N4N062: Your First Wi-FI Network, Part 3
This episode concludes N4N's wireless networking series with detailed discussion of Wi-Fi security (WEP, WPA2, WPA3, and Enterprise variants), roaming protocols (802.11r, 802.11k, 802.11v), and practical considerations for specifying access points. The hosts emphasize that Wi-Fi is a specialized field requiring deep expertise, particularly for large-scale deployments.
Summary
Ethan Banks and Holly Podbilak complete their wireless networking overview by covering three major topics: security, roaming, and access point specification.
On security, they trace the evolution from WEP (Wired Equivalent Privacy)—an early encryption standard that was trivially broken, enabling 'war driving' attacks—through WPA2 (Wi-Fi Protected Access 2) with AES encryption to WPA3, the current standard. They explain that WPA2, while more robust than WEP, is vulnerable to four-way handshake brute-force attacks and the 2017 KRACK vulnerability. WPA3 improves security through Simultaneous Authentication of Equals (SAE) instead of the Pre-Shared Key (PSK) handshake, assigns unique encryption keys per device, and resists offline dictionary attacks. The hosts note WPA3 is now mandatory for Wi-Fi 6E and 7. They also discuss WPA2-Enterprise and WPA3-Enterprise, which use individual user authentication via 802.1X and RADIUS servers rather than shared passwords, enabling credential revocation without network-wide password changes. Enhanced Open Networks (OWE) provides encryption even on open networks without passwords, though the hosts note this is rarely seen in practice, with captive portals being the more common approach.
On roaming, they address the challenge that clients (not access points) make roaming decisions, often resulting in 'sticky clients' that refuse to transition between access points even when signal degrades. To optimize roaming, they discuss three 802.11 standards: 802.11r (Fast BSS Transition) enables seamless handoffs in ~50 milliseconds by passing authentication credentials between access points without re-authentication, preventing Zoom call disruptions. 802.11k (Radio Resource Management) allows access points to inform clients about neighboring access points and signal strengths, reducing the need for clients to scan the air independently. 802.11v (BSS Transition Management) enables soft suggestions for clients to roam to better access points, useful in scenarios like conference rooms where many clients attach to one access point. The hosts explain that proper access point power and channel optimization is critical—access points should not all be at maximum power, as this creates interference and overlapping cells that degrade performance. AI-powered RRM tools now continuously monitor client experience and adjust power and channel assignments dynamically, though optimization is ongoing rather than one-time.
On access point specification, Holly outlines key decision factors: deployment location (indoor vs. outdoor, with outdoor units requiring weatherproofing), use case (dense office environments vs. sparse warehouses with high ceilings and metal interference vs. large public venues like stadiums), cost constraints, antenna types (omnidirectional vs. directional, including software-defined directional antennas), and MIMO configuration (2x2, 3x3, 4x4 spatial streams, with higher MIMO supporting denser client loads). The hosts note that external directional antennas are now less common in office deployments due to software-defined beamforming, but remain standard in large venues like stadiums. They emphasize that Wi-Fi design is highly specialized and that network engineers without Wi-Fi expertise should consult specialists, as Wi-Fi problems generate disproportionate user complaints despite representing a small portion of networking work.
About this episode
In the third installment of the Wi-Fi networks series, Ethan Banks and Holly Podbielak discuss the basics of wireless security, the standards related to roaming between access points, and how to analyze access points to figure out which AP brand will best meet your organization’s needs. AdSpot Sponsor: Meter Most IT teams are managing networks<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/n-is-for-networking/n4n062-your-first-wi-fi-network-part-3/" title="ReadN4N062: Your First Wi-FI Network, Part 3">... Read more »</a>
Key Insights
- WEP encryption was so weak that attackers could capture traffic and decrypt it via brute-force attacks with modest computing power, making 'war driving' a viable hobby in the early 2000s.
- WPA2's vulnerability to four-way handshake capture enables offline password brute-forcing, meaning attackers can grab packets from the air and attempt password cracking without maintaining a live connection.
- WPA3's mandatory requirement for Wi-Fi 6E and 7 creates a compatibility problem where older IoT devices unable to support WPA3 cannot connect to next-generation networks, forcing organizations to maintain legacy security standards.
- Client devices make roaming decisions unilaterally based on perceived signal strength rather than access point decisions, resulting in 'sticky clients' that refuse to roam even when signal quality degrades significantly.
- Access point power levels must be deliberately reduced and carefully tuned rather than maximized, because overlapping coverage at full power causes radio interference and collisions that degrade performance for all users.
- AI-powered RRM tools continuously adjust access point power and channel assignments based on monitored client experience metrics, but optimization is iterative and never reaches a permanent final state due to constantly changing interference sources.
- Large-scale Wi-Fi deployments in stadiums and arenas require extensive external directional antenna arrays mounted throughout venues with no ceilings, representing a fundamentally different design approach than traditional office deployments.
- Most network engineers are not Wi-Fi specialists and lack expertise in MIMO, radio resource management, antenna types, and density planning, requiring vendor or consultant expertise to avoid poor design decisions.
Topics
Transcript
. One of the things you'll learn as a network engineer is that multi-vendor networks are an operational challenge. Life is easier when your gears are like and you're dealing with a small number of vendors. Our sponsor, METR, is a solid option here. They offer an integrated wired, wireless, and cellular stack with hardware and software that they built in-house. Pricing is predictable, and you remain in the driver's seat for your network management if you want to. Check out metr.com slash n4n. That's m-e-t-e-r dot com slash n4n to book a demo. Welcome to N is for Networking. I'm Ethan Banks, your grizzled network veteran suffering from radiation sickness because I stand too close to the access point.…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.
HN840: How to Make a Technology Buying Decision
Sean Morgan, a research director at Deloro Group, discusses how technology buying decisions should extend beyond engineering specifications to include business alignment, ROI calculations, and understanding total cost of ownership. Engineers must shift from viewing IT as a cost center to positioning it as a business enabler by connecting technical decisions to revenue impact and organizational objectives.
IPB207: Flying Blind: Monitoring Might Not See IPv6
The IPv6 Buzz hosts discuss critical gaps in IPv6 monitoring across enterprise networks, highlighting that many monitoring platforms lack IPv6 awareness, vendor parity, and advanced analytical capabilities. They emphasize that while basic IPv6 data ingestion has improved, sophisticated features like cross-protocol event correlation, extension header analysis, and device identity tracking remain significant industry challenges.
N4N063: Link Layer Discovery Protocol
Link Layer Discovery Protocol (LLDP) is a standardized Layer 2 protocol that enables network devices to announce information about themselves to directly connected neighbors, facilitating network topology discovery and device identification in multi-vendor environments. The protocol uses Ethernet frames with special multicast destination MAC addresses to ensure frames don't propagate beyond immediate neighbors, and includes mandatory TLVs (Type-Length-Values) like chassis ID, port ID, and TTL alongside optional ones for extended information.
TCG083: Superintelligence for Everyone: Who Actually Holds the Power?
Three technology experts discuss Mark Zuckerberg's manifesto on distributed superintelligence, examining whether his promises of universal access and individual empowerment align with infrastructure realities. They conclude that while decentralized AI is theoretically safer than centralized control, the manifesto fails to account for human complexity, existing inequalities, and the enormous capital requirements that will likely concentrate power rather than distribute it.