230 likes | 388 Views
ORiNOCO AS-2000 Networks Product Overview. Module contents. What is an ORiNOCO AS-2000 Network Generic network configurations System elements Software Features. ORiNOCO AS-2000 Network a definition.
E N D
ORiNOCO AS-2000 Networks Product Overview
Module contents • What is an ORiNOCO AS-2000 Network • Generic network configurations • System elements • Software • Features
ORiNOCO AS-2000 Networka definition A wireless local area network meant for use in public areas and offices, centered around an “Access Server” and using ORiNOCO wireless systems in laptop & desktop computers. Such a system includes: • One or more ORiNOCO AS-2000: The Access Server that handles the communications for ORiNOCO client devices • One or more laptop computers equipped with ORiNOCO PC Cards and appropriate AS Client Software • One or more desktop computers equipped with ORiNOCO PCI or ISA or USB adapters and appropriate AS Client Software • RADIUS server to control access to the network • AS Manager Software and TFTP server for network configuration and monitoring
ORiNOCO AS-2000 networkWhat is it? A simple description: • Secure (RC4-based, per-user/per-session key exchange, RADIUS user authentication and accounting) • High speed (up to 11Mbps) • Wireless connectivity (IEEE 802.11b) • Installed in environments with a need for increased security such as enterprises, education institutions...
Internet Intranet IP Networks Generic network configuration 10/100base-T Ethernet Encrypted Radio link @ 11 Mbps (shared) Router Backhaul: Leased line, DSL, Cable, wireless ... AS Manager server RADIUS Server Laptop + AS Client + ORiNOCO PC Card ORiNOCO AS-2000 Network Operations Center
Communications Flow • Client establishes RF connection with AS-2000 • Client and AS-2000 establish session key using Diffie-Hellman • Client sends authentication request (user name and password) • AS-2000, through Ethernet, forwards authentication request to RADIUS Server • RADIUS Authenticates, Authorizes, and starts Accounting record • RADIUS responds: • If client is authenticated, service is approved and RADIUS tracks usage • If client is not authenticated, service is denied • After authentication, AS-2000 opens connection to Internet and the Client receives an IP address • Communication between client and AS2000 flows via PPP stack
AS-2000 network Components Client • User’s laptop, ORiNOCO PC card, AS Client software AS-2000 • An access server that receives and transmits RF signals to Client • Through an Ethernet connection, routes the packets to the network server/router (ISP) AS Manager • Software to configure AS-2000, operate network
AS Client Specifications • Software designed to run on Windows95/98/NT, Mac • Requires • minimum 16MB RAM • 5MB hard drive • Extended Type 2 ORiNOCO PC card with ORiNOCO driver • CD-ROM available • Web download available Note: Windows 95 requires DUN 1.3, Windows 98 requires VPN
AS Client Function • Portable high speed, secure access to email, IP networks (Intranet, Internet), etc. • User’s interface to the network • After connection established, laptop performs “normal” functionality for data communications (NT logon etc.) • AS Client used for GUI, DH key exchange, PPP session establishment
AS-2000 System Components • Base unit • Functions as wireless base station • Power supply • ORiNOCO PC card (1 or 2) • Ethernet cables, hub (not included) • Serial cable (not included) • Active Ethernet (option)
AS-2000 Specifications • H/W: • Intel StrongARM 110 processor (32 MB RAM memory, 16 MB Flash Memory) • 10BaseT / 100Base-T (UTP) Ethernet • 2 slots for ORiNOCO PC Cards • 8-pin MiniDin serial connector for optional configuration • Powered via Active Ethernet, using splitter (or via PS) • S/W: • Real-Time Operating System (RTOS) built on VxWorks • Manageability • Jave-based AS manager • CLI, via Telnet or local console • Maximum 250 clients per PC card in the AS-2000
AS-2000 Function • Establishes 2.4GHz RF connection with Client • Support roaming of mobile clients by implementation of an IAPP (Inter Access Point Protocol) • Includes a RADIUS Client for authentication with a RADIUS Server • After authentication, routes data, via Ethernet / backbone network, to the Internet
AS Client Software • AS Client SHIM Driver: • Shown as adapter in Network Neighborhood properties • Also shown as protocol binding to ORiNOCO/WaveLAN IEEE PC card • Can be used next to standard ORiNOCO PC Card Driver • AS Client SHIM Driver activates when AS Client application is started from the desktop • ORiNOCO PC Card driver functions normally when AS Client application is not running
AS Client Software • AS Client Log-in utility • Starts the AS Client application when activated • Allows dynamic association with AS-2000 networks (associations via network names in so-called Network List text file) • Allows entry of Login Name and Password for user authentication by RADIUS Server
AS Manager Specifications • Configuration and monitoring software • Win 95/98/NT/2000 (server or workstation) platform • Java Runtime Environment (JRE) • Requires minimum 64 MB RAM, 30 MB hard drive • Uses a TFTP Server to download image to AS-2000 • Supports up to 50 AS-2000
AS Manager Function • Primary purpose is to configure the AS-2000 • Provides control and monitoring of AS-2000 • Check status and activity of each AS-2000 • Allows setting of AS-2000 parameters • Monitor and change RADIUS parameters • Provides remote link test capabilities: • Assessing the wireless link between the AS2000 and its attached clients, from any point in the network
Major ORiNOCO Features • Security: RC-4 and Diffie-Hellman algorithms • High speed • Industry standards • IP-based (IPX protocol supported) • Up to 11 Mbps bandwidth, and up to ~500 meters • Easy to install, operate, maintain • Interfaces with RADIUS servers • Standard Authentication, Authorization, Accounting for many ISPs • Portability / mobility
Security • Better than wired equivalent privacy (WEP) • Combination of RC-4 and Diffie-Hellman algorithms • Diffie-Hellman for automatic key exchange • RC-4 for encryption/decryption • Over-the-air security: • “Per-user, per-session” RC-4-based encryption • Individual user authentication • Creates “secure path” in shared medium (i.e., over the air)
High Speed • Up to 11 Mbps available • Direct Sequence Spread Spectrum (DSSS)
Industry Standard • IEEE 802.11b • Standard for wireless LANs • Defines PHY and MAC protocols • IEEE 802.3 Ethernet • RADIUS (RFP 2138 Auth and 2139 Account) • WLAN • Specific geographic area
RADIUS • Remote Authentication Dial In User Service • Client/Server based authentication software • A centralized database residing on a server to be shared by multiple remote access servers • Provides “AAA” • Authentication • Authorization • Accounting • Can reside on local server or remotely at any IP address • Already in use by most ISPs and Enterprises
Module summary • What is an ORiNOCO AS-2000 Network • Generic network configurations • System elements • Software • Features