Design Considerations for Branch Office Wireless Networks

This section reviews design considerations for branch wireless network design, including REAP and H-REAP.

Branch Office Considerations

The following are several key design considerations for branch office wireless networks:

■ How many APs are needed, and what are their requirements? Recall that, generally, an AP can support 7 to 8 wireless phones or 20 or more data-only devices. Ports must be available on the local switch to connect the APs to the wired network. Power to the APs, either through PoE or traditional power cabling, is also required.

■ What is the cost of the WLC? It might not be economically feasible for small sites to implement local controllers.

■ What are the bandwidth requirements? Sufficient bandwidth to support the required wireless traffic is needed. If a centralized controller supports branch office APs, the RTT latency between the APs and the WLC should not exceed 200 ms, and only REAPs or H-REAPs should be used, as discussed in the upcoming "REAP" and "Hybrid REAP" sections.

Local MAC

Recall that in a typical LWAPP deployment, the AP MAC functions are split between the lightweight AP and the WLC. LWAPP also supports a local MAC feature in which the full 802.11 functionality is on the lightweight AP; this solution might be appropriate for branch wireless deployments.

With local MAC, the AP provides the MAC management support for association requests and actions. Local MAC allows for the decoupling of the data plane from the control path by terminating all client traffic at the AP's wired port. This allows direct wireless access to resources local to the AP and provides link resiliency because wireless service persists if the LWAPP control path (between the AP and the controller) goes down. This functionality is particularly useful in small remote and branch offices across WAN links where only few APs are needed and the cost of a local controller is not justified. Table 9-7 summarizes the lightweight AP and WLC MAC functions with the local MAC feature; compare this to Table 9-3.

Table 9-7 Local MAC Lightweight AP and WLC MAC Functions

Lightweight AP MAC Functions

WLC MAC Functions

8G2.11: Beacons, probe response

8G2.11 Control: Packet acknowledgment and transmission

8G2.11e: Frame queuing and packet prioritization

8G2.11i: MAC layer data encryption/decryption

8G2.11 MAC management: Association requests and actions

802.11 Proxy association requests and actions

802.11e Resource reservation

802.11i Authentication and key management

REAP

Connecting lightweight APs to a WLC over a WAN is not recommended unless a REAP or H-REAP is used.

KEY POINT

A REAP is a lightweight AP designed to be controlled across WAN links. The LWAPP controller timers are extended on a REAP.

The Cisco 1030 series APs are Cisco first-generation REAP devices (versus the second-generation H-REAP devices described in the next section). REAP capabilities allow a lightweight AP to be deployed remotely from the WLC, to extend wireless management and control support to branch office and small retail locations.

The 1030 series AP is a superset of the 1010 and 1020 APs that can operate as a campus access point or as a REAP device and that delivers the same LAN security, performance, and RF management capabilities as the campus 1010 and 1020 APs. The 1030 AP can operate via most standard WAN technologies, including T1, Frame Relay, and so forth, enabling IT managers to centrally control SSIDs, security parameters, and software loads for unified, enterprise-wide WLAN services.

With a REAP, all control traffic is LWAPP-encapsulated and sent to a Cisco WLC, as it is with other APs. With a REAP, however, client data traffic is not LWAPP-encapsulated, but is locally bridged onto the WAN.

All management control and RF management are available when the WAN link is up and connectivity is available to a Cisco WLC. The REAP continues to provide connectivity to local wireless clients and local network resources if the WAN goes down.

First-generation REAP devices do have a few limitations (which are addressed by H-REAP devices):

■ The Cisco 1030 series AP does not support 802.1Q trunking. All WLANs terminate on a single local VLAN/subnet.

■ With connectivity to the controller, the Cisco 1030 series APs support multiple (up to 16) WLANs. During a WAN outage, the AP goes into standalone mode, and all WLANs except the first WLAN configured on the AP, WLAN 1, are disabled and unavailable. Therefore, multiple WLANs are not recommended.

■ With REAP devices, only Layer 2 security using WEP or WPA-PSK is supported in standalone mode. Layer 3 security polices are not supported on REAP devices.

■ REAPs and clients require a routable IP address, but the embedded Cisco WLC DHCP server is not supported; a local DHCP server must provide IP addresses locally. Network address translation (NAT) is also not supported.

Hybrid REAP

An H-REAP is another option for branch office and remote office deployments. An H-REAP is an enhancement to a REAP that enables customers to configure and control two or three APs in a branch or remote office from the corporate office through a WAN link without deploying a controller in each office. The H-REAPs can switch client data traffic locally and perform client authentication locally when their connection to the controller is lost. When they are connected to the controller, they can also send traffic back to the controller.

An H-REAP supports simultaneous tunneling and local switching. Local switching bridges traffic onto local VLANs, whereas central switching tunnels traffic to a WLC. An H-REAP provides more security options than a REAP for the remote site:

■ Standalone mode: When the H-REAP cannot reach the WLC, it goes into standalone mode and performs its own client authentication; WPA-PSK and WPA2-PSK are supported in standalone mode.

■ Connected mode: When the H-REAP can reach the controller, it is in a connected state and gets help from the controller to complete client authentication. In connected mode, an H-REAP supports many client authentication protocols, including WPA-PSK, WPA2-PSK, VPNs, Layer 2 Tunneling Protocol, 802.1X EAP, and web authentication.

An H-REAP is more delay-sensitive than a REAP; round-trip latency must not exceed 200 ms between the AP and the controller, and LWAPP control packets must be prioritized over all other traffic. An H-REAP supports a one-to-one NAT configuration. It also supports port address translation for all features except true multicast. Multicast is supported across NAT boundaries when configured by using the Unicast option.

An H-REAP can be deployed with a static IP address or it can obtain its IP address via DHCP. The DHCP server must be available locally and must be able to provide the IP address for the H-REAP at bootup.

H-REAP is supported on all the LWAPP WLCs, but only on the 1130AG and 1240AG APs. Figure 9-39 illustrates a typical H-REAP deployment. H-REAP APs should be connected using trunk ports to support switched VLANs.

Figure 9-39 H-REAP Allows APs to Be Remote from the WLC

Headquarters

Headquarters

Figure 9-39 H-REAP Allows APs to Be Remote from the WLC

802.1X

Branch

802.1X

H-REAP Access Point

DHCP Server

Local Switch

DHCP Server

Local Switch

Branch

.Trunk Ports

H-REAP Access Point

NOTE Although H-REAP functionality is limited to three units per site in Cisco UWN code version 4.0, an increase to six units might be available in a maintenance release. Refer to http://www.cisco.com/ documentation for the latest features and limitations of H-REAP.

Branch Office WLAN Controller Options

Depending on the size of the branch and whether integration with Layer 3 infrastructure devices is desired, one of two categories of WLCs is typically deployed in a branch office.

Appliance controllers such as the Cisco 2006 and the Cisco 4400 Series are often used to support six to 25 APs (although versions of the 4400 that support more APs are available). For example, the 4402-12 and 4402-25 could be used in a branch office to support 12 or 25 APs, respectively. These appliance controllers can support from 40 to 500 wireless devices, depending on the mix of data and voice clients. Depending on redundancy requirements, one or two routers would be needed for WAN connectivity to the enterprise network.

Controllers integrated in Layer 3 devices, such as the WLCM for ISRs or the integrated WLC for the Cisco Catalyst 3750G switch, also support six to 25 APs. WAN redundancy can be supported with another router or a pair of these devices.

0 0

Post a comment