Beruflich Dokumente
Kultur Dokumente
www.huawei.com/enterprise
Huawei Confidential
Page 2
Wireless STAs drive WIFI roaming. A wireless STA determines whether to enable roaming based on various conditions, for example, signal strength and quality, number of missed
Huawei Confidential
Page 3
AC6605
Campus Network
PoE switch
Wired and wireless networks cover classrooms and offices.
Access switch AP6010 SN/DN
Convergence switch
When a wireless station (STA) moves (for example, in the figure on the left, the STA moves from A to B in the library, or moves to another area ( to C on the playground), WIFI PoE switch products must support roaming to ensure that Wireless networks cover the real-time services (for example, video and campus and playground. voice services) are not interrupted. WIFI Roaming Classification
AP 6610DN
VLAN1
VLAN2
Layer2 Roaming: If an STA moves from A to B, within the same VLAN. That is layer2 roaming. layer2 roaming applies to small enterprises that are covered only by layer2 network. Layer3 Roaming: If an STA moves from B to C on different layer3 subnets (different VLAN), that is layer3 roaming.Layer3 roaming applies to medium- or large-size enterprises that are covered by Layer3 network.
Huawei Confidential
Page 4
Notes: Some STA s cant support RSN key-cache. When they roaming to a new AP, 802.1X authentication process also need be performed and PMK information is generated again.
Huawei Confidential
Page 5
7. AC will check whether the PMK ID existing. if existing, fast roaming allowed.
AC
Old AP
AP
New AP
For users authenticated in the 802.1x mode, besides the lower-level key negotiation technology, the PMK caching technology is used so that the complex 802.1x authentication is not required after the STA switches APs, which accelerates the switchover. The following figure shows the service process of 802.1x authentication.
STA
PMK Caching
Huawei Confidential
Page 6
The process of switching to AP2 when the STA has associated with AP1 is as follows: 1) The STA cancels the association relationship with AP1, as shown in area 1 in the figure on the left. 2) The STA sends a re-association request with the AC through AP2, as shown in area 2 in the figure on the left. After the STA is associated with the AC, AC updates the user information(including VLAN information) to AP2. 3) At step3, different users have the different mechanisms : For Open users, directly communicate the data services; For WPA2/WPA PSK users, directly negotiate encryption keys with AP;
Campus network
Pre-authentication domain/Isolated domain/Postauthentication domain
AC devices AP2
AP1 1 2
VLAN 1
Switchover
VLAN 1
For 802.1X users, AC will check whether the PMK information existing according to the received PMK ID from STA. if existing, fast roaming is allowed and 802.1X authentication process is omitted. The STA directly negotiates encryption keys with AP. If not existing, 802.1X authentication process must be performed and PMK information is generated again;
Huawei Confidential
Page 7
Server area
Roaming process
The process of switching to AP2 when the STA has associated with AP1 is as follows: 1) The STA cancels the association relationship with AP1, as shown in area 1 in the figure on the left. The STA sends a re-association request with the AC through AP2, as shown in area 2 in the figure on the left. After the STA is associated with the AC, AC updates the user information(including VLAN information) to AP2. At step3, different users have the different mechanisms : For Open users, directly communicate the data services; For WPA2/WPA PSK users, directly negotiate encryption keys with AP; For 802.1X users, AC will check whether the PMK information existing according to the received PMK ID from STA. if existing, fast roaming is allowed and 802.1X authentication process is omitted. The STA directly negotiates encryption keys with AP. If not existing, 802.1X authentication process must be performed and PMK information is generated again;
4 Campus network
Pre-authentication domain/Isolated domain/Postauthentication domain
2)
3 2 AP1
AC devices AP2
3)
VLAN1
Switchover
VLAN2
SSID: HUAWEI
SSID: HUAWEI
4) While roaming is not on the same subnet, AC still regards the STA as from the original subnet (VLAN1). Ensuring the STA maintains its original IP and supports IP communication established In the centralized forwarding scenarios specified by area 4 in the figure on the left, the AC must mark roaming user messages as from pre-roaming VLAN1.
Roaming switchover
Huawei Confidential
Page 8
Thank you
www.huawei.com