Showing posts with label AirTight. Show all posts
Showing posts with label AirTight. Show all posts

Tuesday, July 18, 2017

One week to MFD2: What's in store


We are one week away from the kickoff of Mobility Field Day 2, one of those wireless and mobility focused events from the folks over at Gestalt IT and techfieldday.com.

I’m ecstatic about the lineup for MFD2.  It’s a number of folks whom I’m lacking knowledge in, have interesting products and viewpoints and those that I haven’t heard a ton from.  I just want to take a minute to talk about who’s coming and what I’m excited to hear about. 

Overall, MFD has a cloud and data analytics theme this year.   The companies all have cloud focused products and services.  The push to bring data analytics into our wireless solution sets is really becoming noticeable.

Tuesday, September 2, 2014

Airtight and Scrape: An Interesting Social Wifi Use Case

Social Wifi is one of those polarizing topics where people are either "Meh, I don't care," or "OMG, NOOOOO!"

At the latest Wireless Field Day, I had the pleasure of meeting Drew Lentz (@Wirelessnerd) who I've interacted with over Twitter for a couple years.  At Airtight, he was presenting Scrape, an application and use case for social Wi-Fi.  There's a lot to like about Scrape.  One is that you trade your social media information for a better experience.




Thursday, February 27, 2014

Airtight Networks: A look at WIPS Part 2 - Over the Air

So in Part 1 of this series on Airtight WIPS, we looked at how Airtight determines if an AP is rogue, or an "on-network rogue" by some vendors definition.  Now that we have found an AP is plugged into my network, what do I do with it.  In Airtight, we can quarantine the rogue AP, meaning we will try to prevent clients from associating to it.

In looking at what the Airtight system is doing, I decided to leverage my 1 year eval of Omnipeek aquired from the #WLPC conference.  Thanks @KeithRParsons for putting this on.
But before we look at what Airtight is doing to protect me, let's take a baseline.  Just an example of our client associating to this 



Here you can see a pretty textbook capture of the authentication/association process of "Jake's iPhone 5S" to my survey-5 SSID (open).

Now let's engage the quarantine of this rogue AP.  For this example, we are going to manually quarantine one of my rogue APs.  I chose manual just to ensure I am not accidentally containing any of my home networks and impacting my wife during testing.  Here is a quick screenshot of me doing this.  It's a pretty simple process, just select the rogue AP and clicking the Quarantine button.



Now that we are protecting my clients from the big bad "survey-5" rogue network, I'm going to repeat the process.



So for starters we see a deauthentication frame after both the Association Request and Response.  Let's look at the Deauth sent just after the Association request. The first indication I see is that the deauth frame was sent at 6Mbps, whereas in the previous example, all the management frames were sent at 12Mbps  This tells me this is the Airtight AP sending this frame and spoofing the rogue SSID. Now lets look at the details of this packet:

So the Airtight AP sent a broadcast de-authentication packet spoofed from the rogue SSID.  This is fine since A. this rogue is on my network and B. I've decided to quarantine it.  I was half expecting to see a unicast deauth, but broadcast works fine in this scenario.
Now let's look at the deauthentication that occurs right after the association response.  This time it appears that the deauth is coming from my iPhone.  Notice again that it is sent at 6Mbps.



We can see that the Airtight is now pretending to be my iPhone, saying that my iPhone has decided to leave the rogue SSID.  I honestly didn't expect this, but it totally makes sense.  In addition to make sure the client has left, it makes sense we should also send AP a deauth so it ends the clients session, ensuring the client is dropped if it doesn't listen to the deauth message.  Comparing the signal strength to my client



We see 22dbm difference, so I'm positive that this packet isn't coming from my phone, which is very close to the capture adapter.  Both the rogue and the Airtight AP are in the lab about 30 feet away.
As a side note, I did see some odd behavior on my iPhone during the deauth.  Instead of just disconnecting, the iPhone displayed a PSK entry field, even though this is an open SSID.


