 |
All-in-One
Integrated Wired and Wireless Networking |
The
need to purchase and manage additional network
equipment is eliminated with the elegant
all-in-one design of the WS 2000. Support
for multiple wireless LAN protocols (Wi-Fi®
IEEE 802.11b, 802.11a; 802.11g capable),
as well as an integrated router, gateway
and Power-over-Ethernet (PoE) simplifies
network deployment and management, and reduces
capital expense. Functionality includes
an integrated Stateful Packet Inspection
Firewall, Network Address Translation (NAT),
DHCP server, and WAN connectivity support
for flexible low cost installation.
 |
Second
Generation Wireless LAN: the Power of
Centralized Intelligence |
The
WS 2000 offers the power and cost-efficiencies
of second-generation wireless networking.
Intelligence previously distributed and
duplicated throughout first-generation access
point-based wireless LANs is centralized
and aggregated in the WS 2000 Wireless Switch,
delivering unprecedented power and control—and
reduced deployment and management costs.
Instead of traditional access points, the
WS 2000 works in conjunction with low cost
Access Ports, which are essentially ‘zero
configuration' devices, operational right
out of the box, and can be mounted almost
anywhere—even inside ceiling tiles.

Integrated
Wired-Wireless Networking:WS 2000 in a Retail
Wireless Store
 |
End-to-end
layered security |
WS
2000 supports a comprehensive suite of security
mechanisms—including access-control,
802.1X based authentication, and strong
encryption. In addition, the WS 2000 also
integrates a Stateful Packet Inspection
Firewall for protection against various
types of Denial-of-Service attacks and filtering
network traffic within the Local Area Network
(LAN) and between the LAN and the Wide Area
Network (WAN). The result is a layered security
model that delivers robust end-to-end security.
The WS 2000 supports the best-in-class wireless
security standards of today, and is easily
upgradeable to tomorrow's standards.
 |
Centralized
management |
The
WS 2000 simplifies day-to-day operations
with unified management of hardware, software
configuration, and network policies. Centralized
management also enables the automatic distribution
of configurations to all Access Ports—eliminating
the need and the associated costs to configure
and manage each access point. The WS 2000
also simplifies wireless network deployment
across multiple locations (for example,
multiple retail stores, restaurants or branch
offices), delivering network design consistency
and simplicity, as well as the ability to
centrally manage from a regional Network
Operations Center (NOC) or a data center.
 |
Scaleable
and easy to upgrade |
Adding
capacity and new functionality is easier
and less expensive than an access point-based
wireless LAN. The WS 2000 enables your wireless
network to scale easily as your company
grows. Each WS 2000 supports up to 6 Access
Ports and 3 wireless LANs each with its
own security and network policies. And with
the centralized architecture of the WS 2000,
upgrading to support newer standards, such
as the new 802.11i security standard, is
fast and easy.
 |
Lower
total cost of ownership—outstanding
investment protection |
The
WS 2000 removes the overhead and complexity
of first-generation access point-based wireless
LANs, delivering a wireless network that
is less expensive to implement and manage.
The extensive functionality, expandability,
and centralized management eliminate the
time and management costs associated with
access point-based solutions, providing
a lower total cost of ownership. And the
flexibility to support the standards of
today and tomorrow, as well as the legacy
wireless networks of yesterday, protects
this valuable investment.
|
|
The
WS 2000 offers integrated functionality
including PoE and a CF Card Slot for
additional application support
|
Flexible
mounting options: The WS 2000 can
be mounted on the desk, wall or rack.
The standard 1RU form factor enables
easy mounting in any standard network
rack for co-location with other network
equipment
|
 |
Extensive
WLAN Functionality |
The
comprehensive feature set of the WS 2000
provides full control over wireless LAN
traffic to provide peak performance. Extensive
wireless LAN functionality enables you to
maximize bandwidth and throughput, secure
network traffic, prioritize voice traffic,
conserve power on mobile devices, and provide
dependable connection speeds for users in
challenging wireless environments.
 |
Scalable
Radio Architecture |
Each
WS 2000 supports up to 6 single or dual-band
Access Port radios (802.11b and 802.11a
currently with 802.11g to follow) in the
2.4 as well as 5 GHz frequencies—offering
the broadest radio technology support in
the industry.
 |
Access
Ports: Next-Generation Wireless Access
Devices |
Access
Ports bring a new level of simplicity to
wireless network implementation and management,
as well as an unprecedented upgrade capability.
