Request for Comments: 4118 Intel Corp.
Category: Informational P. Zerfos
UCLA
E. Sadot
Avaya
June 2005
Architecture Taxonomy for
Control and Provisioning of Wireless Access Points (CAPWAP)
Status of This Memo
This memo provides information for the Internet community. It does
not specify an Internet standard of any kind. Distribution of this
memo is unlimited.
Copyright Notice
Copyright (C) The Internet Society (2005).
Abstract
This document provides a taxonomy of the architectures employed in
the existing IEEE 802.11 products in the market, by analyzing
Wireless LAN (WLAN) functions and services and describing the
different variants in distributing these functions and services among
the architectural entities.
Table of Contents
1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2
1.1. IEEE 802.11 WLAN Functions . . . . . . . . . . . . . . 3
1.2. CAPWAP Functions . . . . . . . . . . . . . . . . . . . 5
1.3. WLAN Architecture Proliferation . . . . . . . . . . . 6
1.4. Taxonomy Methodology and Document Organization . . . . 8
2. Conventions . . . . . . . . . . . . . . . . . . . . . . . . 9
3. Definitions . . . . . . . . . . . . . . . . . . . . . . . . 9
3.1. IEEE 802.11 Definitions . . . . . . . . . . . . . . . 9
3.2. Terminology Used in This Document . . . . . . . . . . 11
3.3. Terminology Used Historically but Not Recommended . . 13
4. Autonomous Architecture . . . . . . . . . . . . . . . . . . 13
4.1. Overview . . . . . . . . . . . . . . . . . . . . . . 13
4.2. Security . . . . . . . . . . . . . . . . . . . . . . . 14
5. Centralized WLAN Architecture . . . . . . . . . . . . . . . 15
5.1. Interconnection between WTPs and ACs . . . . . . . . . 16
5.2. Overview of Three Centralized WLAN Architecture
Variants . . . . . . . . . . . . . . . . . . . . . . . 17
5.3. Local MAC . . . . . . . . . . . . . . . . . . . . . . 19
5.4. Split MAC . . . . . . . . . . . . . . . . . . . . . . 22
5.5. Remote MAC . . . . . . . . . . . . . . . . . . . . . . 27
5.6. Comparisons of Local MAC, Split MAC, and Remote MAC. . 27
5.7. Communication Interface between WTPs and ACs . . . . . 29
5.8. Security . . . . . . . . . . . . . . . . . . . . . . . 29
5.8.1. Client Data Security . . . . . . . . . . . . . 30
5.8.2. Security of Control Channel between
the WTP and AC . . . . . . . . . . . . . . . . 30
5.8.3. Physical Security of WTPs and ACs . . . . . . 31
6. Distributed Mesh Architecture . . . . . . . . . . . . . . . 32
6.1. Common Characteristics . . . . . . . . . . . . . . . . 32
6.2. Security . . . . . . . . . . . . . . . . . . . . . . . 33
7. Summary and Conclusions . . . . . . . . . . . . . . . . . . 33
8. Security Considerations . . . . . . . . . . . . . . . . . . 36
9. Acknowledgements . . . . . . . . . . . . . . . . . . . . . . 37
10. Normative References . . . . . . . . . . . . . . . . . . . . 39
1. Introduction
As IEEE 802.11 Wireless LAN (WLAN) technology matures, large scale
deployment of WLAN networks is highlighting certain technical
challenges. As outlined in [2], management, monitoring, and control
of large number of Access Points (APs) in the network may prove to be
a significant burden for network administration. Distributing and
maintaining a consistent configuration throughout the entire set of
APs in the WLAN is a difficult task. The shared and dynamic nature
of the wireless medium also demands effective coordination among the
APs to minimize radio interference and maximize network performance.
Network security issues, which have always been a concern in WLANs,
present even more challenges in large deployments and new
architectures.
Recently many vendors have begun offering partially proprietary
solutions to address some or all of the above mentioned problems.
Since interoperable systems allow for a broader choice of solutions,
a standardized interoperable solution addressing the aforementioned
problems is desirable. As the first step toward establishing
interoperability in the market place, this document provides a
taxonomy of the architectures employed in existing WLAN products. We
hope to provide a cohesive understanding of the market practices for
the standard bodies involved (including the IETF and IEEE 802.11).
This document may be reviewed and utilized by the IEEE 802.11 Working
Group as input in defining the functional architecture of an AP.
