applies to all other VLANs. When you bridge, there is no need to associate a separate SSID with each VLAN. VLAN configurations is the same on both the root and non-root bridges.

Bridge Configuration

In order to configure the bridge for VLANs, like the sample network diagram, complete these steps:
  1. From the AP GUI, click Services > VLAN to navigate to the Services: VLAN page.
    1. The first step is to configure the Native VLAN. In order to do this, choose <New> from the Current VLAN List.
    2. Enter the VLAN number of the Native VLAN in the VLAN ID box. This must match the Native VLAN configured on the switch.
    3. Because interface BVI 1 is associated to the subinterface of the Native VLAN, the IP address assigned to interface BVI 1 must be in the same IP subnet as other infrastructure devices on the network (i.e. interface SC0 on a Catalyst switch that runs CatOS.)
    4. Select the checkbox for the Native VLAN.
    5. Click Apply.
      brvlan1.gif
      Or, from the CLI, issue these commands:
      bridge# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      bridge(config)# interface Dot11Radio0.1
      bridge(config-subif)# encapsulation dot1Q 1 native
      bridge(config-subif)# interface FastEthernet0.1
      bridge(config-subif)# encapsulation dot1Q 1 native
      bridge(config-subif)# end
      bridge# write memory
      
  2. In order to configure other VLANs, follow these steps:
    1. From the Current VLAN List, select New.
    2. Enter the VLAN number of the desired VLAN in the VLAN ID box. The VLAN number must match a VLAN configured on the switch.
    3. Click Apply.
      brvlan10.gif
      Or, from the CLI, issue these commands:
      bridge# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      bridge(config)# interface Dot11Radio0.10
      bridge(config-subif)# encapsulation dot1Q 10
      bridge(config-subif)# interface FastEthernet0.10
      bridge(config-subif)# encapsulation dot1Q 10
      bridge(config-subif)# end
      bridge# write memory
      
    4. Repeat steps 2a through 2c for each VLAN desired or enter the commands from the CLI with appropriate changes to the subinterface and VLAN numbers.
      AP# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      bridge(config)# interface Dot11Radio0.30
      
      bridge(config-subif)# encapsulation dot1Q 30
      
      bridge(config-subif)# interface FastEthernet0.30
      
      bridge(config-subif)# encapsulation dot1Q 30
      
      bridge(config-subif)# end
      bridge# write memory
      
  3. From the SSID Manager (under the Security > SSID Manager menu item,) associate the Native VLAN with an SSID.
    Note: When you bridge, the only SSID that you must associate with a VLAN is the one that correlates to the Native VLAN. You must designate this SSID as the Infrastructure SSID.
    1. From the Current SSID List, select New.
    2. Enter the desired SSID (case-sensitive) in the SSID box.
    3. Select the VLAN number that correlates to the Native VLAN from the dropdown list.
      Note: In order to keep this document within its intended scope, security for an SSID is not addressed.
    4. Click Apply to create the SSID on the radio and associate it to the Native VLAN.
      brssidmgr.gif
    5. Scroll back down to the bottom of the page, and under Global Radio0-802.11G SSID Properties select the SSID from the Set Infrastructure SSID dropdown list. Click Apply.
      /image/gif/paws/46141/brinfra.gifOr from the CLI, issue these commands:
      AP# configure terminal
      Enter configuration commands, one per line.  End with CNTL/Z.
      AP(config)# interface Dot11Radio0
      AP(config-if)# ssid Black
      AP(config-if-ssid)# vlan 1
      AP(config-if-ssid)# infrastructure-ssid
      AP(config-if-ssid)# end
      AP# write memory
      
      Note: When VLANs are in use, SSIDs are configured under the physical Dot11Radio interface, not under any logical subinterface.
      Note: This example does not include authentication. The root and non-root bridges require some form of authentication (Open, Network-EAP, etc.) in order to associate.

Use a RADIUS Server to Assign Users to VLANs

You can configure your RADIUS authentication server to assign users or groups of users to a specific VLAN when they authenticate to the network. For information on this feature, refer to the section Using a RADIUS Server to Assign Users to VLANs of the document Cisco IOS Software Configuration Guide for Cisco Aironet Access Points, 12.4(3g)JA & 12.3(8)JEB.

