Review: Agere ORiNOCO AS-2000, part 2

from ISP-Planet

In Part 1, we established the basic building blocks of our Agere WLANinstalling ORiNOCO cards, drivers, Client Manager, and AS Client software. Today, we continue our saga, describing AS-2000 installation, configuration, and monitoring, explaining how to integrate this wireless access server with an existing wired network.

AS-2000 and AS Manager

Surprisingly, the easiest component to install was the AS-2000. At 2 x 7 x 10″, this petite device is easily mounted on a ceilingpower is optionally passed over Cat5 to the single 10/100 Ethernet port. Radio transmission occurs over ORiNOCO NICs, inserted into one or both CardBus slots. Status LEDs are visible with the removable plastic cover in place. The unit accepts an outside antenna, but is designed for indoor deployment.

In a pinch, the AS-2000 CLI (accessed by serial port or telnet) can be used to load image or configuration updates from a TFTP server or reconfigure addresses. Traffic counters are visible from the CLIa ping client would be a great addition. Admins can also monitor traps or administer the device using its enterprise MIB and a third-party SNMP manager.

Click for full sized image


Device Configuration is password-protected by an SNMP community string with read-write permission. Use this menu to set system, network, physical interface, PPP, IAPP, SNMP, and RADIUS parameters.

System parameters include the ability to administratively take the AS-2000 offline now or later. SNMP parameters include an access table that limits administrative access to specified source IPs. (If you lock yourself out or forget the IPs entered here, you can get back in by resetting the device to factory defaults.)

Click for full sized image

IAPP parameters control communication between ORiNOCO base stations, such as announcement interval and response time, handover timeout and retransmission count. With only one AS-2000, we were unable to exercise handoffbut its intent is to enable roaming by eliminating the need to reconnect when moving from one AS to another.

Dynamic Address Assignment

The AS-2000 can be used in IP and IPX networks. Tech support runs into IPX infrequently, mostly at universities. We limited our testing to IP, and configured PPP parameters to exercise four methods of IP address assignment:

Click for full sized image

Click for full sized image

Click for full sized image

4)   Finally, a RADIUS server can be configured to supply IP addresses when accepting an Access Request. On the AS-2000, select RADIUS as the IP address assignment type and configure RADIUS parameters (discussed in the next section). Actual address assignments are configured on the RADIUS serverif RADIUS does not return an IP address, PPP session establishment fails.

PPP parameters also determine session idle timeout (disable if you want session timeout controlled by RADIUS) and the authentication protocol used between the AS-2000 and your RADIUS server (PAP or CHAP).

RADIUS Authentication

Click for full sized image
Because the AS-2000 relies on RADIUS for authentication, RADIUS parameters must be configured, no matter which address assignment type is used (left). Two sets of parameters are required: a primary authentication server and a primary accounting server. Backup servers can also be configured.

Each RADIUS server is identified by IP address, destination port, and shared secret. These values must match those defined on your RADIUS serverin our case, the Interlink AAA Engine. The RADIUS Statistics button displays counters that are useful in diagnosing connectivity problems.

For example, if an AS Client cannot connect, check the Access Request counter. If this counter is not incrementing, the problem lies between the client and the AS-2000. Otherwise, check the Access Retransmissions counterthis signals connectivity or access issues between the AS-2000 and the RADIUS server. Otherwise, check the Access Rejects counterthis signals authentication failure, such as when the user supplied bad credentials.

We had no real issues integrating the AS-2000 with the Interlink AAA Engine. A bad route caused early retransmissionsthis is where traceroute would have been handy in the AS-2000. We also configured the AAA Engine to ignore an unencapsulated vendor-specific attribute (MAC address) supplied by the AS-2000. After this, it was smooth sailing.

In Part 3, we will cover monitoring.

Latest Articles

Follow Us On Social Media

Explore More