Friday, September 01, 2006

Colubris not playing the game

Many people who operate 'with' the Internet, such as the poor individuals who slave away in the background to make sure you can read this blog, know of and generally abide by RFCs.

An RFC is a 'Request For Comment'. The wikipedia definition is as follows:

In computer network engineering, Request for Comments (RFC) documents are a series of memoranda encompassing new research, innovations, and methodologies applicable to Internet technologies.
Wikipedia

These RFCs assure a level of interoperability which is what makes the Internet tick. If two entities do not know how to communicate you can be assured that nothing will be achieved. RFCs offer a way for two entities to learn how to communicate with each other. Its comparable to a language dictionary.

With that in mind imagine how surprised I was when I discovered that a these Colubris CN3200 Access Controllers I'm playing with do NOT abide by the applicable RFCs. They do something that is very sinister and anti-competitive to say the least.

What they have done is alternated the values sent back to the RADIUS. "So" you might say? These two values are AcctInputOctets and AcctOutputOctets (same for packets, but that doesn't bother me as much). These values are Uploads and Downloads - everything done upon the Internet involves a combination of these two activities. The particular RFC is 2866 if you're that bored.

Now I work with Cisco and Mikrotik software and hardware. Both of which abide by the appropriate RFCs thus playing by the rules. Toss in a Colubris unit and it complicates and undoes this harmony. Now I have to run up another RADIUS box with special modifications to allow me to translate the swapped values to the correct ones in my database. A waste of time and resources when they can simply do what is expected.

Their response when I queried them about this was that "99% of their customers don't have a problem". You can guess my reaction.

My suggestion to you is that if you are in the market for Hotspot Access Controllers - avoid Colurbis. They're welcome to do innovative things but voiding industry accepted practices is unnecessary.

UPDATE:
Well that was a whole lot of time and effort for nothing. I jumped through all the hoops identifying and providing all the evidence they wanted. Compared it against Cisco accounting methods and everything.

Got a call from their Australian product engineer saying "it's a matter of interpretation". He's referring to the RFC and from what perspecting the accounting to be taken. I guess Cisco isn't a good enough de-facto standard.

They're going to try and put it through as a 'product enhancement request' but there has to be a valid business case behind it - and apparently mine isn't particularly valid - bearing the fact that data usage is what costs money in Australia, not time.

My suggestion at this stage - DO NOT USE COLUBRIS if you wish to run multiple brands of NASs with data based accounting.

FreeRADIUS Debug Output:

Output from FreeRADIUS Debug:

Cisco Router:

rad_recv: Accounting-Request packet from host 10.2.1.160:1646, id=9, length=138
NAS-IP-Address = 10.2.1.160
NAS-Port = 4294967287
NAS-Port-Type = Virtual
User-Name = "bjohns@accessezy"
Acct-Status-Type = Stop
Acct-Authentic = RADIUS
Service-Type = Framed-User
Acct-Session-Id = "00000003"
Framed-Protocol = PPP
Framed-IP-Address = 10.2.70.102
Acct-Terminate-Cause = User-Request
Acct-Input-Octets = 44538
Acct-Output-Octets = 276365
Acct-Input-Packets = 265
Acct-Output-Packets = 320
Acct-Session-Time = 61
Acct-Delay-Time = 0


Colubris CN3200 (4.1.1):

rad_recv: Accounting-Request packet from host 192.168.129.221:32770, id=181, length=219
User-Name = "bjohns@accessezy"
NAS-Port = 1
NAS-Port-Type = Wireless-802.11
NAS-Identifier = "R039-00443"
NAS-IP-Address = 192.168.129.221
Acct-Status-Type = Stop
Calling-Station-Id = "00-0B-DB-1A-F7-77"
Called-Station-Id = "00-03-52-02-98-DF"
Event-Timestamp = "Sep 13 2006 04:03:39 UTC"
Acct-Delay-Time = 0
Acct-Session-Id = "171fbc13"
Acct-Authentic = RADIUS
Acct-Session-Time = 29
Acct-Input-Octets = 218357
Acct-Input-Gigawords = 0
Acct-Input-Packets = 286
Acct-Output-Octets = 34912
Acct-Output-Gigawords = 0
Acct-Output-Packets = 212
Acct-Terminate-Cause = User-Request
Framed-IP-Address = 192.168.1.2
WISPr-Location-Name = "Colubris Networks"

Monday, August 28, 2006

That's out of the way

Well I've done it. I've successfully integrated the Colubris CN-3200 series access controller into my hotspot scripty thingy. The MSC-3200 'should' work too... I'll test that soon.