Use a RADIUS Server for Dynamic Mobility Group Assignment

You can also configure a RADIUS server to dynamically assign mobility groups to users or user groups. This eliminates the need to configure multiple SSIDs on the access point. Instead, you need to configure only one SSID per access point. For information on this feature, refer to the section Using a RADIUS Server for Dynamic Mobility Group Assignment of the document Cisco IOS Software Configuration Guide for Cisco Aironet Access Points, 12.4(3g)JA & 12.3(8)JEB.

Bridge Group Configuration on Access Points and Bridges

In general, bridge groups create segmented switching domains. Traffic is confined to hosts within each bridge group, but not between the bridge groups. The switch forwards traffic only among the hosts that make up the bridge group, which restricts broadcast and multicast traffic (flooding) to only those hosts. Bridge groups relieve network congestion and provide additional network security when they segment traffic to certain areas of the network.
Refer to Bridging Overview for detailed information.
In a wireless network, bridge groups are configured on the wireless access points and bridges in order for the data traffic of a VLAN to be transmitted from wireless media to the wired side and vice versa.
Perform this step from the AP CLI in order to enable bridge groups globally on the access point/bridge.
This example uses the bridge-group number 1.
Ap(configure)#bridge 1
Note: You can number your bridge groups from 1 to 255.
Configure the radio interface and the Fast Ethernet interface of the wireless device to be in the same bridge group. This creates a path between these two different interfaces, and they are in the same VLAN for tagging purposes. As a result, the data transmitted from the wireless side through the radio interface is transmitted to the Ethernet interface to which the wired network is connected and vice versa. In other words, radio and Ethernet interfaces that belong to the same bridge group actually bridge the data between them.
In an access point/bridge, you need to have one bridge group per VLAN so that traffic can pass from the wire to the wireless and vice versa. The more VLAN you have that need to pass traffic across the wireless, the more bridge groups that are needed.
For example, if you have only one VLAN to pass traffic across the wireless to wired side of your network, configure only one bridge group from the CLI of the AP/bridge. If you have multiple VLANs to pass traffic from the wireless to wired side and vice versa, configure bridge groups for each VLAN at the radio sub-interface, as well as the Fast Ethernet sub-interface.
  1. Configure the bridge group in the wireless interface with the bridge group dot11radio interface command.
    This is an example.
    AP# configure terminal
    Enter configuration commands, one per line.  End with CNTL/Z.
    AP(config)# interface Dot11Radio0.1
    Ap(config-subif)# encapsulation dot1q 1 native
    Ap(config-subif)# bridge group 1
    
    !--- Here "1" represents the bridge group number.
    
    
    ap(config-subif)# exit
    
  2. Configure the bridge group with the same bridge group number ("1" in this example) in the Fast Ethernet interface so that VLAN 1 traffic is passed across the wireless interface to this wired side and vice versa.
    Ap(config)# interface fastEthernet0.1
    Ap(config-subif)# encapsulation dot1q 1 native
    Ap(config-subif)# bridge group 1
    
    !--- Here "1" represents the bridge group number.
    
    
    Ap(config-subif)# exit
    
    Note: When you configure a bridge group on the radio interface, these commands are set automatically.
    • bridge-group 1 subscriber-loop-control
    • bridge-group 1 block-unknown-source
    • no bridge-group 1 source-learning
    • no bridge-group 1 unicast-flooding
    • bridge-group 1 spanning-disabled
    Note: When you configure a bridge group on the Fast Ethernet interface, these commands are set automatically.
    • no bridge-group 1 source-learning
    • bridge-group 1 spanning-disabled

Integrated Routing and Bridging (IRB)