The innovative design removes duplicate
computing components and management requirements
associated with using access points throughout
a wireless LAN. Access Ports are easily
upgraded with new features and functionality
via the WS 2000, providing excellent investment
protection. A wide range of 802.11a and
802.11b external antenna options enables
the design of coverage patterns for the
most challenging environments.
 |
Voice
Prioritization |
The
WS 2000 provides voice prioritization capabilities
for devices such as VoIP phones, guaranteeing
priority for voice traffic during periods
of network congestion.
 |
Power
Saving for Client Devices |
The
Power Save Protocol (PSP) polling feature
enables devices to maximize battery life
and maintain application performance. The
implementation allows devices to conserve
power between wireless transmissions and
also ensures that packets are stored and
reliably delivered when the device awakens.
 |
Virtual
AP Enables True Virtual Wireless LANS |
Virtual
AP enables the wireless LAN to be segmented
into true multiple broadcast domains—the
wireless equivalent of Ethernet VLANs—providing
the ability to map multiple ESSIDs (Extended
Service Set Identifiers) to multiple BSSIDs
(Basic Service Set Identifiers).
Virtual
AP provides complete control over broadcast
traffic. Control of broadcast traffic, including
network level messages, is extremely important
because of its potential negative effect
on performance. Intelligent control of broadcast
forwarding through proxy ARP and other mechanisms
ensures that broadcast traffic is received
only by the intended recipients. The resulting
reduction in traffic maximizes bandwidth
and network throughput; device battery life
and overall performance are improved with
the elimination of the processing of messages
intended for other recipients; and the possible
compromise in confidentiality and security
of messages is eliminated since broadcast
messages can no longer reach the wrong recipients.
 |
Load
Balancing and Pre-emptive Roaming |
Normal
roaming does not occur until the device
connection has reached a minimum connection
speed of 1 Mbps—normally well beyond
the boundaries of a cell and approximately
halfway through an adjacent cell. Two features,
client load balancing and pre-emptive roaming,
work hand-in-hand to ensure that devices
roam before the connection quality erodes,
providing users with more consistent connection
speeds for smooth application performance.
The WS 2000 provides the information needed
for roaming decisions, ensuring that critical
wireless connections—such as real
time voice and data connections—are
maintained.

Virtual
AP Enables True Virtual LANsAccess Point
VLAN Architecture: Single BSSID
VLAN Performance and Security Issues
In
a typical access point architecture,
VLANs are defined using multiple ESSIDs.
Since access points support only one
BSSID, broadcast traffic intended
only for Faculty and Administration
(ESSID1) will be sent to all VLANs—Students
(ESSID2), Facilities and Security
(ESSID3) and Guests and Visitors (ESSID4).
The resulting processing of unnecessary
messages reduces battery life and
network throughput, and delivery of
messages to unintended recipients
presents security and confidentiality
issues.
|

Access
Port VLAN Architecture: Multiple BSSID
VLAN Improved Performance and Security
Virtual
AP provides support for multiple
BSSIDs, enabling the creation of
true wireless VLANs. Broadcast traffic
is sent only to recipients within
a specific wireless VLAN (ESSID),
improving overall battery life of
client devices and network throughput,
and ensuring security and confidentiality
for broadcast traffic.
|
 |
Automatic
Channel Selection |
The
degradation of RF performance due to environmental
factors is eliminated with Automatic Channel
Select (ACS). ACS optimizes radio channel
planning and installation, scanning and
selecting the best channel for each Access
Port based on noise and signal properties.
 |
Transmit
Power Control |
Transmit
Power Control minimizes radio interference
for sites that require a very dense population
of radios (Access Ports) to support bandwidth
requirements. Configured from within the
WS 2000, this can also be part of a group
policy.
 |
Multicast
Masking |
This
features enables multicast traffic to be
sent to intended clients without any queuing,
providing essential support for push-to-talk
and other multimedia applications.
 |
Proxy
ARP |
Proxy
ARP enables the WS 2000 to respond to ARP
requests on behalf of a mobile client, acting
as the client's agent or Proxy. No longer
burdened with the processing of ARP requests,
the mobile client can temporarily suspend
the WLAN adapter. The result is substantial
savings of battery power on the client device,
while preserving the integrity of the IP
connection.
 |
Storage
of Software Update Packages for Client
Devices |
With
the WS 2000 and AirBEAM Smart, managing
and updating software on Symbol mobile devices
is fast, easy—and automatic. The WS
2000 acts as an FTP server, storing software
updates via a CompactFlash™ card.