1.1. IEEE 802.11 WLAN Functions
The IEEE 802.11 specifications are wireless standards that specify an
"over-the-air" interface between a wireless client Station (STA) and
an Access Point (AP), and also among wireless clients. 802.11 also
describes how mobile devices can associate into a basic service set
(BSS). A BSS is identified by a basic service set identifier (BSSID)
or name. The WLAN architecture can be considered as a type of ’cell’
architecture, in which each cell is the Basic Service Set (BSS), and
each BSS is controlled by the AP. When two or more APs are connected
via a broadcast layer 2 network and all are using the same SSID, an
extended service set (ESS) is created.
The architectural component used to interconnect BSSs is the
distribution system (DS). An AP is an STA that provides access to
the DS by providing DS services, as well as acting as an STA.
Another logical architectural component, portal, is introduced to
integrate the IEEE 802.11 architecture with a traditional wired LAN.
It is possible for one device to offer both the functions of an AP
and a portal.
IEEE 802.11 does not specify the details of DS implementations
explicitly. Instead, the 802.11 standard defines services that
provide functions that the LLC layer requires for sending MAC Service
Data Units (MSDUs) between two entities on the network. These
services can be classified into two categories: the station service
(SS) and the distribution system service (DSS). Both categories of
service are used by the IEEE 802.11 MAC sublayer. Station services
consist of the following four services:
o Authentication: Establishes the identity of one station as a
member of the set of stations that are authorized to associate
with one another.
o De-authentication: Voids an existing authentication relationship.
o Confidentiality: Prevents the content of messages from being read
by others than the intended recipients.
o MSDU Delivery: Delivers the MAC service data unit (MSDU) for the
stations.
Distribution system services consist of the following five
services:
o Association: Establishes Access Point/Station (AP/STA) mapping and
enables STA invocation of the distribution system services.
o Disassociation: Removes an existing association.
o Reassociation: Enables an established association (between AP and
STA) to be transferred from one AP to another or the same AP.
o Distribution: Provides MSDU forwarding by APs for the STAs
associated with them. MSDUs can be either forwarded to the
wireless destination or to the wired (Ethernet) destination (or
both) using the "Distribution System" concept of 802.11.
o Integration: Translates the MSDU received from the Distribution
System to a non-802.11 format and vice versa. Any MSDU that is
received from the DS invokes the ’Integration’ services of the DSS
before the ’Distribution’ services are invoked. The point of
connection of the DS to the wired LAN is termed as ’portal’.
Apart from these services, the IEEE 802.11 also defines additional
MAC services that must be implemented by the APs in the WLAN. For
example:
o Beacon Generation
o Probe Response/Transmission
o Processing of Control Frames: RTS/CTS/ACK/PS-Poll/CF-End/CF-ACK
o Synchronization
o Retransmissions
o Transmission Rate Adaptation
o Privacy: 802.11 Encryption/Decryption
In addition to the services offered by the 802.11, the IEEE 802.11 WG
is also developing technologies to support Quality of Service
(802.11e), Security Algorithms (802.11i), Inter-AP Protocol (IAPP, or
802.11F -- recommended practice) to update APs when a STA roams from
one BSS to another, Radio Resource Measurement Enhancements
(802.11k), etc.
IEEE 802.11 does not specify exactly how these functions are
implemented, nor does it specify that they be implemented in one
physical device. It only requires that the APs and the rest of the
DS together implement all these services. Typically, vendors
implement not only the services defined in the IEEE 802.11 standard,
but also a variety of value-added services or functions, such as load
balancing support, QoS, station mobility support, and rogue AP
detection. What becomes clear from this document is that vendors
take advantage of the flexibility in the 802.11 architecture, and
have come up with many different flavors of architectures and
implementations of the WLAN services.
Because many vendors choose to implement these WLAN services across
multiple network elements, we want to make a clear distinction
between the logical WLAN access network functions and the individual
physical devices by adopting different terminology. We use "AP" to
refer to the logical entity that provides access to the distribution
services, and "WTP" (Wireless Termination Point) to the physical
device that allows the RF antenna and 802.11 PHY to transmit and
receive station traffic in the BSS network. In the Centralized
Architecture (see section 5), the combination of WTPs with Access
Controller (AC) implements all the logical functions. Each of these
physical devices (WTP or AC) may implement only part of the logical
functions. But the DS, including all the physical devices as a
whole, implements all or most of the functions.