Integrated routing and bridging makes it possible to route a specific protocol between routed interfaces and bridge groups, or route a specific protocol between bridge groups. Local or unroutable traffic can be bridged among the bridged interfaces in the same bridge group, while routable traffic can be routed to other routed interfaces or bridge groups
With integrated routing and bridging, you can do this:
  • Switch packets from a bridged interface to a routed interface
  • Switch packets from a routed interface to a bridged interface
  • Switch packets within the same bridge group
Enable IRB on the wireless access points and bridges in order to route your traffic between bridge groups or between routed interfaces and bridge groups. You need an external router or a Layer 3 switch in order to route between bridge groups or between bridge groups and routed interfaces.
Issue this command in order to enable IRB in the AP/bridge.
AP(configure)#bridge irb
Integrated routing and bridging uses the concept of a Bridge-Group Virtual Interface (BVI) in order to route traffic between routed interfaces and bridge groups or between bridge groups.
A BVI is a virtual interface within the Layer 3 switch router that acts like a normal routed interface. A BVI does not support bridging but actually represents the correspondent bridge group to routed interfaces within the Layer 3 switch router. It has all the network layer attributes (such as a network layer address and filters) that apply to the correspondent bridge group. The interface number assigned to this virtual interface corresponds to the bridge group that this virtual interface represents. This number is the link between the virtual interface and the bridge group.
Perform these steps in order to configure the BVI on access points and bridges.
  1. Configure the BVI and assign the correspondent number of the bridge group to the BVI. This example assigns bridge group number 1 to the BVI.
    Ap(configure)#interface BVI 1 
    AP(config-if)#ip address 10.1.1.1 255.255.0.0 
    
    !--- Assign an IP address to the BVI.
    
    
    Ap(config-if)#no shut 
    
  2. Enable a BVI to accept and route routable packets received from its correspondent bridge group.
    Ap(config)# bridge 1 route ip!--- 
    
    !--- 
    
    This example enables the BVI to accept and route the IP packet.
    
    
    It is important to understand that you only need a BVI for the management/native VLAN in which the AP is located (in this example, VLAN 1). You do not need a BVI for any other subinterface, irrespective of how many VLANs and bridge groups you configure on your AP/bridge. This is because you tag the traffic in all other VLANs (except the native VLAN) and send it out to the switch though a dot1q trunked interface onto the wired side. For example, if you have 2 VLANs on your network, you need two bridge groups, but only one BVI correspondent to the management VLAN is sufficient in your wireless network.
    When you enable routing for a given protocol on the bridge group virtual interface, packets that come from a routed interface, but are destined for a host in a bridged domain, are routed to the bridge group virtual interface and are forwarded to the correspondent bridged interface.
    All traffic that is routed to the bridge group virtual interface is forwarded to the correspondent bridge group as bridged traffic. All routable traffic received on a bridged interface is routed to other routed interfaces as if it comes directly from the bridge group virtual interface.
    Refer to Configure Bridging for more detailed information on bridging and IRB.

Interaction with Related Switches

In this section, you are presented with the information to configure, or verify the configuration of the Cisco switches that connect to Cisco Aironet wireless equipment.
Note: In order to find additional information on the commands used in this document, use the Command Lookup Tool (registered customers only) .

Switch Configuration—Catalyst OS

In order to configure a switch that runs Catalyst OS to trunk VLANs to an access point, the command syntax is set trunk <module #/port #> on dot1q and set trunk <module #/port #> <vlan list>.
An example from to the sample network diagram, is:
set trunk 2/1 on dot1q
set trunk 2/1 1,10,30

Switch Configuration—IOS Based Catalyst Switches

From interface configuration mode, enter these commands, if you want to:
  • Configure the switchport to trunk VLANs to an access point
  • On a Catalyst switch that runs IOS
  • The CatIOS includes but is not limited to:
    • 6x00
    • 4x00
    • 35x0
    • 295x
switchport mode trunk
switchport trunk encapsulation dot1q
switchport nonegotiate
switchport trunk native vlan 1
switchport trunk allowed vlan add 1,10,30
Note: IOS based Cisco Aironet wireless equipment does not support Dynamic Trunking Protocol (DTP), so the switch must not try to negotiate it.

Switch Configuration—Catalyst 2900XL/3500XL

From interface configuration mode, enter these commands, if you want to configure the switchport to trunk VLANs to an access point on a Catalyst 2900XL or 3500XL switch that runs IOS:
switchport mode trunk
switchport trunk encapsulation dot1q
switchport trunk native vlan 1
switchport trunk allowed vlan 1,10,30

Verify

Use this section to confirm that your configuration works properly.