AirBEAM® Smart, Symbol's software management
program resident on Symbol mobile devices,
accesses the WS 2000 to automatically download
and install everything from wireless applications
and drivers to operating systems.
The WS 2000 extends the power of Symbol's
award-winning WS 5000 Wireless Switch to
the small and medium enterprise, offering
the first integrated wired and wireless
networking solution, priced and designed
to meet the needs of small to medium enterprises—from
retail stores, warehouses, coffee shops
and restaurants to libraries, small offices
and more.
 |
End-to-End
Layered Security |
There
is no element of networking—wired
or wireless—more important than security.
The WS 2000 offers an integrated firewall
as well as a complete end-to-end layered
security model that supports all of today's
wireless security standards, and is easily
upgradeable to support the standards of
tomorrow. Users can configure security policies
that specify the correct level of control
for users, applications, and devices within
those groups.
Network
Access Control
Access Control Lists (ACLs)
Layer 2 Access Control Lists provide filtering
for advanced network traffic control, enabling
administrators to forward or drop packets
based on protocol type or MAC Addresses.
Authentication
Authentication ensures that only authorized
users and devices can access your network.
The WS 2000 provides a comprehensive set
of authentication mechanisms to support
a variety of security requirements.
Pre-shared
keys
Simple shared authentication through non-wireless
distribution of authentication keys ensures
secure key management.
802.1x/Extensible
Authentication Protocol (EAP)
802.1x and Extensible Authentication Protocol
(EAP) work hand-in-hand, providing the infrastructure
for robust authentication and dynamic key
rotation and distribution. EAP provides
a means for mutual authentication. Authorized
users identify themselves to the wireless
network, and the wireless network identifies
itself to the user—ensuring that unauthorized
users cannot access your network, and authorized
users do not inadvertently join a rogue
network. A wide variety of authentication
types can be used—from user name and
password to voice signatures, public keys,
biometrics, with the ability to upgrade
to support future authentication types.
And dynamic key rotation and distribution
provides a new encryption key per user per
session, greatly increasing the strength
of the chosen encryption algorithm (WEP
or TKIP) used to encode data. The WS 2000
supports a variety of EAP methods, including
TLS, TTLS, PEAP, and SIM.
Kerberos
The industry-standard Kerberos protocol
meets all of the requirements for scalable,
effective security in a mobile environment.
Kerberos features mutual authentication
and end-to-end encryption. All traffic is
encrypted and security keys are generated
on a per-client basis, keys are never shared
or reused, and are automatically distributed
in a secure manner. WS 2000 requires an
external Key Distribution Center (KDC),
such as a Windows® 2000 server.
Encryption
Encryption
ensures that data privacy is maintained
while in transmission. As a rule of thumb,
the stronger the encryption, the more complex
and expensive it is to implement and manage.
The WS 2000 supports a range of encryption
options that provide basic to strong encryption
techniques, providing the flexibility to
select the right level for your data.
Wired
Equivalent Privacy (WEP)
The
802.11 Wired Equivalent Privacy (WEP) provides
static key encryption—a single key
is distributed to all users for encryption
and decryption of data. WEP generates either
a 40- or 128-bit key using the widely used
RC-4 encryption algorithm. WEP allows full
interoperability with legacy clients and
provides basic over-the-air security in
less-critical environments, such as an open
public-access application.
WPA—Temporal
Key Integrity Protocol (TKIP)
WPA-TKIP
addresses well-known vulnerabilities in
WEP encryption. TKIP provides key rotation
on a per-packet basis along with Michael
message integrity check (MIC), which determines
if data has been tampered or corrupted while
in transit. This robust method of encryption
provides a higher level of protection for
your data and protects your network from
a variety of types of attacks. Released
by the WECA industry consortium, WPA is
an early version of the forthcoming IEEE
802.11i security standard.
KeyGuard™—MCM
This
implementation of TKIP is based on the IEEE
802.11i draft security standard. Like WECA's
version of TKIP, KeyGuard provides a different
key for every packet of data, but uses a
different version of message integrity check
(MIC) to determine if data has been tampered
or corrupted during transmission. |