I didn't see the same behavior on my windows laptop, so this may be some Apple specific behavior.  Hopefully one of the Apple guys reads this and leaves a comment (in my dreams).
My windows 7 laptop was able to connect to the AP.  But while I was able to establish a connection, it was very short-lived.  We see the Airtight change gears and send some unicast deauth packets to both the client and AP.
Shortly after connecting, we see omnipeek detect a wireless duration attack, which just appears to be a CTS to self with a very large duration field:


After we this, my laptop starts probing and tries to associate again.  We see the same deauth results and the duration attack is repeated with a different NAV value occurs and the laptop gives up disconnects.  The Airtight appears to say, well if you won't listen to me, I'll just use the duration attack to reduce your ability to do anything on this WLAN until you give up.


I'm sure there are some more methods to the Airtight WIPS.  I know I've heard them speak on ARP poisoning as one of the tools in their toolbelt, but this post is running long as it is. I'm very impressed by Airtights ability to contain rogue clients and access points.  They've also done a great job making the classification of networks easy to manage.  In the next part of this series, I'm going to look at some common scenarios that I've found in my travels as a wireless engineer.  I would consider these scenarios commonplace and they are not designed as ways to "beat" WIPS, but to show off how well the Airtight system combats common rogue technologies and attacks against WLANs.

For Part 3: I'm going to round up some gear and put together some typical rogue AP type scenarios and show how the Airtight system defends and protects your clients.

Sunday, February 16, 2014

Airtight Networks: A look at WIPS Part 1: Over the Wire

When it comes to security, I have a personal motto: Think maliciously, act responsibly.  I really enjoy trying to manipulate clients, exploiting behavior and finding ways to prevent it in the "real world".

For protecting wireless networks in the "real world" one of the best tools is is WIPS.  Word on the street is that the Airtight solution is pretty good.  The presentation by Rick Farina at Wireless Field Day 6 was fun for me.  Rick is a great presenter and brought a lot of fun and energy to a security presentation.  For more on the WFD6 presentation, check out what fellow delegate Lee Badman wrote on his personal blog: http://wirednot.wordpress.com/2014/02/02/airtight-networks-rising/

Also watch his presentation here:

This is the first of a few posts on Airtight Networks WIPS solution.  Part 1 will cover how Airtight does rogue detection, Part 2 will cover containment and OTA communication and Part 3 will cover common Rogue scenarios and look at how

*I will note that Airtight gave me a C55 AP during my visit during WFD5.  While I'm grateful to them for this, these posts are my own opinion and not influenced by their generosity.



Coming from the Cisco world, I see that Airtight takes a very different approach to identifying on-network rogues. Instead of trying to correlate Wi-Fi traffic to wired traffic by listening on the wire (Rogue Detector), scanning CAM tables on switches, or trying to connect to open access points and sending traffic towards the controller (RLDP),  Airtight sends broadcast (or potentially unicast) frames on a vlans connected to the Sensor/AP and then listens to see if those frames are ever sent over the air.

Let's look at the wired side of my Airtight C55 AP.  For example, here the mac addresses from my WIPS mode AP on my network:


You'll notice that there's the management mac and the rest are mac addresses created by the WIPS-mode AP, one for each vlan that we are doing WIPS on.  Here is what I have my AP configured for:

*Note, VLAN125 is present, just not in the picture.


Spanning the port on the Airtight AP, I'm able to capture some of the packets coming from the WIPS-AP.
For simplicity, i wrote a display filter to clean up the data only from the Airtight AP:

(eth.src > f2:91:4a:7f:00:00 and eth.src < f2:91:4a:7f:ff:ff)



You can see it does a lot of GARP for addresses on the VLANs I am monitoring.  I also observed it sending DHCP requests on the VLANs configured as well:


So what does this give us?  Well, by sending these L2 broadcast messages out, the hope is that a rogue (on network) AP will hear the L2 broadcast and forward this traffic out to clients over the air.  Once this happens, the WIPS wireless radio will hear the packet and be able to see that it is from itself.  This allows the Airtight system to tell that an AP is connected to the network.  From here we can Airtight take action against this rogue network/clients connecting to this network.

What's next?  In part 2 of this series, I'm going to look at how the Airtight WIPS prevents clients from connecting to a Rogue AP, as well as looking at some of the options settings.  For Part 3, I'm going to try my hand at some common scenarios to see where the Airtight system works and where it does.

