Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

Mitigating Wireless Chokepoints

by RSS Stefanie Hoffman  |  June 14, 2012  |  Category: Industry Trends & News

*Metaphors aside, it probably goes without saying that office workers are running on more bandwidth these days. More than ever, in between bouts of actual office productivity, desk jockeys are using their systems and mobile devices to shop, play games, stream movies, music and more.

But what happens when personal entertainment habits begin to trump actual work-related office apps when it comes to competing for office bandwidth? It could mean an important executive videoconference call only functions in fits and spurts. Or perhaps it’s elongated wait times during a WebEx presentation that’s being viewed by 100 potential customers.

On a wired network, this problem can be easily rectified by throwing more bandwidth at the problem and providing LAN users dedicated gigabit links to their desktops to remove competition at the chokepoints.  In catastrophic situations and worm outbreaks, IT personnel know exactly which Ethernet cable to pull.  But it gets a little trickier when a wireless network is inserted into the equation.

“The requirements have changed in terms of data needs,” says Koroush Saraf, Fortinet senior director of product management. “The challenge is that, as more devices are getting on wireless, especially with the proliferation of new devices such as tablets and smartphones, wireless has gone from being a nice to have, to essentially a necessity.”

But problems arise when everyone is competing for the same piece of the wireless network pie.

“The new wireless phenomenon harkens back to the early 90s where we had Ethernet hubs,” Saraf says. “The problem with those hubs was that as network demands increased, there was not enough bandwidth to carry all the data that enterprise wanted to carry.”

Fifteen years ago, an organization’s wired network could add throughput by transitioning away from shared to switched Ethernet to provide dedicated bandwidth to each user and increase performance.

“With wireless, because it is always a shared space, that approach doesn’t apply,” Saraf added.

In fact, the overall impact to wireless networks is that they often become bogged down or “choked,” resulting in latency that can cost organizations precious productivity time, and translates into an endless source of frustration for workers.

The good news is that there are ways to mitigate the problems created from the increasing slew of bandwidth-hungry applications and armies of app-happy users in a wireless environment, Saraf says.

To meet increased bandwidth demands, organizations could create more access points and user channels—an endeavor that promises to be costly, time consuming and challenging to troubleshoot for any company.

A more cost effective approach involves visibility and awareness provided by some type of application control technology, Saraf maintains. Organizations need a way to assess which applications are traveling over the wireless network as a basis for setting subsequent rules and policies. Once that traffic is assessed, IT administrators will then need the tools to allocate it to the appropriate channels. For example, if a user’s WebEx or remote desktop traffic is hampered because someone else is watching a Netflix movie, then rules could be created that would prohibit or limit movies and games during business hours and give strict priority to business traffic.

“In the old days, it was common for people to say the network is slow, but we hear that less and less for wired LAN” Saraf says. “With wireless, people say the network is slow because of all the stuff that’s happening on the network. IT has to ensure the right bandwidth is being allocated to the right person and right application.”

Visibility is also an important factor when mapping out wireless network strategy. Being able to see into every corner of their IT environment allows an organization to truly assess what is running on their network and ensure unfettered access to business-critical traffic while restricting or limiting all other unnecessary apps.

“The ability to detect all of the applications running on the network helps IT see what kind of applications are coming through and who is sending them,” Saraf says. “Built-in application packets can be applied that will raze unwanted applications and keep bandwidth to business applications.”

If someone takes exception to those rules, then IT needs to have the tools readily available to allow a particular user, or group, to do things differently, he adds.

The same concept applies to malicious applications, often accessed unintentionally, by workers on the corporate network. Historically with wired networks, organizations could mitigate security issues by pulling a cable. But over the wireless network, organizations will need to rely on blacklisting and location tracking technologies that will automatically block any harmful traffic and pinpoint the location of the offender. Meanwhile, intrusion prevention is also crucial in detecting any abnormal behavior–such as a huge spike in traffic that would spur a DDoS attack–and mitigating threats in real time.

“To be able to have high confidence in application visualization, the wireless controller needs to employ DPI deep packet inspection technology, and apply packet shaping to each wireless session.  Also a dynamic dashboard is needed to point out the top sessions and users for your management,” Saraf says. “It’s more than just IP connectivity.”

by RSS Stefanie Hoffman  |  June 14, 2012  |  Category: Industry Trends & News
Tags: deep packet inspection DPI Netflix WebEx wireless chokepoints
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • June 2013 8
  • May 2013 15
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

hacking challenge Mobile Security trojan privacy iphone derek manky google Anti-Spam FortiGate Zeus UTM SpyEye Antivirus Mac OS X symbianos android webinar challenge botnet virut stuxnet Anonymous reversing bredolab hashdays Firewall adobe Security Research zitmo Fortinet sms exploit conference mobile phones BYOD Malware cybercrime mobile phone reverse engineering facebook Patch Tuesday apple symbian Windows mobile malware mobile Threat Landscape Cryptography symbos/yxes microsoft network security