Verify the Wireless Equipment

  • show vlan—displays all VLANs currently configured on the access point, and their status
    ap#show vlan
    
    Virtual LAN ID:  1 (IEEE 802.1Q Encapsulation)
    
       vLAN Trunk Interfaces:  FastEthernet0.1
    Dot11Radio0.1
    Virtual-Dot11Radio0.1
    
     This is configured as native Vlan for the following interface(s) :
    FastEthernet0
    Dot11Radio0
    Virtual-Dot11Radio0
    
       Protocols Configured:   Address:          Received:        Transmitted:
            Bridging        Bridge Group 1          36954                   0
            Bridging        Bridge Group 1          36954                   0
    
    Virtual LAN ID:  10 (IEEE 802.1Q Encapsulation)
    
       vLAN Trunk Interfaces:  FastEthernet0.10
    Dot11Radio0.10
    Virtual-Dot11Radio0.10
    
       Protocols Configured:   Address:          Received:        Transmitted:
            Bridging        Bridge Group 10          5297                   0
            Bridging        Bridge Group 10          5297                   0
            Bridging        Bridge Group 10          5297                   0
    
    Virtual LAN ID:  30 (IEEE 802.1Q Encapsulation)
    
       vLAN Trunk Interfaces:  FastEthernet0.30
    Dot11Radio0.30
    Virtual-Dot11Radio0.30
    
       Protocols Configured:   Address:          Received:        Transmitted:
            Bridging        Bridge Group 30          5290                   0
            Bridging        Bridge Group 30          5290                   0
            Bridging        Bridge Group 30          5290                   0
    
    ap#
  • show dot11 associations—displays information about associated clients, per SSID/VLAN
    ap#show dot11 associations
    
    802.11 Client Stations on Dot11Radio0:
    
    SSID [Green] :
    
    SSID [Red] :
    
    Others:  (not related to any ssid)
    
    ap#

Verify the Switch

  • On a Catalyst OS based switch, show trunk <module #/port #>—displays the status of a trunk on a given port
    Console> (enable) show trunk 2/1
    * - indicates vtp domain mismatch
    Port      Mode         Encapsulation  Status        Native vlan
    --------  -----------  -------------  ------------  -----------
     2/1      on           dot1q          trunking      1
    
    Port      Vlans allowed on trunk
    --------  ----------------------------------------------------------------
     2/1      1,10,30
    
    Port      Vlans allowed and active in management domain
    --------  ----------------------------------------------------------------
     2/1      1,10,30
    
    Port      Vlans in spanning tree forwarding state and not pruned
    --------  ----------------------------------------------------------------
     2/1      1,10,30
    Console> (enable)
  • On a IOS based switch, show interface fastethernet <module #/port #> trunk —displays the status of a trunk on a given interface
    2950g#show interface fastEthernet 0/22 trunk
    
    Port        Mode         Encapsulation  Status        Native vlan
    Fa0/22      on           802.1q         trunking      1
    
    Port        Vlans allowed on trunk
    Fa0/22      1,10,30
    
    Port        Vlans allowed and active in management domain
    Fa0/22      1,10,30
    
    Port        Vlans in spanning tree forwarding state and not pruned
    Fa0/22      1,10,30
    2950gA#
  • On a Catalyst 2900XL/3500XL switch, show interface fastethernet <module #/port #> switchport —displays the status of a trunk on a given interface
    cat3524xl#show interface fastEthernet 0/22 switchport
    Name: Fa0/22
    Switchport: Enabled
    Administrative mode: trunk
    Operational Mode: trunk
    Administrative Trunking Encapsulation: dot1q
    Operational Trunking Encapsulation: dot1q
    Negotiation of Trunking: Disabled
    Access Mode VLAN: 0 ((Inactive))
    Trunking Native Mode VLAN: 1 (default)
    Trunking VLANs Enabled: 1,10,30,1002-1005
    Trunking VLANs Active: 1,10,30
    Pruning VLANs Enabled: 2-1001
    
    Priority for untagged frames: 0
    Override vlan tag priority: FALSE
    Voice VLAN: none
    Appliance trust: none
    Self Loopback: No
    wlan-cat3524xl-a#
Readmore...