Tuesday, January 28, 2014

Onward to Wireless Field Day 6

So it's time for Wireless Field Day 6, and I don't think I finished a quarter of the blogs I wanted to write for WFD5.  Most of you know that I have been head down studying for my CCIE-W which escaped me for the second time earlier this month.  That has eaten up a bunch of my blogging time, but no excuses, I will find more time to talk about the WFD vendors this time around.

Monday, July 29, 2013

The Next Adventure: Wireless Field Day 5

So in just over 8 days I will be heading to San Jose for Wireless Field Day 5.  I've been a long time follower of the Tech Field Day events, it has been a great way for me to gain exposure to other parts of the industry that I don't get in my dayjob.  I'm very indebted to Stephen and my fellow delegates to inviting me to this event.  In addition to getting to meet some of the best professionals in the industry, I get to see solutions from a lot of different vendors and get to directly interact with them. Stephen and the Tech Field day super-crew have a pretty exciting line-up of sponsors for us to meet.

We have a 5 AP vendors coming:

Motorola and Aerohive have been WFD sponsors before, and I've gone back and reviewed their presentation.  Devin Akin donated some Aerohive lab gear to me last year and I've enjoyed putting it through its paces.  I'm pretty comfortable with their solution and can't wait to see what they have coming.  For Xirrus, Meru and Airtight, I've been digging through their product manuals and marketing material and have a laundry list of questions.  

The next category would be what I would call "Overlay Solutions."
  • 7Signal
    • Wireless Performance and Qualiity of Experience benchmarking system.
  • Fluke Networks
    • Spectrum overlay solution
7Signal as a company wasn't even on my radar 6 months ago.  From the material they have posted on the web, as well as some stuff sent to me by Veli-Pekka via Twitter, I hope to have a pretty good overview of the solution before heading to WFD.  Essentially it's on overlay solution that you can define performance and Quality of Experience (QoE) metrics in and their hardware actively associates and tracks the metrics across your wireless networks.  I've included Fluke here due to their overlay solution as well, but I primarily look at Fluke as a tools vendor.  Without knowing what Fluke intends to bring for Show-and-Tell, I'm including them in this category as well.


And last, but not least we have our wireless tools vendors. This is the like 3 tool vendors I want to see. 
  • Fluke Networks
    • Wireless Survey/Planning Tools, Troubleshooting Tools
  • Metageek
    • Spectrum Analysis and Visualization, Wireless Packet Analysis
  • Wildpackets
    • Packet Capture and Analysis

Some of the most valuable tools in my toolbag come from these vendors.   I use Planner/Surveyor as my design tool and it works for my needs. I have tested some of Fluke's other tools like their OneTouch AT. Even in the Beta, it was a tool with a lot of potential.  So there's lot of things I'm hoping to hear from the folks at Fluke.  Fellow WFD5 delegate Ryan Adzima has a post on their OneTough over at  NoStringsAttachedShow.com

I'm a pretty big fan of the Metageek hardware and software.  In addition to building some of the best Spectrum Visualization software in the market, they come from my hometown of Boise Idaho (Go Broncos!).  I utilize my Wi-Spy more than any other product in my toolbag by a long shot.

Omnipeek from Wildpackets is a solution I've looked at a number of times.  It's the gold standard for packet analysis from both a wired and wireless perspective and they have the solution that will make analysis work even as 802.11ac moves to speeds that will crush our USB 3.0 buses.

Overall, I am really excited to have the opportunity to join the rest of the delegates.  There is a small amount of nervousness surrounding this event for me personally.  For starters, I'm new to the TFD family.  I have met around half of the other delegates at other industry events.  I'm not an industry veteran, having just celebrated my 4th year in the networking industry (hey now, no young-in jokes).  And let's face it, there isn't a CCIE/CWNE number after my name.  But I do have a passion for wireless, networking, and really enjoy the opportunity to participate in the dialog at an event like WFD5.

I hope everyone logs in and participates live using the #WFD5 hashtag on twitter.  I've been asking questions using this method since I started following the delegates on Twitter during TFD3 , and have had delegates ask my questions to the sponsors on more than a few occasions.  You can watch live at http://techfieldday.com/event/wfd5/