16
IT Professional Wi-Fi Trek 2015 #wifitrek The Magic of Analysis Peter Mackenzie CWNE #33 @mackenziewifi

The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

IT Professional Wi-Fi Trek 2015

#wifitrek

The Magic of AnalysisPeter Mackenzie CWNE #33

@mackenziewifi

Page 2: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

01111000101000101100101010100011101010101010101010101101010101010101010110010101000101

10101000111001001110100011101110101100110100100010101000101010101000101111000101110011

10101010101010001010101010001011101010101010101010101100100100111011000101001011101011

Your Magic Wand

Used correctly, a protocol analyser is

your troubleshooting and analysis

magic wand

Page 3: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Power and Limitation of a Protocol Analyser

The packets never lie!

Lets you see exactly what is happening on your network

You can only see the packets

If your problem is not manifested in the packets, you will not see it.

For Wi-Fi, a Spectrum Analyser is also a key troubleshooting tool

Sometimes the lack of packets can point you in the right direction

Page 4: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

POS Cross-Chatter – Who’s Talking To Who?

Page 5: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

When to Capture?

Troubleshooting

Protocol analysers shouldn’t only be used as a last resort

Performance Analysis

Baselining

What is normal

Understanding the 802.11 environment

Education

Finding out how things work

Page 6: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Troubleshooting Methodology

Assume nothing

Talk to the end users experiencing the problem

Observe the problem

A bit like real detective work

Look for leads and then follow them

Page 7: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Troubleshooting Methodology

Looking for leads

Suspicious protocols, nodes & conversations

Anything abnormal (Know what is normal)

Know your protocol

Baseline

Following leads

Filtering

Select-related

More captures

Page 8: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Know Your Protocol Wireless and Wired

Page 9: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Vendor Differences - Example Cisco – Beacon

WMM Parameter Element Motorola/Zebra– Beacon

WMM Information Element

Page 10: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Performance Analysis

Beacons, Probe Request & Probe

Responses = 92.5% of Total

Retries

Per Channel

Per AP

Per Client

Page 11: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Capture Before you Write

Can’t I just read the Standard?

Standard vs proprietary

Standard interpretation

Page 12: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

802.11 Power Save

Beacon ACK Data

(more =1)

ACK Data

(more =0)

Sleep PS-

Poll

ACK PS-

Poll

ACK

AP

Client

Page 13: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Power Save – As Implemented

Page 14: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Proprietary 802.11n Protection Mechanism

Intel(R) Centrino(R) Ultimate-N 6300 AGN – Power Save

Page 15: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Win Arguments with Packets

Prove it with a capture

The packets never lie!

Page 16: The Magic of Analysis - Certified Wireless Network ... · The packets never lie! Lets you see exactly what is happening on your network You can only see the packets If your problem

#wifitrek

Questions