The hardest part was trying to decide on where to set the access controller type. I could have set in in the NAS table in the database which would make sense but that would mean doing something on the server side whenever you installed one of these things. So I did it on the other end. On the access controller you simply pass 'nas_brand=mikrotik/colubris' back with the rest of the user authen data. My scripts read that and tweak things in the background to suit.

The tweaks are mainly what to set in the database for the radius reply for that user and the slight modifications of the template files with the differences in login forms. I think I must have done something right for the start because doing this wasn't difficult at all.

Now I just have document the changes, make a pretty howto (not much to do there) and create suitable location content that reflects the corporate identity of accessEzy.

Wednesday, August 23, 2006

Colubris CN/MSC-3200 Access Controllers

I've been working on a hotspot backend system for the last three months and its been in production for almost two months now. Since it has been working so well they want me to adapt it for use in hotels.

The currently installed hotels use a Colubris CN-3200 or a MSC-3200 Access Controller. These units can interact with a backend service in a number of ways. Currently they use a "NOC" method where they simply pass everything to a remote server and then the remote server authenticates the user so the user never actually uses anything on the access controller itself.

The method which I use is that the access controller makes the initial connection and then passes the user through to a remote server. The remote server then passes the user back to the access controller which then authenticates against the remote server. This might sound like more effort/waste but it offers far more flexibility - for example I can have a remote web server and a separate authentication server. This is identical to how the Mikrotik RouterOS systems work.

Given this tweaking my application isn't too difficult. Just a case of either setting or detecting which access controller is in use and make the necessary adjustments to the templates and database. I should have this done in a few weeks since I have to revamp some bits to optimise the process.

It would be interesting to try some more access controller brands and see if I can achieve some across market compatibility. Although I'm happy with the RouterOS and Colubris units - together they cover pretty much every purpose I can think of.

Tuesday, August 15, 2006

Mooloolaba Beach WiFi

Completed the installation of the fourth Maroochy Hotspot site. Located at the Mooloolaba Beach caravan park it provides coverage to a large chunk of what is one of Australia's favourite tourist destinations. Google Maps link

Installation is the same as the others, however it receives its backhaul signal from us via a repeater located on top of the Raffles Resort Hotel just east of its location. Not the best situation to be in as I hate relying upon untrusted third parties for a mission critical feed. However the alternatives are limited - to run a phone line would be next to impossible and setting up a repeater point elsewhere would take time and money.

Now we have reasonable Hotspot coverage of the Mooloolaba/Maroochydore beach front. We also cover a large part of the northern Coolum beach frontage.

Mudjimba Caravan Park is still pending installation. We are talking with the owners of a few residential blocks nearby - we might be able to gain a feed from one of these locations into the park.

I have also updated the software versions running on the Mikrotik routers - they're now running 2.9.28. This new version introduces a new licensing scheme where the update period is now version based, not time based. Meaning that I can continue updating the routers up to the end of RouterOS v3 which could be 10 years from now. The old method was that you had 1 or 3 years to do updates.

Sunday, August 06, 2006

Coolum Beach Caravan Park WiFi

I can safely say that the Maroochy Council Coolum Beach Caravan Park now has wireless Internet access. Making a total of four Maroochy Parks enabled, two more to go.

The install was a bit involved as it required a separate Internet feed. We brought ADSL in to a phone point near the intended Hotspot location, set it up with a router and Access Point which transmits it to the actual Hotspot router located on the roof of a nearby building (the high point of the site). The DSL router and Access Point are located on the outside of a demountable building in a weather proof enclosure.

This saves everyone the hassle of digging trenches and running conduit and cables.

The equipment used is as follows:
Netgear DG834 ADSL Modem/Router
Senao NL-2611CB3 PLUS (Deluxe) Access Point w/5dBi antenna
WRAP2 w/8dBi planar directional and 10dBi Waveguide omni-directional antennas

Monday, July 31, 2006

The limited abilities of the Prism chipset

I've come to the conclusion that the Intersil Prism chipset is only good for the purposes it was originally manufactured for. That is a simple wireless client and maybe a very basic wireless access point. Use it for anything else and it 'might' work but generally it won't.

But even then it has its issues as I have discovered. When used within a Mikrotik RouterOS system it has issues with connecting to Access Points with WEP enabled. For example I attempted to connect to a Netgear DSL modem/router/AP and it would work fine for about 10min and then just stop responding even tho it is still associated. I managed to overcome this issue by using a seperate Senao Access Point, even then it didn't work 100% as it didn't want to talk to its wireless client neighbours, only the AP and the router behind it.

For now on I will be using CM9's and SR5/9 miniPCI cards, which are all Atheros based.

I wish there were more wireless chipset vendors that catered for this particular market - but I guess we can't have everything and consolidation was bound to occur.