Network Working Group B. O'Hara
Request for Comments: 3990 P. Calhoun
Category: Informational Airespace
J. Kempf
Docomo Labs USA
February 2005
Configuration and Provisioning for Wireless Access Points (CAPWAP) Problem Statement
1. Introduction
With the approval of the 802.11 standard by the IEEE in 1997, wireless LANs (WLANs) began a slow entry into enterprise networks. The limited data rates of the original 802.11 standard, only 1 and 2 Mbps, limited the widespread adoption of the technology. 802.11 found wide deployment in vertical applications, such as inventory management, point of sale, and transportation management. Pioneering enterprises began to deploy 802.11, mostly for experimentation.
O'Hara, et al. Informational [Page 1]
RFC 3990 CAPWAP Problem Statement February 2005 2. Problem StatementLarge WLAN deployments introduce several problems. First, each AP is an IP-addressable device requiring management, monitoring, and control. Deployment of a large WLAN will typically double the number of network infrastructure devices that require management. This presents a significant additional burden to the network administration resources and is often a hurdle to adoption of wireless technologies, particularly because the configuration of each access point is nearly identical to the next. This near-sameness often leads to misconfiguration and improper operation of the WLAN.
O'Hara, et al. Informational [Page 2]
RFC 3990 CAPWAP Problem Statement February 2005
In currently fielded devices, the physical portions of this network system are one or more 802.11 access points (APs) and one or more central control devices, alternatively described as controllers (or as access controllers, ACs). Ideally, a network designer would be able to choose one or more vendors for the APs and one or more vendors for the central control devices in sufficient numbers to design a network with 802.11 wireless access to meet the designer's requirements.
3. Security Considerations
The devices used in WLANs control network access and provide for the delivery of packets between hosts using the WLAN and other hosts on the WLAN or elsewhere on the Internet. Therefore, the functions for control and provisioning of wireless access points, require protection to prevent misuse of the devices.
O'Hara, et al. Informational [Page 3]
RFC 3990 CAPWAP Problem Statement February 2005
To provide comprehensive radio coverage, APs are often installed in locations that are difficult to secure. The CAPWAP architecture may reduce the consequences of a stolen AP. If high-value secrets, such as a RADIUS shared secret, are stored in the AC, then the physical loss of an AP does not compromise these secrets. Further, the AC can easily be located in a physically secure location. Of course, concentrating all the high-value secrets in one place makes the AC an attractive target, and strict physical, procedural, and technical controls are needed to protect the secrets.
O'Hara, et al. Informational [Page 4]
RFC 3990 CAPWAP Problem Statement February 2005
Full Copyright Statement