Lightweight Access Point Protocol LWAPP
In the Cisco Unified Wireless Architecture, a wireless LAN controller (WLC) is used to manage the wireless access point configuration and firmware creating an LWAPP tunnel. LWAP provides the control messaging protocol and data encapsulation. In other words, the wireless client data packets are encapsulated between the access point and the WLC. Figure 8-21 illustrates how a WLC controls a wireless access point over an LWAPP tunnel.
The following steps are illustrated in Figure 8-21:
1 The wireless client sends a packet to the wireless access point.
2 The wireless access point decrypts the packet and encapsulates it with an LWAPP header, forwarding it to the WLC.
3 The WLC removes the LWAPP header and forwards the packet to its destination in the corporate wired network.
Figure 8-21 LWAPP Tunnel
Figure 8-21 LWAPP Tunnel
Lightweight Wireless Access
Lightweight Wireless Access
NOTE When a client on the corporate wired network sends replies to the wireless client, the packet first goes into the WLC where it is encapsulated with an LWAPP header and forwarded to the appropriate wireless access point. Subsequently, the access point removes the LWAPP header and encrypts the packet if necessary.
The LWAPP control messages are encrypted using the AES-CCM encryption method. The shared encryption key is derived and exchanged when the access point joins the WLC.
NOTE The payload of the encapsulated LWAPP data is not encrypted. Therefore, you should follow infrastructure protection best practices to protect the wired network.
The following are the major steps or stages used in the LWAPP:
Step 1 Discovery: The wireless access point looks for a controller. The LWAPP Discovery Response from the controller contains the following important information from the WLC:
— Controller name (sysName)
— Controller type
— Controller capacity
— Current wireless access point load in the WLC
— Master controller status information used for redundancy
— Access point manager IP address and the number of access points joined to the manager
(a) When the AP is powered on, if a static IP address has not been previously configured, the AP issues a DHCP DISCOVER to get an IP address.
(b) If Layer 2 mode is supported, the AP attempts a Layer 2 LWAPP Discovery by sending an Ethernet broadcast message.
(c) If Layer 2 mode is not supported or the AP fails to find a WLC, the AP attempts a Layer 3 LWAPP Discovery.
(d) If a Layer 3 LWAPP Discovery also fails, the AP reboots and retries the first step.
Step 2 Join: The wireless access point attempts to establish a secured relationship with a controller.
Step 3 Image Data: The wireless access point downloads code from the WLC when needed.
Step 4 Config: The wireless access point receives the configuration from the WLC.
Step 5 Run: The wireless access point and the WLC are operating normally, and service data is exchanged.
Step 6 Reset: The wireless access point clears the current state, and this process starts over again.
The WLC provides support for radio resource management (RRM). The following are some of the advantages of RRM:
• Continuous analysis of RF environment
• Dynamic channel and power management
• Coverage hole detection and correction
• Coverage resiliency
The WLCs elect a radio frequency (RF) group leader who analyzes RF data and neighbor relationships to make more optimized decisions about the RF environment for wireless infrastructure. Multiple RF domains can coexist within a single RF Group. These RF domains can be intercontroller or intracontroller, as illustrated in Figure 8-22.
Figure 8-22 Multiple RF Domains
Figure 8-22 Multiple RF Domains
Why is this important to security? A good wireless network design that includes network resiliency is important for the overall security of your wireless network. The WLC has a built-in understanding of the signal strength that exists between lightweight access points within the same network. These controllers can use this information to create a dynamic optimal RF topology for the network. When a Cisco LWAPP-enabled access point boots up, it immediately looks for a wireless LAN controller within the network. After it finds a wireless LAN controller, the LWAPP-enabled access point sends out encrypted "neighbor" messages. These neighbor messages include the MAC address and signal strength of any neighboring access points. In a single wireless LAN controller network, the controller uses this neighbor information to determine the relative spatiality of the access points in the network. The controller then tunes each access point channel and optimal signal strength for optimal coverage and capacity.
When wireless LAN controllers are clustered in the network, a default controller is chosen. All the controllers feed the default controller information to their registered access points. The default controller correlates information for all the access points in the network and then pushes out the optimal channel and power for every access point on the network. The algorithms built into the Cisco Unified Wireless Network architecture prevent the interruption of wireless connectivity.
Continue reading here: Wireless Intrusion Prevention System Integration
Was this article helpful?
Readers' Questions
-
costanzo1 year ago
- Reply