1.2. CAPWAP Functions
To address the four problems identified in [2] (management,
consistent configuration, RF control, security) additional functions,
especially in the control and management plane, are typically offered
by vendors to assist in better coordination and control across the
entire ESS network. Such functions are especially important when the
IEEE 802.11 WLAN functions are implemented over multiple entities in
a large scale network, instead of within a single entity. Such
functions include:
o RF monitoring, such as Radar detection, noise and interference
detection, and measurement.
o RF configuration, e.g., for retransmission, channel selection,
transmission power adjustment.
o WTP configuration, e.g., for SSID.
o WTP firmware loading, e.g., automatic loading and upgrading of WTP
firmware for network wide consistency.
o Network-wide STA state information database, including the
information needed to support value-added services, such as
mobility and load balancing.
o Mutual authentication between network entities, e.g., for AC and
WTP authentication in a Centralized WLAN Architecture.
The services listed are concerned with the configuration and control
of the radio resource (’RF Monitoring’ and ’RF Configuration’),
management and configuration of the WTP device (’WTP Configuration’,
’WTP Firmware upgrade’), and also security regarding the registration
of the WTP to an AC (’AC/WTP mutual authentication’). Moreover, the
device from which other services, such as mobility management across
subnets and load balancing, can obtain state information regarding
the STA(s) associated with the wireless network, is also reported as
a service (’STA state info database’).
The above list of CAPWAP functions is not an exhaustive enumeration
of all additional services offered by vendors. We included only
those functions that are commonly represented in the survey data, and
are pertinent to understanding the central problem of
interoperability.
Most of these functions are not explicitly specified by IEEE 802.11,
but some of the functions are. For example, the control and
management of the radio-related functions of an AP are described
implicitly in the MIB, such as:
o Channel Assignment
o Transmit Power Control
o Radio Resource Measurement (work is currently under way in IEEE
802.11k)
The 802.11h [5] amendment to the base 802.11 standard specifies the
operation of a MAC management protocol to accomplish the requirements
of some regulatory bodies (principally in Europe, but expanding to
others) in the following areas:
o RADAR detection
o Transmit Power Control
o Dynamic Channel Selection
1.3. WLAN Architecture Proliferation
This document provides a taxonomy of the WLAN network architectures
developed by the vendor community in an attempt to address some or
all of the problems outlined in [2]. As the IEEE 802.11 standard
purposely avoids specifying the details of DS implementations,
different architectures have proliferated in the market. While all
these different architectures conform to the IEEE 802.11 standard as
a whole, their individual functional components are not standardized.
Interfaces between the network architecture components are mostly
proprietary, and there is no guarantee of cross-vendor
interoperability of products, even within the same family of
architectures.
To achieve interoperability in the market place, the IETF CAPWAP
working group is first documenting both the functions and the network
architectures currently offered by the existing WLAN vendors. The
end result is this taxonomy document.
After analyzing more than a dozen different vendors’ architectures,
we believe that the existing 802.11 WLAN access network architectures
can be broadly categorized into three distinct families, based on the
characteristics of the Distribution Systems that are employed to
provide the 802.11 functions.
o Autonomous WLAN Architecture: The first architecture family is the
traditional autonomous WLAN architecture, in which each WTP is a
single physical device that implements all the 802.11 services,
including both the distribution and integration services, and the
portal function. Such an AP architecture is called Autonomous
WLAN Architecture because each WTP is autonomous in its
functionality, and no explicit 802.11 support is needed from
devices other than the WTP. In such architecture, the WTP is
typically configured and controlled individually, and can be
monitored and managed via typical network management protocols
like SNMP. The WTPs are the traditional APs with which most
people are familiar. Such WTPs are sometimes referred to as "Fat
APs" or "Standalone APs".
o Centralized WLAN Architecture: The second WLAN architecture family
is an emerging hierarchical architecture utilizing one or more
centralized controllers for managing a large number of WTP
devices. The centralized controller is commonly referred to as an
Access Controller (AC), whose main function is to manage, control,
and configure the WTP devices that are present in the network. In
addition to being a centralized entity for the control and
management plane, it may also become a natural aggregation point
for the data plane since it is typically situated in a centralized
location in the wireless access network. The AC is often co-
located with an L2 bridge, a switch, or an L3 router, and may be
referred to as Access Bridge or Access Router in those particular
cases. Therefore, an Access Controller could be either an L3 or
L2 device, and is the generic term we use throughout this
document. It is also possible that multiple ACs are present in a
network for purposes of redundancy, load balancing, etc. This
architecture family has several distinct characteristics that are
worth noting. First, the hierarchical architecture and the
centralized AC affords much better manageability for large scale
networks. Second, since the IEEE 802.11 functions and the CAPWAP
control functions are provided by the WTP devices and the AC
together, the WTP devices themselves may no longer fully implement
the 802.11 functions as defined in the standards. Therefore, it
can be said that the full 802.11 functions are implemented across
multiple physical network devices, namely, the WTPs and ACs.
Since the WTP devices only implement a portion of the functions
that standalone APs implement, WTP devices in this architecture
are sometimes referred to as light weight or thin APs.
o Distributed WLAN Architecture: The third emerging WLAN
architecture family is the distributed architecture in which the
participating wireless nodes are capable of forming a distributed
network among themselves, via wired or wireless media. A wireless
mesh network is one example within the distributed architecture
family, where the nodes themselves form a mesh network and connect
with neighboring mesh nodes via 802.11 wireless links. Some of
these nodes also have wired Ethernet connections acting as
gateways to the external network.
1.4. Taxonomy Methodology and Document Organization
Before the IETF CAPWAP working group started documenting the various
WLAN architectures, we conducted an open survey soliciting WLAN
architecture descriptions via the IETF CAPWAP mailing list. We
provided the interested parties with a common template that included
a number of questions about their WLAN architectures. We received 16
contributions in the form of short text descriptions answering those
questions. 15 of them are from WLAN vendors (AireSpace, Aruba,
Avaya, Chantry Networks, Cisco, Cranite Systems, Extreme Networks,
Intoto, Janusys Networks, Nortel, Panasonic, Trapeze, Instant802,
Strix Systems, Symbol) and one from the academic research community
(UCLA). Out of the 16 contributions, one describes an Autonomous
WLAN Architecture, three are Distributed Mesh Architectures, and the
remaining twelve entries represent architectures in the family of the
Centralized WLAN Architecture.
The main objective of this survey was to identify the general
categories and trends in WLAN architecture evolution, discover their
common characteristics, and determine what is performed differently
among them and why. In order to represent the survey data in a
compact format, a "Functional Distribution Matrix" is used in this
document, (mostly in the Centralized WLAN architecture section), to
tabulate the various services and functions in the vendors’
offerings. These services and functions are classified into three
main categories:
o Architecture Considerations: The choice of the connectivity
between the AC and the WTP. The design choices regarding the
physical device on which processing of management, control, and
data frames of the 802.11 takes place.
o 802.11 Functions: As described in Section 1.1.
o CAPWAP Functions: As described in Section 1.2.
For each one of these categories, the mapping of each individual
function to network entities implemented by each vendor is shown in
tabular form. The rows in the Functional Distribution Matrix
represent individual functions that are organized into the above
mentioned three categories. Each column of the Matrix represents one
vendor’s architecture offering in the survey data. See Figure 7 as
an example of the Matrix.
This Functional Distribution Matrix is intended for the sole purpose
of organizing the architecture taxonomy data, and represents the
contributors’ views of their architectures from an engineering
perspective. It does not necessarily imply that a product exists or
will be shipped, nor an intent by the vendor to build such a product.
The next section provides a list of definitions used in this
document. The rest of this document is organized around the three
broad WLAN architecture families that were introduced in Section 1.3.
Each architecture family is discussed in a separate section. The
section on Centralized Architecture contains more in-depth details
than the other two families, largely due to the large number of the
survey data (twelve out of sixteen) collected that fall into the
Centralized Architecture category. Summary and conclusions are
provided at the end to highlight the basic findings from this
taxonomy exercise.
2. Conventions
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
document are to be interpreted as described in RFC 2119 [3].
3. Definitions
3.1. IEEE 802.11 Definitions
Station (STA): A device that contains an IEEE 802.11 conformant
medium access control (MAC) and physical layer (PHY) interface to the
wireless medium (WM).
Access Point (AP): An entity that has station functionality and
provides access to distribution services via the wireless medium (WM)
for associated stations.
Basic Service Set (BSS): A set of stations controlled by a single
coordination function.
Station Service (SS): The set of services that support transport of
medium access control (MAC) service data units (MSDUs) between
stations within a basic service set (BSS).
Distribution System (DS): A system used to interconnect a set of
basic service sets (BSSs) and integrated local area networks (LANs)
to create an extended service set (ESS).
Extended Service Set (ESS): A set of one or more interconnected basic
service sets (BSSs) with the same SSID and integrated local area
networks (LANs), which appears as a single BSS to the logical link
control layer at any station associated with one of those BSSs.
Portal: The logical point at which medium access control (MAC)
service data units (MSDUs) from a non-IEEE 802.11 local area network